Before you deploy

Compliance and data residency, in plain language

How to check where an AI agent puts your data, which rules apply to your use case, and what evidence a supplier should be able to hand over. Written for the person who has to sign, not for a compliance specialist.

This is guidance for evaluating suppliers. It is not legal advice, and it does not replace your own counsel or your regulator.

On this page

Where to start

Start with your own use case, not with the supplier’s compliance page. Write down what data the agent will see, what actions it may take, and who is affected when it is wrong. Everything else follows from those three answers.

The same agent can be unremarkable in one deployment and heavily regulated in another. An assistant drafting campaign copy sees little personal data and takes reversible actions. The same technology screening job applicants changes the legal picture entirely. Obligations attach to the use, so assessing the product in isolation will always give you the wrong answer.

A practical order of work: define the use case, classify the data, decide controller and processor roles, then ask the supplier for evidence. Reversing that order is how organisations end up negotiating a data processing agreement after the pilot has already run on live customer records.

The frameworks that matter

Six come up in almost every European B2B evaluation. For each, the useful question is narrow and answerable.

GDPR
EU and UK data protection law. Applies whenever the agent touches personal data about people in those regions.Ask: Who is controller and who is processor, what is the lawful basis, and where is the data processing agreement?A supplier saying it is GDPR compliant tells you nothing on its own. Compliance is a property of your deployment, not of a product.
EU AI Act
Risk-tiered rules for AI systems placed on the EU market, phasing in through 2026 and 2027.Ask: Which risk tier does our use case fall into, and what does the supplier provide to support our deployer duties?Readiness is not certification. There is no EU AI Act certificate to hold up, so ask what specifically has been prepared.
ISO/IEC 42001
Certifiable management-system standard for how an organisation governs AI.Ask: Show the certificate, the scope statement, the issuing body, and the expiry date.Scope is everything. A certificate covering one product line says little about the agent you are buying.
ISO/IEC 27001
Information-security management. Long-established and widely held.Ask: Same three questions: certificate, scope, issuer.Necessary background hygiene. It says nothing about model behaviour or oversight.
SOC 2 Type II
An audit report on security controls operating over a period, common with US suppliers.Ask: The full report under NDA, not the badge, and the date range it covers.Read the exceptions section. That is the part the badge omits.
Sector rules
DORA, HIPAA, MiFID, medical device rules and similar, depending on where you operate.Ask: Has the supplier been deployed under this regime before, and by whom?Sector regulators care about your accountability, not your supplier's roadmap.

Where your data actually goes

Data residency is not one question. It is six, and a supplier can answer the first one honestly while the rest tell a different story.

Application and database
Where the agent's own records live: conversations, task history, configuration, customer records it has copied. Usually the easiest question to get a straight answer on.
Model inference
Where the prompt actually goes when the agent reasons. Many suppliers host the application in one region and call a model API in another. This is the most common gap between what is promised and what happens.
Logs and telemetry
Prompts and outputs are frequently retained for debugging, safety review or quality evaluation, sometimes in a different region and often for longer than the primary data. Ask for the retention schedule per store.
Sub-processors
The model provider, the cloud host, the vector store, the observability tool, the support desk. Each is a place your data goes. Ask for the current list, the notification period for changes, and your right to object.
Support access
Whether support staff can read customer data, from where, and under what approval. A perfect hosting map is undone by an engineer with standing production access from outside the region.
Backups and disaster recovery
Backups often sit outside the primary region by design. If residency is contractual for you, it has to cover the copies as well as the original.

Ask for the answer as a table, one row per component, with region and retention period. Suppliers who have done the work produce it quickly. Suppliers who have not will offer a reassurance instead, and that is itself the answer.

Transfers out of the EEA

Most agent platforms depend on at least one model provider, and many of those are outside the EEA. That is workable, but it has to be documented rather than assumed.

  • Adequacy. The destination country has an adequacy decision, or the recipient is certified under a relevant framework. Check that the certification actually covers the entity you contract with.
  • Standard contractual clauses. The usual route where adequacy does not apply. Confirm which module is used and that it is attached to your agreement, not referenced in general terms.
  • Transfer impact assessment. Required alongside the clauses. Ask whether the supplier has one you can rely on, and what technical measures it cites.
  • Onward transfers. Your supplier’s sub-processors have sub-processors. Ask how far the chain is mapped, and what happens when a link in it changes.

