Data residency comes up as a warning in almost every role and sector overview in this directory — think of the GDPR, American subprocessors, and uncertainty about who can access your data. This overview is the entry point that answers that warning: which types of AI tools with EU or Dutch hosting exist, and what to watch for when choosing one; categories and examples verified on 2026-08-07.
Within the structure of this directory, this page occupies a specific place on the AI tool ecosystem map. Where functional overviews classify based on what a product does (such as text generation, code assistance, or analysis), this overview forms an overarching entry point for the constraint of data location and infrastructure. It helps organizations navigate the AI software decision path when data sovereignty is a hard requirement.
To avoid overlap with existing pages, the scope is clear: for an inventory of specific Dutch market players and their profile, we refer to the overview of Dutch AI companies. When data absolutely must not leave your own organization and you are considering local runtime software, consult the page on local LLM tools. And for platforms focused on auditability, policy enforcement, and compliance reporting, we refer to the sister page on AI governance and compliance platforms. This page bundles the criteria, product categories, and edge cases surrounding hosting within the European Union and the Netherlands.
Why Hosting Location Matters
In practice, software selection often equates hosting location with compliance. While storing and processing data on European or Dutch soil is a crucial step, a thorough analysis requires a more nuanced picture of what data location does and does not solve.
Processing personal data or sensitive business data through artificial intelligence brings specific obligations under the General Data Protection Regulation (GDPR). When data is sent to servers outside the European Economic Area (EEA), this constitutes a transfer to a third country. This requires a legal basis, such as an adequacy decision or entering into Standard Contractual Clauses (SCCs), combined with a Data Transfer Impact Assessment (DTIA). Choosing a hosting location within the EU considerably simplifies this issue because the data physically remains within the jurisdiction of the GDPR. To check off the concrete GDPR obligations when implementing AI systems step by step, you can use the GDPR privacy checklist for AI.
It is, however, a common misconception that hosting within the EU automatically removes all privacy and security risks. Physical data location does not by definition guarantee three things:
- Access Rights and Key Management: A server physically located in Frankfurt or Amsterdam can be managed by an entity whose employees outside the EU have access to the unencrypted data or the encryption keys.
- Use of Training Data: Where the server is located says nothing about the contractual terms. A vendor may process your data on European soil but still use the submitted prompts and documents to further train models.
- Powers of Foreign Governments: If a European hosting facility falls under the subsidiary of an American organization, the US CLOUD Act can lead to American investigative authorities demanding access to data stored on European soil.
It is also important to distinguish this from the European AI regulation (AI Act). The AI Act primarily regulates the risk categories of AI applications, transparency obligations, and quality requirements for data and governance. The AI Act generally does not impose a direct obligation to host on EU territory, unless this follows from specific requirements for high-risk systems or national security and government guidelines. For background on the regulations surrounding AI risk categories and transparency obligations, read the explanation of the EU AI Act. Anyone who wants to read more about the geopolitical context of European dependency in the technology sector can turn to the analysis on AI and digital sovereignty in Europe.
This overview serves as a central reference point for the data residency warnings mentioned in the role-specific pages of this directory. It provides the frameworks to assess vendor claims about "European hosting" at their true value.
Where the Supply Lies: Categories of EU- and NL-Hosted AI Tools
The landscape of AI facilities with a European or Dutch data location is diverse. Below are the six main categories. Every product mentioned serves solely as an example to illustrate the category and is explicitly not a recommendation.
Dutch AI Companies and Specialized Providers
Dutch AI providers build applications and specialized models originally designed to meet the strictest GDPR requirements and local legislation. These parties typically use data centers in the Netherlands or Western Europe and have their legal entity fully registered in the Netherlands.
- Characteristics: Direct contracts under Dutch law, Dutch-language support, and transparent agreements about processing locations. This is a class that includes both SaaS applications for specific sectors (such as recruitment, law, or healthcare) and custom solutions.
- Examples: Textkernel (specialized in recruitment AI with European data center options) and Slimmer AI (developer of AI software for financial compliance and process automation with Western European hosting).
- Location Option: EU/NL-hosted variants are available by default. To see which Dutch players are active, we refer to the guide on Dutch AI companies.
EU Cloud Providers and Regional Options
Infrastructure providers physically and legally anchored in the European Union offer sovereign cloud services and AI infrastructure (such as GPU clusters and hosted inference APIs). In addition, large international hyperscalers offer European "regional options."
- Characteristics: Pure EU providers fall under the jurisdiction of EU member states and are not affected by extraterritorial legislation from third countries. With global hyperscalers, the data is physically stored within the EU, but the legal parent entity remains a point of attention. To gain insight into the physical data center capacity, energy impact, and regional presence of AI infrastructure in the Netherlands, read the analysis on data centers and AI in the Netherlands.
