GDPR Compliant AI: No Third-Party Processor, No International Transfer
No product can make your business GDPR-compliant on its own, and we won't pretend otherwise. What on-premise AI does is take the hardest question out of the assessment: where the personal data goes. With Local AI, it doesn't go anywhere.
GDPR compliant AI is less about the model and more about where it runs. Local AI from AgentHub runs on a machine in your own building, so for the AI step there is no third-party processor to appoint under Article 28, no international transfer to justify under Chapter V, and nothing is used to train models. You remain the controller.
Book a Call — Bring Your DPO
Data processing agreement signed before go-live · Irish, PhD-led team · Co-founded by a Security Architect
The product is Local AI: a dedicated machine in your office running open-weight models, with private chat, document spaces and assistants. Every byte stays inside your building.
What Makes an AI Tool GDPR Compliant?
Nothing about the model itself — the deployment does it. GDPR compliance for AI means a lawful basis, a contract with any processor handling the data (Article 28), a justification for any transfer outside the EEA (Chapter V), appropriate security (Article 32), a current record of processing (Article 30) and an impact assessment where the processing is high-risk (Article 35).
A cloud chatbot makes three of them harder: it adds a processor, it usually adds a transfer, and staff tend to start using it before anyone has done the paperwork. On-premise AI removes the first two entirely for the AI step and gives you somewhere sanctioned to point the third. That is the whole of our GDPR claim — no more, no less.
AI and GDPR: The Five Questions Your DPO Will Ask
If you don't have a DPO, these are the questions you'd be asked by the Data Protection Commission after a complaint. Better to have the answers first.
| The question | With a cloud AI chatbot | With Local AI on your premises |
|---|---|---|
| Who is the processor for the AI step? | The AI provider — a contract to sign, assess and review | Nobody. The model runs on your machine. We're a processor only for the support access you grant, under a DPA we sign |
| Where is the personal data processed? | The provider's servers, usually outside Ireland and often outside the EEA | In your building, on your network |
| Is there an international transfer? | Frequently — standard contractual clauses and a transfer impact assessment to prepare | No. Nothing crosses a border, so Chapter V doesn't arise for the AI step |
| Is our data used to train models? | Depends on the tier and the settings each member of staff chose | Never — ours or anyone else's. Models arrive trained and stay that way |
| What happens when we delete something? | You request erasure from the provider and hope the copies are gone | You delete it under your own policy; there is no third-party copy to chase |
Two of our guides go deeper on the questions above: what a data processor is under GDPR — including why consumer AI tools are usually controllers rather than your processors — and whether ChatGPT is safe for confidential information, which covers when a pasted client file becomes a personal data breach under Article 4(12).
GDPR Compliance and AI: What On-Premise Deployment Does for Each Obligation
The honest version — including the rows where it does nothing for you.
| GDPR obligation | What Local AI does | What stays with you |
|---|---|---|
| Art. 5 — minimisation and storage limitation | Documents are only indexed if you put them in a space; delete one and it leaves every future answer | Deciding which folders are in scope and how long they're kept |
| Art. 6 / Art. 9 — lawful basis, special-category data | Nothing. The tool doesn't create a lawful basis | Establishing the basis for the processing, as for any other tool |
| Art. 28 — processors | Removes the AI provider from the list. We act as processor only for support access, under a signed DPA | Keeping the DPA with us on file and under review |
| Art. 30 — record of processing | One fewer processor and one fewer transfer to describe each year | Keeping the record current |
| Art. 32 — security of processing | Personal data stays inside your network, behind your own access controls, on hardware you physically hold. Sign-in via your Microsoft 365 or Google Workspace | Who's in which group; your wider security policy |
| Art. 35 — impact assessment | Makes it shorter — the "where does it go" section has a one-word answer | Deciding whether the processing is high-risk and doing the assessment |
| Chapter V — international transfers | Doesn't arise for the AI step. No standard contractual clauses, no transfer impact assessment | Nothing for the AI step |
| Art. 17 — erasure | Erasure means erasure — no third-party copy left behind | Acting on the request under your existing procedure |
AI and GDPR Compliance for Solicitors, GPs and Accountants
The businesses that would benefit most from AI on their documents are exactly the ones whose documents can't casually go to a third party. A solicitor's matter file contains the other side's personal data as well as the client's, and plenty of commercial contracts explicitly forbid passing documents to an external processor. A GP or dental practice holds health data — special-category data under Article 9 — where the bar for any new processor is highest. An accountant's year-end files hold payroll and directors' details for dozens of clients at once.
