You recognise a GDPR-compliant AI tool by five answers.
GDPR-compliant AI tools process your data inside the EU, contractually exclude its use for model training, disclose their subprocessors, offer a data processing agreement under Art. 28 GDPR and delete on request with proof. If any one of those is missing, the tool is not defensible for internal documents, no matter how well the model answers.
The department that wants an AI tool rarely decides alone. Sooner or later someone from IT or privacy joins the table and asks questions a product demo does not answer. This page collects exactly those questions, explains why they get asked, and turns them into a checklist you can take into your next vendor call.
What does GDPR-compliant even mean for AI?
One clarification simplifies a lot: GDPR-compliant is not a certificate a product either carries or lacks. There is no seal to buy and no authority that approves AI tools. What can be compliant is a specific processing operation, in a specific company, for a specific purpose.
That has an uncomfortable consequence: responsibility stays with you. The vendor is a processor, you are the controller under the GDPR. When a vendor advertises that its tool is GDPR-compliant, that is at best shorthand for "we provide the building blocks you need for a compliant deployment". At worst it is marketing.
So it does not pay to look for the seal. It pays to ask for the building blocks. Five of them decide almost everything.
The five points that decide everything
- Data processing agreement
- Without an agreement under Art. 28 GDPR there is no basis for a service provider to process personal data on your behalf. The DPA governs purpose, duration, categories of data and the technical and organisational measures. It belongs in the standard package, not in an ad-hoc negotiation.
- Subprocessors
- Almost every AI product relies on further providers, at minimum for hosting and for the language model. You need the full list with role and location, plus a commitment that changes are announced in advance. A vendor who will not share that list cannot answer your question about the data path.
- Server location
- Where do documents, index and embeddings live, and where does the language model run? Those are two separate questions and they get conflated constantly. A vendor can host in Frankfurt and still call a model in the US for every answer. Both paths belong on the table.
- Training exclusion
- Are your inputs used to improve models? What matters is not the toggle in the settings but the contractual commitment. An update can reset a toggle. It cannot reset a contract.
- Deletion terms and proof
- How long does a full deletion take, what exactly does it cover, and do you get a record of it? Document copies, index, embeddings and caches are four different things. A deletion promise that only covers the document copies is incomplete.
Checklist for IT and privacy
Ten questions every vendor should face. A vendor who answers all ten with evidence is auditable. One who dodges more than two is not.
Is there a data processing agreement under Art. 28 GDPR, with the technical and organisational measures attached?
Without a DPA there is no legal basis for processing by a service provider.
Is there a complete subprocessor list with role and location?
Without it the data path cannot be assessed, not even by the best privacy officer.
Are subprocessor changes announced in advance, with a right to object?
Otherwise the data path changes without you finding out.
Where do document copies, index and embeddings live, and in which country?
Storage location determines third-country transfer and applicable law.
Where does the language model run, and who operates it?
Hosting and model calls are two separate paths. Usually only one gets mentioned.
Is the use of your data for model training contractually excluded?
A setting in a portal is not a commitment. An update can reset it.
How long does a full deletion take, and what exactly does it cover?
Document copies, index, embeddings and caches are four different things.
Do you receive a record of the deletion?
Without proof you cannot evidence the deletion internally.
Are there role-based access rights and audit logs for production access?
Not everyone in the company should be able to query every document.
Who at the vendor can access production customer data?
A named, logged group is something else than "our staff".
This checklist does not replace a legal assessment of your specific deployment. It covers the points that experience shows decide vendor selection.
US vendors and the Cloud Act, without the drama
The US Cloud Act obliges US companies to hand over data on a lawful order, including data stored outside the United States. What counts is control over the data, not the location of the server. A European data centre operated by a US group therefore does not fully resolve the question.
That does not make US vendors unusable. The EU-US Data Privacy Framework provides an adequacy decision that transfers can rely on, and many companies work on exactly that basis. It does mean a residual risk remains, one you should assess deliberately rather than overlook.
The balance lands differently depending on the data. For marketing copy it is uncritical. For engineering drawings, costings or test reports it is not, because trade secret protection sits alongside data protection there. In that category many industrial companies deliberately choose a European path.
This page does not replace legal advice. It is meant to give you the questions you take into the internal discussion.
What goes wrong in practice
- The toggle instead of the contract
- Switching training off in the settings feels like the job is done. It is a configuration, not an entitlement. If the commitment is not in the contract, you do not have it.
- The pilot without privacy
- A team starts a test, uploads real documents and seeks approval afterwards. If the data protection officer then says no, the effort is lost and trust is damaged. Approval before the test costs two weeks. Approval after the test can cost the project.
- An EU region is not an EU vendor
- Selecting a European region in a cloud console does not change which group owns the provider. That is a different matter from a European company running European infrastructure, even when both look identical on a slide.
- Shadow IT is the real exposure
- As long as there is no approved route, an unapproved one appears by itself. Engineers paste specifications into private chatbot accounts because they need an answer. A properly vetted tool is therefore also a privacy instrument: it removes the reason for the detour.
How KoAssist meets these requirements
KoAssist is built for exactly this review. Hosting and indexing run in ISO 27001 certified data centres in Germany, language processing through a European provider on EU infrastructure. There is no US provider in the data path.
The Art. 28 DPA is standard, with the technical and organisational measures attached. The subprocessor list with roles and locations is part of the security document, and changes are announced 30 days in advance. Training on your data is contractually excluded and technically isolated. On written request all data held by us is deleted within 48 hours, including index, embeddings and caches, with a deletion record.
One more point goes beyond privacy: every answer cites file and page. That is not only about verifying the substance. It also makes visible which document was drawn on in the first place.
What IT and privacy usually ask next
The answers refer to running AI systems on internal company documents.
Is there a GDPR certificate for AI tools?
No. There is no official seal that designates an AI product as GDPR-compliant. What can be compliant is a specific processing operation, not a product as such. Vendors can demonstrate that they supply the necessary building blocks: a data processing agreement, disclosed subprocessors, server location, training exclusion and deletion commitments. Assessing the deployment remains with the controlling company.
Is EU hosting by the vendor enough?
Not necessarily. Alongside the storage location, what matters is who controls the data and where the language model runs. A US group with a European data centre still falls under the US Cloud Act. And a vendor can host in Germany while calling a model outside the EU for every answer. Ask about both paths separately.
What is the difference between excluding training by setting and by contract?
A setting is a configuration that can change, including through a product update or a change of plan. A contractual commitment is an enforceable right. For internal documents the commitment should sit in the data processing agreement or the terms, not only as a toggle in a portal. When in doubt, ask to be shown the clause.
Do we need a data protection impact assessment?
That depends on the use case. It becomes relevant when the processing is likely to result in a high risk to the rights of data subjects, for example large-scale processing of personal data or systematic evaluation of employees. Searching technical documentation without personal data is usually assessed differently from HR data. That assessment belongs with your data protection officer.
How do we handle documents containing personal data?
Technical documents carry personal data more often than expected, for instance names of inspectors, engineers or contacts in reports. What works in practice is usually a combination of role-based access rights, clearly separated knowledge spaces and a deliberate decision about which repositories get connected at all. Not every source has to enter the index just because it technically could.
What should be settled before a pilot?
At least three things: the data processing agreement is signed, the subprocessor list has been assessed, and it is agreed which repositories the pilot connects. Postponing these until after the test risks having to repeat it, or losing approval altogether. Settling them upfront usually takes less time than fixing them afterwards.
Less searching.
More engineering.
In a 30-minute demo, we show KoAssist working with your own documents and discuss setup, integrations and pricing for your team size.