Knowledge · Law and data residency

US providers and data residency: what to watch for

The leading models come from the US. What that means for your data, and which four measures actually help.

Information, not legal advice.

All entries

01 Where we start

Claude, ChatGPT, Copilot and Gemini come from American companies — anyone automating in Europe has to deal with that fact.

02 A European region is not a European company

That the data centre region sits in Frankfurt or Ireland says something about where data is stored, and nothing about where the provider is based.

03 Why the provider's seat counts

A company based in the US is subject to American law, wherever its servers stand.

04 What a data processing agreement settles and what it does not

It settles the purpose, the duration and the instruction-bound nature of the processing; it does not set aside a foreign legal order.

05 The Swiss DSG and the GDPR side by side

Both allow the use but tie it to conditions: data minimisation, purpose limitation, traceability and a basis for transfers abroad. The four questions you have to answer are in Using AI under Swiss data protection law.

05a What the EU AI Act has to do with it

The AI Act does not regulate data residency but the risk of the system — which tier ordinary automation falls into is in The EU AI Act for Swiss companies.

06 The measures that actually help

Send less data to the model, strip personal references before the call, switch retention off at the provider, and log what was read.

07 Measure 1: send only what is needed

A contract does not have to run through a model in full when only three fields are needed.

08 Measure 2: strip personal references first

Names, addresses and contract numbers can be substituted before the model call and restored afterwards.

09 Measure 3: switch retention and training off

On business contracts it can usually be switched off that inputs are stored or used for training — that has to be checked and documented. What applies differs by provider and contract type and has to be checked per provider before use.

10 Measure 4: log it

Being able to show which document was read and which result was produced covers the larger part of the documentation duty.

11 The European route: Mistral

Mistral is a European provider, hosted in France, and so the direct route when data residency carries the decision. Which model we run for which job and where it runs is in AI models and data residency.

12 The own route: self-hosting

An open model on your own infrastructure cuts the whole question off, because no data leaves the building.

13 The open models and where they come from

Kimi, GLM and Qwen are open models originating in China; we name a provider and a seat only where we can evidence them, and we run these models self-hosted only — then their origin has no bearing on the data flow.

14 Llama and Meta

Meta is a US provider, but the models are open and can be self-hosted — the same applies: self-hosted means nothing flows out.

15 What we check before we use a model

The provider's seat, the operating region, the contractual position on retention and training, whether it can be logged — and whether the job needs the model at all.

16 Our rule

If a model does not meet these conditions we do not use it, however well it scores in tests.

17 What you should write down internally

Which tools are approved and who may do what with them belongs in a written rule — what it looks like is in What belongs in an internal AI policy.


Related entries: Using AI under Swiss data protection law · The EU AI Act for Swiss companies · What belongs in an internal AI policy · AI models and data residency

Information, not legal advice.

Describe a process. We will tell you whether automating it pays — even when the answer is no.

Book a call