GDPR Compliant AI: No Third-Party Processor, No International Transfer

No product can make your business GDPR-compliant on its own, and we won't pretend otherwise. What on-premise AI does is take the hardest question out of the assessment: where the personal data goes. With Local AI, it doesn't go anywhere.

GDPR compliant AI is less about the model and more about where it runs. Local AI from AgentHub runs on a machine in your own building, so for the AI step there is no third-party processor to appoint under Article 28, no international transfer to justify under Chapter V, and nothing is used to train models. You remain the controller.

Book a Call — Bring Your DPO

Data processing agreement signed before go-live · Irish, PhD-led team · Co-founded by a Security Architect

Built in Ireland, for Irish Businesses
GDPR-compliant on-premise AI machine installed in an Irish office, with no data leaving the building

The product is Local AI: a dedicated machine in your office running open-weight models, with private chat, document spaces and assistants. Every byte stays inside your building.

For Irish Businesses Whose Files Carry Other People's Personal Data

SolicitorsGP & Dental PracticesAccountantsHR TeamsRecruitment Agencies
Plain English

What Makes an AI Tool GDPR Compliant?

Nothing about the model itself — the deployment does it. GDPR compliance for AI means a lawful basis, a contract with any processor handling the data (Article 28), a justification for any transfer outside the EEA (Chapter V), appropriate security (Article 32), a current record of processing (Article 30) and an impact assessment where the processing is high-risk (Article 35).

A cloud chatbot makes three of them harder: it adds a processor, it usually adds a transfer, and staff tend to start using it before anyone has done the paperwork. On-premise AI removes the first two entirely for the AI step and gives you somewhere sanctioned to point the third. That is the whole of our GDPR claim — no more, no less.

AI and GDPR

AI and GDPR: The Five Questions Your DPO Will Ask

If you don't have a DPO, these are the questions you'd be asked by the Data Protection Commission after a complaint. Better to have the answers first.

The questionWith a cloud AI chatbotWith Local AI on your premises
Who is the processor for the AI step?The AI provider — a contract to sign, assess and reviewNobody. The model runs on your machine. We're a processor only for the support access you grant, under a DPA we sign
Where is the personal data processed?The provider's servers, usually outside Ireland and often outside the EEAIn your building, on your network
Is there an international transfer?Frequently — standard contractual clauses and a transfer impact assessment to prepareNo. Nothing crosses a border, so Chapter V doesn't arise for the AI step
Is our data used to train models?Depends on the tier and the settings each member of staff choseNever — ours or anyone else's. Models arrive trained and stay that way
What happens when we delete something?You request erasure from the provider and hope the copies are goneYou delete it under your own policy; there is no third-party copy to chase

Two of our guides go deeper on the questions above: what a data processor is under GDPR — including why consumer AI tools are usually controllers rather than your processors — and whether ChatGPT is safe for confidential information, which covers when a pasted client file becomes a personal data breach under Article 4(12).

Article by Article

GDPR Compliance and AI: What On-Premise Deployment Does for Each Obligation

The honest version — including the rows where it does nothing for you.

GDPR obligationWhat Local AI doesWhat stays with you
Art. 5 — minimisation and storage limitationDocuments are only indexed if you put them in a space; delete one and it leaves every future answerDeciding which folders are in scope and how long they're kept
Art. 6 / Art. 9 — lawful basis, special-category dataNothing. The tool doesn't create a lawful basisEstablishing the basis for the processing, as for any other tool
Art. 28 — processorsRemoves the AI provider from the list. We act as processor only for support access, under a signed DPAKeeping the DPA with us on file and under review
Art. 30 — record of processingOne fewer processor and one fewer transfer to describe each yearKeeping the record current
Art. 32 — security of processingPersonal data stays inside your network, behind your own access controls, on hardware you physically hold. Sign-in via your Microsoft 365 or Google WorkspaceWho's in which group; your wider security policy
Art. 35 — impact assessmentMakes it shorter — the "where does it go" section has a one-word answerDeciding whether the processing is high-risk and doing the assessment
Chapter V — international transfersDoesn't arise for the AI step. No standard contractual clauses, no transfer impact assessmentNothing for the AI step
Art. 17 — erasureErasure means erasure — no third-party copy left behindActing on the request under your existing procedure
In Practice

AI and GDPR Compliance for Solicitors, GPs and Accountants

The businesses that would benefit most from AI on their documents are exactly the ones whose documents can't casually go to a third party. A solicitor's matter file contains the other side's personal data as well as the client's, and plenty of commercial contracts explicitly forbid passing documents to an external processor. A GP or dental practice holds health data — special-category data under Article 9 — where the bar for any new processor is highest. An accountant's year-end files hold payroll and directors' details for dozens of clients at once.

