S8

simple8

Procurement and assessment guide

GDPR-oriented AI API procurement.

A buyer checklist for roles, processing agreements, hosting, subprocessors, retention, security and responsible AI operations.

When can an AI API be procured responsibly under data protection law?

No single feature automatically makes an AI API GDPR compliant. Hosting in the EU or Germany, a data processing agreement (DPA), and encryption are important evidence, but they do not replace an assessment of purpose, data flows, roles, legal basis, deletion, security, data subject rights and actual operations.

No legal advice

This guide provides general procurement and assessment information. It does not replace legal advice or an assessment of the specific use case by the data protection officer and responsible legal team.

Assessment from use case to evidence

  1. 1
    Record purpose, users, inputs, outputs, recipients, systems and storage locations in the data flow.
  2. 2
    Determine the controller, processors and any joint controllers based on who actually makes the relevant decisions.
  3. 3
    Check legal basis, special categories under Article 9, purpose limitation and data minimization.
  4. 4
    Set storage, logging and deletion periods for each data type.
  5. 5
    Document processing under Article 28 in a data processing agreement (DPA), including instructions, assistance, deletion and audit rights.
  6. 6
    Review subprocessors, change notifications, and objection or termination options.
  7. 7
    Assess third-country transfers against an adequacy decision or appropriate safeguards such as standard contractual clauses.
  8. 8
    Test technical and organizational measures in accordance with Article 32 in a risk-related manner.
  9. 9
    Establish operational processes for data subject rights, deletion, rectification, access requests, incidents and evidence.
  10. 10
    Consider a data protection impact assessment under Article 35 and assess automated decisions separately under Article 22.

Evaluate providers using verifiable evidence

There is no universal ranking. Each assessment must address the specific use case and contract.
CriterionRequired evidenceWarning signalQuestion for the provider
Data flowCurrent data flow diagramUnclear storage or training pathsWhich data leaves which system?
DPADraft data processing agreement (DPA) under Article 28General privacy page onlyHow are instructions and deletion implemented?
SubprocessorsList, locations, tasks, change processChange without noticeWhat exit rights exist?
Third-country transferAdequacy decision or SCCs with a transfer assessmentAn EU region is incorrectly treated as proof that no transfer occursFrom where can support staff and telemetry systems access the data?
SecurityTechnical and organisational measures, audit reports and an incident processCertificate logos onlyWhat controls apply to our data class?
deletionRetention periods, API process and backup policyIndefinite log retentionHow is deletion proven?
AuditAudit rights and available evidenceNo verifiable evidenceWhat reports do we receive regularly?

simple8 product evidence

This section contains simple8 product information, not an independent legal assessment.

simple8 product information describes hosting and data processing in Germany, no use of external generative AI platforms in standard operation, separate language modes, and optional quality hints. Procurement teams should confirm these product statements against the contract, technical documentation and current evidence.

Complete the decision file

Document before approval

Frequently asked questions

Is a DPA sufficient for GDPR compliance?

No. A data processing agreement (DPA) governs processing by a processor, but it does not replace the legal basis, data minimisation, security, deletion, data subject rights or an assessment of actual operations.

When are standard contractual clauses needed?

SCCs can be an appropriate guarantee for certain third country transfers where an adequacy decision does not apply. In addition, the specific transfer situation must be evaluated.

Does EU hosting automatically make an AI API GDPR compliant?

No. Even with EU hosting, teams must still assess roles, legal basis, support access, subprocessors, logs, deletion and security.

How should subprocessors be assessed?

Require each subprocessor's name, role, location, data access, contractual chain, and a binding process for changes and objections.

When is a DPIA necessary?

A DPIA is necessary if the processing is likely to cause a high risk to rights and freedoms. Article 35, supervisory lists and the specific use case determine the test.

Is an AI Act classification the same as a GDPR risk assessment?

No. The AI Act and GDPR address different questions. Complete the assessments separately, then connect their controls in operational governance.

How should procurement teams compare AI providers?

Compare verifiable evidence for each use case, not advertising claims or blanket rankings.

What evidence belongs in the procurement record?

Record the data flows, role determination, contracts, subprocessors, transfer assessment, technical and organisational measures, deletion, tests, DPIA decision, AI Act classification and approvals.

Primary sources and standards

  1. General Data Protection Regulation (EN)
  2. Regulation (EU) 2024/1689, EU AI Act (EN)
  3. European Commission: AI Act timeline (EN)
  4. BfDI: AI questionnaire (EN)