Sovergate
← Back to Blog
Compliance12 min read · 5 October 2026

GDPR-Compliant LLM APIs Compared (2026)

Ten LLM APIs compared on the five things that decide whether an EU company can use them: the DPA, where inference runs, training, prompt retention and the CLOUD Act. Checked against vendor documentation in October 2026.

Short answer:no LLM API is GDPR-compliant on its own — you stay the controller. If you need frontier models, use Amazon Bedrock, Google Vertex AI or Azure OpenAI with an EU deployment (never “global”) and accept the residual CLOUD Act risk in your DPIA. If that risk is unacceptable, use an EU-headquartered provider: Mistral for the most capable models, or IONOS, STACKIT, OVHcloud or Scaleway for open-weight models that are not stored at all.

“Is this LLM API GDPR compliant?” is the wrong question, but it is the one every EU legal team asks. GDPR applies to you, not to the vendor. What differs between vendors is how much of your compliance work they make possible, and how much risk they leave you to document.

We compared the options EU companies actually shortlist: the two big US model labs, the three US hyperscalers' EU regions, and five EU-headquartered providers.

The five questions that matter

1. Is there a DPA, and how is it signed? Article 28 GDPR requires a written processor contract. Every provider in this comparison incorporates its DPA into its terms. Check which version you accepted, and file a copy.

2. Where does inference run — not just where data is stored? Many providers default to “global” routing, which can process your prompts in any region. EU storage at rest does not mean EU processing.

3. Is your data used for training? None of the paid API offerings below train on your prompts by default. Free tiers, feedback buttons and preview models are where exceptions hide.

4. How long are prompts retained, and can you turn it off? The default is often 30 days of abuse-monitoring logs. Zero data retention is usually approval-only — rarely a switch you can flip yourself.

5. Is the provider subject to the US CLOUD Act? A US company can be compelled to hand over data stored anywhere, including in its EU regions. Only ownership changes this, not location.

Every provider in this comparison offers a DPA and, for paid API use, does not train on your data by default. The real differences are questions 2, 4 and 5.

Comparison table

ProviderHQEU inferenceDefault prompt retentionZero retentionCLOUD Act
OpenAI APIUSApproved customers onlyUp to 30 days (abuse logs)On approvalYes
Anthropic Claude APIUSNo (global or US only)Up to 30 daysOn approvalYes
Azure OpenAI (Microsoft Foundry)USYes — Data Zone EU or regionalFlagged prompts may be stored for reviewOn approvalYes
Amazon BedrockUSYes — EU regions and EU inference profilesNone by default (some model exceptions)DefaultYes
Google Vertex AIUSYes — EU multi-region or regional endpoints24h cache; flagged prompts up to 90 daysPartly self-serveYes
Mistral AIFranceYes — via api.eu.mistral.ai30 days (abuse monitoring)On approvalNo US parent
IONOS AI Model HubGermanyYes — GermanyNot loggedDefaultEU parent, has US subsidiary
STACKIT AI Model ServingGermanyYes — GermanyNot storedDefaultNo US parent
OVHcloud AI EndpointsFranceYes — Gravelines, FranceBilling data onlyDefaultEU parent, has US subsidiary
Scaleway Generative APIsFranceYes — Paris, FranceNot stored (except abuse cases)DefaultNo US parent

“On approval” means the provider decides whether you are eligible, usually through its sales or account team. “Default” means prompts are not stored unless you opt in to something that stores them. Details and exceptions for each provider follow below.

US model labs, direct

OpenAI API

OpenAI offers EU data residency (requests go to eu.api.openai.com) and zero data retention, but neither is self-serve. You need approval for retention controls before you can create an EU-region project at all, and data residency endpoints cost 10% more for models released from March 2026. By default, abuse monitoring logs keep inputs and outputs for up to 30 days.

We cover the full setup, including where the settings live, in OpenAI and GDPR: what EU companies need to know.

Anthropic Claude API

Anthropic's direct API has no EU option. The inference_geo parameter accepts only global (the default, which may run in any geography) and us, and workspace data at rest can only be stored in the US. The DPA is incorporated into the commercial terms, and EEA customers contract with Anthropic Ireland.

Inputs and outputs are deleted within 30 days by default. Zero data retention is arranged through sales, and some of the newest models require 30-day retention regardless.

