When can an AI API be procured responsibly under data protection law?
No single feature automatically makes an AI API GDPR compliant. Hosting in the EU or Germany, a data processing agreement (DPA), and encryption are important evidence, but they do not replace an assessment of purpose, data flows, roles, legal basis, deletion, security, data subject rights and actual operations.
No legal advice
This guide provides general procurement and assessment information. It does not replace legal advice or an assessment of the specific use case by the data protection officer and responsible legal team.
Assessment from use case to evidence
- 1Record purpose, users, inputs, outputs, recipients, systems and storage locations in the data flow.
- 2Determine the controller, processors and any joint controllers based on who actually makes the relevant decisions.
- 3Check legal basis, special categories under Article 9, purpose limitation and data minimization.
- 4Set storage, logging and deletion periods for each data type.
- 5Document processing under Article 28 in a data processing agreement (DPA), including instructions, assistance, deletion and audit rights.
- 6Review subprocessors, change notifications, and objection or termination options.
- 7Assess third-country transfers against an adequacy decision or appropriate safeguards such as standard contractual clauses.
- 8Test technical and organizational measures in accordance with Article 32 in a risk-related manner.
- 9Establish operational processes for data subject rights, deletion, rectification, access requests, incidents and evidence.
- 10Consider a data protection impact assessment under Article 35 and assess automated decisions separately under Article 22.
Regulatory status as of July 14, 2026
The EU AI Act applies in stages. Prohibitions and AI literacy obligations have applied since 2 February 2025, rules for general-purpose AI since 2 August 2025, and most provisions from 2 August 2026. Under the enacted timetable, certain obligations for high-risk systems covered by Article 6(1) apply from 2 August 2027. AI Act classification is a separate assessment and does not replace a GDPR assessment. The regulation is binding, while European Commission pages explain the timetable. Proposals and guidance must be identified as such.
Evaluate providers using verifiable evidence
| Criterion | Required evidence | Warning signal | Question for the provider |
|---|---|---|---|
| Data flow | Current data flow diagram | Unclear storage or training paths | Which data leaves which system? |
| DPA | Draft data processing agreement (DPA) under Article 28 | General privacy page only | How are instructions and deletion implemented? |
| Subprocessors | List, locations, tasks, change process | Change without notice | What exit rights exist? |
| Third-country transfer | Adequacy decision or SCCs with a transfer assessment | An EU region is incorrectly treated as proof that no transfer occurs | From where can support staff and telemetry systems access the data? |
| Security | Technical and organisational measures, audit reports and an incident process | Certificate logos only | What controls apply to our data class? |
| deletion | Retention periods, API process and backup policy | Indefinite log retention | How is deletion proven? |
| Audit | Audit rights and available evidence | No verifiable evidence | What reports do we receive regularly? |
simple8 product evidence
This section contains simple8 product information, not an independent legal assessment.
simple8 product information describes hosting and data processing in Germany, no use of external generative AI platforms in standard operation, separate language modes, and optional quality hints. Procurement teams should confirm these product statements against the contract, technical documentation and current evidence.
Complete the decision file
Frequently asked questions
Is a DPA sufficient for GDPR compliance?
No. A data processing agreement (DPA) governs processing by a processor, but it does not replace the legal basis, data minimisation, security, deletion, data subject rights or an assessment of actual operations.
When are standard contractual clauses needed?
SCCs can be an appropriate guarantee for certain third country transfers where an adequacy decision does not apply. In addition, the specific transfer situation must be evaluated.
Does EU hosting automatically make an AI API GDPR compliant?
No. Even with EU hosting, teams must still assess roles, legal basis, support access, subprocessors, logs, deletion and security.
How should subprocessors be assessed?
Require each subprocessor's name, role, location, data access, contractual chain, and a binding process for changes and objections.
When is a DPIA necessary?
A DPIA is necessary if the processing is likely to cause a high risk to rights and freedoms. Article 35, supervisory lists and the specific use case determine the test.
Is an AI Act classification the same as a GDPR risk assessment?
No. The AI Act and GDPR address different questions. Complete the assessments separately, then connect their controls in operational governance.
How should procurement teams compare AI providers?
Compare verifiable evidence for each use case, not advertising claims or blanket rankings.
What evidence belongs in the procurement record?
Record the data flows, role determination, contracts, subprocessors, transfer assessment, technical and organisational measures, deletion, tests, DPIA decision, AI Act classification and approvals.