GDPR-compliant AI vendors
AI vendors that publicly attest to GDPR compliance with a Data Processing Agreement and EU adequacy or Standard Contractual Clauses for cross-border transfers.
GDPR compliance for an AI vendor means more than a privacy policy footer — it requires a written DPA under Article 28, sub-processor disclosure, breach notification within 72 hours, support for data subject rights (access, deletion, portability, objection), and an appropriate cross-border transfer mechanism (adequacy, SCCs, or BCRs). The vendors below have publicly attested to GDPR compliance. Enterprise buyers should still request the DPA and verify the AI-specific clauses (training-data, sub-processors, retention).
Vendors with GDPR
Anthropic
Score 11.44 · low
Amazon (AWS)
Score 12.34 · low
Salesforce
Score 12.74 · low
Adobe
Score 13.74 · low
Cohere
Score 13.79 · low
IBM
Score 14.11 · low
Microsoft
Score 14.68 · low
SAP
Score 16.63 · low
OpenAI
Score 18.36 · low
Google DeepMind
Score 18.85 · low
Oracle
Score 19.89 · low
Palo Alto Networks
Score 19.89 · low
Nuance (Microsoft)
Score 20.86 · moderate
Writer
Score 20.93 · moderate
Mistral AI
Score 21.81 · moderate
AI21 Labs
Score 22.34 · moderate
Workday
Score 22.45 · moderate
Mosaic (Databricks)
Score 22.6 · moderate
Nvidia
Score 22.63 · moderate
SentinelOne
Score 22.96 · moderate
Scale AI
Score 23.3 · moderate
Hugging Face
Score 24.05 · moderate
Aleph Alpha
Score 24.29 · moderate
Snowflake
Score 24.36 · moderate
ServiceNow
Score 24.4 · moderate
Datadog
Score 24.41 · moderate
SambaNova
Score 24.5 · moderate
PolyAI
Score 24.72 · moderate
Palantir
Score 25.09 · moderate
Databricks
Score 25.4 · moderate
Cloudflare
Score 25.89 · moderate
Slack
Score 26.47 · moderate
GitHub Copilot
Score 27.12 · moderate
Vanta
Score 27.24 · moderate
Zoom
Score 27.35 · moderate
Atlassian
Score 28.51 · moderate
Preferred Networks
Score 29.03 · moderate
Synthesia
Score 29.28 · moderate
Kensho (S&P Global)
Score 29.4 · moderate
Khanmigo (Khan Academy)
Score 29.49 · moderate
Casetext
Score 29.77 · moderate
Kyutai
Score 29.85 · moderate
CoreWeave
Score 29.93 · moderate
Stripe
Score 29.97 · moderate
Harvey
Score 30.27 · moderate
LexisNexis
Score 30.29 · moderate
Arize AI
Score 30.6 · moderate
Grammarly
Score 30.74 · moderate
Moveworks
Score 30.84 · moderate
Sakana AI
Score 30.94 · moderate
Buyer checklist
- Request and review the DPA — pay special attention to training-data clauses and sub-processor flow-down.
- Verify the cross-border transfer mechanism: EU-US DPF certification, SCCs, or adequacy decision.
- For SCCs, ask whether the vendor has a current Transfer Impact Assessment per Schrems II.
- Confirm the breach notification SLA — GDPR requires "without undue delay"; enterprise contracts typically negotiate 24-72 hour windows.
- Map sub-processors to their adequacy or transfer mechanism; the chain is only as strong as the weakest link.
Compliance is necessary, not sufficient. Holding GDPR is a meaningful baseline, but no certification covers AI-specific risk end-to-end. Layer this on top of vendor-specific diligence — sub-processor disclosure, training-data policy, model card transparency, dependency-chain mapping.