Skip to main content
gdpraigerman-companiesdata-sovereigntycompliance

GDPR-Compliant AI for German Companies

What GDPR-compliant AI requires — DPA, third-country transfers, training terms — and how to decide where each part of an AI system runs, model call included.

Jan ZajfertFebruary 19, 2026(Updated: October 1, 2026)9 min read

Your legal team just asked a question no one in the room could answer: does your AI vendor qualify as a data processor under GDPR, and if so, have you signed a data processing agreement with them? If the answer involves any hesitation, your company is probably in violation right now — not because you did something wrong, but because most AI tools were not built with this question in mind.

German mid-market companies between 20 and 500 employees are in a specific bind. Enterprise AI platforms from SAP or Microsoft are often oversized and expensive for a company this size, and take months to configure. Consumer tools like ChatGPT process data on servers in the United States, which brings GDPR Articles 44 to 49, the rules governing data transfers outside the EU, into play. The middle ground — a system built for your size, inside the tools you already use, with every transfer named and covered by contract — has been mostly empty.

What is GDPR-compliant AI?

GDPR-compliant AI is an AI system in which every processing step involving personal data is covered by a legal basis, a data processing agreement under Article 28 GDPR and, where data leaves the EU, a lawful third-country transfer, the model call included. AILoopwise agrees with you, per project, where each part of the system runs and who can access the data, and names the model call too, which with Claude does not run in Germany.

DSGVO-konforme KI Starts with Where the Data Lives

GDPR compliance for an AI system is not a policy you write. It is an architecture decision you make before writing a single line of code.

When a German mid-market company uses a US-based AI service, even through a European subsidiary, Article 44 applies: personal data may not be transferred to a third country unless that country ensures an adequate level of protection. The EU-US Data Privacy Framework is an adequacy decision, but it covers only certified companies, and it may fall the way its two predecessors did.

The practical consequence: if a tax advisory firm in Stuttgart uploads client documents to ChatGPT or another US-hosted AI service, that is a data transfer to the US. If those documents contain names, financial information, or tax IDs — they do, of course — that is a third-country transfer, and it needs a documented legal basis — which few AI vendors document cleanly.

The alternative: decide where the application and the data run, and choose where the model call goes. With Claude via Anthropic's API it goes to Anthropic, with no guarantee that it stays in the EU; with an EU-hosted or self-hosted model it can stay in the EU.

At AILoopwise we agree with you, per project, where each part of the system runs and who can access the data — typically inside your own systems and accounts. The model layer is not fixed: Anthropic's Claude via its API, or another provider where the project requires it. When a project uses Claude via Anthropic's API, the model call runs at Anthropic, not on a German server, and that step is governed by contract. If inference itself must stay in the EU, that belongs on the table before the project starts, because Anthropic's API does not guarantee it.

Data sovereignty for AI means knowing, for every step, where it runs and who can access it — the model call included — and being able to name it to your auditor. Not a DPA document you sign and forget.

Private AI Germany: The Architecture Behind the Compliance

GDPR Article 28 requires that if you use a third party to process personal data on your behalf — a data processor — you must have a written contract specifying what they can do with that data. Most AI vendors offer this as a standard DPA. The problem is not the contract. The problem is what happens to the data technically, regardless of what the contract says.

Three points decide whether a DPO can sign off on an AI deployment: where each part of the system runs, who can access the data, and whether the model provider trains on it.

Where each part runs. Application, database, document index and model call are separate steps, and each can run somewhere different. A system built into your own infrastructure keeps most of them in systems you already administer; the model call is the step that most often runs elsewhere, and with Claude via Anthropic's API it does.

Who can access the data. In a hosted product, the separation between customers and departments is the vendor's design, assessed from its documentation and contract. In a system built into your own tools, it rests on the accounts and access rights you already manage, and your DPO checks it the same way as the rest of your IT.

