GDPR compliant AI tools are AI chatbots, agents and model services that an organisation can use lawfully because the processing behind them is documented, contracted and controlled. No tool is compliant on its own. Compliance depends on your purpose and lawful basis, the processor terms you sign, where prompts are processed, which sub-processors are involved, how long data is kept, and whether you carried out a DPIA.
Why no AI tool is GDPR compliant on its own
The GDPR places its duties on organisations, not on software. Under Article 4(7), the controller is whoever decides the purposes and means of processing; under Article 4(8), a processor handles personal data on the controller’s behalf. When an employee pastes a customer complaint into an assistant, your organisation is normally the controller, and the vendor behind the assistant is a processor you answer for.
So when a vendor page says “GDPR compliant”, read it as a narrower promise: the vendor offers terms and controls that make lawful use possible. The rest sits on your side of the contract:
- A lawful basis for each purpose under Article 6, plus an Article 9 condition whenever prompts carry health, biometric, genetic or other special-category data.
- The Article 5 principles. Transparency, purpose limitation, minimisation and storage limitation apply to prompts, files and outputs as much as to any database.
- Security appropriate to the risk under Article 32, from encryption to who can read conversation history.
Breaching the principles or the lawful-basis rules can cost up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher, under Article 83(5).
One AI-specific point is easy to miss. In Opinion 28/2024 the European Data Protection Board said that a model developed with unlawfully processed personal data could make its later deployment unlawful too, unless the model has been duly anonymised. Ask vendors how their models were trained, not only what happens to your prompts.
A GDPR checklist for AI tools
Send these thirteen questions to every vendor on the shortlist and keep the written answers with your DPIA. Each row cites the GDPR provision the answer supports, checked against the regulation text on EUR-Lex in October 2026.
| # | Check | What to ask the vendor | GDPR anchor |
|---|---|---|---|
| 1 | Processor terms | Does a data processing agreement with the Article 28 terms cover the AI features themselves? | Art. 28(3) |
| 2 | Processing location | Where does inference run, and where are prompts, outputs and logs stored? | Art. 44 |
| 3 | Sub-processors | Who are all the sub-processors, including model providers and hosting? How are changes notified, and can you object? | Art. 28(2) and 28(4) |
| 4 | Training use | Are prompts, files or outputs used to train or improve any model? What is the default, and who can change it? | Art. 5(1)(b), 28(3)(a) |
| 5 | Retention | How long are prompts, outputs, abuse-monitoring copies and logs kept, and can an admin shorten that? | Art. 5(1)(e) |
| 6 | Deletion | Can you delete conversations, user histories and all data at contract end, including copies? | Art. 17, 28(3)(g) |
| 7 | Transfer mechanism | For processing or support access outside the EEA, which Chapter V tool applies: adequacy, the Data Privacy Framework or standard contractual clauses? | Art. 44 to 46 |
| 8 | Security | Encryption at rest and in transit, admin access controls and integration with your identity provider | Art. 32 |
| 9 | Logging and audit | Can you see who used the tool and with which data, and can you audit the vendor? | Art. 28(3)(h), 30 |
| 10 | Data subject rights | Can you find, export or erase one person’s data across prompts, files and outputs? | Chapter III, Art. 28(3)(e) |
| 11 | Automated decisions | Will outputs feed decisions with legal or similarly significant effects on a person? | Art. 22 |
| 12 | DPIA support | Will the vendor supply the architecture, data flows and sub-processor details your assessment needs? | Art. 35, 28(3)(f) |
| 13 | Self-hosting option | Can the model run in your own environment when the data is too sensitive to leave it? | Art. 25 |
Two patterns cause most surprises:
- Feature-level exceptions. A data processing agreement can cover the core assistant but not an add-on. Microsoft’s documentation, for example, states that its data protection addendum and the EU Data Boundary do not apply to the web search queries Copilot sends to Bing, for which Microsoft acts as a controller. Check web search, plug-ins, connectors and optional third-party models one by one.
- The sub-processor chain. In Opinion 22/2024 the EDPB concluded that controllers should have the identity of all processors and sub-processors readily available at all times, whatever the risk, and that the final decision to engage a sub-processor stays with the controller. For AI tools, the model provider is usually the sub-processor that matters most.
Where the EU-US Data Privacy Framework stands
Many AI vendors are US companies or run on US hyperscalers, so Chapter V matters. Article 44 requires every transfer outside the EU, onward transfers included, to meet its conditions. The status as of October 2026:
- The adequacy decision. The Commission adopted the EU-US Data Privacy Framework decision, Implementing Decision (EU) 2023/1795, on 10 July 2023. Personal data can flow under it to US companies that participate in the framework.
- The first court test. On 3 September 2025 the General Court dismissed Philippe Latombe’s action for annulment in Case T-553/23, confirming that the United States ensured an adequate level of protection when the decision was adopted. The Court added that the Commission must monitor the US framework continuously and can suspend, amend or repeal the decision if it changes.
