EU vs US Hosting for AI Agents, Data Residency
Direct answer: If your AI agent handles personal data about people in the EU, where that data is processed is a legal question, not a formality. The EU's top court struck down the old Privacy Shield framework in its Schrems II ruling. A replacement exists, the EU-US Data Privacy Framework, and US companies can certify under it. EU hosting is still the simpler option for most regulated buyers, because it avoids the transfer question rather than answering it.
Where a cloud AI agent processes data is not a technicality. It has been to court, twice. Anyone deploying an agent for EU customers needs a working grasp of it, even when a vendor handles the implementation.
Ojin is a Berlin company and sells EU data residency, so it has a commercial interest in this answer.
The Schrems II background, briefly
In 2020, the Court of Justice of the European Union's Schrems II ruling invalidated the EU-US Privacy Shield, a framework that had previously provided a straightforward mechanism for transferring personal data from the EU to the US. The court found that US surveillance law did not protect EU citizens to the standard EU law requires (Case C-311/18, 16 July 2020).
That left companies two options. Use a different transfer mechanism, usually Standard Contractual Clauses with extra safeguards on top, which the European Data Protection Board set out in its Recommendations 01/2020. Or keep EU data in the EU and avoid the question.
This created genuine legal uncertainty and additional compliance burden for any company transferring EU personal data to US-based infrastructure, including AI agent platforms processing EU customer data on US servers, for several years following the ruling.
The current framework: EU-US Data Privacy Framework
In 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework, a new mechanism (replacing the invalidated Privacy Shield) that allows transfers of EU personal data to US companies that have self-certified compliance with the framework's requirements. This provides a legally recognised pathway for EU-to-US data transfers that did not exist in the years immediately following Schrems II.
However, this framework has itself faced legal challenges from privacy advocacy groups on grounds similar to those that led to Schrems II's invalidation of the previous framework, and its long-term legal durability is not guaranteed to remain unchallenged indefinitely. Companies relying on this framework for AI agent deployments involving EU personal data should treat it as the current best available mechanism, while remaining aware that this area of law has changed before and could change again. The full text is Commission Implementing Decision (EU) 2023/1795, published on EUR-Lex. It lists the safeguards, the redress route and the review schedule. Read it rather than a summary if the decision matters to your deployment.
Why EU hosting remains the simpler path for many companies
Regulated buyers ask this before they ask anything about conversation quality.
Many companies now keep EU data in the EU and stop there. That is most common in finance, healthcare and anything selling to the public sector, where a buyer will ask the question in procurement whatever the law currently allows. It requires a vendor with real EU deployment, not a compliance page.
Hosting location is not the only thing that decides where data can be reached, either. Hosting location is not the whole answer. The US CLOUD Act lets US authorities compel a US provider to hand over data it holds, wherever the servers are. So ask who controls the processing company, not just which data centre runs the workload.
EU hosting does not clear the rest of GDPR. Lawful basis, data subject rights and data protection by design all still apply, as covered in GDPR and AI agent deployments. It removes one contested question, not the obligation.
Where the company sits, and why that is not the whole answer
Ojin is headquartered in Berlin and offers a Data Processing Agreement covering GDPR obligations for its Human AI Agents. Where processing happens is confirmed in the contract for each customer, rather than inferred from the head office address.
Apply that standard to every vendor, Ojin included. "EU compliance" is used as marketing language by companies with no EU infrastructure behind it. The checkable question is where processing and storage actually happen for your deployment.
What this means practically for a procurement decision
Ask whether EU hosting is the default or a paid region option. The answer differs by vendor, and it belongs in the contract rather than in a sales conversation.
Three questions settle it, and they sit alongside build versus buy.
Does the vendor host in the EU, for your deployment rather than in general. Will they put it in the contract. And if data does leave the EU, which transfer mechanism are they relying on.
Get the answers into the contract. "GDPR compliant" is a broader claim than a residency guarantee, which is why vendors reach for it.
If you are already running on US infrastructure
Most companies asking this question are not starting fresh. They have an agent live on a US
platform and someone in legal has just raised it.
Find out what actually leaves the EU. Not everything does. In many stacks the transcript
crosses the Atlantic and the recording does not, or the reverse. The answer is per component,
and most teams have never mapped it.
