The short answer: a BI platform that keeps personal data inside the EU (or your own datacenter), runs its AI without calling a third-party LLM, and can produce the audit logs, processor terms and DPIA support that the GDPR and EU AI Act require. This guide shows how to verify each before you sign.
Last reviewed: July 2026
Two regimes govern AI analytics in the EU. The GDPR (Regulation (EU) 2016/679) has applied since 2018 and covers any processing of personal data — lawful basis, data-subject rights, security (Article 32), processor terms (Article 28) and impact assessments (Article 35). The EU AI Act (Regulation (EU) 2024/1689) adds a second, product-safety-style layer on top.
On 2 August 2026, the core of the EU AI Act becomes applicable, including the obligations for "high-risk" AI systems listed in Annex III. Analytics and BI software is not automatically high-risk: it falls under these rules only when used for an Annex III purpose, such as screening job applicants, scoring creditworthiness, or determining access to essential services. Prohibited practices have applied since 2 February 2025, and rules for general-purpose AI models since 2 August 2025.
When your BI does touch a high-risk use, Article 12 requires the system to keep automatic logs over its lifetime, alongside risk management, data governance and human oversight. Even outside high-risk uses, those same audit logs are among the strongest ways to demonstrate GDPR accountability.
“High-risk AI systems shall technically allow for the automatic recording of events (logs) over the lifetime of the system.”
The single most important compliance question is not the tool, but the job you give it. The same dashboard is ordinary analytics when it tracks revenue and high-risk AI when it ranks job applicants. Map each AI use case against Annex III before you assume the heavier obligations apply.
Maximum EU AI Act fine for the most serious violations — up to €35 million or 7% of worldwide annual turnover, whichever is higher (Article 99).
EU AI Act, Article 99Before shortlisting any AI analytics vendor, confirm each of these. They map directly to GDPR and EU AI Act obligations for EU mid-market buyers.
Confirm where personal data is stored and processed. For EU mid-market firms the safe default is hosting inside the EU/EEA, or on your own infrastructure, so the cross-border transfer question never arises.
Many "AI analytics" tools forward your data to an external model API. Ask whether prompts, rows or schema ever leave your environment. Self-hosted or on-premise models keep inference local.
If your use case is high-risk under Annex III, the system must keep automatic event logs over its lifetime. Even when it isn't, audit logs are strong evidence of accountability under GDPR Art. 5(2).
For high-risk processing you must run a Data Protection Impact Assessment. A good vendor supplies the technical documentation, data-flow diagrams and model information you need to complete one.
Any vendor that processes personal data on your behalf must sign a GDPR Art. 28 DPA with documented sub-processors. Check the sub-processor list and how you're notified of changes.
Ask for encryption in transit and at rest, access controls, and independent evidence such as ISO 27001 or a SOC 2 report. Vague "bank-grade security" claims are not evidence.
If any data reaches a non-adequate country, you need Standard Contractual Clauses plus a transfer impact assessment and supplementary measures. Keeping data in the EU avoids this entirely.
Financial entities must meet DORA's ICT third-party rules; Swiss buyers must meet the revised FADP (revDSG). Confirm the vendor can be an accountable ICT provider and supports Swiss data residency.
Use this table in vendor calls. The middle column is the question to ask; the right column is the answer that should make you walk away.
