Where Does Your Data Go? EU Storage for AI Tools
By CodexierPublished 5 min read
Almost every AI vendor now says it offers EU data storage. That sentence answers only one of the questions GDPR asks you to answer as the controller. Where data is stored, where it is processed, which sub-processors touch it and whether it trains the vendor's models are four separate questions, and the answers sit in different documents. This guide explains each one so you can check a vendor in an afternoon.
Residency vs processing location
When a vendor advertises EU residency, it usually means conversation logs, uploaded files and account data are stored in an EU region. The model itself may still run in another region when EU capacity is short, and prompts may pass through a global routing layer. Look for the phrase in the terms that covers processing, often labelled data residency for inference or regional processing, and whether it applies to your plan or only to enterprise contracts.
Sub-processors and third-country transfers
Under GDPR the vendor is normally your processor, and every company it uses to deliver the service is a sub-processor. The list is public for serious vendors and changes over time; you should be able to subscribe to updates. Each entry shows a purpose and a location.
- Cloud hosting and the model provider itself, often a separate company from the app you buy.
- Content moderation and abuse monitoring, which may keep prompts for a limited period.
- Support tooling, where staff outside the EU can sometimes view data to resolve a ticket.
- Analytics and logging services that receive metadata about your usage.
A transfer to a country outside the EU/EEA needs a legal basis under chapter V of GDPR: an adequacy decision, such as the EU–US Data Privacy Framework for certified US companies, or standard contractual clauses with a transfer assessment. The framework is in force but has been challenged before, so a vendor that also signs standard contractual clauses gives you a fallback. Our guide to ChatGPT at work and GDPR covers the staff side of this.
Training on your data: opt-in and opt-out
Whether your inputs improve the vendor's models is decided by the plan, not by the product name. The same assistant can train on data in a free personal account and not in a business workspace. Settings can also change when terms are updated.
| Tier | Typical default | What to verify |
|---|---|---|
| Free or personal account | Inputs may be used for training unless you opt out | Where the opt-out is, and whether it covers past data |
| Business or team workspace | Excluded from training by default | That the exclusion is in the contract, not only in a help page |
| API access | Excluded by default; logs kept for abuse monitoring | Retention period and whether zero-retention is available |
| Enterprise agreement | Negotiated terms, often regional processing | Which commitments are written into your order form |
Defaults change. Read the current terms of the plan you are paying for before you roll a tool out.
Questions to ask any AI vendor
- Where are prompts, files and outputs stored, and for how long?
- Where is the model run for our plan, and can processing leave the EU?
- Which sub-processors receive our data, and how are we told about changes?
- Is our data used for training, and where does the contract say so?
- Can support staff outside the EU view our content, and under what controls?
- Do you sign a DPA with standard contractual clauses as a fallback?
- How do we delete data, and how do we export it if we leave?
A vendor that answers these in writing within a few days is usually fine for ordinary business data. Vague answers, or a DPA that only exists for the most expensive tier, tell you where the tool belongs in your policy.
When on-premise or EU-only is worth it
Strict EU-only processing, an EU-based model host or running an open model on your own servers costs more in money and maintenance, and the models available are sometimes a step behind. It is worth it in a few clear cases:
- You process health data, children's data or other sensitive categories.
- Your customers, often public sector or large enterprises, require EU-only processing in their contracts.
- Your risk assessment concludes that third-country transfers are not acceptable for this data.
- You need the system to keep running under your own control, independent of a single vendor's terms.
When you do not need it: for drafting marketing copy, summarising public documents or internal brainstorming without personal data, a business tier from a major vendor with a proper DPA is usually enough. Paying for a bespoke setup there buys little. If you are unsure where your use cases fall, an AI integration audit maps data flows tool by tool, or you can book a short call to sort it out first.
Frequently asked questions
Is it enough that the vendor says data is stored in the EU?
No. Storage is one question. You also need to know where processing happens, which sub-processors are involved, whether support can access data from outside the EU and what the contract says about training.
Can we use US-based AI tools under GDPR?
Yes, if there is a valid transfer basis, such as the vendor's certification under the EU–US Data Privacy Framework or standard contractual clauses, and you have a DPA. Document the assessment in case IMY or a customer asks.
Does turning off chat history stop training?
In some tools it does, in others it only hides history from you. The answer is in the vendor's data usage terms for your plan, not in the interface. Business tiers usually settle it contractually.
Who in the company should own this check?
Whoever owns your GDPR records, together with the person buying the tool. The check belongs in the same place as your record of processing activities, not in someone's inbox.
Not sure where your AI data actually goes?
Book a free 15-minute call. We look at the tools you use or plan to use, point out which questions still lack answers and tell you whether an audit is worth it or a policy update is enough.
Book a free 15-minute call