Check whether your vendor is certified. The EU-US Data Privacy Framework covers US companies
that have self-certified. If yours has, you have a lawful basis today. If it has not, you are
relying on Standard Contractual Clauses and you need the supplementary measures to go with them.
Work out what a move would cost. Conversation history, embeddings, recordings and audit logs
all live somewhere. Getting a number for that migration makes the decision concrete instead of
theoretical.
Decide on a trigger, not a date. Most teams cannot move immediately and do not need to. What
they need is a written answer to what would force the move: a new regulated client, a public
sector tender, or another adverse ruling.
Where the argument usually lands
For a consumer app with EU users and no regulated buyer, US hosting under the current framework
is defensible and plenty of serious companies do it.
For anything selling into finance, healthcare, insurance or the public sector, EU hosting tends
to win on procurement grounds before it wins on legal ones. The buyer's own compliance team asks
the question, and an EU answer ends the conversation in one line while a US answer starts a
review.
That is the practical split. The law permits both. Procurement does not treat them equally.
What procurement actually asks
Procurement asks four questions, usually in this order.
Where is the data processed, physically. Not the vendor's headquarters, not where the contract is signed. Which region the inference runs in and which region the recordings sit in, named, and contractually fixed.
Who is the processor and who is the controller. In almost every deployment the customer is the controller and the vendor is the processor, and the Data Processing Agreement has to say so before legal will look at anything else.
What happens on subprocessors. Most AI stacks are assembled from several vendors, and each one that touches personal data is a subprocessor that has to be listed and notified on change. This is where "we are EU-based" claims usually come apart, because the face model is EU-hosted and the language model behind it is not.
What the exit looks like. How data is returned, in what format, and how quickly it is deleted afterwards. Most buyers raise this late, but they do raise it.
Vendors who answer all four specifically clear legal review faster than vendors who point at a compliance page.
The cost of getting it wrong later
Rehosting a live deployment is not a configuration change. Conversation history, embeddings, recordings and audit logs all live somewhere, and moving them mid-contract means a migration project nobody budgeted for, usually triggered by a compliance review rather than a technical need.
That is the argument for settling the question at selection. Fixing the region before the first production conversation avoids the migration entirely.
Public bodies apply a stricter test than commercial buyers, and they apply it earlier.
Several EU member states have their own sovereignty requirements layered on top of GDPR, and some
will not accept a US-owned processor regardless of where the servers sit, because of the CLOUD
Act point above. For those buyers, EU hosting is a qualification criterion rather than a
preference, and a vendor without it is filtered out before the evaluation begins.
Frequently asked questions
Does GDPR compliance require EU hosting, or is US hosting with appropriate safeguards also compliant?
GDPR does not strictly require EU hosting, transfers to the US (or other countries) are permitted with appropriate safeguards, currently including reliance on the EU-US Data Privacy Framework for certified companies, or Standard Contractual Clauses with supplementary measures for others. EU hosting is the simpler, lower-uncertainty path given the legal history around cross-border transfer mechanisms, but it is not the only compliant option.
Where does Ojin sit on this?
Ojin is a German company based in Berlin and provides a Data Processing Agreement. Region of processing is set per deployment and confirmed in the contract, so the honest answer is to ask for it in writing rather than infer it from the head office address.
Is the EU-US Data Privacy Framework likely to be invalidated the way the previous Privacy Shield was?
This cannot be predicted with certainty. The framework has faced legal challenges, and its underlying legal basis addresses some but not necessarily all of the concerns that led to the Privacy Shield's invalidation. Companies relying on it should stay informed of relevant legal developments rather than assuming permanent stability, and should consider EU hosting as a hedge against this uncertainty for higher-stakes or highly regulated deployments.
Does data residency within the EU protect against all forms of data access risk, including EU government access?
EU-based hosting addresses the specific cross-border transfer concerns central to the Schrems II line of cases, which focused on US government surveillance access to data transferred to US infrastructure. It does not eliminate all conceivable data access risk (EU law enforcement access under appropriate legal process, for instance, remains a separate consideration), but it does address the specific, historically significant compliance risk that has driven much of the EU-US data transfer debate.
Next steps for choosing a hosting region
See also: Cloud AI Agent, the full guide · GDPR and AI agent deployments · Brand safety when deploying a Human AI Agent · Demo: docs.ojin.ai
