EU vs US Hosting for AI Agents, Data Residency
Direct answer: For a company processing personal data of EU residents through an AI agent, where that data is hosted and processed is a live legal question, not a settled formality, following the Court of Justice of the EU's Schrems II ruling, which invalidated the previous EU-US Privacy Shield framework and raised the bar for transfers of EU personal data to the United States. The current EU-US Data Privacy Framework (adopted in 2023) provides a mechanism for compliant transfers to certified US companies, but EU-based hosting remains the simpler, lower-risk path for many companies, particularly those in regulated industries or serving EU public sector clients, because it avoids the cross-border transfer question entirely.
Data residency for cloud AI agent deployments serving EU users is not an abstract compliance nicety, it is a specific legal question with a history of regulatory and judicial scrutiny that companies deploying AI agents for EU customers need to understand, at least at a working level, even when relying on a platform vendor to handle the technical implementation.
Ojin is a Berlin company and hosts in the EU, so the answer below is one it has a commercial interest in. That does not change the law, but it is worth saying out loud.
The Schrems II background, briefly
In 2020, the Court of Justice of the European Union's Schrems II ruling invalidated the EU-US Privacy Shield, a framework that had previously provided a straightforward mechanism for transferring personal data from the EU to the US. The ruling (Case C-311/18, 16 July 2020) found that US surveillance law did not provide EU data subjects with protections equivalent to EU law, which meant companies could no longer rely on the invalidated framework and needed to either use other transfer mechanisms (like Standard Contractual Clauses, with additional safeguards, which the European Data Protection Board spelled out in its Recommendations 01/2020 on supplementary measures) or avoid the cross-border transfer question by keeping EU personal data within the EU.
This created genuine legal uncertainty and additional compliance burden for any company transferring EU personal data to US-based infrastructure, including AI agent platforms processing EU customer data on US servers, for several years following the ruling.
The current framework: EU-US Data Privacy Framework
In 2023, the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework, a new mechanism (replacing the invalidated Privacy Shield) that allows transfers of EU personal data to US companies that have self-certified compliance with the framework's requirements. This provides a legally recognised pathway for EU-to-US data transfers that did not exist in the years immediately following Schrems II.
However, this framework has itself faced legal challenges from privacy advocacy groups on grounds similar to those that led to Schrems II's invalidation of the previous framework, and its long-term legal durability is not guaranteed to remain unchallenged indefinitely. Companies relying on this framework for AI agent deployments involving EU personal data should treat it as the current best available mechanism, while remaining aware that this area of law has changed before and could change again. The adequacy decision itself is published in full on EUR-Lex as Commission Implementing Decision (EU) 2023/1795 of 10 July 2023, which sets out the specific safeguards, redress mechanisms, and periodic review process the Commission relies on, and is the primary reference for any company wanting the actual legal text rather than a secondary summary of it.
Why EU hosting remains the simpler path for many companies
This is the question Ojin is asked first by any regulated buyer, ahead of anything about conversation quality, and it is the right order to ask them in.
Given this legal history and ongoing uncertainty, many companies, particularly those in regulated industries (finance, healthcare, government-adjacent services) or those serving EU public sector clients with specific data sovereignty requirements, choose to avoid the cross-border transfer question entirely by ensuring EU personal data processed through an AI agent is hosted, processed, and stored within the EU, using an AI agent platform or infrastructure provider with genuine EU-based deployment options.
Hosting location is not the only thing that decides where data can be reached, either. The US CLOUD Act lets US authorities compel a US-based provider to produce data it holds regardless of which country the servers sit in, which is why the question to put to a vendor is who controls the processing entity, not only which data centre the workload runs in.
This does not eliminate all compliance obligations (GDPR's broader requirements around lawful basis, data subject rights, and data protection by design still apply regardless of hosting location, as covered in GDPR and AI agent deployments), but it does remove one specific and historically contentious compliance question from the equation.
