AI Compliance

GDPR Compliant AI Tools in 2026: A Checklist for Chatbots, Agents and Providers

No AI tool is GDPR compliant on its own. This guide gives a checklist tied to the articles of the GDPR, explains where the EU-US Data Privacy Framework stands, and compares four kinds of AI tools on facts their vendors publish.

GDPR compliant AI tools are AI chatbots, agents and model services that an organisation can use lawfully because the processing behind them is documented, contracted and controlled. No tool is compliant on its own. Compliance depends on your purpose and lawful basis, the processor terms you sign, where prompts are processed, which sub-processors are involved, how long data is kept, and whether you carried out a DPIA.

Why no AI tool is GDPR compliant on its own

The GDPR places its duties on organisations, not on software. Under Article 4(7), the controller is whoever decides the purposes and means of processing; under Article 4(8), a processor handles personal data on the controller’s behalf. When an employee pastes a customer complaint into an assistant, your organisation is normally the controller, and the vendor behind the assistant is a processor you answer for.

So when a vendor page says “GDPR compliant”, read it as a narrower promise: the vendor offers terms and controls that make lawful use possible. The rest sits on your side of the contract:

  • A lawful basis for each purpose under Article 6, plus an Article 9 condition whenever prompts carry health, biometric, genetic or other special-category data.
  • The Article 5 principles. Transparency, purpose limitation, minimisation and storage limitation apply to prompts, files and outputs as much as to any database.
  • Security appropriate to the risk under Article 32, from encryption to who can read conversation history.

Breaching the principles or the lawful-basis rules can cost up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher, under Article 83(5).

One AI-specific point is easy to miss. In Opinion 28/2024 the European Data Protection Board said that a model developed with unlawfully processed personal data could make its later deployment unlawful too, unless the model has been duly anonymised. Ask vendors how their models were trained, not only what happens to your prompts.

A GDPR checklist for AI tools

Send these thirteen questions to every vendor on the shortlist and keep the written answers with your DPIA. Each row cites the GDPR provision the answer supports, checked against the regulation text on EUR-Lex in October 2026.

#CheckWhat to ask the vendorGDPR anchor
1Processor termsDoes a data processing agreement with the Article 28 terms cover the AI features themselves?Art. 28(3)
2Processing locationWhere does inference run, and where are prompts, outputs and logs stored?Art. 44
3Sub-processorsWho are all the sub-processors, including model providers and hosting? How are changes notified, and can you object?Art. 28(2) and 28(4)
4Training useAre prompts, files or outputs used to train or improve any model? What is the default, and who can change it?Art. 5(1)(b), 28(3)(a)
5RetentionHow long are prompts, outputs, abuse-monitoring copies and logs kept, and can an admin shorten that?Art. 5(1)(e)
6DeletionCan you delete conversations, user histories and all data at contract end, including copies?Art. 17, 28(3)(g)
7Transfer mechanismFor processing or support access outside the EEA, which Chapter V tool applies: adequacy, the Data Privacy Framework or standard contractual clauses?Art. 44 to 46
8SecurityEncryption at rest and in transit, admin access controls and integration with your identity providerArt. 32
9Logging and auditCan you see who used the tool and with which data, and can you audit the vendor?Art. 28(3)(h), 30
10Data subject rightsCan you find, export or erase one person’s data across prompts, files and outputs?Chapter III, Art. 28(3)(e)
11Automated decisionsWill outputs feed decisions with legal or similarly significant effects on a person?Art. 22
12DPIA supportWill the vendor supply the architecture, data flows and sub-processor details your assessment needs?Art. 35, 28(3)(f)
13Self-hosting optionCan the model run in your own environment when the data is too sensitive to leave it?Art. 25

Two patterns cause most surprises:

  • Feature-level exceptions. A data processing agreement can cover the core assistant but not an add-on. Microsoft’s documentation, for example, states that its data protection addendum and the EU Data Boundary do not apply to the web search queries Copilot sends to Bing, for which Microsoft acts as a controller. Check web search, plug-ins, connectors and optional third-party models one by one.
  • The sub-processor chain. In Opinion 22/2024 the EDPB concluded that controllers should have the identity of all processors and sub-processors readily available at all times, whatever the risk, and that the final decision to engage a sub-processor stays with the controller. For AI tools, the model provider is usually the sub-processor that matters most.

