GDPR-Compliant AI: How to Use LLMs Under the GDPR (2026 Guide)
By Felix Wunderlich -
Published October 6, 2026. Vendor terms and legal statuses checked against primary sources at publish time, and we revisit this guide as they change.
- You are the controller and your LLM vendor or gateway is your processor, with every model provider behind a gateway as a sub-processor. Compliance is how you set up and document that chain.
- Five questions decide whether a vendor setup holds: where inference runs, what the provider retains, whether anyone trains on your data, how sub-processor changes are notified, and which transfer tool covers any hop outside the EEA.
- Check the defaults per vendor. Claude in the EU runs through AWS Bedrock or Google Vertex AI, OpenAI's EU data residency is set up through its sales team, and the cloud platforms offer both EU and global deployments, so the option you pick decides where a prompt runs.
This guide covers the common case: calling a model through an API from a product that handles personal data, such as support tickets, CVs or contracts. It explains the roles, the five questions, how the leading AI labs and cloud providers (OpenAI, Anthropic, Mistral, Microsoft Azure, AWS and Google Cloud) answer them in October 2026, and what an AI gateway changes.
Who is the controller, processor and sub-processor?
When your product sends personal data to an LLM, your company is the controller and the API vendor that runs the model on your instructions is a processor, even when the service is standardised and offered take it or leave it.1 Sweden's data protection authority applies the same reading to generative AI.2 Put a gateway in between and it becomes your processor, while the model providers behind it become its sub-processors, which need your authorisation, advance notice of changes and the same contractual obligations.3 If you are yourself a processor for your customers, the gateway is the sub-processor on the list you give them.
Two details matter in practice. The processor depends on the route, not the model brand: Claude on Anthropic's API is processed by Anthropic, Claude on Bedrock or Vertex AI by AWS or Google, and GPT on Azure by Microsoft.4 And a vendor that trains on your prompts becomes a controller for that processing.3 Using a vendor never moves the risk away from you, since a controller can be fined for processing its processor carried out on its behalf.5
The five questions to ask any LLM vendor
| Question | Why it matters | What good looks like |
|---|---|---|
| 1. Where does inference run? | The contracting entity, the storage location and the inference location are separate settings, and inference is where the model reads your prompt. | An EU or EEA inference location stated for the exact model and endpoint you call (EU vs EEA explained). |
| 2. What does the provider retain? | Abuse-monitoring logs are personal data with a retention period of their own. | A stated retention window, zero data retention where you need it, and no stored conversations you can't delete. |
| 3. Does anyone train on your data? | Training is the vendor's own purpose, which makes it a controller for that processing. | No training on API traffic in the contract, preview and experimental models included. |
| 4. How are sub-processor changes notified? | You must hear about a new sub-processor before it sees your data and be able to object. | Advance notice sent to you, an objection window, and a remedy if you object. |
| 5. Which transfer tool covers hops outside the EEA? | Every transfer needs a legal basis, onward transfers included.3 | Inference in the EEA, an importer on the DPF list, or SCCs with a transfer impact assessment. |
How the leading AI labs and cloud providers answer them (October 2026)
Each row comes from the vendor's own documentation, checked on October 5, 2026. Terms change often, so check the pages behind each footnote before you choose.
| API | EU inference | Default retention | Trains on API data | Sub-processor changes | US transfer tool |
|---|---|---|---|---|---|
| OpenAI API6 | Europe region (EEA and Switzerland), after sales approval | Abuse logs up to 30 days | No, opt-in only | Notice, 30 days to object, then termination | SCCs, not on the DPF list |
| Anthropic API4 | No, global or US; EU via Bedrock or Vertex AI | Deleted within 30 days, flagged content up to 2 years | No | Reasonable notice, 15 days to object; terminate for convenience | SCCs, not on the DPF list |
| Azure OpenAI7 | Data Zone EU or a regional deployment; Global can run anywhere | Not stored by the model; review store in your geography | No | 6 months for customer data, 30 days for AI sub-processors; terminate without penalty | SCCs; DPF-certified, not relied on |
| AWS Bedrock8 | An EU Region or the EU inference profile; Global routes worldwide | Not stored by default; some models up to 30 days | No | 30 days; terminate, stop using or move Region | SCCs; AWS is covered by the DPF |
| Google Vertex AI9 | EU multi-region or an EU region; the global endpoint has no guarantee | Logged only when flagged, up to 90 days | No | 30 days; object within 90 days by terminating | DPF, SCCs as fallback |
| Mistral AI10 | Opt-in EU endpoint (EU and EFTA); the default makes no inference-location commitment | 30 rolling days | No by contract, except Labs and preview models | Reasonable notice, 10 days to object | EU company; SCCs for sub-processors outside the EU |
Three patterns stand out:
- EU residency is a setting you choose. A European contracting entity does not decide where a prompt runs, and regional endpoints often cost more: 10% for regional Claude endpoints on Bedrock, 1.1 times list price on Mistral's EU endpoint, and 10% for OpenAI's EU residency on models released since March 2026.
