Several LLM providers now offer GDPR-aligned options that keep processing inside the EU, though the strength of that guarantee varies by provider and plan. Microsoft's Azure OpenAI Service can be configured to process and store data in EU regions with contractual commitments limiting where it moves, Amazon Bedrock and Google Vertex AI similarly offer EU region hosting for models available through those platforms, and European-headquartered model providers such as France's Mistral and Germany's Aleph Alpha offer models built and hosted within the EU from the start, which simplifies the transfer analysis considerably. OpenAI and Anthropic, both US companies, offer enterprise data residency and processing commitments for EU customers along with standard contractual clauses to cover any transfer, but because they remain US entities, some organizations in especially sensitive sectors still prefer a provider with no US corporate ownership at all. The option that removes the cross-border transfer question entirely is self-hosting an open-weight model, such as Llama, Mistral, or Qwen, inside an EU-based datacenter under the company's own control, since no data crosses a border regardless of where the model architecture originated. As of 2026, specific regional hosting and residency terms should be verified directly with each provider before committing. Nanobase AI evaluates EU-hosted API options against self-hosted deployment for clients based on their actual data residency requirements.

Evaluate the contract, not just the region selector

Selecting "EU region" in a cloud console setting is not the same thing as a verified, contractually binding guarantee that personal data stays within the EU and is handled the way GDPR requires. The actual protection comes from the underlying contract terms, subprocessor list, and training-data policy, which have to be checked directly rather than assumed from a region setting in a dashboard. This is general information about a fast-moving vendor landscape, not a legal opinion on any specific provider's current terms, which should always be verified directly before committing.

What to verify before signing

Item to verifyWhy it matters
Actual data processing and storage regionA region setting in the UI does not always guarantee every subprocessor and backup also stays in-region
Standard contractual clauses or equivalent transfer mechanismRequired if any processing occurs outside the EU despite the primary region setting
Training data opt-outConfirms customer prompts are not used to improve the vendor's models
Subprocessor listReveals any third parties the primary vendor relies on, each of which needs its own compliance check
Data retention and deletion termsDetermines whether the vendor honors erasure requests on a timeline compatible with GDPR
Certifications held (SOC 2, ISO 27001)Independent evidence of the vendor's security practices, though not a substitute for the contract terms above

Microsoft's Azure OpenAI Service, Amazon Bedrock, and Google Vertex AI all offer EU region hosting for models available on those platforms, and European-headquartered providers such as France's Mistral and Germany's Aleph Alpha build and host models within the EU from the start, which simplifies the transfer analysis since there is no US parent entity to reason about. OpenAI and Anthropic, both US companies, offer enterprise data residency and processing commitments alongside standard contractual clauses to cover any transfer, though some organizations in especially sensitive sectors still prefer a provider with no US corporate ownership at all.

The self-hosting alternative, quantified

Self-hosting an open-weight model, such as Llama, Mistral, or Qwen, inside an EU-based datacenter under the company's own control removes the cross-border transfer question entirely, since no data crosses a border regardless of where the model architecture originated; this trades the vendor evaluation checklist above for the on-premise deployment cost and operational tradeoffs covered separately. Organizations with the sharpest data sovereignty requirements, or the least trust in relying on a third party's contractual promises, often land on self-hosting for this reason even when a compliant API option exists.

Questions to put directly to a vendor

A vendor that answers these five questions clearly and in writing is a materially safer bet than one that points back to a general privacy page.

  1. Which specific regions does data pass through, including any backup, logging, or monitoring infrastructure, not just the primary inference region?
  2. Is customer prompt and response data used for any model training or improvement, by default or opt-in only?
  3. What is the complete list of subprocessors involved in delivering the service?
  4. What is the contractual timeline for honoring a data deletion or erasure request?
  5. Which independent certifications are current, and can documentation be provided rather than just referenced?

Frequently asked questions

Is choosing an EU-region API endpoint sufficient for GDPR compliance on its own?

Region selection is a necessary but not sufficient step; the underlying contract still needs standard contractual clauses or equivalent protection for any data that does leave the EU through a subprocessor, backup, or support process not covered by the region setting alone.

Does self-hosting eliminate the need for a GDPR compliance review?

No, self-hosting removes the cross-border transfer question specifically, but the organization still needs to run the same GDPR compliance analysis for lawful basis, data minimization, and individual rights that applies to any AI system processing personal data.

How often should vendor compliance terms be re-checked?

At least annually, and immediately after any material change to the vendor's terms of service, since data residency commitments, subprocessor lists, and training policies are areas vendors update periodically as their own infrastructure evolves.

How Nanobase AI helps

Nanobase AI evaluates EU-hosted API options against self-hosted deployment for clients based on their actual data residency requirements, running the vendor checklist above and comparing it directly to the on-premise alternative.

Ready to discuss your project? Contact Nanobase AI or email hello@bumu.tech.