Skip to main content
Data Residency & Sovereignty

Your AI prompts cross borders
you didn't know existed.

Every time you paste data into ChatGPT, Claude, or any AI tool, your information travels to data centers governed by different laws. GDPR, PIPL, DPDP Act, and LGPD each impose different rules on where AI data can live — and the penalties for getting it wrong are material.

Quick Answer

Data residency determines where your AI data is physically stored and processed. Different countries have different rules: the EU (GDPR) allows cross-border transfers with safeguards, while China (PIPL) and Russia (242-FZ) require data to stay within their borders. Most major AI providers now offer regional data residency options — OpenAI supports 10 regions, AWS Bedrock locks Claude to your chosen geography, and Google Vertex AI provides region-locked processing across 40+ global regions. The safest approach for organizations operating across multiple jurisdictions is to use a local gateway (like Purfect Shield) that redacts sensitive data before it ever leaves your network — eliminating the residency question at its source.

Region-by-Region Data Residency Explorer

Select a jurisdiction to see its specific requirements, how they affect AI usage, and which providers can operate there.

General Data Protection Regulation (GDPR)

European Economic Area (EEA) + Switzerland

Transfer-Regulated

Key Provision

Article 44-49: Cross-border transfers require a legal mechanism ensuring 'essentially equivalent' protection. The EU-US Data Privacy Framework provides one adequacy pathway for US transfers.

Residency Requirement

No mandatory localization. Personal data may be transferred outside the EEA only when protected by an adequacy decision, Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs).

What This Means for AI

When personal data of EU residents is used to train an AI model on infrastructure outside the EEA, the training run itself constitutes a regulated transfer. Organizations must document the legal basis for every cross-border data movement — including AI inference requests that flow to non-EEA data centers.

Provider Options

  • OpenAI: EU data residency available (eu.api.openai.com) — both at-rest storage and inference residency for eligible ChatGPT Enterprise/Edu customers
  • AWS Bedrock: EU regional endpoints (Frankfurt, Ireland) keep Claude model data within EEA
  • GCP Vertex AI: EU regions available for model inference — data stays within chosen region
  • Azure OpenAI: EU regional deployments available for data residency compliance

Penalties: Up to €20 million or 4% of global annual turnover, whichever is higher — for violations of cross-border transfer rules (Article 83).

AI Provider Data Residency Comparison

Not all AI providers handle your data the same way. Here's how the major options compare on residency controls.

ProviderRegionsAt-Rest ResidencyInference ResidencyTraining Policy
OpenAI (Direct API)10 regions: EU, US, UK, Japan, Canada, South Korea, Singapore, Australia, India, UAEYes — eligible customers can pin storage to specific regions. Requires MAM or ZDR for EU/UAE inference residency.EU, US, UAE — available for eligible ChatGPT Enterprise/Edu customers. API inference residency in EU and UAE requires zero data retention (ZDR) or MAM.Opt-out available. API data not used for training by default. ChatGPT Enterprise/Edu data excluded.
Anthropic (via AWS Bedrock)US, EU, Japan, Australia — regional endpoints guarantee data stays within geographyYes — region-locked by AWS infrastructure. Data stored in chosen AWS region.Yes — regional endpoints (e.g., us.anthropic.claude-*) ensure inference stays within the selected geography. Global endpoints route dynamically across regions.Not used for training when accessed via Bedrock/Vertex. Direct Anthropic API may retain for abuse monitoring (30 days max for Trusted Organizations).
Anthropic (Direct API)US-based processing (no regional endpoints for direct API as of mid-2026)No regional choice for direct API — US-based storage. For EU data residency, use Bedrock or Vertex.No — all direct API inference routes to US infrastructure.Not used for training. Inputs/outputs retained 30 days for abuse monitoring (Trusted Organizations program).
Google (Vertex AI)40+ GCP regions globally including EU, Asia-Pacific, AmericasYes — data stored in the GCP region selected for the Vertex AI endpoint.Yes — inference processing stays within the selected GCP region. No cross-region routing.Not used for training. Vertex AI provides contractual commitments on data isolation.
Purfect Shield (Local Gateway)Your machine — data never leaves your network for processingN/A — sensitive data is redacted before reaching any AI provider. Original data stays on your device.N/A — AI providers only receive redacted/replaced tokens. The sensitive content never reaches external infrastructure.N/A — providers never see the original sensitive data. Redacted prompts contain only placeholder tokens.