| Evaluation criterion | What to ask the vendor | Red flag |
|---|---|---|
| Data location | Where exactly is our data stored and processed, and can we choose EU-only or self-hosting? | "It's in the cloud" with no named region or country. |
| AI model hosting | Does the AI run on your own models, or do you call an external LLM API? | Data is sent to a third-party model and can't be turned off. |
| Data used for training | Is our data ever used to train or fine-tune your models? | Customer data trains shared models by default. |
| Audit logging | Can we export immutable logs of every AI query and data access? | No per-query logs, or logs you can't export. |
| DPA & sub-processors | Will you sign a GDPR Art. 28 DPA and publish your sub-processor list? | No DPA, or an undisclosed chain of sub-processors. |
| Certifications | Can you share an ISO 27001 certificate or SOC 2 report? | Only marketing claims, no third-party attestation. |
| Pricing model | Is pricing fixed and predictable, or per-token / per-query? | Costs scale with usage, so compliance-heavy logging gets expensive. |
Where your data lives and where the AI model runs are the two decisions that drive most of your compliance exposure. Four broad models, from most to least exposed:
| Deployment model | Data location | LLM data egress | Compliance implication | Best for |
|---|---|---|---|---|
| Public SaaS cloud AI | Vendor's cloud, often outside the EU | Data sent to third-party LLM APIs | Highest transfer & AI Act exposure; needs SCCs + TIA | Low-sensitivity data, fast pilots |
| EU-region cloud | Vendor cloud, EU/EEA region | May still call external models | Residency solved; check LLM egress & sub-processors | EU firms wanting managed hosting |
| Self-hosted / on-premise | Your datacenter or private cloud | None — models run locally | Strong data sovereignty; you control logs & DPIA | Regulated mid-market, finance, health |
| Air-gapped | Isolated network, no internet | None by design | Maximum control for classified/critical data | Highly sensitive or sovereign workloads |
Adaptrix was built for exactly this problem. It is one option among several — here is how it maps to the checklist above, honestly.
AI agents plan and answer analytical questions without shipping your data to an external model.
Open models self-hosted in Adaptrix's German datacenters; on-premise deployment planned for Enterprise Plus.
Prompts, rows and schema stay inside your boundary; nothing is sent to a third-party model API.
For the most sensitive environments, a fully disconnected deployment is planned for Enterprise Plus.
Every AI query and data access can be logged, supporting GDPR accountability and Article 12-style record-keeping.
Predictable annual pricing with no per-token fees, so thorough logging never inflates your bill.
No. Most analytics and BI is not high-risk. It only falls under the high-risk obligations when used for an Annex III purpose — for example screening job candidates, scoring creditworthiness, or deciding access to essential services. Outside those uses, the AI Act's high-risk duties (including Article 12 logging) generally do not apply, though the GDPR always does.
That is the date the core of the EU AI Act becomes applicable, including obligations for high-risk AI systems in Annex III: risk management, data governance, record-keeping (Article 12), transparency and human oversight. Prohibited practices have applied since February 2025 and general-purpose AI model rules since August 2025.
Potentially, but you take on the transfer problem the CJEU raised in Schrems II. You need Standard Contractual Clauses, a transfer impact assessment and supplementary measures, and you must check whether data reaches a third-party LLM. Keeping data and inference in the EU removes most of this burden.
Rarely. There is no single official "GDPR certificate." Look instead for a signed Art. 28 DPA, a published sub-processor list, Art. 32 security evidence such as ISO 27001 or SOC 2, and clear answers on data residency. Treat "GDPR-certified" badges with caution.
The revised Swiss FADP (revDSG), in force since 1 September 2023, is closely aligned with the GDPR but is a separate law with its own breach-notification and DPIA duties and criminal sanctions of up to CHF 250,000 against responsible individuals. Swiss buyers should confirm Swiss data residency and a revDSG-ready processor agreement.
DORA, applicable since 17 January 2025, treats your analytics vendor as an ICT third-party provider. You need contractual resilience, incident-reporting and exit clauses, and critical providers fall under EU oversight. Ask whether the vendor can meet DORA's ICT third-party requirements.
See how agentic analytics runs on Adaptrix's own EU infrastructure with no LLM egress and audit logs built in.
Every legal claim on this page links to a primary source. Verify current text before making compliance decisions.
This buyer's guide is general information, not legal advice. Regulatory text and dates change; confirm the current position with the primary sources linked above and your own counsel before making purchasing or compliance decisions. Statutory penalty figures are quoted from the cited legislation; any illustrative examples are labelled as such.