The evaluation checklist

Twelve items, in the order they are worth doing. Each one is a document or a contractual answer, not an opinion.

  1. 01

    Name the personal data categories the agent will see, before you look at any product.

  2. 02

    Establish controller and processor roles in writing, and sign the data processing agreement.

  3. 03

    Get hosting and processing regions per component: application, database, model inference, logs, backups.

  4. 04

    Get the sub-processor list, the change-notification period, and your right to object.

  5. 05

    Confirm in the contract whether your data trains models, improves the product, or is read by humans.

  6. 06

    Get the retention schedule for prompts, outputs and logs, and the deletion mechanism you can actually invoke.

  7. 07

    For transfers outside the EEA, confirm the mechanism: adequacy, standard contractual clauses, and a transfer impact assessment.

  8. 08

    Get certificates with scope statements, and read the exceptions in any SOC 2 report.

  9. 09

    Document the human oversight your deployment relies on, and check the product enforces it rather than a prompt.

  10. 10

    Confirm audit logging is complete enough to reconstruct why the agent acted, and that you can export it.

  11. 11

    Run a data protection impact assessment where the processing is high risk, and keep it current.

  12. 12

    Agree exit terms: data export format, deletion certificate, and how long access lasts after termination.

Claims to push back on

None of these mean a supplier is untrustworthy. They mean the sentence is doing less work than it appears to, and the follow-up question is where the information is.

The claimWhat to ask next
Compliant with GDPR and the EU AI ActCompliance depends on your use case. A blanket claim without a data processing agreement, a scoped certificate or a transfer mechanism is a slogan.
EU hostedAsk which component. The application can be in Frankfurt while inference and logging are not.
We never store your dataAlmost always means the primary store. Check prompt logs, safety review queues and support tooling.
Enterprise grade securityNot a standard, not audited, and not a sentence a compliance officer can rely on.
Certification in progressFine to hear, but it is a plan. Ask for the auditor, the scope and the target date, then treat it as absent until it exists.
Human in the loopAsk where the loop is enforced. If oversight lives in a prompt rather than in the product, it is a preference, not a control.

Common questions

What does data residency mean for an AI agent?
Data residency is the country or region where your data is stored and processed. For an AI agent it has three parts that are often confused: where the application and its database sit, where the model runs when it generates a response, and where logs, transcripts and evaluation data are kept. A supplier can host the application in the EU while the model call leaves the region, so ask about all three separately.
Is an AI agent covered by GDPR?
If the agent processes personal data of people in the EU or UK, yes. In most deployments the buyer is the controller and the supplier is a processor, which means you need a data processing agreement, a documented lawful basis, a record of processing, and a list of sub-processors. Automated decisions with legal or similarly significant effects carry additional obligations under Article 22.
Does the EU AI Act apply to a company buying an agent?
It can. Obligations fall mainly on providers, but organisations that deploy an AI system have their own duties, including human oversight, using the system as instructed, monitoring, and informing affected workers. Whether the heavier duties apply depends on the use case, not on the product: the same agent can be low risk in marketing and high risk in recruitment or credit decisions.
Is ISO/IEC 42001 the same as being compliant?
No. ISO/IEC 42001 certifies that a supplier runs a management system for AI, in the same way ISO/IEC 27001 certifies an information-security management system. It is evidence of process discipline, not evidence that a specific agent is lawful in your use case. Ask for the certificate, the scope statement and the issuing body, because scope is where these certificates differ most.
Will my data be used to train the supplier's models?
Ask, and get the answer in the contract rather than the marketing page. Three separate questions matter: is your content used to train foundation models, is it used to improve the supplier's own product, and is it retained for human review of quality or safety. A supplier can answer no to the first and yes to the other two.
What evidence should a supplier be able to produce?
A data processing agreement, a current sub-processor list with notification terms, hosting and processing regions per component, a retention schedule, any certificates with their scope, a penetration-test summary, and a description of human oversight and audit logging. If a claim exists only on a slide, treat it as a claim and not a fact.