Compliance · Europe
Sovereign AI for Europe: data control isn’t a hosting region.
A European data centre run by a US provider is still reachable under the CLOUD Act. Self-hosted AI on infrastructure you control answers that, and we design for each EU rule from the start.
- Office
- Berlin, Germany
- Core rules
- GDPR, EU AI Act, DORA
- Germany
- §203 and §201 StGB
- Switzerland
- Revised FADP since Sept 2023
In short
European organisations using AI must meet GDPR, the EU AI Act and sector rules such as DORA, and in Germany professional-secrecy law (§203 StGB). Hosting in an EU region is not enough if a US provider controls the service; self-hosted AI on infrastructure you control keeps data out of reach and decisions documented.
The rules
Rule by rule.
GDPR-compliant AI starts with where the data goes.
Self-hosted AI keeps personal data, including health and biometric data, inside your environment, which removes most of the transfer and processor questions cloud AI raises.
GDPR →EU AI ActThe EU AI Act, after the Digital Omnibus.
Most internal knowledge assistants are not high-risk, but the classification must be documented. Some automations are high-risk, and their deadline moved to 2 December 2027.
EU AI Act →DORADORA-ready AI: less third-party risk, a real exit plan.
Since 17 January 2025, EU financial entities must manage ICT third-party risk, keep a register of ICT arrangements and plan exits. Self-hosted AI with code you own makes that simpler.
DORA →Our angle
What matters in Europe.
- GDPR: no AI vendor in the personal-data path.
- CLOUD Act: a provider you don’t control can be compelled to hand over data; self-hosting removes that.
- §203 StGB: for German lawyers, tax advisers and doctors, self-hosting avoids unlawful disclosure of client secrets.
- DORA: concrete exit plans when you own the code.
- Switzerland: the revised FADP (in force 1 September 2023) can fine individuals up to CHF 250,000; we offer a Swiss hosting story.
- EU AI Act: classification documented; high-risk Annex III duties from 2 December 2027.
FAQ
Questions, answered.
Do you have a local team in Europe?
Yes. Our Berlin, Askanischer Pl. 4 office works with clients in Europe, including Germany, Austria and Switzerland.
Is self-hosting always required?
Not always. Some rules allow vetted cloud services. Self-hosting removes the hardest questions, and we tell you when it is not needed.
Related
By industry
Sector-specific rules and use cases.
Learn more →Security
How we protect your deployment.
Learn more →Access control
Who uses which agent, on what data.
Learn more →General information, not legal advice. Have your counsel confirm how each rule applies to you. Updated October 2026.
Start with two weeks of evidence, not a sales call.
A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.