Training on your data. It depends on the provider and the contract; the blanket line that no provider trains on your data is wrong. Anthropic writes for its commercial products, including the API: "By default, we will not use your inputs or outputs from our commercial products"; an exception applies when users explicitly send feedback (Anthropic Privacy Center, read 2026-09-30). Mistral describes an opt-out right for pay-as-you-go API customers instead: "Customers retain full control over this processing and have the right to opt out at any time." (Mistral Help Center, read 2026-09-30). An opt-out has to be exercised; it does not exclude training by default. Independently of training, a language model does not take your documents into its weights: they are retrieved for context and used for one response. The provider does store inputs and outputs for a limited period; for the Anthropic API the default is 30 days (Anthropic Privacy Center, read 2026-09-30).

These three points together — where each part runs, who can access the data, and which providers' terms exclude training — are what a DPO (Datenschutzbeauftragter) needs to sign off on an AI deployment. Not a vendor's marketing page, but answers they can check.

What Private AI Actually Means for Your Team

The compliance story matters to your legal and data protection teams. The people using the system every day have a more immediate question: does it actually work?

A mid-sized German company typically has its knowledge distributed across three places. Internal documents — PDFs, Word files, policy manuals — sitting on a file server or in SharePoint. Structured data in systems like DATEV, SAP, or a CRM. And tacit knowledge in people's heads that never got written down.

A private AI deployment addresses the first category directly. Upload your document library once. The system processes each file — PDFs, Word documents, CSVs — chunks them into segments the LLM can reason over, embeds them into vectors, and stores them in an index. After that, your team queries the library in plain German.

"Was sagt unsere Betriebsvereinbarung zu Homeoffice-Regelungen?" The system retrieves the relevant sections, passes them to the LLM with the question, and returns an answer with citations to the source documents. The answer is only as good as what is in your documents — which is exactly what you want, because the system is not guessing or hallucinating from training data. It is reading your files.

For a tax advisory firm with 50 employees, this might mean thousands of regulatory documents instantly searchable. For a manufacturing company, it might mean maintenance manuals for 200 machines accessible from a tablet on the shop floor. The same approach handles both; the use case is yours to define.

One honest caveat: a document-based system only knows what you have put into it. Tacit knowledge, undocumented decisions, and data sitting in DATEV or SAP require additional integration work. The document layer is the right starting point for most companies, but it is a starting point.

Frequently Asked Questions

What is GDPR-compliant AI exactly?

An AI system in which every processing step involving personal data has a legal basis, a data processing agreement under Article 28 GDPR and, where data leaves the EU, a lawful third-country transfer. That includes the model call. Where each part runs is something AILoopwise agrees with you per project.

Does AI have to be hosted in Germany to be GDPR-compliant?

No. Article 44 GDPR restricts transfers to third countries, not within the EU, and Article 45 allows transfers on the basis of an adequacy decision. European hosting is a risk decision against adequacy decisions that can fall, not a legal obligation.

Do you need a data processing agreement for AI?

Yes, as soon as an external provider processes personal data on your behalf. Article 28(3) GDPR prescribes its contents, from documented instructions to audit rights.

Do AI providers train on my data?

Each provider sets its own rule. Anthropic does not use inputs and outputs from its commercial products, including the API, for training by default; Mistral gives pay-as-you-go API customers an opt-out right that has to be exercised.

Does AILoopwise run the language model in Germany?

It depends on the project. For a project that uses Claude via Anthropic's API, no: the model call runs at Anthropic, not on a German server. We agree with you, per project, where each part of the system runs and who can access the data — typically inside your own systems and accounts.

The Compliance Requirements and the Product Requirements Are the Same

GDPR-compliant AI turns out to be more useful for mid-market companies than non-compliant alternatives — not as a coincidence, but as a direct result of how the constraints shape the system.

Building the system on your own documents means the AI's answers rest primarily on them, not on someone else's. Excluding training provider by provider, in the contract, means your competitive information stays yours.

A vendor who builds for the global consumer market and bolts on a DPA afterward has to paper over the gaps between how the system works and what the contract says. A system designed for GDPR from the architecture up names its remaining gaps, such as the model call, instead of papering over them.


Book a 30-minute intro call — we go through your documents and the systems you already use, and show you where each part of an AI system would run in your setup.

Claude and Anthropic are trademarks of Anthropic, PBC. AILoopwise is an independent AI implementation company; the use of these names does not imply endorsement by Anthropic.

GDPR-Compliant AI for German Companies | AILoopwise