EU data residency for AI tools: what GDPR actually requires.
Every AI vendor's pricing page now claims to be "EU-hosted." Most of them are not, in the way procurement teams assume the phrase means. This post is a plain reading of the relevant GDPR articles for procurement teams evaluating AI tools, with the four questions to ask a vendor that separate honest claims from marketing.
I am the CTO of Attera, so the writing here has a point of view. Where the rules apply equally to us and to competitors I say so directly. Where they reveal something about a competitor's posture I say that too.
01The three articles that actually matter
GDPR is long. For procurement teams reviewing an AI vendor, three articles do most of the work:
- Article 28. Processor obligations and the requirement for a written Data Processing Agreement between controller and processor.
- Article 44. The general prohibition on transferring personal data outside the European Economic Area, unless a specific legal mechanism authorises it.
- Article 46. The specific legal mechanisms that permit transfer outside the EEA: adequacy decisions, Standard Contractual Clauses, Binding Corporate Rules.
Articles 5, 6, 25, 30, and 32 are also relevant for lawful basis, data-protection-by-design, records-of-processing, and security of processing. They are not the place where "EU-hosted" claims get tested. The 28-44-46 trio is.
02What "EU-hosted" should actually mean
The phrase as it appears on a typical AI vendor's pricing page can mean any of:
| Claim | What it might mean | What it does not necessarily mean |
|---|---|---|
| "EU-hosted" | The customer-facing application servers are in an EU AWS, Azure, or GCP region. | Customer data never leaves the EU. (See sub-processor section.) |
| "EU data residency" | Data is stored at rest on EU infrastructure. | Data is processed only on EU infrastructure. AI inference, in particular, often happens outside the EU. |
| "EU-only processing" | Both storage and processing happen on EU infrastructure. | Sub-processors are EU entities. AWS Frankfurt is still operated by a US company subject to the CLOUD Act. |
| "EU sovereign" | Infrastructure is operated by an EU legal entity, not just located in the EU. | The hardware is sourced from EU manufacturers. (No one credibly claims this.) |
The gap that matters is between "stored in the EU" and "processed in the EU." For an AI tool, the second one is the harder claim. A vendor can run their application servers in Frankfurt, store user data in an EU-region S3 bucket, and still send every inference request to an OpenAI endpoint in the United States. The S3 bucket is technically EU-hosted. The data path is not.
03Article 28: the DPA test
Article 28 requires a written Data Processing Agreement between the controller (the customer) and each processor (the vendor). The DPA must set out, at minimum:
- Subject matter and duration of processing.
- Nature and purpose of processing.
- Type of personal data and categories of data subject.
- Obligations and rights of the controller.
- The processor's obligations including: only processing on documented instructions, confidentiality, security of processing, sub-processor management, assistance with data subject requests, breach notification, deletion or return on termination, and demonstrable compliance.
The procurement test
Ask the vendor for their DPA before you sign anything. Read it. If they ask you to fill out a request form, take that as a signal: a DPA you cannot read without engaging sales is a DPA you should be reading before you engage sales. Attera's full DPA is at attera.io/dpa with no NDA or gate. Most reputable vendors do the same. The ones that do not are a soft no.
04Articles 44-46: the transfer test
Article 44 prohibits transferring personal data to a "third country" outside the EEA unless the transfer satisfies one of the mechanisms in Articles 45 to 49. The most common mechanisms are:
- Article 45 adequacy decision. The European Commission has formally found that the third country provides adequate protection. The currently in-force adequacy decisions cover the UK, Switzerland, Japan, South Korea, and, since 2023, the US (under the EU-US Data Privacy Framework, replacing Privacy Shield which the CJEU struck down in Schrems II).
- Article 46 Standard Contractual Clauses (SCCs). A set of European Commission-approved contract terms imported into the controller-processor contract. The 2021 SCCs are the current text. SCCs alone are not sufficient post-Schrems II; a Transfer Impact Assessment (TIA) is also required to evaluate whether the destination country's surveillance regime undermines the protections SCCs are meant to provide.
- Article 46 Binding Corporate Rules (BCRs). For intra-group transfers within a multinational. Approved by a lead supervisory authority. Used by large vendors with consolidated global processing.
