EU servers are not a firewall
The server location is not crucial – what matters is whether personal data is sent to AI models at all The lawyer who did everything right A lawyer from Hamburg has been using a German AI platform for contract analysis…
Av Raitschin Raitschew · · Oppdatert
The server location is not crucial – what matters is whether personal data is sent to AI models at all
The lawyer who did everything right
A lawyer from Hamburg has been using a German AI platform for contract analysis for three months. German servers. ISO certified. Privacy policy checked. Data processing agreement signed.
He uploads an employment contract. Client's name: Maria Schneider. Date of birth. Tax ID. Salary. Everything included.
The lawyer is satisfied. GDPR compliant. German platform. What could possibly go wrong?
What he did not consider: The data is sent for processing to an AI model. This model is operated by a US company – OpenAI, Anthropic, or Google. And these companies are subject to the CLOUD Act.
In August 2025, Marc Carniaux, Vice President of Microsoft France, confirmed before the National Assembly: In the case of a formally correct US request, Microsoft is legally obliged to hand over data. Despite EU Data Boundary. Despite encryption. Despite all contracts.
The client data of Maria Schneider was sent to an AI model controlled by a US company. The German server location of the platform does not change that.
Was that really GDPR compliant?
The thesis that no one wants to hear
The server location is not the decisive factor.
What matters is another question: Are personal data sent to an AI model operated by a US company?
If yes, then complex legal questions arise. Third country transfers. CLOUD Act. FISA 702. A compliance situation that depends on political developments in Washington.
If no – if you anonymize data before transmission – then the GDPR does not apply to this data. Recital 26 states it clearly: Anonymized information is not subject to data protection.
No personal data sent = no data protection obligations for this transfer.
This is the structurally safest solution.
The fundamental problem: Where is the data processed?
The German AI landscape has developed significantly in recent years. There are now several platforms offering AI services focused on data protection and EU hosting:
DeutschlandGPT advertises with BSI C5 certification, ISO 27001, and hosting in the Telekom data center in Frankfurt. Langdock from Berlin has gained over 1,500 customers and is SOC 2 Type II certified. Logicc from Hamburg relies on Azure Frankfurt and AWS Bedrock EU. MeinGPT from SelectCode hosts the platform at Hetzner in Germany.
These are reputable providers with well-thought-out security concepts. The German server locations and certifications are real advantages compared to the direct use of ChatGPT or Claude.
But upon closer inspection, a structural problem emerges that all these solutions share – and it is not due to the providers themselves:
The leading AI models – ChatGPT, Claude, Gemini – are developed and operated by US companies. OpenAI, Anthropic, Google. Even if these models are provided through European cloud regions (Azure EU, AWS EU, GCP EU), control remains with US companies.
And US companies are subject to US law.
The difference between storage and processing
Here lies a common misunderstanding. Many platforms advertise that data is stored on German or European servers. This is correct and important.
But: Storage is not the same as processing.
When you upload a document and have it analyzed by an AI, the data is sent for processing to an AI model. This model runs on infrastructure controlled by US companies – even if the servers are physically located in Frankfurt or Dublin.
This is the critical point that many overlook.
The legal dilemma: Why EU servers do not automatically protect
The CLOUD Act – The extraterritorial law
In 2013, the US Department of Justice demanded Microsoft hand over emails stored on servers in Dublin. Microsoft refused. The case went through the courts. The Second Circuit ruled in favor of Microsoft.
The reaction of the US Congress? The Clarifying Lawful Overseas Use of Data Act. Passed in 2018. Retroactively. Clearly.
The core statement is in Section 2713: US authorities can compel US companies to hand over data, “regardless of whether they are located inside or outside the United States.”
The physical server location is not legally decisive. What matters is the control over the data. And this control lies with the companies operating the AI models.
The BMI report from the University of Cologne from December 2025 states unequivocally: “The ability of US authorities to secure data in this way cannot be reliably excluded by technical or organizational measures alone.”
FISA Section 702 – Mass surveillance
The Foreign Intelligence Surveillance Act allows US intelligence agencies to monitor non-US persons outside the USA. Without individual judicial approval. Without specific suspicion.
Affected are “Electronic Communication Service Providers” – which also include cloud providers and AI services.
The 2024 expansion further extends the circle of cooperating companies.
This was exactly the reason why the ECJ declared the Privacy Shield invalid in the Schrems II ruling: US surveillance programs are not proportionate by EU standards. EU citizens have no judicially enforceable legal protection in the USA.
Structurally, nothing has changed.
Article 48 GDPR – The unresolved conflict
Article 48 of the GDPR prohibits the recognition of judgments and decisions of authorities from third countries without an international agreement. Such a mutual legal assistance agreement between the EU and the USA regarding the CLOUD Act does not exist.
