Where Your Prompt Goes: Data Privacy and Residency When AI Is Hosted Abroad
2026-07-21 • Source: KR & Associates
A prompt pasted into a hosted AI assistant can carry personal data across the EU boundary at the point of use. What the GDPR requires, what Schrems II changed, and how to verify a provider's guarantees. The second article in a four-part series with KR & Associates.
*This article is part of a four-part series on European digital sovereignty, published in partnership with [KR & Associates](https://kevinryan.io).*
When an employee pastes a customer's details into a hosted AI assistant, the prompt does not stay on the desk. It travels to the provider's servers, wherever those sit, is processed there, and the answer returns. That short journey can move personal data collected in the European Union across a border, and whether it is lawful has been argued over for more than a decade. Two ideas help in thinking about it. Data residency concerns where data is stored and processed. Data sovereignty concerns whose law governs it. For AI the two come apart at the moment of use, because a capable model is often hosted somewhere other than where its users are.

## The root of the problem
The shortage of residency compliant foundation models is the root of the problem. When the strongest models are hosted outside the EU, teams that want their capability send data to them, and that choice settles where the data goes. The options that keep data closer to home are models hosted in EU regions and, for the most sensitive workloads, inference run on premises or at the edge.
Inference is the stage at which the model produces an answer from the prompt, and it runs on the provider's servers. A prompt that contains personal data is therefore sent to wherever those servers are located, so data gathered in the EU can leave it at the point of use. Hosting in an EU region helps, provided the guarantee also covers processing, support access and backups, and confidential computing can keep the data protected while it is in use.
## What the law says
Transfers outside the EU engage Chapter V of the GDPR, and the law here has been unsettled. The Court of Justice struck down the Safe Harbour arrangement, then struck down its successor, the Privacy Shield, in the Schrems II judgment of 2020, holding that United States surveillance law did not give EU individuals protection essentially equivalent to that under EU law. The response was the EU-US Data Privacy Framework, built with a redress mechanism for people in the EU and adopted as an adequacy decision in 2023. It remains in force, though a challenge has reached the Court of Justice as Case C-703/25 P. Max Schrems, whose complaints brought down the earlier arrangements, called the framework a step towards "a third flawed deal". For a transfer today the lawful routes are the Data Privacy Framework adequacy where it applies, Standard Contractual Clauses supported by a transfer impact assessment, and supplementary measures where the destination law falls short. While the appeal is pending the basis is not settled, so a multi-year commitment should be planned on that footing.
## Verifying the guarantee
Provider guarantees deserve the same scrutiny. A commitment to residency or to zero data retention is worth only as much as the proof behind it, and such commitments should be capable of being checked rather than taken on trust. The evidence that supports them is contractual terms, independent audits, recognised certifications and technical attestation. Judging which assurances are enough for a given data flow is a matter of judgement. [KR & Associates](https://kevinryan.io) and European Tech Map have the know-how to guide these decisions and put a sound solution in place.
## A short sequence
A short sequence settles most cases before a prompt is ever sent. Establish whether the prompt carries personal data. Find where inference runs. Confirm the transfer mechanism. Record how the provider's guarantees can be verified. Compliance is bound up with capability here, because the tool that helps a team most may be the one that raises the hardest transfer question, which makes the design stage the place to resolve it.
*By Peter Houghton, Kevin Ryan & Andy Wijman, KR & Associates*
*Source: Lauren Fedor and Javier Espinoza, Financial Times, 7 October 2022.*
Tags: security, policy