Where the EU-US Data Privacy Framework stands

Many AI vendors are US companies or run on US hyperscalers, so Chapter V matters. Article 44 requires every transfer outside the EU, onward transfers included, to meet its conditions. The status as of October 2026:

  • The adequacy decision. The Commission adopted the EU-US Data Privacy Framework decision, Implementing Decision (EU) 2023/1795, on 10 July 2023. Personal data can flow under it to US companies that participate in the framework.
  • The first court test. On 3 September 2025 the General Court dismissed Philippe Latombe’s action for annulment in Case T-553/23, confirming that the United States ensured an adequate level of protection when the decision was adopted. The Court added that the Commission must monitor the US framework continuously and can suspend, amend or repeal the decision if it changes.
  • The appeal. Mr Latombe appealed on 31 October 2025. Case C-703/25 P was listed as pending at the Court of Justice when we checked in October 2026.

In practice, confirm whether the vendor and each US sub-processor participate in the framework, keep the Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) available as a fallback, and record which mechanism covers which flow. The Court of Justice struck down the two earlier US frameworks in Schrems I and Schrems II, so a contingency plan is ordinary prudence.

EU hosting narrows the transfer question without closing it. The EDPB’s processor opinion observes that a processor handling data inside the EEA may still face third-country law in some circumstances, which is the practical gap between residency and sovereignty.

Four kinds of AI tools, compared

The vendor facts below come from each vendor’s own documentation, verified October 2026. Being listed is not a recommendation, and none of these products is “GDPR compliant” by itself: each gives a controller a different set of levers.

CategoryExamples checkedWhere inference runsUse of your data for trainingThe main GDPR question
EU-hosted SaaS assistantsMistral Vibe (formerly Le Chat), LangdockIn the EU by defaultOff by default on enterprise plans; check lower plansWhich features or sub-processors move data outside the EU?
US SaaS with EU residency optionsChatGPT Enterprise and Edu, Microsoft Copilot, Gemini in Google WorkspaceEU options exist, depending on plan, setting and featureNot used by default on business plansDo the EU options cover processing, or only storage at rest?
Cloud model APIs with EU regionsMicrosoft Foundry, Amazon Bedrock, OpenAI API, Mistral APIThe region or data zone you deploy inNot used for training by default at Microsoft, AWS and OpenAI; Mistral uses an opt-out toggleDid you choose an EU-bound deployment type, and what is retained?
Self-hosted open-weight modelsModels you run on your own servers or private cloudYour infrastructureNo vendor receives the promptsAre your own retention, security and access controls good enough?

EU-hosted SaaS assistants

Mistral Vibe. Mistral’s assistant, previously called Le Chat, now runs under the Vibe name. Its help centre says data is hosted in the EU by default unless you explicitly use the US API endpoint, and that some features can temporarily transfer data to sub-processors outside the EU under Article 46 safeguards; Enterprise customers can switch some of those features off organisation-wide. Vibe Enterprise is opted out of model training by default, while Free, Pro and Team rely on a privacy toggle. Mistral publishes its data processing addendum on its legal site.

Langdock. The Berlin-based company says its multi-tenant service runs on Microsoft Azure servers inside the EU, that customer data is never used to train or improve AI models, and that a data processing addendum is available. It also offers single-tenant, customer-cloud and on-premises deployment. With an EU vendor on a US hyperscaler, confirm how the hyperscaler’s transfers are covered.

US SaaS with EU residency options

ChatGPT Enterprise and Edu. OpenAI says it does not train on business data by default, signs a data processing addendum for ChatGPT Business, Enterprise and the API, and lets Enterprise and Edu admins set retention. New Enterprise and Edu workspaces can keep customer content at rest in Europe, and since January 2026 eligible Enterprise, Edu and Healthcare customers can choose in-region GPU inference in Europe. Personal ChatGPT accounts are another matter, as our ChatGPT confidentiality guide explains plan by plan.

