The short answer: you can use LLMs such as Claude, GPT, Gemini or Mistral with the personal data of EU customers, as long as you get five things right. A lawful basis for the processing. A data processing agreement with the model provider. An EU-region endpoint where you need processing to stay in Europe. As little personal data in each prompt as the task allows. And a DPIA when the use is likely to be high risk. Most GDPR trouble with AI features comes from logs, prompts and retention settings, not from the model.
I am Md Fahad Mia, a software and AI engineer who integrates LLMs into production products, including the backend of an AI marketing and CRM platform with five orchestrated agents. This is the practical version: what the providers actually offer as of September 2026, and the patterns I build in for clients that serve people in the EU. I am an engineer, not a lawyer, so have your data protection officer or counsel sign off on your own case.
Which LLM providers keep data in the EU
Data residency options have changed a lot in two years, and they are not the same across providers. Here is where each one stood when I checked their documentation in September 2026.
| Provider | EU processing option | Retention and training |
|---|---|---|
| OpenAI | EU data residency since February 2025 for the API, ChatGPT Enterprise and Edu, through the eu.api.openai.com endpoint. It requires approval for zero data retention or modified abuse monitoring. | API data has not been used for training by default since 1 March 2023. Abuse-monitoring logs are kept for up to 30 days by default. |
| Anthropic (Claude) | No first-party EU residency on the Claude API itself, which offers global or US processing. EU processing is available through Amazon Bedrock EU inference profiles or the EU endpoint on Google Cloud Vertex AI, at roughly a 10% premium. Claude on Microsoft Foundry has no EU option yet. | Commercial API inputs and outputs are deleted within 30 days by default, and commercial customer content is not used for training. Zero data retention is available by arrangement. |
| Google (Gemini on Vertex AI) | The EU multi-region endpoint keeps machine-learning processing inside EU member states. The UK and Switzerland are not included, and the global endpoint gives no residency guarantee. | Governed by your Google Cloud terms and data processing addendum. |
| Microsoft (Azure OpenAI) | Data Zone EU deployments process data within the EU Data Boundary. Global deployments may process data in any region. | Governed by your Azure terms and data processing addendum. |
| Mistral AI | Headquartered in Paris. Data is hosted in the EU by default, and the US endpoint is opt-in. | Some features may pass data to listed sub-processors under Standard Contractual Clauses. |
Two practical notes. First, the region you pick in code has to be the region you actually get. A client library that silently falls back to a global endpoint during an outage breaks your residency promise without anyone noticing, so I make the region explicit and fail closed. Second, these options change often. Re-check them before you sign a contract, not after.
The legal pieces, in plain terms
- Lawful basis. Every use of personal data needs one. For a support assistant it is often the contract with the customer or a legitimate interest, which needs a documented balancing test.
- A processor contract. The model provider processes data on your behalf, so Article 28 requires a written data processing agreement. The business terms of the major providers include one. Consumer accounts do not belong anywhere near customer data.
- International transfers. US providers can rely on the EU-US Data Privacy Framework, which is still valid. The General Court dismissed the Latombe challenge in September 2025, and an appeal is pending, so keep Standard Contractual Clauses as a fallback. Engineers and contractors outside the EU need SCCs too, which I cover in hiring a remote developer in Europe.
- A DPIA when risk is high. Article 35 requires a data protection impact assessment where processing is likely to be high risk, for example systematic profiling with significant effects on people, or large-scale processing of health and other special-category data.
- Automated decisions. Article 22 gives people the right not to be subject to decisions based solely on automated processing that have legal or similarly significant effects. Keep a human in the loop for anything like that.
- Training on personal data. If you fine-tune a model on customer data, the EDPB's Opinion 28/2024 applies. Whether a model counts as anonymous is judged case by case, and unlawful processing during development can taint its later use.
The stakes: breaches of the core principles, of Article 22 or of the transfer rules can reach €20 million or 4% of worldwide turnover, whichever is higher. Failures under Articles 25, 28 and 35 sit in the lower tier of €10 million or 2%.
Build patterns that keep personal data out of trouble
This is where most of the real work is. Contracts cover you on paper. These patterns decide what actually happens to your customers' data.
- Minimise before the prompt. Send only the fields the task needs. Replace names, emails, phone numbers and account IDs with placeholder tokens before the call, then swap the real values back into the answer. The model can reason about "Customer A's order" just as well as about a real name. This is Article 5(1)(c) data minimisation, applied where it counts.