* Data as of July 2026. Provider policies change — always verify current terms with your provider's documentation. Cloud marketplace routes (Bedrock, Vertex, Azure) generally provide stronger residency guarantees than direct API access.

Compliance Framework Reference

A quick reference to the major data residency and AI governance frameworks affecting AI deployments worldwide.

FrameworkJurisdictionResidencyTransfer MechanismPenalties
GDPREU / EEA + SwitzerlandTransfer-regulated (no mandatory localization)Adequacy decisions, SCCs, BCRs, EU-US DPFUp to €20M or 4% global annual turnover
PIPL (China)People's Republic of ChinaStrict localization for CII and large processorsSecurity assessment, standard contract, or certificationUp to RMB 50M (~$7M) or 5% annual revenue + business suspension
Russia 242-FZRussian FederationStrict localization — initial storage must be within RussiaAllowed only after initial local storageUp to RUB 18M (~$195K) for repeated violations + service blocking
DPDP Act (India)Republic of IndiaConditional — government may restrict transfers by notificationGeneral permission subject to government blacklist of countriesUp to INR 250 crore (~$30M)
LGPD (Brazil)Federative Republic of BrazilTransfer-regulated (no mandatory localization)Adequacy decisions, SCCs, BCRs, specific consentUp to 2% revenue, limited to R$ 50M (~$10M) per violation
EU AI ActEU / EEANo direct localization — but data governance requirements for high-risk AIN/A — data governance (Article 10) requires dataset provenance, quality, and bias documentationUp to €35M or 7% global annual turnover for prohibited practices; up to €15M or 3% for other violations

GDPR — AI Applicability

AI training/inference using EU personal data outside EEA = regulated transfer. EU AI Act adds data governance requirements for high-risk AI.

PIPL (China) — AI Applicability

AI processing of Chinese personal data must occur domestically. Foreign AI APIs effectively blocked for regulated entities.

Russia 242-FZ — AI Applicability

Western AI services processing Russian citizen data outside Russia = non-compliant. On-prem or domestic AI required.

DPDP Act (India) — AI Applicability

Currently permissive but architecture should anticipate future localization requirements. Financial sector: RBI localization applies.

LGPD (Brazil) — AI Applicability

Cross-border AI processing permitted with documented transfer mechanism. ANPD 2024 regulation clarified AI workload framework.

EU AI Act — AI Applicability

High-risk AI systems: training/validation/testing datasets must be relevant, representative, and well-governed. High-risk obligations apply from August 2, 2026.

Where Does Your AI Prompt Data Travel?

When you send a prompt to an AI model, your data crosses network boundaries, jurisdiction borders, and provider infrastructure — each step governed by different laws.

AI Prompt Data Journey — Cross-Border Data Flow👤 UserYour Device🛡️ Shield GatewayRedacts PII, secrets,PHI, PCI beforedata leaves network✓ Sensitive data stays localRaw promptRedacted promptRedacted promptRedacted prompt🇺🇸 US WestOpenAI / Anthropic🇪🇺 EU FrankfurtBedrock / Vertex AI🇯🇵 Asia-PacificAWS Tokyo / GCPAI Provider Infrastructure(Data now crosses border)✅ With Shield:Only placeholder tokens leave❌ Without Shield:Raw PII/secrets cross border🟠 Shield Gateway = local redaction | 🔵 Regions = AI provider data centers | Dashed line = jurisdiction boundary

The redaction approach: sensitive data never leaves your network. AI providers only see placeholder tokens — eliminating jurisdiction risk at the source.

Frequently Asked Questions

Common questions about data residency, sovereignty, and what they mean for your AI usage.

No — GDPR does not mandate that personal data must stay within the EU. Instead, it requires that when personal data is transferred outside the European Economic Area, it must be protected by a legal mechanism that ensures 'essentially equivalent' protection. These mechanisms include adequacy decisions (the EU has determined certain countries have adequate protection), Standard Contractual Clauses (SCCs), or Binding Corporate Rules (BCRs). The key is documented compliance — not geographic restriction. The EU-US Data Privacy Framework provides one pathway for transfers to the United States. For AI specifically: if you're using ChatGPT or Claude to process EU personal data on US-based infrastructure, you need a valid transfer mechanism documented — the fact that data leaves the EU is not itself a violation, but doing so without safeguards is.

