Back to blogAI & Software

Onboarding EU Clients: GDPR and Data Residency from Day One

EU teams ask about hosting, subprocessors, and DPIAs before they ask about model choice. How we structure discovery and contracts so compliance is part of scope, not a surprise in week three.

Share this article

GDPR and EU client onboarding: PAI Technologies blog

A US team might ask about accuracy first. A Swiss or German client often asks where data is processed, which subprocessors touch prompts, and whether a DPIA is needed before production traffic. That is healthy, not a blocker if scoped early.

At PAI Technologies we treat compliance questions as inputs to architecture, not tickets for “later.” Our active EU work includes Gordon for M-agi-c Solutions (Switzerland), with production stacks on AWS eu-central-2 (Zurich) and documented data flows from discovery onward.

This article is how we onboard EU clients: what we clarify in the first two calls, how that appears in the statement of work, and what engineering implements in the same sprint as features.

Why EU clients lead with compliance questions

GDPR and Swiss FADP-style regimes care about purpose limitation, data minimisation, subprocessors, and cross-border transfers. AI adds prompt logging, embeddings, and model providers, each a subprocessor decision.

Founders who skip these questions in week one often face DPO review in week eight with architecture already wrong for region locks or retention. We map legal requirements before we quote build time.

India-based delivery with EU hosting is normal for us: engineering in Delhi, data processing in the client-required region, communication async-first across CET and IST.

What we clarify in the first two calls

EU AI project discovery: data categories and hosting region
Data inventory and residency decided before stack choices are frozen.

Data categories: personal data in prompts, logs, embeddings, or training? Special categories? If users paste free text, assume PII until proven otherwise.

Hosting: required region (eu-central-2 Zurich for Gordon-class), existing VPC, or greenfield on our recommended EU setup. We do not default US regions for EU contracts.

Subprocessors: model providers, vector DB, observability, email, listed for your vendor review with purpose and data types.

Retention: how long prompts and logs are kept; deletion path for end users; whether embeddings must be purged on erasure requests.

  • Lawful basis and role (controller vs processor) documented
  • Cross-border transfer mechanism if any India/US processing occurs
  • Security contact and incident notification expectations

From discovery to statement of work

Milestones include a short data-flow diagram and subprocessor table, not a 200-page legal pack, but enough for your DPO or counsel to sign off before heavy traffic.

Acceptance criteria reference compliance behaviours: region lock enforced, logs redacted, retention job tested, alongside functional AI criteria.

Commercially, we align milestone payments with demoable compliance artefacts, not only UI features. EU clients appreciate seeing evidence, not promises.

Engineering implementation in the same sprints

GDPR-ready AI deployment on eu-central infrastructure
Region locks, encryption, and access controls shipped with features, not after.

Region-specific deployment, encryption in transit and at rest, least-privilege IAM, and structured logging with redaction are part of feature sprints, not a separate “compliance phase.”

Gordon’s stack choices reflect this: EU endpoints, documented flows for cooking-related user data, and subprocessors reviewed with M-agi-c stakeholders early.

We hand over runbooks: how to rotate keys, purge user data, and update the subprocessor list when you add a tool.

Checklist for EU inbound briefs

Include required region, data categories, existing security standards, and whether personal data appears in AI prompts. We respond with approach, timeline, and compliance artefacts included in scope.

EU onboarding is smoother when one stakeholder owns both product and privacy questions for v1, even if counsel reviews in parallel.

Email Info@thepaitechnologies.com with your brief; we have run Gordon-scale EU AI and UK hardware (MythraCore) with the same async delivery rhythm as US clients, compliance just starts on day one.

Share this article