- New models often launch on global endpoints first. Azure documents the order as Global, then Data Zone, then regional, and some new or preview models start on global endpoints only.
- Some models come with mandatory retention. Anthropic's covered models, currently the Claude Fable and Mythos families, require 30-day retention on every platform that offers them unless Anthropic grants an exception.
Transfers to the US in 2026
Each hop outside the EEA needs a transfer tool.3 The EU-US Data Privacy Framework covers only US organisations on its list: Microsoft, Amazon (with AWS) and Google are listed, while OpenAI and Anthropic are not and rely on Standard Contractual Clauses.11 The General Court upheld the framework in September 2025, an appeal is pending before the Court of Justice, and the Commission's next review is due around 2027.12 Encryption does not solve a transfer for inference, because the model has to read the prompt in the clear.13 What matters is the transfer tool, or keeping inference in the EEA.
Model swaps and fallbacks are sub-processor changes
Every new provider that receives personal data needs paperwork: a DPA when you call it directly, or advance notice and an objection window from your gateway when it sits behind one.3 The EDPB expects you to know every processor and sub-processor in the chain at all times,14 which an automatic fallback to an unlisted provider quietly breaks. Pin fallbacks to providers and regions you have already authorised, and subscribe to each vendor's sub-processor notices.
What an AI gateway changes
A gateway is your processor and the model providers are its sub-processors. You have one DPA, your own sub-processor list carries one AI entry (the gateway's published list gives you the full chain), and the gateway carries the provider agreements and stays fully liable for them.3 It does not change who the controller is, and its own hosting location says nothing about where inference runs: a gateway in Stockholm can still route a prompt to a US endpoint.
How Opper, our own gateway, handles it:15
- One processor, one DPA. Opper Technology AB, a Swedish company, is your processor under a published DPA. Every model provider is listed on the trust center and receives your data only when you call one of its routes, with 30 days' notice before a sub-processor is added or replaced.
- Inference location per route. The platform runs in AWS Stockholm and inference follows the route you call. An EU route's model id keeps inference in Europe on every plan, and on Control Plane a Model access rule enforces EU locations for the whole organization. Every EU route is listed under EU-hosted models.
- Retention and training per route. No prompts are stored by default, Opper never trains on your data, and each route shows its provider's retention and training posture.
- Evidence. Opper is ISO/IEC 27001:2022 certified, with the controls on the trust center. The full picture is on the GDPR-compliant AI gateway page.
A GDPR checklist for shipping an LLM feature
- Send only the personal data each task needs, and redact where you can.
- Name the processor for every route you call: the vendor or the cloud behind it.
- Have a DPA in place (one built into the terms you accept counts) and check it covers instructions, security, sub-processors, assistance, deletion and audits.
- Get the full sub-processor list and subscribe to change notices.
- Confirm where inference runs for each model, and pin EU routes where your policy needs them, fallbacks included.
- Record each provider's retention, and set your own log and trace retention in writing.
- Record the transfer tool for every hop outside the EEA.
- Check whether the feature needs a Data Protection Impact Assessment (DPIA), and review it when models change.
GDPR and AI FAQ
Does the GDPR apply to AI?+
Yes, whenever an AI system processes personal data, which for an LLM means whenever a prompt, a retrieved document or an output relates to an identifiable person. The GDPR has no AI exception, and the EU AI Act does not replace it: Article 2(7) of the AI Act says it "shall not affect" the GDPR, so both apply side by side.