The procurement test
Ask the vendor: (1) is any personal data transferred outside the EEA, and if so, to which third country, and (2) which legal mechanism authorises the transfer? An honest vendor will give you a one-paragraph answer. A defensive vendor will route you to their security page. A misleading vendor will say "EU-hosted, full stop" and you will not learn until the DPA review that their LLM inference goes to the US under SCCs.
The CLOUD Act wrinkle. The US CLOUD Act of 2018 gives US law enforcement authority to compel US-headquartered cloud providers to produce data, including data stored on EU servers. This applies to AWS, Microsoft Azure, Google Cloud, and any US provider's EU region. The EU-US Data Privacy Framework provides a legal route for transfer but does not eliminate the underlying CLOUD Act exposure. Some regulated industries treat this as material risk.
05The sub-processor question
The single most useful question to ask an AI vendor is: "Show me your full sub-processor list, and for each one, tell me whether customer data flows through it on the document path."
A typical AI vendor's sub-processor list looks like this:
- AWS or Azure or GCP: hosting and storage
- OpenAI or Anthropic or Google: LLM inference (this is the one that matters)
- PostHog, Mixpanel, or Amplitude: product analytics
- Sentry or Datadog: error monitoring
- SendGrid or Mailgun: transactional email
- Stripe: billing
- Intercom or HubSpot: customer support
Of these, the LLM inference provider is the one that sees the content of customer documents. The others see metadata (filenames, user IDs, error messages). For an AI tool processing financial or sustainability documents, the LLM provider is the sub-processor that determines whether the "EU-hosted" claim holds for content.
What Attera's sub-processor list looks like
One entry. Tailscale, for private network coordination between the machines we operate in Belgium. Customer data does not transit Tailscale's servers; the service handles key exchange and NAT traversal only. There is no LLM inference sub-processor because we run the inference ourselves on a workstation in Leuven. The model file is on disk; we can show you on a video call.
This is unusual. Most AI vendors cannot say it. We are not saying competitors are doing anything wrong by using OpenAI or Anthropic; the EU-US Data Privacy Framework legally authorises the transfer under SCCs. We are saying that for procurement teams whose risk tolerance does not include US-headquartered LLM providers, the choice of vendor narrows considerably.
06The four questions
If you are evaluating an AI tool and want to test the EU-hosted claim quickly, four questions get you most of the way there.
- "Where is customer data stored at rest, and in which legal entity's infrastructure?" Look for a specific data centre region named, and an entity name (AWS Frankfurt under AWS Europe; OVH France under OVH Cloud; etc.). Vague answers are a signal.
- "Where does AI inference happen?" The most common honest answer is "OpenAI in the US, transferred under SCCs and the EU-US Data Privacy Framework." A vendor that runs inference on EU infrastructure will say so plainly.
- "What is your full sub-processor list, and which sub-processors see document content?" The list should be public. The document-path sub-processor should be one or two entities. If it is six, ask why.
- "Can I read your DPA without an NDA?" The answer should be yes. If it is no, you have an honesty signal.
07Where "EU-hosted" is meaningful, and where it is marketing
"EU-hosted" is meaningful when the vendor can tell you the specific physical location of the inference machine, name the operator of that machine, and demonstrate that no third country touches the document path. It is marketing when the vendor's pricing page says "EU-hosted" but their sub-processor list reveals US-headquartered LLM and analytics providers handling customer content.
This does not mean US-headquartered vendors are categorically uncompliant. It means the "EU-hosted" claim, used loosely, does not carry the weight that a DPO or procurement team often thinks it does. A careful read of the sub-processor list is the difference.
If you'd like a 20-minute call to walk through these four questions against the vendors on your shortlist, book a slot. We'll do it without trying to sell you anything. Zeff and Charles join. We do this for free because it improves the quality of conversations we have with the vendors that survive your shortlist, including us.
08Further reading
- GDPR consolidated text (EUR-Lex).
- 2021 Standard Contractual Clauses.
- EU-US Data Privacy Framework.
- EDPB Recommendations 01/2020 on supplementary measures (Transfer Impact Assessment).
- The full Attera DPA and security page.
This post is not legal advice. For specific procurement decisions consult your DPO or qualified external counsel.