US companies are caught in a dilemma:
- In compliance with the CLOUD Act: Potential GDPR violation
- In refusal: US sanctions
Microsoft has clarified its position. Marc Carniaux confirmed it before the French National Assembly: In the case of a formally correct request, Microsoft will hand over the data.
The Cologne report
In December 2025, a legal opinion from the University of Cologne commissioned by the BMI was made public through a freedom of information request.
The core statement: For sensitive data, public administration, and critical infrastructure, the use of cloud services under US control is fundamentally “incompatible” with digital sovereignty and full GDPR compliance.
Fundamentally incompatible. Not “difficult.” Not “possible with additional measures.” Incompatible.
The EU-US Data Privacy Framework – A temporary solution
Since July 10, 2023, the EU-US Data Privacy Framework allows data transfers to certified US companies without additional guarantees. The major AI providers are certified.
The DPF offers:
- An Executive Order 14086 with “proportionality” requirements for US intelligence agencies
- A two-tier complaint mechanism
- Annual reviews
This is an improvement compared to the time after Schrems II without an adequacy decision.
The uncertainty factors
FISA 702 has not been reformed. The law remains unchanged.
The word “proportional” is interpreted differently in the USA than in the EU. What is considered proportional in Washington could fail before the ECJ.
The Data Protection Review Court is not an independent jurisdiction in the classical sense. The judges are appointed by the US Attorney General. The proceedings are not public.
The Privacy and Civil Liberties Oversight Board (PCLOB), which was supposed to oversee surveillance practices, has been weakened by the dismissal of members. The BfDI expressed “serious concern.”
Schrems III on the horizon
Max Schrems and noyb have referred to the DPF as a “copy of the failed Privacy Shield.” A judicial review is likely.
Any company that relies solely on the DPF for its AI usage carries a residual risk. Not today. But possibly tomorrow.
The landscape of German supervisory authorities: Different assessments
The critical voices
The Data Protection Conference (DSK) stated in November 2022 with a narrow majority (9:8): The proof that Microsoft 365 is operated in compliance with data protection law “cannot be established on the basis of the Microsoft data protection addendum.”
The European Data Protection Supervisor (EDSB) stated in March 2024: The EU Commission itself violates data protection regulations with its use of Microsoft 365.
The pragmatic voices
In November 2025, the Hessian Data Protection Officer Prof. Dr. Alexander Roßnagel declared Microsoft 365 to be usable in compliance with data protection – referring to the DPF and Microsoft's EU data boundary.
IT security researchers criticized that no technical review had taken place.
The core problem
The supervisory authorities assess differently. They review contracts and documentation, but not the technical reality of data flows.
In the end, the using company bears the risk. Not the AI provider. Not the supervisory authority. You.
The structural solution: Anonymization before transmission
What does NOT provide sufficient protection
EU server location alone: The server location determines where data is stored. But if this data is sent for processing to an AI model under US control, the storage location is no longer decisive.
Encryption with provider key: If the AI provider has the key, they can decrypt. And if they can decrypt, they can hand over.
Standard Contractual Clauses (SCCs): After Schrems II, SCCs are only effective with “Supplementary Measures.” The EDPB recommendations show how complex this is in practice.
Contractual assurances: “We will contest requests” is not the same as “We will not hand over.” In the end, US law applies to US companies.
What structurally protects
Anonymization before transmission: If no personal data is sent to the AI model, there is no personal data that could be handed over.
This is not risk minimization. This is risk elimination for this specific aspect.
The legal basis for anonymization
Recital 26 of the GDPR:
“The principles of data protection should therefore not apply to anonymized information, i.e., information that does not relate to an identified or identifiable natural person, or personal data that has been anonymized in such a way that the data subject cannot or can no longer be identified.”
This is not an interpretation. This is the text of the law.
Anonymized data = no personal data = GDPR not applicable to this data.
The EDPB confirms: Genuine anonymization lifts data protection obligations.
Why anonymization trumps all other measures
Regardless of server location: It does not matter whether the server is in Frankfurt, Dublin, Singapore, or Virginia. If no personal data is sent, there is nothing to protect.
Regardless of AI provider: It does not matter whether OpenAI, Anthropic, Google, or Mistral operates the model. No access to personal data is possible if none is transmitted.
Regardless of the Data Privacy Framework: If Schrems III comes and the DPF is declared invalid, your processes remain unaffected. No dependence on political developments.
Anonymized data + any AI model = no GDPR relevance for the transmitted data
This is the mathematical certainty that no other measure can provide.