For most regulated entities in China — especially Critical Information Infrastructure (CII) operators and large data processors — using ChatGPT or other Western AI APIs that process data outside mainland China is effectively prohibited under the PIPL. Personal data gathered in China must generally be stored domestically, and cross-border transfers require government security assessments. Organizations operating in China typically need to use China-hosted AI services (such as Baidu ERNIE, Alibaba Tongyi Qianwen, or SenseTime) or maintain separate, localized AI infrastructure. Multinational companies often run parallel AI stacks: one for their China operations using domestic providers, and another for global operations using Western AI services — with strict data separation between the two environments.

This depends on the provider and your account type. For OpenAI's consumer ChatGPT (free/Plus tiers), your conversation data may be used to improve the models unless you opt out through the settings menu. For ChatGPT Enterprise and Edu, customer data is not used for training. For the API, data is not used for training by default. However — and this is the key data residency concern — even when training is opt-out, your prompts and responses are processed in data centers chosen by the provider, which may cross jurisdictional boundaries. OpenAI offers data residency in 10 regions for eligible customers, but the free ChatGPT product does not offer regional storage choice. The safest approach for organizations is to use enterprise-tier services with data residency commitments — or use a local redaction gateway like Purfect Shield that removes sensitive data before it ever reaches any AI provider.

The EU AI Act (enforceable for high-risk AI from August 2, 2026) does not directly mandate data localization, but its Article 10 data governance requirements create indirect residency obligations. High-risk AI systems must document the provenance, quality, and governance of their training, validation, and testing datasets — including where data originated and how it was processed. Fines reach up to 4% of global annual turnover (€35M maximum for prohibited practices). For organizations deploying AI in the EU, this means: (1) you must know where your AI data lives, (2) you must document its journey, and (3) you must be able to prove that datasets are relevant and representative for your deployment context. The practical effect is that organizations may choose to keep AI data within EU infrastructure to simplify compliance documentation — even though the Act doesn't explicitly require it.

As of mid-2026, the major providers offer varying levels of data residency control. OpenAI supports at-rest data residency in 10 regions (EU, US, UK, Japan, Canada, South Korea, Singapore, Australia, India, UAE) and inference residency in the EU, US, and UAE for eligible enterprise customers — accessed via region-specific API endpoints (eu.api.openai.com, us.api.openai.com, ae.api.openai.com). Anthropic's Claude offers regional data residency through cloud partners: AWS Bedrock guarantees data stays within US, EU, Japan, or Australia through regional endpoints; GCP Vertex AI provides the same through its 40+ global regions. Anthropic's direct API does not currently offer regional processing. Google's Vertex AI provides region-locked processing across all GCP regions. Microsoft's Azure OpenAI offers regional deployments. The key pattern: cloud marketplace routes (Bedrock, Vertex) provide stronger residency guarantees than direct API access.

These three terms are often used interchangeably but have distinct meanings in regulatory compliance. Data residency refers to where data is physically stored or processed — the geographic location of the servers. Data sovereignty means that data is subject to the laws of the country where it resides — a legal concept, not a physical one. Data localization is the strictest form: a legal requirement that data must be stored and/or processed within a specific country's borders. Every localization requirement implies residency, but not every residency requirement implies sovereignty. For example, storing EU personal data in a US-based AWS region in Frankfurt means the data resides in Germany (residency = EU) but may still be subject to US law under the CLOUD Act (sovereignty question). Organizations need to address all three dimensions when architecting AI data flows.

Related Articles

Keep your AI data where it belongs.

Purfect Shield redacts sensitive data before it ever reaches an AI provider — so your PII, secrets, and confidential business data never cross jurisdictional boundaries. No residency risk. No compliance headaches. Just safe AI usage.

Last updated: July 25, 2026. This page covers data residency requirements as of mid-2026. AI provider data residency offerings change frequently — always verify current terms with your provider.