Want Claude with EU processing?Use it through Amazon Bedrock's EU inference profiles or Google Vertex AI's EU multi-region endpoint. Claude on Microsoft Foundry offers no EU data zone.

US hyperscalers in EU regions

Bedrock, Vertex AI and Azure can all keep inference inside the EU, and all three include the DPA in their standard terms. They share three catches: the “global” option is usually cheaper and routes outside the EU, the newest models often launch on global first, and the parent company is American.

Azure OpenAI (Microsoft Foundry)

  • —Three deployment types: Global (processed in any Azure region), Data Zone EU (processed within the EU Data Boundary) and Standard regional (processed in the chosen geography).
  • —Data Zone EU can include EFTA countries such as Norway and Switzerland, so it is not strictly the EU.
  • —New models arrive on Global first, then Data Zone, then regional — and regional has no guaranteed availability date.
  • —Data Zone deployments cost about 10% more than Global for current GPT models.
  • —Prompts are not used for training and not shared with OpenAI. Turning off abuse-monitoring storage requires applying for modified abuse monitoring, which is limited to managed customers.

Amazon Bedrock

  • —Bedrock does not store model inputs or outputs by default. Exceptions apply to some frontier models, whose traffic may be kept for up to 30 days for abuse detection.
  • —Use EU geographic inference profiles, not global ones. Global profiles route to all commercial regions and are about 10% cheaper — which is exactly why teams pick them by accident.
  • —Check the destination regions of each profile rather than relying on the prefix. Calling an EU profile from London or Zurich adds those regions as destinations.
  • —Some models are only available through global routing when called from EU regions. You can block global inference organisation-wide with a service control policy.
  • —The AWS European Sovereign Cloud (Brandenburg, generally available since January 2026) offers Bedrock, but with a very limited open-weight model selection so far.

Google Vertex AI

  • —The EU multi-region endpoint keeps machine-learning processing inside EU member states. The global endpoint gives no data residency guarantees.
  • —Gemini, Claude and Mistral models are available on the EU multi-region endpoint. Some preview models are only offered on global.
  • —Non-global endpoints cost about 10% more.
  • —Gemini caches data in memory for 24 hours by default; you can disable this per project.
  • —Abuse monitoring can log flagged prompts for up to 90 days. Customers under a Google Cloud Master Agreement are exempt by default; others must request an exception.

EU-headquartered providers

Mistral AI

Mistral is French, has no US parent and offers the most capable models of any EU-headquartered provider. The DPA is incorporated into its terms and data is hosted in the EU by default.

But EU hosting is not the same as EU inference. Mistral does not commit to an inference location on its default endpoint. For guaranteed EU inference, use api.eu.mistral.ai, which costs 1.1× and does not support Agents, Batch or Files. Prompts are kept for 30 days for abuse monitoring; zero data retention must be requested and justified, and Mistral decides.

Mistral's Labs and preview models are an exception to its no-training commitment. Keep personal data away from them.

IONOS, STACKIT, OVHcloud and Scaleway

These four EU cloud providers serve open-weight models — Llama, gpt-oss, Qwen, Mistral and Gemma variants — through OpenAI-compatible APIs, priced per token. All four state that prompts and outputs are not used for training, and all four process them in their own EU data centres.

  • —IONOS AI Model Hub (Germany): prompts are never logged, only metadata. The DPA applies as part of the contract and the service is in BSI C5 scope. Default rate limits are low.
  • —STACKIT AI Model Serving (Germany, Schwarz Group): no request data is stored and the service is in BSI C5 scope. It has the smallest model catalogue of the four.
  • —OVHcloud AI Endpoints (France): only billing data is kept and the DPA is part of the contract terms. SecNumCloud does not cover this service.
  • —Scaleway Generative APIs (France): prompts are not stored, except up to two weeks if your traffic harms the service. It has the broadest catalogue, including Mistral models, but retires models quickly.

The trade-off is model quality: none of these serve frontier models at the level of the newest GPT, Claude or Gemini releases. For extraction, classification, summarisation and RAG, open-weight models are often good enough. For complex reasoning, test before you commit.

