A procurement and governance checklist for European businesses assessing AI tools that may process personal data.
The three questions that actually decide this
"Is this AI tool GDPR compliant?" is the wrong question — compliance is a property of how you use a tool, not of the tool itself. Three concrete questions determine whether a given tool can be used lawfully in a European business.
- Does your input get used to train the provider's models? If yes, you have almost certainly lost control of personal data in a way you cannot undo or explain to a data subject.
- Where is the data processed and stored? Transfers outside the EEA need a lawful transfer mechanism.
- Can you get a Data Processing Agreement and a sub-processor list? Without a DPA under Article 28, you cannot lawfully use a processor at all.
Nearly every practical decision follows from these three.
Consumer tier versus business tier — the single biggest factor
The same brand can be both compliant and completely unusable depending on which tier you buy. This is the most common and most expensive mistake European businesses make.
| Free / consumer accounts | Business, Team or Enterprise tiers | |
|---|---|---|
| Training on your data | Commonly enabled by default | Contractually excluded on major business tiers |
| DPA available | Usually not | Yes |
| Sub-processor transparency | Limited | Documented and usually change-notified |
| Admin controls, retention settings | Minimal | Configurable |
| Audit logging | No | Yes |
| Suitable for personal or confidential data | No | Yes, with proper configuration |
The practical rule: an employee using a free AI account with customer data is a data protection incident waiting to be discovered. The remedy is usually not banning AI — it is buying the business tier and blocking the consumer one.
Where the major providers stand
Positions change, so verify current terms before relying on this — but broadly:
| Provider | EU data residency | Training on business data | Notes |
|---|---|---|---|
| Microsoft Copilot (M365) | EU Data Boundary available | Excluded for commercial data | Strongest position for organisations already in Microsoft 365; inherits existing tenant controls |
| Google Workspace / Gemini | EU regions available | Excluded for Workspace business data | Similar inheritance benefit for Workspace organisations |
| OpenAI (Team/Enterprise/API) | EU data residency offered on business plans | Excluded by default on business tiers and API | Consumer ChatGPT is a different proposition entirely |
| Anthropic Claude (Team/Enterprise/API) | Commercial terms exclude training on business inputs | Excluded by default | DPA available |
| AWS Bedrock / Azure OpenAI | Choose your region explicitly | Not used to train foundation models | Best control for regulated workloads; the model runs inside your cloud tenancy |
For heavily regulated European organisations, running models through Azure OpenAI or AWS Bedrock in an EU region is usually the cleanest answer, because it turns an AI question into a cloud question you have already answered.
Transfers outside the EEA
Post-Schrems II, transfers to the US rest on the EU–US Data Privacy Framework for certified organisations, or Standard Contractual Clauses plus a transfer impact assessment. Most major AI providers are DPF-certified, which simplifies this considerably — but check current certification status rather than assuming, and keep the assessment on file.
If you would rather not have the argument at all, EU-region processing removes the transfer question entirely.
The EU AI Act sits on top of GDPR
They are separate regimes and you need both. GDPR governs personal data; the AI Act governs the AI system by risk tier. For most business use — drafting, summarising, coding assistance, internal search — you land in the limited or minimal risk tiers, where the main obligations are transparency and AI literacy.
The tiers that create real work are the prohibited practices (which include some emotion recognition in workplaces) and high-risk uses, which notably include employment, worker management and access to essential services. If you are using AI in recruitment or HR decisions in Europe, that is a materially different compliance exercise, not a routine tooling choice.
A workable policy for most businesses
- Choose one approved platform per use case and licence it properly at business tier.
- Block the consumer equivalents at the network or identity layer — otherwise shadow use continues.
- Publish a short acceptable-use rule in plain language: what may go in, what may not, and who to ask.
- Complete a DPIA where the use is likely high risk — particularly anything touching HR, monitoring or vulnerable individuals.
- Record the tool in your ROPA with lawful basis, retention and transfer mechanism.
- Configure retention to the shortest period that meets the business need.
- Keep a human review step wherever output affects a person's rights, employment or access to a service.
Frequently asked questions
Can we use AI on customer personal data at all?
Yes, with a lawful basis, a DPA, appropriate configuration and transparency to data subjects. The prohibition people imagine does not exist — the discipline required does.
Is an on-premise or open-weight model automatically safer?
It removes the transfer and processor questions, but you inherit every security, retention and access control obligation yourself. Safer only if you actually operate it well.
Do we need consent to use AI on personal data?
Usually not — legitimate interests or contract are more often the appropriate basis. Consent is frequently the wrong basis for workplace processing because it is rarely freely given.