- Pin the region and fail closed. Configure the EU endpoint explicitly per environment, and make the integration refuse to run rather than fall back to a global region.
- Turn retention down. Use zero data retention where the provider offers it and your use qualifies. Then look at your own stack. Full prompts sitting in an observability tool, an error tracker or a debug log are the most common leak I find. Redact them or keep only metadata, with short retention.
- Keep retrieval in the EU and behind permissions. For retrieval-augmented generation, store embeddings in an EU-region database such as Postgres with pgvector, and enforce the same access rules as the rest of the app. On the Tryneth backend, row-level security covered 97 of 98 tables, so the AI could only retrieve what the signed-in user was allowed to see.
- Make deletion reach the AI layer. When a customer asks to be erased, their data has to disappear from conversation logs, caches and embeddings as well as the main database. Design for that on day one, because retrofitting it is painful.
- Human review for consequential outputs. Anything that affects a person's money, access or opportunities goes to a human before it takes effect.
- Tell people. Your privacy notice should say that AI is used and which provider processes the data. Your interface should say when they are talking to an AI, which the EU AI Act has required since August 2026. More on that in what the EU AI Act means for small businesses.
The model is rarely where GDPR goes wrong. The prompt, the log and the retention setting are.
A pre-launch checklist
- Lawful basis documented for each AI use.
- Data processing agreement signed with the model provider, and SCCs or the Data Privacy Framework covering any transfer.
- EU endpoint pinned, with no silent fallback.
- Personal data minimised or pseudonymised before each prompt.
- Zero or minimal retention configured, and prompt logging redacted.
- Vector store and conversation logs in an EU region, behind the app's access rules.
- Erasure requests reach logs, caches and embeddings.
- DPIA done if the use is likely to be high risk.
- Human review in place for consequential decisions.
- Privacy notice and AI disclosure updated.
How I deliver this for clients
I build AI features for companies that serve people in the EU, working inside your own cloud accounts under a data processing agreement with Standard Contractual Clauses. The checklist above becomes part of the acceptance criteria, so compliance is tested like any other feature. AI and automation projects start at $5,000 and are paid in four milestones: 25% after each 25% of the work is finished and reviewed, with no deposit. How that works is in milestone payments for software projects.
Questions about GDPR and LLMs
Can I use the OpenAI API with EU customer data under GDPR?
Yes, with the right setup. Use a business account with OpenAI's data processing agreement, consider its EU data residency option through the eu.api.openai.com endpoint, minimise personal data in prompts, and document your lawful basis. API data has not been used for training by default since March 2023.
Does Claude offer EU data residency?
Not on Anthropic's own API as of September 2026, which offers global or US processing. For EU processing, run Claude through Amazon Bedrock EU inference profiles or the EU endpoint on Google Cloud Vertex AI, usually at around a 10% price premium. Commercial Claude API data is not used for training.
Do LLM providers train on data sent through their APIs?
Not by default for business API use at the major providers. OpenAI has not trained on API data by default since 1 March 2023, and Anthropic does not train on commercial customer content. Consumer chat apps are a different matter, which is why customer data belongs only in business accounts.
Do I need a DPIA for an AI chatbot?
Not always. Article 35 requires one when processing is likely to result in a high risk, such as systematic profiling with significant effects or large-scale processing of health data. A support bot that sees order numbers is often below that bar, but many companies run a light DPIA anyway because it documents the design choices.
Is the EU-US Data Privacy Framework still valid in 2026?
Yes. The General Court dismissed the Latombe challenge in September 2025, and the appeal to the Court of Justice is pending. Because the framework could still fall, it is sensible to keep Standard Contractual Clauses in place as a fallback for US providers.
Is Mistral the safest choice for GDPR?
It helps, because Mistral is based in Paris and hosts data in the EU by default. But residency is one factor among several. Minimising what goes into prompts, controlling retention and logging, and signing the right contracts matter as much with any provider, including an EU one.
Adding AI to a product that serves Europe
If you want an LLM feature that your data protection officer will sign off, start with a scoping call. You get a written plan that names the provider, the region, the data flows and the safeguards, with a fixed price and four milestones you pay for only once each is done. See what hiring me looks like, read about AI and automation, or start a project today.