Meanwhile the work carries on. The trainee who needs 40 pages of correspondence summarised by four o'clock is already pasting it into a public chatbot, with the best of intentions and no record of what went where. A blanket ban doesn't stop that; it moves it to a personal phone. GDPR-compliant AI, in practice, means giving that trainee the same tool on hardware you control — so the sanctioned route is also the easy one. Our private AI page covers the confidentiality side in more depth; the on-premise AI page covers what the installation asks of your IT.
Three Steps, With the Paperwork Done Before Go-Live
The Call — With Your Adviser
Bring your DPO, your solicitor or whoever signs off on processors. We'd rather answer the Article 28 and Chapter V questions early than have them stall a rollout later.
DPA Signed, Then Installed
We sign a data processing agreement for the support access you grant, then supply the machine, install it on your network and connect your existing sign-in.
Your Policies Keep Applying
Retention, access and deletion follow the policies you already have, because the files never left your systems. We handle updates, model upgrades and backups.
Who Does What: AgentHub as Processor, You as Controller
Written down so it can go straight into your Article 30 record.
| Area | AgentHub (processor for support access only) | You (data controller) |
|---|---|---|
| The machine and software | Supplies, installs, updates and upgrades the models | Provides a network port, a socket and a place for it |
| Access to personal data | Only through the support access you grant, under the DPA | Decides who in your organisation can see which spaces |
| Training data | Never uses your documents or conversations to train any model | Nothing to do — there's no opt-out to remember |
| Backups | Runs backups of documents and spaces on the schedule agreed with you; restores to a replacement machine on failure | Agrees the schedule and where backups live |
| Retention and erasure | Nothing to hold, so nothing to erase on our side | Applies your existing retention policy; deletes under your own procedure |
| Records and assessments | Gives you the facts for the Article 30 entry and any DPIA | Keeps the record and does the assessment |
| Phone, email and leads automation | Our cloud agents are hosted by us — a different arrangement with its own DPA. See AI Receptionist and Email Manager | Decides which work belongs on premises and which in the cloud |
What Clients Say About Working With Us
Since installing AgentHub's AI receptionist, we haven't missed a single patient call. It handles appointment queries after hours and our front desk staff can focus on in-clinic care.
Our inbox was drowning us. AgentHub's email manager now categorises everything and drafts responses that sound exactly like us. Response times went from 48 hours to under 4.
An Irish Team That Answers the GDPR Questions First
Built in Ireland
An Irish company under the Irish DPC's jurisdiction, installing machines in Irish offices — see who we are.
PhD-Led Team
Founded by a Computer Science PhD with 27+ years in software, including 15 years at IBM Ireland.
Security First
Co-founded by a Security Architect. Access through your own identity provider, no inbound ports, a DPA before go-live.
No Compliance Theatre
We'll tell you which obligations on-premise AI removes, and which ones it doesn't touch. The table above includes both.
AI and GDPR: Your Questions Answered
Is AI GDPR compliant?
AI isn't compliant or non-compliant in itself — the deployment is. Compliance comes from a lawful basis, processor contracts, transfer justifications, security, records and, where needed, an impact assessment. On-premise AI removes the processor and transfer questions for the AI step; the rest stays with you as controller.
Can I use ChatGPT under GDPR?
Possibly, with the right tier, a processor agreement, a transfer assessment and staff who never use the free version alongside it. The practical difficulty is that staff start pasting before the paperwork exists. On-premise AI gives them a sanctioned tool with no processor or transfer to assess.
Do I need a DPIA for AI?
It depends on the processing, not the tool: large-scale special-category data or systematic monitoring usually needs one. Local AI doesn't remove that decision, but it shortens the assessment — the "where does the data go" section has a one-word answer, and there is no processor or transfer to analyse.
Is on-premise AI automatically GDPR compliant?
No, and anyone who says otherwise is selling something. It removes the third-party AI processor and the international transfer for the AI step and keeps personal data behind your own access controls. Lawful basis, retention, access decisions and any impact assessment remain your responsibility as controller.
Who is the data processor with Local AI?
For the AI processing itself, nobody — it runs on your machine. AgentHub acts as a processor only for the support access you choose to grant us, and we sign a data processing agreement covering it before go-live. You remain the data controller throughout.
Does the EU AI Act change any of this?
It sits alongside GDPR rather than replacing it. Most office uses of an AI assistant aren't high-risk under the Act, though transparency duties can apply where AI output reaches the public. We'll flag anything relevant to your use on the call — bring your adviser.
Ready to Take the Hardest Question Out of Your Assessment?
Tell us what the AI would be reading. Bring your DPO or your adviser — these are the questions we'd rather answer early.
Prefer to talk? Email sghaith@agenthub.ie or call 087 788 2676.
