Generative AI disrupts compliance habits. Data minimisation, legal basis, transfers outside the EU: all of these arise as soon as a model processes personal data, wherever it runs.
The friction points with the GDPR
- Data transfers outside the European Union to third-party servers.
- Difficulty guaranteeing minimisation and purpose limitation.
- Storage and reuse of queries by the vendor.
- Informing data subjects and handling their rights.
On-site processing: a structural answer
When the model runs on your servers, with no outbound connection, most of these frictions disappear: no transfer outside the EU, no third party keeping your data, a clear and auditable processing perimeter.
What you still need to document
On-premise does not exempt you from rigour: processing records, retention periods, security (encryption, access control). What it mainly does is reduce the number of guarantees you have to obtain from a third party, since the perimeter stays under your direct control.
So the real question is not “AI or GDPR”, but “where does the AI run, and with what guarantees”. On-site, the perimeter is yours. Hosted, everything depends on where the servers sit, on the processing agreement and on the no-reuse commitment: all perfectly documentable, provided you require it in writing.