Microsoft Copilot. Microsoft states that Copilot, formerly Microsoft 365 Copilot, is covered by its GDPR and EU Data Boundary commitments, and that prompts, responses and Graph data are not used to train foundation models. Three settings decide how far that holds for an EU tenant: flex routing, which can move inferencing to the United States, Canada or Australia at peak load; Anthropic models, which Microsoft excludes from the EU Data Boundary and keeps off by default in the EU, EFTA and UK; and web search, whose Bing queries sit outside the addendum. Our explainer on Copilot flex routing walks through each one.

Gemini in Google Workspace. Google’s Workspace privacy hub says customer data, prompts included, is not used to train models without the customer’s permission, and treats it as customer data under the Cloud Data Processing Addendum. Data regions can keep Gemini processing in the EU: for Gemini in the Workspace apps since June 2025, on Enterprise Plus and the Assured Controls add-ons, and for the Gemini app since June 2026, on Enterprise Plus, Education Plus and Standard, and Frontline Plus.

Cloud model APIs with EU regions

APIs suit teams that build their own assistant or agent, and the deployment type is the main residency lever.

  • Microsoft Foundry. Standard deployments process prompts within the geography you choose. A DataZone deployment created in an EU member state may process data in any EU member state, while Global deployments can process anywhere the model runs. Prompts are not used to train foundation models without permission, but abuse monitoring can store them for review in your resource’s geography unless you are approved for modified abuse monitoring.
  • Amazon Bedrock. Geographic cross-Region inference profiles, such as the EU profile, keep processing inside that geography; global profiles do not. Model providers have no access to prompts or completions, and the retention settings include a zero-retention mode. Any retained data is stored in the Region that processed the request.
  • OpenAI API. Projects created with European data residency are handled in-region with zero data retention. The option applies only to new projects.
  • Mistral API. Hosted in the EU by default. Its training opt-out is an “Anonymous improvement data” toggle, separate from the Vibe setting, so set both.

Self-hosted open-weight models

Running an open-weight model on your own servers or in your own private cloud takes the model vendor out of the processing chain. There is no processor for inference, no international transfer and no vendor training setting to police. Your own duties remain, from a lawful basis and retention rules for prompts and logs to access control, security, erasure requests and a check of the model licence. This is the role of private AI deployment: the most sensitive data classes stay on infrastructure you control, while less sensitive work can use other categories.

How the EU AI Act adds to the GDPR

The GDPR governs the personal data; the AI Act regulates the AI system around it. Two of its duties already reach ordinary workplace assistants:

  • AI literacy, Article 4. In application since 2 February 2025. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, reworded it: providers and deployers must take measures to support the AI literacy of their staff, without having to guarantee any particular level. The Commission’s Q&A adds that no certificate is required and that organisations can keep an internal record of training.
  • Transparency, Article 50. Since 2 August 2026, people must be told when they interact with an AI system unless it is obvious, and deployers must disclose deepfakes and AI-generated text published on matters of public interest. Generative systems placed on the market before that date have until 2 December 2026 for the marking duty in Article 50(2). Our guide to Article 50 disclosure has the detail.
  • Bias testing with special-category data. The Omnibus inserted Article 4a, which permits special categories of personal data to be processed for bias detection and correction only where strictly necessary, with safeguards such as pseudonymisation and deletion once the bias is corrected.

High-risk obligations follow on 2 December 2027 for Annex III uses and 2 August 2028 for AI in Annex I products. Article 99(4) of the AI Act allows fines of up to EUR 15 million or 3% of worldwide annual turnover for breaches of Article 50, separately from any GDPR fine.

A procurement sequence that holds up in an audit

  1. Map the use case. Record the purpose, the people affected and the data categories, flagging special-category or client-confidential material.
  2. Set the lawful basis and the boundary. Choose the Article 6 basis, and decide which data classes may leave your infrastructure at all.
  3. Shortlist by category. Match each data class to a category in the table above; the most sensitive class sets the floor.
  4. Send the checklist. Ask all thirteen questions in writing and file the answers.
  5. Run the DPIA before go-live. Article 35 requires one before processing likely to result in a high risk, naming new technologies as a factor. A combined DPIA and FRIA avoids writing the same analysis twice.
  6. Configure, then record. Turn off optional training, set retention, choose the EU deployment type, decide on web search and third-party models, and log each setting in your Article 30 record of processing.
  7. Train and disclose. Give staff role-specific guidance under Article 4, and add AI disclosures wherever Article 50 applies.
  8. Re-check defaults at every sub-processor notice and at least once a year, because vendors change both.

