Residency is not the same as no transfers
Under Chapter V of the GDPR, a transfer happens whenever personal data is made accessible to a recipient in a third country. That includes a support engineer at a non-EU affiliate or subprocessor logging in remotely, or a model API hosted outside the EU, even when the files themselves stay in Frankfurt or Stockholm. Transfers need a basis: an adequacy decision, such as the EU–US Data Privacy Framework of July 2023 for certified US companies, or the 2021 standard contractual clauses backed by a transfer impact assessment. Ownership matters too. Under the US CLOUD Act of 2018, a provider subject to US jurisdiction can be ordered to produce data it controls, wherever that data is stored.
DPAs and the subprocessor chain
Article 28 requires a contract with every processor, covering instructions, confidentiality, security, deletion or return of data, audits and the use of subprocessors. For AI content tools the subprocessor chain is the part to read closely, because it includes the model providers: every company whose models process your prompts and files, and the places each one runs them. Ask for the full list, advance notice of changes and a right to object. Check too whether the vendor uses your data for its own purposes, such as improving its products; for that processing it acts as a controller in its own right, which your agreement should rule out or govern.
Personal data hides in creative inputs
Marketing inputs rarely look like personal data, but they often are. Briefs name customers or paste CRM segments; reference photos show employees, models and passers-by; voice recordings uploaded for cloning identify a person; photographs carry location data in their EXIF metadata. Faces and voices processed to identify someone are biometric data, a special category under Article 9 that needs an explicit condition such as consent. Face and voice cloning usually warrant a data protection impact assessment under Article 35 before any work starts. The simplest control is minimisation: keep personal data out of prompts unless the job needs it, and strip metadata before upload.
Retention, zero retention and deletion
Two kinds of retention get confused. Your asset library should be stored, under the DPA, for as long as you need it. What should not be stored is the copy of your prompts and files held by model providers after processing, for training, abuse monitoring or anything else; zero-retention agreements close that gap. Ask as well how long logs and backups persist, how a deletion request for one person's data is handled across generated assets, and what confirmation you receive at contract end. Synthetic White offers EU or US data residency, has zero-retention agreements with its model providers, and trains no model on anything customers upload.
Updated 25 September 2026