← All pages

GDPR

Definition: A direct reference to the EU General Data Protection Regulation (GDPR) — the EU’s core data-privacy law — used to define “Applicable Data Protection Law,” justify a Data Processing Addendum, explain how data is legally transferred across borders (e.g., adequacy decisions, Standard Contractual Clauses, or a designated EU representative under Article 27), or list user rights in a Privacy Policy. Risk level: Not predatory on its own — a GDPR citation signals compliance, not risk. It’s tracked here because GDPR is the only regulatory framework consistently cited across this dataset (the EU AI Act is almost never named — see Notes & Trends below), which makes GDPR-reference patterns useful for comparing how seriously each provider documents its EU-law compliance.

Note on provenance: This concept page covers the sources/GenGA/ (GenGA/Open Terms Archive) dataset, which has no pre-tagged JSONL — all tagging here is LLM-assigned by direct reading. See each linked platform page’s methodology note.


Platforms Using This Clause

PlatformDocument TypeDateLink
ChatGPTBusiness Privacy Policy2025-11-11link
ChatGPTData Processor Agreement2025-11-11link
ChatGPTPrivacy Policy2025-11-11link
Claude.aiData Processor Agreement2025-11-11link
Claude.aiPrivacy Policy2025-11-11link
DeepSeekPrivacy Policy2025-12-08link
Le ChatData Processor Agreement2025-11-11link
Google Generative AI ServicesPrivacy Policy2026-02-20link
Le ChatPrivacy Policy2025-11-11link
Llama APITerms of Service2025-11-13link
Microsoft CopilotPrivacy Policy2026-01-30link
PerplexityData Processor Agreement2025-11-11link
PerplexityPrivacy Policy2025-11-11link
Qwen ChatPrivacy Policy2026-04-09link

Common Wording

Yes, we are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, and the API in support of their compliance with GDPR and other privacy laws. — ChatGPT, Business Privacy Policy, 2025-11-11

We rely on the European Commission’s adequacy decisions pursuant to Article 45(1) GDPR when transferring your Personal Data to any country that has been considered to provide an adequate level of protection. For other jurisdictions, we rely on the Standard Contractual Clauses (“SCCs”) as approved by the European Commission pursuant to Article 46(2)(c) GDPR and on the UK Data Transfer Addendum. — ChatGPT, Privacy Policy, 2025-11-11

Adequacy decisions. These are decisions from the European Commission under Article 45 GDPR (or equivalent decisions under other laws) where they recognise that a country outside of the EEA offers an adequate level of data protection. […] Standard contractual clauses. The European Commission has approved contractual clauses under Article 46 GDPR that allows companies in the EEA to transfer data outside the EEA. — Claude.ai, Privacy Policy, 2025-11-11

GDPR Certification: Art 27 representation by Prighter […] UK-GDPR Certification: Art 27 representation by Prighter […] powered by Prighter - GDPR Compliance / Privacy Representation for EU, Switzerland, UK and Turkey. — DeepSeek, Privacy Policy, 2025-12-08

“Applicable Data Protection Law” means any applicable privacy, data security, or data protection law or regulation, including, to the extent applicable, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 applicable since 25 May 2018 (the “GDPR”) and the California Consumer Privacy Act of 2018, as amended, and associated regulations promulgated thereunder (“CCPA”). — Le Chat, Data Processor Agreement, 2025-11-11

Under certain privacy laws, including the General Data Protection Regulation in the EU, you may have the right to: […] — Google Generative AI Services, Privacy Policy, 2026-02-20

We take the necessary steps to ensure that all contracts with service providers who process personal data outside the European Union have adequate safeguards in compliance with Article 46 of the GDPR. — Le Chat, Privacy Policy, 2025-11-11

In the event of international data transfers of Applicable Personal Data that are subject to the MGPT’s European Data Protection Requirements, Section 4 of the European Region Terms of the MGPT shall apply. — Llama API, Terms of Service, 2025-11-13

Microsoft has taken on the added responsibilities of a data controller under GDPR when processing Personal Data in connection with its business operations incident to providing its services to Microsoft’s commercial customers, such as billing and account management; compensation; internal reporting and business modelling; and financial reporting. — Microsoft Copilot, Privacy Policy, 2026-01-30

“Controller to Processor Clauses” means (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 2 (Controller to Processor) (“EU SCCs”)… — Perplexity, Data Processor Agreement, 2025-11-11

iuro Rechtsanwälte GmbH t/a Prighter and Prighter Ltd. (collectively, “Prighter Group”)… is our representative in the European Economic Area (“EEA”) for the purposes of the EU GDPR and the United Kingdom (“UK”) for the purposes of the UK GDPR. — Perplexity, Privacy Policy, 2025-11-11

When we transfer your personal data outside of the European Union, European Economic Area, Switzerland or the United Kingdom, we ensure that it benefits from an adequate level of data protection by relying on: (a) Adequacy decisions… under Article 45 GDPR… (b) Standard contractual clauses. The European Commission has approved contractual clauses under Article 46 of the GDPR… — Qwen Chat, Privacy Policy, 2026-04-09


Providers cite GDPR in sharply different ways. OpenAI, Anthropic, Mistral (Le Chat), and Perplexity (in its DPA) each have their own in-house EU entity or execute their own GDPR Article 28 Data Processing Addendum directly, citing specific GDPR Articles (45, 46) for cross-border transfer mechanisms. DeepSeek and Perplexity’s consumer Privacy Policy both use a third-party representative-as-a-service vendor, Prighter, for EEA/UK Article 27 obligations — confirming Prighter is a multi-provider industry utility, not a single-provider arrangement. Google cites GDPR only generically (“the General Data Protection Regulation in the EU”) without naming specific Articles, despite running one of the most detailed legal-basis frameworks in this dataset. Microsoft is the only provider to disclose a dual role: Processor for ordinary customer data, but self-declared GDPR Controller for its own business operations (billing, internal reporting) layered on top of customer relationships. Perplexity’s Privacy Policy is the only document here that also cites the EU-U.S. Data Privacy Framework (DPF), a transatlantic-transfer mechanism distinct from SCCs/adequacy decisions. Qwen Chat is the only provider that added a GDPR citation mid-history: its Privacy Policy had no GDPR reference through 2026-03-19, then gained Article 45/46 citations in a 2026-04-09 rewrite — an unusual direction of change, since most other providers’ GDPR language is stable from baseline. Not one of the 14 platform pages above cites the EU AI Act by name. GDPR is the only EU regulatory framework consistently named in this dataset’s source documents — a notable gap given the dataset’s “genai-eu” framing. (Perplexity’s own Acceptable Use Policy is a partial exception: it names the AI Act, but in a conduct policy, not a GDPR-style data-protection document, so it isn’t tracked on this page.)