Does AI data have to stay in the EU or UK?
Neither EU GDPR nor UK GDPR imposes a general rule that all personal data must stay locally. International transfers require the applicable conditions to be met, alongside the other data-protection obligations.
Local hosting can support a residency requirement. It does not by itself resolve processing elsewhere, access by an overseas recipient, backups or onward transfers. Map the actual recipients and data flows before reaching a conclusion.
Sources checked 20 September 2026. General procurement guidance, not a legal opinion. Have qualified counsel assess the actual arrangement.
Separate the security service from the AI provider
A single hosting-region answer cannot describe every part of an employee AI interaction.
- Security backend
- Where configuration, account records and retained events are hosted.
- Prompt inspection
- Where prompts or files are processed, and which content is retained.
- Destination AI provider
- The AI account's own processing, storage, training and retention terms.
What evidence should accompany each answer?
Record the data categories, processing and storage locations, retention and deletion terms, subprocessors and support access. Link the applicable contract, architecture or configuration evidence, and name an owner for unanswered questions. A local storage region does not establish the location of every processing or access path.
Blank review worksheet. It contains no observed product results.
What the EU rules ask you to verify
The EDPB identifies a transfer where a controller or processor subject to GDPR makes personal data available to another organisation outside the EEA. Chapter V provides routes through adequacy decisions, appropriate safeguards, and exceptions for specific circumstances.
Where a relevant adequacy decision applies, additional Article 46 safeguards are not required for that transfer. When using safeguards such as standard contractual clauses, assess whether they work in the destination and whether supplementary measures are needed. Other GDPR obligations still apply.
Schrems II invalidated the former EU-US Privacy Shield and clarified the assessment needed for Article 46 transfer tools. Use the current regulator guidance and adequacy list for the recipient and transfer in question.
Check the UK transfer route separately
The ICO's January 2026 guide uses a three-step test: UK GDPR applies to the processing, you initiate the transfer to an organisation outside the UK, and the recipient is a separate legal entity. Making information accessible can count, even without moving the stored copy.
A restricted transfer needs UK adequacy regulations, appropriate safeguards or an applicable exception. Safeguards can include the UK IDTA, the UK Addendum or UK binding corporate rules. The ICO requires a transfer risk assessment when relying on safeguards; UK legislation now calls this a data protection test.
Keep the legal-entity and contract map with the technical data-flow map. An EU answer does not automatically document a UK transfer.
A local database with overseas access
A UK organisation stores personal data in London. A separate support provider in India can access it under the support contract.
The ICO uses this kind of access arrangement to illustrate a restricted transfer. The storage address has not changed, but personal information is made accessible to a separate overseas organisation. Check the applicable transfer conditions and support controls.
This illustrates a review question. It is not a description of Aona's support arrangements or a decision about your deployment.
Five checks for the procurement record
Use the blank worksheet above and attach the evidence for each answer.
1. Processing and storage
Name each location for prompts, files, configuration, events and backups. Confirm which data is transient and which is retained.
2. Recipients and access
Identify the legal entities, subprocessors and support locations that can receive or access personal data. Local servers do not settle remote-access questions.
3. Transfer mechanism
For a relevant international transfer, document the applicable adequacy decision, safeguards and assessment, or narrowly applicable exception. Check EU and UK routes separately.
4. Retention and deletion
Record content and event retention separately, including backups, deletion at exit and any legal or security exceptions.
5. Operating evidence
Keep the applicable agreement, architecture, configuration and assurance evidence with a named review owner. A marketing region list alone is not the complete record.
Where Aona fits
Aona secures employees' AI use. Backend hosting can be in your cloud, on-premises or on Aona-managed servers. Prompt processing is a separate choice: the user device, your environment or Aona-managed servers, subject to the required feature configuration.
Aona-managed regional options include France (Paris), Germany (Frankfurt) and the United Kingdom (London), alongside Australia, the United States, Singapore and Hong Kong. Agree which content and records are processed or retained in the selected configuration. The destination AI provider has its own handling terms.
Aona has completed a SOC 2 Type II examination covering Security, Confidentiality and Availability. Request the report to review the auditor’s findings and the full system scope. Data retention is configurable per customer, for example 30, 90 or 180 days. Agree retention and deletion settings for the data in your selected deployment.