- The appeal. Mr Latombe appealed on 31 October 2025. Case C-703/25 P was listed as pending at the Court of Justice when we checked in October 2026.
In practice, confirm whether the vendor and each US sub-processor participate in the framework, keep the Commission’s standard contractual clauses (Implementing Decision (EU) 2021/914) available as a fallback, and record which mechanism covers which flow. The Court of Justice struck down the two earlier US frameworks in Schrems I and Schrems II, so a contingency plan is ordinary prudence.
EU hosting narrows the transfer question without closing it. The EDPB’s processor opinion observes that a processor handling data inside the EEA may still face third-country law in some circumstances, which is the practical gap between residency and sovereignty.
Four kinds of AI tools, compared
The vendor facts below come from each vendor’s own documentation, verified October 2026. Being listed is not a recommendation, and none of these products is “GDPR compliant” by itself: each gives a controller a different set of levers.
| Category | Examples checked | Where inference runs | Use of your data for training | The main GDPR question |
|---|---|---|---|---|
| EU-hosted SaaS assistants | Mistral Vibe (formerly Le Chat), Langdock | In the EU by default | Off by default on enterprise plans; check lower plans | Which features or sub-processors move data outside the EU? |
| US SaaS with EU residency options | ChatGPT Enterprise and Edu, Microsoft Copilot, Gemini in Google Workspace | EU options exist, depending on plan, setting and feature | Not used by default on business plans | Do the EU options cover processing, or only storage at rest? |
| Cloud model APIs with EU regions | Microsoft Foundry, Amazon Bedrock, OpenAI API, Mistral API | The region or data zone you deploy in | Not used for training by default at Microsoft, AWS and OpenAI; Mistral uses an opt-out toggle | Did you choose an EU-bound deployment type, and what is retained? |
| Self-hosted open-weight models | Models you run on your own servers or private cloud | Your infrastructure | No vendor receives the prompts | Are your own retention, security and access controls good enough? |
EU-hosted SaaS assistants
Mistral Vibe. Mistral’s assistant, previously called Le Chat, now runs under the Vibe name. Its help centre says data is hosted in the EU by default unless you explicitly use the US API endpoint, and that some features can temporarily transfer data to sub-processors outside the EU under Article 46 safeguards; Enterprise customers can switch some of those features off organisation-wide. Vibe Enterprise is opted out of model training by default, while Free, Pro and Team rely on a privacy toggle. Mistral publishes its data processing addendum on its legal site.
Langdock. The Berlin-based company says its multi-tenant service runs on Microsoft Azure servers inside the EU, that customer data is never used to train or improve AI models, and that a data processing addendum is available. It also offers single-tenant, customer-cloud and on-premises deployment. With an EU vendor on a US hyperscaler, confirm how the hyperscaler’s transfers are covered.
US SaaS with EU residency options
ChatGPT Enterprise and Edu. OpenAI says it does not train on business data by default, signs a data processing addendum for ChatGPT Business, Enterprise and the API, and lets Enterprise and Edu admins set retention. New Enterprise and Edu workspaces can keep customer content at rest in Europe, and since January 2026 eligible Enterprise, Edu and Healthcare customers can choose in-region GPU inference in Europe. Personal ChatGPT accounts are another matter, as our ChatGPT confidentiality guide explains plan by plan.
Microsoft Copilot. Microsoft states that Copilot, formerly Microsoft 365 Copilot, is covered by its GDPR and EU Data Boundary commitments, and that prompts, responses and Graph data are not used to train foundation models. Three settings decide how far that holds for an EU tenant: flex routing, which can move inferencing to the United States, Canada or Australia at peak load; Anthropic models, which Microsoft excludes from the EU Data Boundary and keeps off by default in the EU, EFTA and UK; and web search, whose Bing queries sit outside the addendum. Our explainer on Copilot flex routing walks through each one.
Gemini in Google Workspace. Google’s Workspace privacy hub says customer data, prompts included, is not used to train models without the customer’s permission, and treats it as customer data under the Cloud Data Processing Addendum. Data regions can keep Gemini processing in the EU: for Gemini in the Workspace apps since June 2025, on Enterprise Plus and the Assured Controls add-ons, and for the Gemini app since June 2026, on Enterprise Plus, Education Plus and Standard, and Frontline Plus.
Cloud model APIs with EU regions
APIs suit teams that build their own assistant or agent, and the deployment type is the main residency lever.
- Microsoft Foundry. Standard deployments process prompts within the geography you choose. A DataZone deployment created in an EU member state may process data in any EU member state, while Global deployments can process anywhere the model runs. Prompts are not used to train foundation models without permission, but abuse monitoring can store them for review in your resource’s geography unless you are approved for modified abuse monitoring.
- Amazon Bedrock. Geographic cross-Region inference profiles, such as the EU profile, keep processing inside that geography; global profiles do not. Model providers have no access to prompts or completions, and the retention settings include a zero-retention mode. Any retained data is stored in the Region that processed the request.
