Trust and compliance · 2026-09-11

GDPR and AI APIs: international transfers, SCCs and the transfer impact assessment

When a call to an AI API becomes an international data transfer, which safeguards the GDPR accepts, why standard contractual clauses are not the whole file, and where LLMTR sits in that chain, stated plainly.

Diagram of the chain behind an AI API call, marking the points where GDPR Chapter V requires a safeguard for the international transfer.

The question is not where the model sits

It is tempting to reduce compliance to a single checkbox: the model is hosted in the European Union, therefore there is no transfer. GDPR Chapter V does not work that way. What gets examined is the full path of the personal data, and that path has more than one actor: whoever receives the request, whoever routes it, whoever runs the model, and whoever keeps records.

One link outside the European Economic Area is enough for an international transfer to exist, even when the model computation happens in a European data centre. So the first useful question is not where the model is, but how many hands the data passes through and where each of them is.

Adequacy, standard contractual clauses and the TIA

The easiest route is an adequacy decision: the European Commission finds that a third country offers an equivalent level of protection, and the transfer needs no further safeguard. The list of countries with a decision in force is short and public.

Without adequacy, the usual instrument is the standard contractual clauses of Implementing Decision (EU) 2021/914, arranged in modules according to the relationship between the parties.

Signing them does not close the file. Since Schrems II a transfer impact assessment is also expected: an analysis of whether the destination country's legal framework actually lets those clauses be honoured, and which supplementary measures are needed if it does not.

Where LLMTR sits, stated plainly

LLMTR is established in Turkey, and Turkey holds no adequacy decision from the European Commission. If you send personal data through the platform that is an international transfer, and choosing and documenting the safeguard for it is yours to do as the controller.

Picking an EU-hosted model from the catalog does not change this. Where the model is processed and where the platform routing the request is established are two separate facts, and an honest compliance write-up treats them separately.

What does reduce the scope is what you send and what is kept. LLMTR does not store prompt content or model responses in its database, and access to the providers that require it sits behind a per-provider consent record, tied to the account and revocable from settings.

What this article will not claim: that a data processing agreement with standard contractual clauses is published today and ready to download. There is not one. If your compliance process requires it, ask for it in writing before you integrate — here and at any other provider.

Shrink the scope before arguing about the safeguard

A good share of transfer arguments disappear when the personal data never enters the prompt. That is not always possible, but reducing it almost always is.

  • Replace identifiers with internal references before building the prompt, and undo the substitution when the response comes back.
  • Separate the text the model needs from the record that surrounds it; both are rarely required.
  • Document which categories of data may appear in a prompt and treat that list as part of your record of processing activities.
  • Record the legal basis and the chosen safeguard before the first deployment, not after the first audit.
  • Revisit the decision whenever the provider, the model or a sub-processor's country changes.

What you can verify and what you can only request

Part of this is verifiable without talking to anyone: which legal entity appears in the privacy policy, what the disclosure notice says, whether a consent record exists and whether it can be withdrawn.

The rest only arrives by asking in writing: the sub-processor list with locations, a commitment to notify before that list changes, and the clause module matching your relationship. A provider who answers this with a marketing page is answering that they do not have it.

Frequently asked questions

Is there an international transfer if the model runs inside the European Union?

There can be. A transfer depends on the full path of the data, not only on where the model runs: if any link in the chain is outside the European Economic Area, GDPR Chapter V applies.

Are standard contractual clauses enough on their own?

The clauses are the instrument, not the whole file. Since Schrems II a transfer impact assessment of the destination country's legal framework is also expected, along with supplementary measures where needed.

Does Turkey hold an adequacy decision from the European Commission?

No. A transfer to a Turkish entity therefore needs another Article 46 safeguard, normally standard contractual clauses together with their impact assessment.

Related posts