How VDF AI fits

VDF AI deploys on-premises, in your private cloud or VPC, or air-gapped. In those deployments, inference, embeddings, private retrieval, logs and orchestration run in the environment you control, and production use requires no third-party model API sub-processor. If you decide to connect an external model, that provider is one you choose and govern under your own policy.

On the evidence side of the checklist, it offers a region-pinned data plane with customer-controlled storage, configurable retention and deletion for indexes, logs and source connectors, and audit records of every prompt, tool call, retrieval and response, streamed to your SIEM. The model router enforces model policy by domain, sensitivity and residency requirement. Role-based access control is included on every plan, and on-premises deployments sign users in natively with Microsoft Entra ID. The VDF AI Trust Center sets out the sub-processor position and the compliance mapping in full.

Your obligations as controller stay with you. What changes is how many parties and places your AI processing involves.

Sources

Frequently asked questions

What makes an AI chatbot GDPR compliant?

The organisation running it does, by meeting its duties as controller. That means a lawful basis for each purpose, a processor agreement with the vendor that contains the Article 28 terms, a clear answer on where prompts are processed and how any transfer outside the EEA is covered, retention limits, a way to handle erasure and other data subject requests, and a DPIA where the risk is high. Since August 2026 the EU AI Act also requires that people are told they are dealing with an AI system unless that is obvious.

Is Microsoft Copilot GDPR compliant?

Microsoft states that Copilot is covered by its existing GDPR and EU Data Boundary commitments and that prompts, responses and Microsoft Graph data are not used to train foundation models. Whether your tenant holds up depends on three settings. Flex routing can process EU prompts in the United States, Canada or Australia at peak load unless an admin turns it off, Anthropic models are excluded from the EU Data Boundary, and web search queries sent to Bing fall outside Microsoft's data protection addendum. Check all three and record the decisions.

Do we need a DPIA before using an AI tool?

Often, yes. Article 35 of the GDPR requires a data protection impact assessment before any processing that is likely to result in a high risk to people, and it names new technologies as a factor. It is mandatory for large-scale processing of special categories of data and for systematic evaluation that leads to decisions with significant effects. An assistant used on customer, patient, employee or client files usually meets that bar. Run it before go-live and update it when the vendor changes sub-processors, regions or defaults.

Can EU companies still use US AI providers after the Data Privacy Framework ruling?

Yes. The EU-US Data Privacy Framework adequacy decision of July 2023 still allows transfers to US companies that participate in it. The General Court upheld it in September 2025, and the appeal to the Court of Justice was still pending in October 2026. Check that the provider and its US sub-processors are certified, keep standard contractual clauses available as a fallback, and document which mechanism covers each data flow. Two earlier frameworks were struck down, so plan for change rather than assume permanence.

Does an EU-hosted AI provider remove GDPR transfer risk?

It reduces it but does not remove it. EU hosting means prompts and files are stored and usually processed inside the EU, so the main Chapter V question falls away for that processing. You still need to read the sub-processor list, because model providers, hyperscalers and support teams can sit outside the EU, and some features may move data out temporarily. The EDPB also notes that a processor handling data inside the EEA can still be exposed to third-country law in some circumstances.

Is a self-hosted LLM automatically GDPR compliant?

No, but it removes the hardest questions. When an open-weight model runs on your own servers, no model vendor processes the prompts, so there is no processor agreement, international transfer or vendor training setting to manage for inference. You remain the controller and still need a lawful basis, access controls, security, retention rules for prompts and logs, and a way to answer erasure requests. Check the model licence too, and ask how the model was trained, since the EDPB links unlawfully processed training data to deployment risk.

Filed under
GDPRAI compliancedata sovereigntyAI procurementEU AI Actprivate AI
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading