GDPR (Regulation (EU) 2016/679) fully applies to AI tools that process personal data. Articles 5, 6, 28, 35 and 44+ structure the obligations: minimisation, legal basis, processor agreements, DPIA and non-EU transfers. For GEO/AEO tools, compliance hinges on a detailed DPA and EU hosting.

Relevant GDPR articles for AI tools

  • Article 5 — Principles: lawfulness, minimisation, accuracy, storage limitation. An AI tool may process only strictly necessary data.
  • Article 6 — Legal basis: legitimate interest or contract in most B2B cases, to be documented.
  • Article 28 — Processor: written agreement between controller and SaaS processor required, with 8 mandatory clauses (see DPA).
  • Article 28(4) — Sub-processors: prior authorisation and a public list of sub-processors (including LLM providers).
  • Article 35DPIA required for high-risk processing (profiling, predictive AI, automated decisions).
  • Articles 44-49 — Non-EU transfers: Standard Contractual Clauses (SCC) or Data Privacy Framework, complemented by a transfer impact assessment (TIA) since the Schrems II ruling.

GEO/AEO tools — a specific case

AI visibility tools process personal data as soon as a brand maps to a natural person's name (entrepreneur, director, freelancer), or when prompts contain direct or indirect identifiers. GDPR compliance is therefore not optional in this segment.

OpenRouter / OpenAI / Anthropic as sub-processors

Every GEO/AEO tool calls LLMs through OpenRouter, OpenAI, Anthropic or Google. These vendors are sub-processors under Article 28(4). The controller (you) must:

  • Have a signed DPA with the GEO/AEO SaaS.
  • Review the public list of sub-processors and their locations.
  • Receive notification of any addition or removal of a sub-processor.

Non-EU transfers and the CLOUD Act

A US SaaS, even when physically hosted in Europe (e.g. AWS Frankfurt), remains subject to the CLOUD Act. For regulated sectors, the CNIL recommends an EU-incorporated vendor.

AI Labs Audit compliance

  • French SAS, hosted on OVH SAS (France).
  • Signed DPA downloadable from the customer account (not "on request").
  • Public sub-processor list (OVH, OpenRouter) with locations.
  • AGS_SHADOW_DPA_RESTRICTED mode blocks non-EU judges for regulated sectors (banking, healthcare, defence, public sector).
  • DPIA template supplied to ease Article 35 compliance.

See our GDPR/EU AI Act benchmark of GEO tools for detail.

Across AI answers, a brand appears just 1 time in 6. Does yours show up?

Every question asked to ChatGPT without your name in the answer is a competitor recommended instead of you — measured across 6,820 real AI answers.