Berlin as a specific example of EU-based hosting
Ojin, the Human AI Company, headquartered in Berlin, offers EU-based hosting for the platform behind its Human AI Agents, which is specifically relevant for companies wanting to avoid the EU-US cross-border transfer question for their AI agent deployment. This is a genuine, structural advantage for companies serving EU customers or operating in regulated EU industries, distinct from marketing language about "EU compliance" that some vendors use without genuine EU-based infrastructure behind it, the specific, verifiable question to ask any vendor is where the actual data processing and storage occurs for your specific deployment, not simply whether the vendor claims general GDPR compliance.
What this means practically for a procurement decision
Ojin's Human Agents run on EU infrastructure by default rather than as a paid region option, which is the distinction worth probing with any vendor.
For a company evaluating AI agent vendors and serving EU customers, a question that sits alongside build versus buy, the practical questions are: does the vendor offer genuine EU-based hosting (not just a general compliance claim), can this be confirmed and contractually guaranteed for your specific data, and if EU-based hosting is not available or not chosen, what specific transfer mechanism and safeguards does the vendor rely on for data that leaves the EU. These questions should be resolved and documented as part of the vendor contract, not left as an assumption based on general marketing claims about "GDPR compliance," which is a broader and less specific claim than a confirmed data residency guarantee.
What procurement actually asks
The question arrives in a predictable order, and knowing it saves a quarter.
Where is the data processed, physically. Not the vendor's headquarters, not where the contract is signed. Which region the inference runs in and which region the recordings sit in, named, and contractually fixed.
Who is the processor and who is the controller. In almost every deployment the customer is the controller and the vendor is the processor, and the Data Processing Agreement has to say so before legal will look at anything else.
What happens on subprocessors. Most AI stacks are assembled from several vendors, and each one that touches personal data is a subprocessor that has to be listed and notified on change. This is where "we are EU-based" claims usually come apart, because the face model is EU-hosted and the language model behind it is not.
What the exit looks like. How data is returned, in what format, and how quickly it is deleted afterwards. Rarely asked early, always asked eventually.
An answer that is short and specific to all four moves faster than a lengthy compliance page.
The cost of getting it wrong later
Rehosting a live deployment is not a configuration change. Conversation history, embeddings, recordings and audit logs all live somewhere, and moving them mid-contract means a migration project nobody budgeted for, usually triggered by a compliance review rather than a technical need.
That is the practical argument for settling the question at selection rather than treating it as something to sort out at scale. The cheapest time to be in the right jurisdiction is before the first production conversation.
Frequently asked questions
Does GDPR compliance require EU hosting, or is US hosting with appropriate safeguards also compliant?
GDPR does not strictly require EU hosting, transfers to the US (or other countries) are permitted with appropriate safeguards, currently including reliance on the EU-US Data Privacy Framework for certified companies, or Standard Contractual Clauses with supplementary measures for others. EU hosting is the simpler, lower-uncertainty path given the legal history around cross-border transfer mechanisms, but it is not the only compliant option.
Where does Ojin sit on this?
As an EU-based processor. Data for EU customers stays inside the bloc, which removes the transfer question rather than answering it, and that is the point.
Is the EU-US Data Privacy Framework likely to be invalidated the way the previous Privacy Shield was?
This cannot be predicted with certainty. The framework has faced legal challenges, and its underlying legal basis addresses some but not necessarily all of the concerns that led to the Privacy Shield's invalidation. Companies relying on it should stay informed of relevant legal developments rather than assuming permanent stability, and should consider EU hosting as a hedge against this uncertainty for higher-stakes or highly regulated deployments.
Does data residency within the EU protect against all forms of data access risk, including EU government access?
EU-based hosting addresses the specific cross-border transfer concerns central to the Schrems II line of cases, which focused on US government surveillance access to data transferred to US infrastructure. It does not eliminate all conceivable data access risk (EU law enforcement access under appropriate legal process, for instance, remains a separate consideration), but it does address the specific, historically significant compliance risk that has driven much of the EU-US data transfer debate.
Next steps for choosing a hosting region
See also: Cloud AI Agent, the full guide · GDPR and AI agent deployments · Brand safety when deploying a Human AI Agent · Demo: docs.ojin.ai
