All posts
Privacy · Finance operations·August 2026

GDPR compliance, EU data residency and digital sovereignty are not the same thing

Location is only one part of data protection. Understanding the difference between these four concepts is essential when choosing AI and billing infrastructure.


Location is only one part of data protection

Contracts can contain names, email addresses, signatures, commercial terms, bank details and other confidential information.

When AI is used to interpret those contracts, buyers often ask:

  • Is the platform GDPR compliant?
  • Is the data stored in Europe?
  • Is the provider European?
  • Can a foreign authority access the data?
  • Is the information used to train AI models?

These questions are related, but they are not interchangeable. A platform may store data in the EU without providing complete digital sovereignty. A US provider may process European data lawfully. A European provider may still rely on non-European infrastructure or subprocessors.

Lawfulness
GDPR compliance
Answers"Is data processed lawfully?"
CoversCollection, use, security, retention
Does not coverWhere data is physically stored
CheckData Processing Agreement
ResponsibleController and processor together
Location
EU data residency
Answers"Where is the data stored?"
CoversDatabase, backups, logs, AI processing
Does not coverLegal processing obligations
CheckSubprocessor and region documentation
ResponsibleVendor infrastructure configuration
Masking
Pseudonymisation
Answers"Have direct identifiers been masked?"
CoversNames, emails, signatures, phone numbers
Does not coverFull anonymisation under GDPR
CheckProcessing architecture documentation
ResponsibleVendor technical pipeline
Control
Digital sovereignty
Answers"Who ultimately controls the system?"
CoversInfrastructure, keys, jurisdiction, access
Does not coverCompliance or residency alone
CheckOwnership, subprocessors, exit terms
ResponsibleOrganisation procurement assessment

GDPR compliance

GDPR compliance concerns how personal data is collected, used, secured, retained and shared.

Important principles include:

  • lawfulness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • limited retention;
  • integrity and confidentiality;
  • accountability.

The European Data Protection Board describes data minimisation as limiting personal data to what is adequate, relevant and necessary for the stated purpose.

For contract-processing software, relevant questions include:

  • What personal information is required?
  • What is the lawful basis for processing it?
  • How long is it retained?
  • Which subprocessors receive it?
  • Is it used for model training?
  • Can it be deleted or exported?
  • What security controls protect it?

GDPR compliance is therefore a continuing operational responsibility—not simply a hosting-region setting.

EU data residency

Data residency describes where data is physically stored or processed.

A company may require its primary database, file storage, backups, logs, AI processing and analytics data to remain within the EU or EEA.

For example, Supabase currently offers several European deployment locations, including Frankfurt, Stockholm, Paris and Ireland. Each project is deployed to a selected primary region, and choosing the appropriate region remains the customer's responsibility.

However, selecting an EU database region does not automatically mean every part of an application remains in Europe. A company must also examine:

  • AI model providers;
  • monitoring and analytics tools;
  • support systems;
  • email services;
  • edge functions;
  • backups;
  • disaster-recovery locations;
  • subprocessors.

A credible residency claim should describe the complete data flow, not only the location of the main database.

International data transfers

Using a non-European provider is not automatically prohibited under GDPR.

European personal data may be transferred outside the EEA through recognised legal mechanisms, including adequacy decisions, Standard Contractual Clauses and other appropriate safeguards. The European Commission's modernised Standard Contractual Clauses are specifically designed to support transfers from the EU or EEA to recipients in third countries.

This means statements such as “US cloud providers are illegal in Europe” are inaccurate. The more useful questions are:

  • Is personal data transferred internationally?
  • Which transfer mechanism is used?
  • What supplementary technical and organisational protections apply?
  • Can the processing be limited to European infrastructure?
  • Does the customer's industry impose stricter requirements?

Banks, insurers, healthcare organisations and public-sector buyers may apply more restrictive procurement and risk policies than the legal minimum.

Pseudonymisation and anonymisation

Removing direct identifiers before AI processing can reduce risk, but the terminology matters.

Pseudonymisation replaces or removes direct identifiers while retaining the possibility of reconnecting the information to an individual using additional data. Pseudonymised information generally remains personal data and therefore remains subject to GDPR.

Original contract data
After local masking
Anna Svensson
cust-contact-01
anna.svensson@company.se
ref_0281@masked
+46 70 123 4567
[REDACTED]
Signature: [image present]
[REMOVED]
SE556789-0123 (org. number)
[MASKED]

Anonymisation removes the ability to identify an individual irreversibly. Truly anonymised data are no longer treated as personal data under GDPR. Achieving reliable anonymisation can be difficult, particularly when information can be recombined with other datasets.

A vendor should therefore describe its approach as local masking or pseudonymisation of direct identifiers, unless the complete processing chain can demonstrate irreversible anonymisation.

Digital sovereignty

Digital sovereignty is broader than privacy compliance or data residency. It considers who ultimately controls:

  • the infrastructure;
  • encryption keys;
  • software and intellectual property;
  • administrative access;
  • operational support;
  • legal jurisdiction;
  • portability and exit;
  • dependency on third-country providers.

The European Commission describes technological sovereignty as Europe's ability to develop and control important technologies, data and infrastructure while reducing strategic reliance on non-EU providers.

A product hosted in an EU data centre is therefore not necessarily fully sovereign if it remains controlled by a non-European company or depends heavily on non-European services. Equally, being incorporated in Europe does not make a platform sovereign if its entire infrastructure and AI-processing chain are controlled elsewhere.

How to evaluate an AI contract platform

Buyers should review at least five areas.

Area
Key question
Data collection
Is the platform processing only the information it needs?
Residency
Where are contracts, metadata, logs and backups stored?
AI processing
Which model provider receives the content, and in which region?
International transfers
Which legal mechanism and safeguards apply?
Control
Who can access the data, keys and underlying infrastructure?

They should also ask whether:

  • customer data is used to train shared models;
  • retention periods can be configured;
  • direct identifiers can be removed before AI analysis;
  • subprocessor changes are communicated;
  • data can be deleted after processing;
  • audit logs are available;
  • different customers can receive dedicated environments.

Where Verdix fits

A defensible position for AI-powered agreement software is based on specific, verifiable architectural controls rather than broad claims of complete sovereignty.

The architecture should aim to:

  • store customer data in selected EU regions;
  • remove or replace direct identifiers before AI processing;
  • minimise the contract content transferred to external services;
  • document every subprocessor and processing location;
  • prevent customer data from being used to train shared AI models;
  • apply encryption, retention and access controls;
  • offer stronger isolation for regulated enterprise customers.

Claims that all sensitive information remains entirely local should only be made when the complete processing chain—including AI inference, logs and backups—supports that statement.

The takeaway

These four concepts address different questions:

  • GDPR compliance: Is personal data processed lawfully and responsibly?
  • EU data residency: Where is the data stored and processed?
  • Pseudonymisation: Have direct identifiers been separated or masked?
  • Digital sovereignty: Who ultimately controls the technology, infrastructure and access?

A buyer should evaluate all four. For AI-powered billing and agreement operations, the strongest approach combines data minimisation, European processing options, local masking of direct identifiers and clear control over where contract information travels.

Operationalise customer and partner agreements with EU-first infrastructure and privacy controls designed into the workflow.