Meanwhile the work carries on. The trainee who needs 40 pages of correspondence summarised by four o'clock is already pasting it into a public chatbot, with the best of intentions and no record of what went where. A blanket ban doesn't stop that; it moves it to a personal phone. GDPR-compliant AI, in practice, means giving that trainee the same tool on hardware you control — so the sanctioned route is also the easy one. Our private AI page covers the confidentiality side in more depth; the on-premise AI page covers what the installation asks of your IT.

How It Works

Three Steps, With the Paperwork Done Before Go-Live

1

The Call — With Your Adviser

Bring your DPO, your solicitor or whoever signs off on processors. We'd rather answer the Article 28 and Chapter V questions early than have them stall a rollout later.

2

DPA Signed, Then Installed

We sign a data processing agreement for the support access you grant, then supply the machine, install it on your network and connect your existing sign-in.

3

Your Policies Keep Applying

Retention, access and deletion follow the policies you already have, because the files never left your systems. We handle updates, model upgrades and backups.

Roles

Who Does What: AgentHub as Processor, You as Controller

Written down so it can go straight into your Article 30 record.

AreaAgentHub (processor for support access only)You (data controller)
The machine and softwareSupplies, installs, updates and upgrades the modelsProvides a network port, a socket and a place for it
Access to personal dataOnly through the support access you grant, under the DPADecides who in your organisation can see which spaces
Training dataNever uses your documents or conversations to train any modelNothing to do — there's no opt-out to remember
BackupsRuns backups of documents and spaces on the schedule agreed with you; restores to a replacement machine on failureAgrees the schedule and where backups live
Retention and erasureNothing to hold, so nothing to erase on our sideApplies your existing retention policy; deletes under your own procedure
Records and assessmentsGives you the facts for the Article 30 entry and any DPIAKeeps the record and does the assessment
Phone, email and leads automationOur cloud agents are hosted by us — a different arrangement with its own DPA. See AI Receptionist and Email ManagerDecides which work belongs on premises and which in the cloud
Client Stories

What Clients Say About Working With Us

Since installing AgentHub's AI receptionist, we haven't missed a single patient call. It handles appointment queries after hours and our front desk staff can focus on in-clinic care.
AB
Dr Aoife Brennan
Practice Manager, Sandymount Medical Centre
Our inbox was drowning us. AgentHub's email manager now categorises everything and drafts responses that sound exactly like us. Response times went from 48 hours to under 4.
DO
Declan O'Brien
Managing Partner, O'Brien & Keane Solicitors
Why AgentHub

An Irish Team That Answers the GDPR Questions First

🇧🇪

Built in Ireland

An Irish company under the Irish DPC's jurisdiction, installing machines in Irish offices — see who we are.

🧠

PhD-Led Team

Founded by a Computer Science PhD with 27+ years in software, including 15 years at IBM Ireland.

🔒

Security First

Co-founded by a Security Architect. Access through your own identity provider, no inbound ports, a DPA before go-live.

⚖️

No Compliance Theatre

We'll tell you which obligations on-premise AI removes, and which ones it doesn't touch. The table above includes both.

FAQ

AI and GDPR: Your Questions Answered

Is AI GDPR compliant?

AI isn't compliant or non-compliant in itself — the deployment is. Compliance comes from a lawful basis, processor contracts, transfer justifications, security, records and, where needed, an impact assessment. On-premise AI removes the processor and transfer questions for the AI step; the rest stays with you as controller.

Can I use ChatGPT under GDPR?

Possibly, with the right tier, a processor agreement, a transfer assessment and staff who never use the free version alongside it. The practical difficulty is that staff start pasting before the paperwork exists. On-premise AI gives them a sanctioned tool with no processor or transfer to assess.

Do I need a DPIA for AI?

It depends on the processing, not the tool: large-scale special-category data or systematic monitoring usually needs one. Local AI doesn't remove that decision, but it shortens the assessment — the "where does the data go" section has a one-word answer, and there is no processor or transfer to analyse.

Is on-premise AI automatically GDPR compliant?

No, and anyone who says otherwise is selling something. It removes the third-party AI processor and the international transfer for the AI step and keeps personal data behind your own access controls. Lawful basis, retention, access decisions and any impact assessment remain your responsibility as controller.

Who is the data processor with Local AI?

For the AI processing itself, nobody — it runs on your machine. AgentHub acts as a processor only for the support access you choose to grant us, and we sign a data processing agreement covering it before go-live. You remain the data controller throughout.

Does the EU AI Act change any of this?

It sits alongside GDPR rather than replacing it. Most office uses of an AI assistant aren't high-risk under the Act, though transparency duties can apply where AI output reaches the public. We'll flag anything relevant to your use on the call — bring your adviser.

Ready to Take the Hardest Question Out of Your Assessment?

Tell us what the AI would be reading. Bring your DPO or your adviser — these are the questions we'd rather answer early.

Prefer to talk? Email sghaith@agenthub.ie or call 087 788 2676.