"GDPR-compliant document AI" is not a certification you can look up. The GDPR regulates how personal data is handled by a controller (you) and a processor (the vendor who handles documents on your behalf), so what you can check is the contract, where the data is stored and processed, who can reach it, who else handles it, and how long it stays. This page separates those questions, shows what eight vendors publish about them, and ends with ten questions to ask any provider.
Documents are where this matters most. An invoice, a payslip, an ID or a contract carries names, addresses and account numbers, and a document AI service reads all of it.
Residency, processing and access are three different questions
Data residency is where the data sits at rest: the region of the storage holding your files and results. It is the question vendors answer most often, because it is the easiest to offer: an EU region.
Processing location is where the data is computed on. A document AI pipeline usually has several steps, including OCR, layout analysis and a language model, and each can run in a different place or at a different provider. An EU storage region does not say where inference happens.
Access is who can reach the data and from where. Under GDPR Chapter V, moving personal data to a third country is regulated, and remote access by a vendor's staff or sub-processors outside the EU can be treated as a transfer, so it belongs on the same checklist as storage.
A vendor can be right on the first and silent on the other two. That is why "we have an EU region" is a starting point, not an answer.
Sovereignty is a fourth question
Sovereignty is about which company holds the data and which legal system can compel it. A vendor established outside the EU that is subject to the GDPR, for example because it offers services to people in the EU, generally has to designate a representative in the EU under Article 27, which also sets out exceptions. Separately, US law (18 U.S.C. 2713, the CLOUD Act) requires US providers to preserve and disclose data in their possession, custody or control whether it is stored inside or outside the United States. Whether that reaches a particular EU-hosted deployment is a legal question for your counsel; the useful step is to know which company is the processor and where it is established.
What vendors publish
The table lists what each vendor's own pages say about an EU option and about zero retention, as read on 30 September 2026. It is a summary of published statements, not an audit; vendors change these terms, so check the linked page before you decide.
| Vendor | EU option, as published | Zero retention, as published |
|---|---|---|
| Reducto | EU data residency on the Growth and Enterprise plans; documents "processed, stored, and deleted exclusively within the EU" | Available on Growth and above, per its documentation |
| Extend | EU1 region in Frankfurt, listed in its API reference | Per-run zero retention; on pay-as-you-go it is enabled through a support request (security page) |
| LandingAI | EU region, same price as the US region | Team plan and above, at one extra credit per page |
| LlamaParse (EU compliance, data privacy) | EU instance in Frankfurt; its EU data processing terms use Standard Contractual Clauses and state that access by US-based personnel can occur | Uploads are cached for 48 hours unless caching is disabled |
| Mistral OCR | Data hosted in the EU by default, with a US endpoint as an opt-in | Pay-as-you-go accounts by request, approved or denied by Mistral |
| Azure Document Intelligence | Processed in the region of your resource | Input and results stored temporarily in that region and deleted after 24 hours |
| Google Document AI | EU multi-region or single regions, chosen when the processor is created | Not stated on the regions page |
| AWS Textract | Content stored in the region you use | Its FAQ says that, unless you opt out with an AWS Organizations policy, some content may be stored in another region and used to improve the service |
Two patterns stand out. First, "EU region" means different things: hosting, a legal boundary on all document data, or a storage choice with processing terms that permit access from elsewhere. Second, zero retention is usually a plan, an account type or a request, not a default, so ask which one applies to you.
Ten questions to ask any document AI vendor
- Where is content stored, where is it processed (including OCR and language model inference), and from where can staff reach it? This separates residency, processing and access (GDPR Chapter V).
- Which legal entity is the processor, where is it established, and, if it is outside the EU, does Article 27 require an EU representative and is one named?
- Can a non-EU authority compel disclosure from the vendor or its parent company? Ask for the vendor's position in writing, since it is a legal question.
- Is there a data processing agreement that covers what Article 28(3) requires: processing only on your instructions, confidentiality, security, assistance, deletion or return, and audit rights?
- Who are the sub-processors that see document content (cloud, OCR and language model providers), where do they run, and how are you told about changes? The processor stays liable for them under Article 28(4).
- What mechanism covers each transfer outside the EU: an adequacy decision, Standard Contractual Clauses or another safeguard? (Articles 45 and 46).
- Is customer data used to train models, by the vendor or its language model providers? Ask that the answer is in the contract.
- What is the default retention window, is zero retention default, opt-in or tied to a plan, what does it cost, and how long do backups and logs persist? (Storage limitation, Article 5(1)(e)).
- What does the security certificate actually cover? Ask for the scope statement of an ISO 27001 certificate, which systems and sites it includes, rather than the badge. A certificate is a security management standard and does not by itself show GDPR compliance.
- How do you get out: data return, verified deletion, and a deployment option with no outbound calls for inference. "Self-hosted" that still calls a hosted language model is not air-gapped.
What zero retention does and does not mean
Zero data retention means the vendor does not keep your documents or results after processing, apart from what is needed to return them to you. Implementations differ: a deletion window of hours rather than days, a per-request flag, an account-level mode, or a contract term. It also has side effects. For example, LandingAI's own documentation says its Ground API is not available under zero retention. So the question is not whether a vendor has zero retention but how it is turned on, who can turn it on, what it disables and what it costs.
Where anyformat fits
anyformat is a Madrid-based, EU-headquartered company and is ISO 27001 certified; see ISO 27001 certification. Its terms of service include a data processing addendum, and anyformat acts as processor for the documents you upload. Zero retention is a mode available on request, enabled by anyformat for your organisation.
Here is what we do not claim. This page does not state a hosting region for the default cloud, and it is not a statement that every processing step, including every language model call, stays inside the EU. If your requirement is that every step stays inside your boundary, the option built for that is the on-premise and air-gapped deployment, which runs with no calls to outside services and is in production at a government customer. There is more in on-premise and air-gapped document extraction, and plan details on the pricing page. Ask us the ten questions above and expect written answers; ask every other vendor the same.
Frequently asked questions
Is there a GDPR certification for document AI?
No product-level certificate shows that a vendor is "GDPR compliant". ISO 27001 is a security management standard, which helps with the security obligations in the GDPR but does not cover them all. What you can check is the contract, the processing chain, the locations and the retention terms.
Does EU data residency make a vendor GDPR compliant?
No. Residency covers where data is stored. Processing location, access from outside the EU, sub-processors and retention are separate questions, and the contract has to cover them.
Do I need a data processing agreement with a document AI vendor?
If the vendor processes personal data on your behalf, Article 28(3) requires a contract or other legal act with specific terms. Ask for the agreement before you send real documents.
Can a vendor established outside the EU be used under the GDPR?
It can, using the transfer mechanisms in Chapter V and an EU representative where Article 27 applies. The practical work is in checking which mechanism covers each step and where the data is actually processed.
What is zero data retention?
A mode in which the vendor does not keep your documents or results after processing. Check whether it is on by default, who can enable it, how quickly data is deleted and what features it disables.