Practical example: The difference in everyday life
Scenario: Law firm analyzes employment contract
Without anonymization:
Input to AI: "Analyze this employment contract between Müller GmbH and Mr. Max Mustermann, born on 15.03.1985, residing at Bahnhofstraße 12, 80331 Munich, Tax ID 12 345 678 901..."
- → Complete personal data is sent to the AI model
- → This data reaches systems under US control
- → CLOUD Act: US access theoretically possible
- → GDPR: Art. 44ff. applicable, complex legal basis required
- → In the case of Schrems III: Legal basis may fall away
With anonymization:
Input to AI: "Analyze this employment contract between [[ORG-1]] and [[PER-1]], born on [[DAT-1]], residing at [[ADR-1]], Tax ID [[ID-1]]..."
- → Only placeholders reach the AI model
- → No personal data leaves your system
- → CLOUD Act: Access only provides anonymous placeholders
- → GDPR: Not applicable to the transmitted data
- → In the case of Schrems III: No change required
After processing
The AI responds with placeholders: “[[PER-1]] is entitled to 30 vacation days according to the contract...”
The re-transformation inserts the original data: “Max Mustermann is entitled to 30 vacation days according to the contract...”
The lawyer receives a fully usable analysis. With client names. With specific references. Without personal data ever reaching an external system.
The decision matrix: When to use which approach
Not all data is equally sensitive. Not every processing requires the same protective measures. But the decision should be made consciously.
| Data type | Standard AI | Anonymization |
|---|---|---|
| Publicly available information | ✓ Sufficient | Optional |
| Business data without personal reference | ✓ Sufficient | Optional |
| Business data with personal reference | ⚠️ Risk assessment | Recommended |
| Customer data | ⚠️ Risk assessment | Urgently recommended |
| Client data (lawyers) | ❌ Professional secrecy | Mandatory |
| Patient data | ❌ Art. 9 GDPR | Mandatory |
| Employee data | ⚠️ Works council | Recommended |
| Financial data with personal reference | ⚠️ Regulatory | Urgently recommended |
| Authority data | ❌ BMI report | Mandatory |
The special categories
Article 9 of the GDPR defines “special categories of personal data”: Health data, biometric data, genetic data, political opinions, religious beliefs, trade union membership, sexual orientation.
Stricter requirements apply to this data. Processing is generally prohibited, with narrowly defined exceptions.
Sending a patient report to an AI system – regardless of where it is hosted – is a high-risk operation. Anonymization is not “recommended” here. It is practically mandatory.
The professional secrecy holders
Lawyers, tax advisors, auditors, doctors – they all have special confidentiality obligations. Criminally sanctioned. Relevant to professional law.
§ 203 StGB protects professional secrecy. The disclosure of entrusted secrets is punishable.
If a lawyer enters client data into an AI system controlled by a US company – is he then disclosing a secret?
The legal debate is still ongoing. But the practical consequence is clear: Those who want to be on the safe side anonymize.
Recommendations for action
For companies wanting to use AI
Immediately: Inventory. What AI tools are being used? What personal data is being transmitted? Who approved it?
Short term: Transfer Impact Assessment for each service. This is not an optional exercise. After Schrems II, it is mandatory. Document the risks.
Medium term: Evaluate anonymization solution. Not necessary for all use cases. But essential for sensitive data.
Long term: Exit strategy in case the DPF falls. What happens in Schrems III? Which processes are affected? How quickly can you switch?
For regulated industries
Lawyers: The confidentiality obligation under § 43a BRAO is non-negotiable. Client data in AI systems? Only anonymized.
Tax advisors: § 57 StBerG defines the obligation to maintain confidentiality. Tax returns contain highly sensitive data. Anonymization is the safe way.
Doctors: Patient data are special categories under Art. 9 GDPR. The medical confidentiality obligation under § 203 StGB is criminally protected. No compromises possible.
Financial service providers: BaFin has clear requirements for outsourcing. AI services from US providers? Check MaRisk compliance. Anonymization significantly reduces regulatory risk.
The checklist
- ☐ What personal data are we sending to AI services?
- ☐ Who operates the AI models we use?
- ☐ What legal basis do we have for this transfer?
- ☐ Have we conducted a Transfer Impact Assessment?
- ☐ What happens in the event of a Schrems III ruling?
- ☐ Have we evaluated an anonymization solution?
- ☐ Is our data protection officer involved?
- ☐ Is the works council informed (if applicable)?
The new way of thinking
The old question
“Is my AI provider GDPR compliant?”
This question is misleading. It suggests that GDPR compliance is a characteristic of the provider. Something that can be purchased. A tick on a list.
GDPR compliance is the result of an interplay of technology, organization, and law. The provider can contribute. But the responsibility lies with you.
The right question
“Am I sending personal data to AI systems controlled by US companies?”