Note that IONOS and OVHcloud both operate US subsidiaries. Their EU parent companies are not US persons, but lawyers disagree on how far a US subsidiary extends CLOUD Act reach. STACKIT (Schwarz Group) and Scaleway (iliad Group) have no US parent.

What about Aleph Alpha? It no longer offers a public pay-as-you-go API. Its PhariaAI platform is deployed on customer infrastructure, and in September 2026 it signed an agreement to merge into Cohere, pending regulatory approval.

Should you migrate from OpenAI to an EU-hosted model?

Switching providers will not save you from a GDPR fine on its own. Most GDPR enforcement around AI so far has targeted missing legal bases, missing transparency and missing processor contracts — fix those first. But US transfers are not risk-free either: Meta's €1.2 billion fine in 2023 was for transferring EU personal data to the US.

Migration makes sense when:

  • —your DPIA concludes that CLOUD Act exposure is not acceptable — common for health data, public sector work and some financial services;
  • —you cannot get OpenAI's approval for EU residency and zero retention, and a hyperscaler EU deployment is not an option either;
  • —your use case runs well on open-weight models, so you give up little quality.

The technical switch is small. The four EU clouds expose OpenAI-compatible APIs, so moving is often a change of base_url, API key and model name. The real cost is re-evaluating output quality on your own prompts.

What no API provider does for you

Whichever API you choose, these remain your obligations as the controller:

  • —a lawful basis under Article 6 GDPR for every AI feature that processes personal data;
  • —a DPIA where processing is high-risk, including the transfer risk of your chosen provider;
  • —an entry in your Record of Processing Activities;
  • —your own logs. If your AI system is high-risk under the EU AI Act, Article 12 requires you to keep automatic logs for at least six months — and zero retention at the provider means the provider keeps nothing for you. See how to log LLM calls for GDPR compliance.

Choosing an EU LLM provider and then sending your prompt logs to a US observability tool undoes the point. Your logs contain the same personal data as your prompts, so scrub PII before logging and keep them in the EU.

Frequently asked questions

Is there a GDPR-compliant LLM API?

No API makes you GDPR-compliant on its own, because you remain the controller. What a provider can offer is a DPA, inference inside the EU, no training on your data and little or no prompt retention. Amazon Bedrock, Google Vertex AI and Azure OpenAI can all keep inference in the EU if you avoid their global deployment options. EU-headquartered providers such as Mistral, IONOS, STACKIT, OVHcloud and Scaleway additionally avoid a US parent company.

Is the OpenAI API GDPR compliant?

It can be used compliantly — its DPA is incorporated into the OpenAI Services Agreement — but EU data residency and zero data retention are only available to customers OpenAI approves. Without approval, API data is processed by default outside a guaranteed EU region and kept for up to 30 days in abuse monitoring logs. OpenAI is a US company, so the CLOUD Act applies regardless of region.

Does EU data residency solve the CLOUD Act problem?

No. Residency controls where data is stored and processed. The CLOUD Act applies to providers under US jurisdiction regardless of where the data sits. Only providers without US ownership avoid it, and even EU-headquartered groups with US subsidiaries carry some debated exposure. Document the residual risk in your transfer impact assessment and DPIA.

Can I use Claude with EU data residency?

Not through Anthropic's direct API: as of October 2026 it offers only global or US-only inference. For EU processing, use Claude through Amazon Bedrock's EU cross-region inference profiles or Google Vertex AI's EU multi-region endpoint. Claude on Microsoft Foundry has no EU data zone.

Which LLM APIs do not store prompts?

Amazon Bedrock does not store inputs or outputs by default, with exceptions for some frontier models. IONOS, STACKIT, OVHcloud and Scaleway state that they do not store prompts. OpenAI, Anthropic, Azure OpenAI and Mistral keep prompts for abuse monitoring by default and offer zero data retention only on approval.

Sources

Provider terms change often. Check the current documentation before you sign or configure anything.

This comparison is maintained by Sovergate. We build EU AI Act Article 12 logging infrastructure for companies using LLMs in high-risk contexts — independent of which LLM provider you use. It is for informational purposes only and does not constitute legal advice.

Last checked against vendor documentation: 5 October 2026.

Picked your LLM provider? Now keep the logs in the EU too.

Two lines of code. PII scrubbed locally. Logs stored in Germany. Article 12 compliance reports ready for your legal team.