When a transfer occurs at all
According to the European Data Protection Board's Guidelines 05/2021, version 2.0, a transfer occurs when three conditions are met: the exporter is subject to the GDPR for the processing, it makes the data available to another controller or processor, and that recipient is located in a third country. An EU processor that passes data to a sub-processor in a third country also makes a transfer. Your own employee accessing data from abroad, by contrast, is not another controller; that is not a transfer, but the security obligations remain.
In practice, this means: “EU-hosted” is not enough if a group company, a support team or a security team outside the EEA can access the data as a separate entity; group companies are legally separate entities. And even without a transfer, the same guidelines require the controller to take into account the legal risks of any third country in which its service provider is involved.
What a transfer can rely on
- Adequacy decision. For US organisations that participate in the EU-US Data Privacy Framework, data may flow freely, according to the Commission's page. Check the certification of the specific legal entity and the categories of data covered, not the group brand.
- Standard contractual clauses under Implementing Decision (EU) 2021/914, combined with an assessment of the law and practice of the third country and, where necessary, supplementary measures. This follows from the Schrems II judgment (C-311/18) and the Board's Recommendations 01/2020.
- Derogations under Art. 49 GDPR, such as consent in an individual case. For regular processing, they are not a viable route.
Where things stand: the General Court of the European Union dismissed the Latombe action against the adequacy decision on 3 September 2025 (T-553/23). The appeal C-703/25 P is pending before the Court of Justice as of 23 September 2026; there is no Advocate General's opinion or judgment yet. This translates into a design rule: keep a fallback route to standard contractual clauses ready, together with triggers for reassessment, because certification and adequacy status can change.
The map you need
For every operation, that is storage, model processing, monitoring, support, abuse review, incident handling and backups, you should record: exporter and importer as legal entities, countries, data and purpose, frequency, model and cloud route, transfer mechanism, impact assessment, supplementary measures, handling of government access requests, and deletion route.
This is work, and it shows you how many operations you had not counted before. The fewer stations a tool has, the shorter the map; but it will not be empty for any service that uses models outside your organisation.
What two major providers state themselves
| OpenAI (ChatGPT Enterprise, Edu, API) | Data storage in Europe can be selectedSince 5 February 2025, OpenAI has offered data residency in Europe for ChatGPT Enterprise, ChatGPT Edu and the API, and since 16 January 2026 also processing on GPUs in Europe for eligible Enterprise, Edu and Healthcare customers. According to its pricing overview, ChatGPT Business has no data residency. Source. |
|---|---|
| Anthropic (Claude) | Storage in the USAccording to Anthropic, it may route requests to selected countries in the US, Europe, Asia and Australia; the data is stored in the US. For the API, US-only processing can be selected, at 1.1 times the price for newer models; Enterprise plans with usage-based billing can also choose where processing takes place. Anthropic does not document an EU-only option. Source. |
| Both | “No training” is not “no storage”These are four different commitments: no training, no retention, no human review, region. They differ by product and by layer. |
What companies in Germany say
- 71%
- use cloud services from US providers
- 8%
- would prefer US providers; 91% would prefer providers from Germany
- 43%
- currently see no equivalent European alternative to the US hyperscalers
- 87%
- miss transparency about data processing and access rights in “sovereign” offerings from international providers
Source: Bitkom Cloud Report 2026, published on 17 June 2026; telephone survey of 603 companies with 20 or more employees. The first two figures refer to companies that use or plan to use the cloud, or for which the provider's origin matters. 64% of cloud users feel compelled by the US government's policies to rethink their cloud strategy, up from 50% the year before. The last figure explains why a seal alone no longer convinces: people are asking about access rights.
The honest paragraph about us
Biwak also uses external services, some of them international. The website and account service run at Vercel Inc. in the US, with the account service pinned to Frankfurt; the database for the Biwak account is operated by Supabase Pte. Ltd of Singapore in Frankfurt am Main. Standard contractual clauses apply to both. Model requests go from your computer via this service to Microsoft Azure. The contracting party is Microsoft Ireland Operations Limited in Dublin, a company of the US group Microsoft; processing happens in Azure's EU Data Zone, and stored data remains in Germany. According to Microsoft, inputs and outputs are accessible neither to other customers nor to the model makers; suspicious requests may be stored for abuse detection and reviewed by humans. Only if Azure rejects a task does it go to PREM SA in Lugano, Switzerland, which is covered by an adequacy decision under Art. 45 GDPR. Prem forwards to its compute partners Nebius and TensorX in the EU and the United Kingdom; access runs over Cloudflare's network. The recipients and their addresses are listed in section 9, the model route in section 14 of the privacy policy.
So at Biwak, “Processed in the EU” means: processed in Azure's EU Data Zone, which according to Microsoft can also include EFTA states such as Norway and Switzerland, with a company of the US group Microsoft as contracting party; as a fallback, a contracting party in Switzerland, with computing partners in the EU according to Prem. By the standard of this article, the Azure route therefore also belongs in your assessment. If you need a chain entirely within the EEA, Biwak cannot currently provide it.
What you should ask a provider
- Which legal entities, not brands, process the data, and in which countries?
- Who can access it, and from which country: support, security, operations, abuse review?
- Which layer does each commitment apply to: workspace, local program, cloud, API, extensions?
- Which mechanism justifies the transfer, and has the third country been assessed?
- What happens with government access requests, and will you be informed about them?
- How is data deleted, including from queues, caches and backups, and how is that proven?
Frequently asked questions
Does an EU region solve the third-country problem?
Only if no other entity outside the EEA gains access. The assessment follows access, not just the location of the data centre. So do not just ask about the region; ask about remote access by support, security and operations, and have the countries and legal entities named.
Is the EU-US Data Privacy Framework safe?
It is in force: the Commission permits transfers to participating US organisations, and the General Court of the EU dismissed the Latombe action on 3 September 2025. The appeal C-703/25 P is pending as of 23 September 2026. If you rely on the framework, keep a fallback route to standard contractual clauses and a trigger for reassessment ready.
We use a German tool. Is that enough?
Only if the chain underneath fits as well. A German provider with a US model in the background transfers data, and that transfer is attributable to you. The question is never the company address, but the list of sub-processors with legal entity, country and mechanism.
What if we want to avoid third-country transfers entirely?
Then check every station, including model providers, support access and the services behind the website and account. Biwak does not currently meet this requirement: the fallback contracting party for the models is PREM SA in Switzerland, and the services for the website and account are based in the US and Singapore. Even on the primary route, Microsoft Azure in the EU Data Zone, the contracting party is a company of the US group Microsoft.
Sources
- EDPB: Guidelines 05/2021 on the interplay between Art. 3 and Chapter V GDPR, version 2.0
- EDPB: Recommendations 01/2020 on supplementary measures, version 2.0
- European Commission: EU-US data transfers (Data Privacy Framework)
- Court of Justice of the EU: Case C-703/25 P (Latombe v Commission)
- Implementing Decision (EU) 2021/914 (standard contractual clauses for third-country transfers)
- OpenAI: Data residency in Europe, 5 February 2025, updated on 16 January 2026
- Anthropic: Where are your servers located?, 15 June 2026
- Anthropic: Data residency (inference_geo), documentation
- Bitkom: Cloud Report 2026, 17 June 2026
- Biwak: Privacy policy, sections 9 and 14
This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.
