Data Residency & GDPR

EU data residency is a design decision about where workloads, prompts, documents, logs, backups and support access are processed—not a logo on a cloud region. A credible deployment records each data flow, gives the customer a chosen EU, private-cloud or on-premise boundary, and documents any transfer or subprocessor that remains.

Start with a data-flow inventory

For an enterprise buyer, “where do our data go?” is not one question. It includes source systems, uploaded documents, prompt context, embeddings, model requests, telemetry, backups, support access and incident records. Each flow needs an owner, a purpose, a destination, a retention rule and a transfer decision.

EUHub AI designs deployments around the environment selected for the engagement: an EU-only public-cloud region, the customer’s private cloud, or an on-premise environment. The website itself currently runs in Google Cloud europe-west1 in Belgium; customer-system architecture is agreed per project. A deployment design should never imply that all possible customers have identical data paths.

Choose the deployment boundary that matches the risk

The right boundary depends on the data category, regulatory obligations, internal security model, operational team and model requirements. An EU public-cloud deployment can reduce operational burden while retaining regional control. A private-cloud or on-premise deployment can provide tighter isolation and customer control, but it shifts more operating responsibility to the customer or delivery team.

The decisive question is not whether a platform says “EU”. It is whether the architecture identifies every processor and subprocessor, records where each category of data is handled, and gives the customer a practical way to test and audit the boundary.

Deployment choices to discuss during an AI architecture review
Deployment optionTypical data boundaryOperational responsibilityEvidence to request
EU public cloudCustomer-approved EU region and managed servicesShared between customer and delivery teamRegion diagram, service inventory, access controls
Private cloudCustomer-controlled tenancy and network boundaryCustomer or agreed managed operatorNetwork design, identity model, backup and incident runbook
On-premiseCustomer site or hardware boundaryCustomer with defined support responsibilitiesHardware baseline, patching, logging and recovery procedure

DPA, subprocessors and transfer decisions

Where EUHub AI processes personal data on behalf of a customer, the parties should agree a Data Processing Agreement that reflects the actual processing, roles, instructions, security measures, deletion/return process and audit arrangements. GDPR Article 28 and Article 32 are useful reference points, but the agreement must match the concrete system rather than reuse generic language without review.

Subprocessor transparency is operational: the customer needs a current list of relevant hosting, model, monitoring and support providers, the reason each is used, and a process for notifying changes where the agreement requires it. A self-hosted or on-premise design can reduce some third-party exposure, but it does not remove the need to document administrators, support channels and telemetry.

International transfers require an explicit design

If a data flow leaves the European Economic Area, treat that as a documented architecture and legal decision. Record the destination, provider role, transfer mechanism, supplementary safeguards and residual risk. Standard Contractual Clauses and transfer-impact assessments can be relevant, but they are not a substitute for understanding the actual technical flow.

The simplest way to reduce a transfer risk can be to avoid the transfer: keep prompts, documents, logs and model inference inside a selected EU or customer-controlled environment where that is technically and commercially appropriate. Where a flow cannot be avoided, document why, minimize the data and confirm the controls with qualified privacy counsel.

Security, retention and proof for procurement

A defensible deployment combines encryption in transit and at rest, least-privilege access, role separation, audit logging, monitored backups and an incident process. The actual controls depend on the chosen environment and contract; do not advertise a control that is not part of the delivered design.

For retention, define what is stored, why it is stored, who can access it, and what triggers deletion or return. A customer should be able to request evidence such as an architecture diagram, access matrix, subprocessor inventory, runbook, log-retention setting, backup policy and deletion procedure. Request a data-processing architecture review to map those artifacts before a pilot is approved.

Frequently asked questions

Can AI prompts and documents remain in the EU?

They can when the selected model, hosting, storage, logging and support design support that boundary. The architecture must document each flow rather than relying on a broad regional statement.

Do we need a Data Processing Agreement?

Where a supplier processes personal data on your behalf, a DPA is commonly required to define the roles, instructions, security expectations, subprocessors, audit rights and deletion or return process. Obtain legal review for your situation.

How do we assess subprocessors?

Maintain an inventory of hosting, model, monitoring and support providers; identify what data each may receive; record their location and role; and define how customers are informed when the list changes.

What happens if a provider needs non-EEA processing?

Document the exact flow, destination, purpose, transfer mechanism and safeguards. Minimize the data and obtain privacy/legal review before approving the architecture.

Can an on-premise model remove all data-protection work?

No. On-premise deployment changes the boundary but does not remove responsibilities for access, logging, retention, security, staff access, incident handling or contractual roles.

What evidence should procurement request?

Request a data-flow diagram, deployment and region statement, DPA, subprocessor list, access matrix, retention policy, security controls, incident process and documented handover responsibilities.

Primary sources

  1. Regulation (EU) 2016/679 (GDPR) — EUR-Lex
  2. Standard Contractual Clauses for international transfers — European Commission
  3. EDPB recommendations and guidance — European Data Protection Board
  4. Google Cloud locations — Google Cloud