Data protection
Blog/Data residency requirements for AI in Europe: GDPR, Schrems II, and where your prompts actually go
For AI assistants

Data residency requirements for AI in Europe: GDPR, Schrems II, and where your prompts actually go

By Samuel Seidel · Published September 9, 2026 · 8 min read

"Our AI vendor has an EU region" answers a narrower question than most people think it does. It tells you where the servers sit. It doesn't necessarily tell you which country's courts can order that vendor to hand over your data, and that second question is exactly what the Schrems II line of cases put back on the table for any US-headquartered vendor, regardless of where its EU region physically is. This isn't legal advice; verify current requirements with counsel before making a compliance decision on it.

The GDPR transfer framework, briefly

GDPR restricts transfers of personal data to countries outside the EU/EEA unless the destination offers an adequate level of protection, whether through an adequacy decision covering that country, appropriate safeguards such as Standard Contractual Clauses, or a narrower derogation. The point of the framework is that moving data across a border shouldn't lower the level of protection that data would otherwise have inside the EU. Where a vendor is headquartered, and what legal regime it operates under, matters to that analysis independently of where its servers are physically located.

What Schrems II actually decided

In its ruling in Case C-311/18, commonly known as Schrems II, the Court of Justice of the European Union invalidated the EU-US Privacy Shield framework as a valid mechanism for transferring personal data from the EU to the US. The Court's concern centered on US surveillance law giving US authorities access to data held by US companies in ways that didn't meet the EU's standard of essential equivalence to EU protections, regardless of contractual promises made by the receiving company. Standard Contractual Clauses remained usable, but the ruling required exporters to assess, on a case-by-case basis, whether the law of the destination country actually allows the importer to comply with the clauses in practice. Confirm the exact date and the case's current standing with a primary legal source before citing it in a compliance document; the description above reflects the substance of the ruling rather than a verified citation you should rely on as final.

Why this doesn't go away just because a vendor has an EU region

The practical effect that matters here is jurisdictional, not geographic. A company headquartered in the US, or with a US parent, can be subject to US legal process reaching data under its control, including data physically stored in an EU data center, because the obligation runs to the company, not to the server rack. That's the exposure an "EU region" checkbox doesn't remove: the data may sit in Frankfurt or Dublin, but the entity that can be compelled to produce it is still answerable to a different jurisdiction. Whether that specific exposure is acceptable for your use case, and what contractual or technical measures might address it, depends on your risk tolerance and your counsel's assessment, not on marketing language about "EU data residency."

What actually removes that specific exposure

The cleanest way to remove a US-jurisdiction transfer question is to remove the US entity from the chain entirely: an EU-incorporated operator, with no US parent company and no US-incorporated entity anywhere in the ownership or contracting structure, for the specific vendor handling your data. That's the exact positioning GPUwerk uses for its own infrastructure: hardware physically in EU-Central, operated by PRINT IT! SE, a Societas Europaea registered in Prague, with no US parent and no US region in the chain for a US legal order to be served on, as described on our private LLM hosting page. That structure answers the jurisdictional question directly rather than through a contractual promise layered on top of a US-controlled entity.

It's worth being precise about what that does and doesn't cover. Removing the US-jurisdiction exposure is one specific piece of a GDPR-compliant deployment, not the whole of it. You, as the controller, remain responsible for the lawfulness of your own processing, your legal basis, data minimization, security measures, and the rest of GDPR's obligations regardless of which vendor or infrastructure you use. An EU-only, no-US-parent hosting setup narrows one real risk; it doesn't substitute for the rest of a compliance program.

Questions worth putting to any AI vendor

See private LLM hosting for how GPUwerk answers each of those for its own dedicated-machine setup, including the published DPA and sub-processor list.

Related pages

An EU-only chain, start to finish.

Dedicated infrastructure in EU-Central, operated by an EU company with no US parent in the chain.

See private LLM hosting Read the DPA