- OpenAI API. Projects created with European data residency are handled in-region with zero data retention. The option applies only to new projects.
- Mistral API. Hosted in the EU by default. Its training opt-out is an “Anonymous improvement data” toggle, separate from the Vibe setting, so set both.
Self-hosted open-weight models
Running an open-weight model on your own servers or in your own private cloud takes the model vendor out of the processing chain. There is no processor for inference, no international transfer and no vendor training setting to police. Your own duties remain, from a lawful basis and retention rules for prompts and logs to access control, security, erasure requests and a check of the model licence. This is the role of private AI deployment: the most sensitive data classes stay on infrastructure you control, while less sensitive work can use other categories.
How the EU AI Act adds to the GDPR
The GDPR governs the personal data; the AI Act regulates the AI system around it. Two of its duties already reach ordinary workplace assistants:
- AI literacy, Article 4. In application since 2 February 2025. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, reworded it: providers and deployers must take measures to support the AI literacy of their staff, without having to guarantee any particular level. The Commission’s Q&A adds that no certificate is required and that organisations can keep an internal record of training.
- Transparency, Article 50. Since 2 August 2026, people must be told when they interact with an AI system unless it is obvious, and deployers must disclose deepfakes and AI-generated text published on matters of public interest. Generative systems placed on the market before that date have until 2 December 2026 for the marking duty in Article 50(2). Our guide to Article 50 disclosure has the detail.
- Bias testing with special-category data. The Omnibus inserted Article 4a, which permits special categories of personal data to be processed for bias detection and correction only where strictly necessary, with safeguards such as pseudonymisation and deletion once the bias is corrected.
High-risk obligations follow on 2 December 2027 for Annex III uses and 2 August 2028 for AI in Annex I products. Article 99(4) of the AI Act allows fines of up to EUR 15 million or 3% of worldwide annual turnover for breaches of Article 50, separately from any GDPR fine.
A procurement sequence that holds up in an audit
- Map the use case. Record the purpose, the people affected and the data categories, flagging special-category or client-confidential material.
- Set the lawful basis and the boundary. Choose the Article 6 basis, and decide which data classes may leave your infrastructure at all.
- Shortlist by category. Match each data class to a category in the table above; the most sensitive class sets the floor.
- Send the checklist. Ask all thirteen questions in writing and file the answers.
- Run the DPIA before go-live. Article 35 requires one before processing likely to result in a high risk, naming new technologies as a factor. A combined DPIA and FRIA avoids writing the same analysis twice.
- Configure, then record. Turn off optional training, set retention, choose the EU deployment type, decide on web search and third-party models, and log each setting in your Article 30 record of processing.
- Train and disclose. Give staff role-specific guidance under Article 4, and add AI disclosures wherever Article 50 applies.
- Re-check defaults at every sub-processor notice and at least once a year, because vendors change both.
How VDF AI fits
VDF AI deploys on-premises, in your private cloud or VPC, or air-gapped. In those deployments, inference, embeddings, private retrieval, logs and orchestration run in the environment you control, and production use requires no third-party model API sub-processor. If you decide to connect an external model, that provider is one you choose and govern under your own policy.
On the evidence side of the checklist, it offers a region-pinned data plane with customer-controlled storage, configurable retention and deletion for indexes, logs and source connectors, and audit records of every prompt, tool call, retrieval and response, streamed to your SIEM. The model router enforces model policy by domain, sensitivity and residency requirement. Role-based access control is included on every plan, and on-premises deployments sign users in natively with Microsoft Entra ID. The VDF AI Trust Center sets out the sub-processor position and the compliance mapping in full.
Your obligations as controller stay with you. What changes is how many parties and places your AI processing involves.
Sources
- GDPR, Regulation (EU) 2016/679, on EUR-Lex
- AI Act, Regulation (EU) 2024/1689, on EUR-Lex
- Digital Omnibus on AI, Regulation (EU) 2026/1744
- EDPB Opinion 28/2024 on AI models
- EDPB Opinion 22/2024 on processors
- General Court press release, Latombe v Commission
- Appeal in Case C-703/25 P, Official Journal
- European Commission, EU-US data transfers
- European Commission, standard contractual clauses
- European Commission, AI literacy Q&A
- Mistral, Le Chat is now Vibe
- Mistral, where data is stored
- Mistral, training opt-out
- Langdock, security
- OpenAI, enterprise privacy
- OpenAI, data residency in Europe
- Microsoft, data and privacy in Microsoft Copilot
- Microsoft, web search in Copilot
- Google, Workspace generative AI privacy hub
- Google, data regions for Gemini in Workspace
- Google, data regions for the Gemini app
- Microsoft Foundry, data privacy
- Amazon Bedrock, data protection
- Amazon Bedrock, cross-Region inference
- Amazon Bedrock, data retention