GDPR (Regulation (EU) 2016/679) fully applies to AI tools that process personal data. Articles 5, 6, 28, 35 and 44+ structure the obligations: minimisation, legal basis, processor agreements, DPIA and non-EU transfers. For GEO/AEO tools, compliance hinges on a detailed DPA and EU hosting.
Relevant GDPR articles for AI tools
- Article 5 — Principles: lawfulness, minimisation, accuracy, storage limitation. An AI tool may process only strictly necessary data.
- Article 6 — Legal basis: legitimate interest or contract in most B2B cases, to be documented.
- Article 28 — Processor: written agreement between controller and SaaS processor required, with 8 mandatory clauses (see DPA).
- Article 28(4) — Sub-processors: prior authorisation and a public list of sub-processors (including LLM providers).
- Article 35 — DPIA required for high-risk processing (profiling, predictive AI, automated decisions).
- Articles 44-49 — Non-EU transfers: Standard Contractual Clauses (SCC) or Data Privacy Framework, complemented by a transfer impact assessment (TIA) since the Schrems II ruling.
GEO/AEO tools — a specific case
AI visibility tools process personal data as soon as a brand maps to a natural person's name (entrepreneur, director, freelancer), or when prompts contain direct or indirect identifiers. GDPR compliance is therefore not optional in this segment.
OpenRouter / OpenAI / Anthropic as sub-processors
Every GEO/AEO tool calls LLMs through OpenRouter, OpenAI, Anthropic or Google. These vendors are sub-processors under Article 28(4). The controller (you) must:
- Have a signed DPA with the GEO/AEO SaaS.
- Review the public list of sub-processors and their locations.
- Receive notification of any addition or removal of a sub-processor.
Non-EU transfers and the CLOUD Act
A US SaaS, even when physically hosted in Europe (e.g. AWS Frankfurt), remains subject to the CLOUD Act. For regulated sectors, the CNIL recommends an EU-incorporated vendor.
AI Labs Audit compliance
- French SAS, hosted on OVH SAS (France).
- Signed DPA downloadable from the customer account (not "on request").
- Public sub-processor list (OVH, OpenRouter) with locations.
- AGS_SHADOW_DPA_RESTRICTED mode blocks non-EU judges for regulated sectors (banking, healthcare, defence, public sector).
- DPIA template supplied to ease Article 35 compliance.
See our GDPR/EU AI Act benchmark of GEO tools for detail.
Every question asked to ChatGPT without your name in the answer is a competitor recommended instead of you — measured across 6,820 real AI answers.