Is there a GDPR certification for AI tools?+
Only for specific processing operations. Article 42 of the GDPR allows voluntary certification of a defined processing operation for up to three years, and none of the schemes on the EDPB's register is AI-specific, so no AI tool carries a general GDPR certification. ISO/IEC 27001, SOC 2 and ISO/IEC 42001 are useful evidence when you assess a vendor.
Is an AI gateway a processor or a sub-processor?+
A gateway is your processor, because it handles prompts on your instructions, and the model providers it routes to are its sub-processors. You have a DPA with the gateway (often part of its terms), the gateway has sub-processing agreements with the providers and stays fully liable for them under Article 28(4), and it must notify you before it adds or replaces one.
Is the EU-US Data Privacy Framework still valid for AI providers?+
Yes, as of October 2026. The General Court upheld it on September 3, 2025, and an appeal (C-703/25 P) is pending before the Court of Justice. It only covers US organisations on the DPF list: Microsoft, Amazon and Google are listed, OpenAI and Anthropic are not and rely on Standard Contractual Clauses instead.
What happens when my AI provider adds a new sub-processor?+
Under Article 28(2) it must tell you in advance so you can object. Notice periods, objection windows and remedies vary by vendor, from a ten-day objection window to six months' notice, and the usual remedy after an objection is terminating the affected service. Switching models or adding a fallback provider yourself is the same kind of change, seen from your side.
Do I need a DPIA to use an LLM?+
Often, when the feature handles personal data at scale, sensitive data or employee data, or scores people. A Data Protection Impact Assessment is the controller's written risk assessment for processing likely to result in a high risk, so you write it and review it when you change models or providers. Your processor has to help: Opper's DPA commits it to assist under Articles 32 to 36, which cover the DPIA.
Is redacted or pseudonymised prompt data still personal data?+
Often it still is for you, because you can re-identify it. The Court of Justice held in C-413/23 P that pseudonymised data may not be personal data for a recipient who cannot re-identify the person, but your own obligations remain, and Germany's data protection authorities warn that removing names and addresses is regularly not enough when context still identifies someone.
Build it so the paperwork stays true
GDPR-compliant AI is less about which model you pick than about whether your setup still matches your documents after the next model launch, the next outage and the next cheaper route. Pin the routes, know the retention at every hop, and keep the chain short and documented, so "who has my data?" has a quick answer. If you want that as one EU-hosted processor in front of 700+ models, browse the EU-hosted routes, read the DPA, and see how the GDPR-compliant AI gateway handles the rest. This guide is not legal advice; take it to your DPO as the map for that conversation.
Footnotes
-
EDPB, Guidelines 07/2020 on the concepts of controller and processor, paragraphs 30, 95 and 151 to 160, footnote 54. ↩
-
IMY, GDPR vid användning av generativ AI (in Swedish). ↩
-
General Data Protection Regulation (EU) 2016/679: Articles 4, 5, 25, 28, 35, 42, 44 to 46. ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Anthropic: API and data retention, data residency, retention, covered models, Claude on Bedrock, commercial terms, DPA, sub-processors, trust center. ↩ ↩2
-
OpenAI: data controls and residency, DPA, sub-processor list, trust portal. ↩
-
Microsoft: data privacy for models sold by Azure, deployment types, supplier management, GDPR, DPA, ISO/IEC 42001. ↩
-
AWS: cross-Region inference, data retention, abuse detection, data protection, sub-processors, DPA, ISO/IEC 42001. ↩
-
Google Cloud: data residency, locations, abuse monitoring, zero data retention, sub-processors, Cloud DPA, transfer solution, ISO/IEC 42001. ↩
-
Mistral AI: regional inference, data location, privacy policy, commercial terms, DPA, trust center. ↩
-
EU-US Data Privacy Framework adequacy decision (EU) 2023/1795, the DPF participant list, and the Standard Contractual Clauses, Decision (EU) 2021/914. ↩
-
General Court, press release on T-553/23 Latombe v Commission; appeal C-703/25 P; Commission, first DPF review COM(2024) 451. ↩
-
EDPB, Recommendations 01/2020 on supplementary measures, Use Case 6. ↩
-
EDPB, Opinion 22/2024 on reliance on processors and sub-processors and the September 2026 summary for controllers. ↩
-
Opper: Data Processing Agreement, trust center and sub-processor register, security overview. ↩