This question forces an analysis of the actual data flow. Not the marketing promises. Not the contracts. The reality.
And it opens up a solution: If you do not send personal data, you have solved this specific problem. No third country transfer discussion for this data. No Schrems III worries. No CLOUD Act risks.
The realization
EU servers are better than US servers. This is undisputed.
But: If the data is sent for processing to AI models under US control, the storage location is no longer the decisive factor.
The only structurally safe solution: Do not send personal data.
Anonymization is not “one option among many.” For sensitive data, it is the only solution that works independently of political and legal developments.
All other measures – EU servers, encryption, contracts, certifications – are important and correct. But they are risk-minimizing. Not risk-eliminating.
The difference is fundamental.
The conclusion
The AI revolution is real. The productivity gains are enormous. No company can afford to ignore this technology.
But its use must be responsible.
The question is not: Which AI platform has the prettiest data protection badges?
The question is: Which data leaves my company? And how can I control that?
For public information and general business data without personal reference, the answer is simple: Use AI tools at your best discretion.
For sensitive data – client data, patient data, employee data, customer data – the answer is also clear: Anonymize before you send.
Not because AI providers are unreliable. But because the legal situation is complex, can change, and you bear the responsibility.
Anonymization gives you back control. Regardless of what is decided in Washington, Brussels, or Luxembourg.
This is not fear. This is precaution.
This is not a compromise solution. This is the best solution.
About anymize.ai
anymize.ai is the firewall for personal data. We enable the secure use of AI services through automatic document anonymization – with over 95% recognition rate and unique bidirectional functionality.
Our technology detects and replaces personal data before they leave your company. After AI processing, the original data is restored. You receive personalized results without transferring personal data.
Our approach: GDPR compliance through technology, not through trust.
Frequently Asked Questions (FAQ)
Are EU servers sufficient for GDPR-compliant AI use?
The server location alone is not decisive. If personal data is sent for processing to AI models operated by US companies, the CLOUD Act applies – regardless of where the data is stored. The safest solution: Anonymize personal data before transmission.
What is the safest way to use AI with sensitive data?
The safest approach is to anonymize personal data before transmission to AI systems. If no personal data is sent, the GDPR does not apply to this transfer, and there is no data that could be handed over.
Why is the CLOUD Act relevant for German companies?
The US CLOUD Act of 2018 obliges US companies to hand over data “regardless of where the data is located.” If AI models are operated by US providers such as OpenAI, Anthropic, or Google, they can be compelled to hand over data – even if the servers are in the EU.
What happens to my AI usage in the event of a Schrems III ruling?
If the ECJ declares the EU-US Data Privacy Framework invalid, the legal basis for data transfers to US companies falls away. Companies relying solely on the DPF would have to adjust their AI usage. Anonymized data would not be affected – they do not fall under the GDPR and do not require a transfer basis.
Can lawyers use AI tools without concern?
For general research and publicly available information: yes. For client data: only with anonymization. The lawyer's confidentiality obligation under § 43a BRAO and the professional secrecy under § 203 StGB prohibit uncontrolled disclosure of client information. Anonymization before transmission is the safe way.
How does bidirectional anonymization work?
In bidirectional anonymization, personal data is replaced by placeholders before AI transmission (e.g., “Max Müller” → “[[PER-1]]”). The AI processes only anonymized data. After receiving the AI response, the placeholders are replaced with the original data. The result: Personalized, usable answers – without personal data having left the company.
Act now: GDPR-compliant AI use with anymize.ai
Do you want to take advantage of ChatGPT, Claude, and other AI models – without data protection risks?
anymize.ai offers:
- ✓ Automatic detection of personal data (>95% accuracy)
- ✓ Bidirectional anonymization with restoration of original data
- ✓ Processing of documents, not just prompts
- ✓ Integration into existing workflows (API, Zapier, Make.com, n8n)
- ✓ German development, GDPR compliant
Sources
- BMI/University of Cologne: Legal opinion on cloud usage (December 2025)
- EDPB Guidelines 05/2021 on the interplay of Art. 3 and Chapter V GDPR
- DSK resolution on Microsoft 365 (November 2022)
- EDSB decision on the EU Commission's use of Microsoft 365 (March 2024)
- HBDI Hessen: Press release on Microsoft 365 (November 2025)
- Marc Carniaux, Microsoft France: Statement before the National Assembly (August 2025)
- Max Schrems/noyb: Statements on the EU-US Data Privacy Framework
- GDPR Recital 26
- US CLOUD Act, Section 2713
- FISA Section 702
This article is for informational purposes only and does not constitute legal advice. For specific questions regarding the GDPR compliance of your AI usage, please contact your data protection officer or a specialized lawyer.