- Examples: Hetzner (German cloud provider with infrastructure in Germany and Finland) and Scaleway (French cloud provider with dedicated GPU clusters and AI hosting on European soil).
- Location Option: Fully hosted on EU territory with EU legal entities.
Self-Hosting on Your Own Hardware
For organizations with the highest privacy and security requirements, running AI models on their own physical servers or in a private colocation data center forms the hard boundary. No byte of data goes to an external vendor.
- Characteristics: Maximum control over data, network traffic, encryption, and access management. However, it does require substantial investments in hardware (GPUs), cooling, power, and specialized personnel for management and maintenance.
- Examples: Deploying open-source inference executables on your own NVIDIA DGX systems or local Linux servers equipped with high-end consumer or enterprise GPUs.
- Location Option: Locally running variant at your own location or in a dedicated Dutch data center. See also the guide on local LLM tools.
Open-Source and Open-Weight Models for Self-Management
Instead of using closed APIs, organizations can download open-weights models and host them themselves on a European cloud infrastructure of their choice or on their own hardware.
- Characteristics: Complete freedom in choosing the hosting provider. The model itself is a set of parameters; you decide where the processing takes place. This lets you combine state-of-the-art AI capabilities with strict data residency. Consult the overview of open-source models for available weights that can be deployed.
- Examples: Models from the Mistral family (developed by the French company Mistral AI) and Meta's Llama series, deployed within a shielded European Virtual Private Cloud (VPC).
- Location Option: Full flexibility to run as an EU/NL-hosted or local variant. To objectively compare the linguistic performance of European and local models in the Dutch language, consult the benchmark for Dutch tests.
Governance and Compliance Platforms with EU Storage
This concerns the category of software that monitors, anonymizes, filters, and audits the use of AI within organizations. These platforms act as an intermediate layer (proxy) between the end user and the AI model.
- Characteristics: The storage of audit logs, prompts, user identities, and compliance reports takes place within the EU. Many of these platforms can automatically remove personal data before the request is sent to an underlying model.
- Examples: Credo AI (AI governance platform with options for European data storage) and Private AI (solution for detecting and anonymizing sensitive data in data flows, locally or within the EU).
- Location Option: Available as an EU-hosted SaaS or as an installation method within your own network boundary. A complete picture of this category can be found on the page about AI governance platforms.
Specialized Privacy-Friendly AI Services
This includes SaaS solutions and API wrappers explicitly designed around the principle of privacy-by-design and data-minimal processing.
- Characteristics: Guarantees that submitted data is not used for model training, combined anonymization techniques, and processing that is guaranteed to take place within EU data centers.
- Examples: Mistral La Plateforme (API services hosted within European data centers) and Aleph Alpha (German AI provider focused on transparency and hosting in European data centers).
- Location Option: Delivered as an EU-hosted service by default. To discover how you apply privacy-enhancing techniques and anonymization layers when using generative AI, consult the article on privacy-friendly AI use.
What to Watch for With EU or NL Hosting: Assessment Criteria
Assessing an AI vendor on data location requires more than asking the question "is the server in Europe?" To avoid being caught off guard, you should include the specific assessment criteria below in your due diligence.
1. Actual Storage Versus Headquarters
Separate the location of the server from the registered office of the parent company. A vendor may use a data center in Eemshaven or Frankfurt, but if the corporate seat is in the United States, US legislation on data requests still applies. Check the privacy policy and terms and conditions to see which legal system applies to the agreement and which entity is the contracting party.
2. Subprocessors and the Processing Chain
An AI tool rarely uses just one server. Many SaaS applications forward specific tasks to external microservices — for example, for speech-to-text conversion, vector embeddings, or content moderation. Request a complete list of all subprocessors. Check for each subprocessor:
- Where processing and storage physically take place.
- Whether any of the subprocessors transfer data outside the EEA.
- Whether you are notified in advance when a new subprocessor is added to the chain (with the right to object).
3. Transfer Clauses and Exceptions
When a vendor states that data is located in the EU, check the exception clauses in the data processing agreement (DPA). Sometimes EU hosting applies only to data-at-rest (stored data), while telemetry, error logs, system diagnostics, or backups are still sent to servers outside the EU. Also pay attention to which transfer mechanisms (such as the EU-US Data Privacy Framework or Standard Contractual Clauses) are included as a fallback option.
4. Data Retention and Deletion Periods
Investigate how long input data (prompts) and output data (generated texts or files) are retained on the vendor's servers. Standard questions here include:
- Is there a 'zero data retention' (ZDR) policy, in which requests are wiped from memory immediately after generating the response?
- If data is retained for abuse detection (trust & safety), how long is this retention period (for example, 30 days) and where are those specific retention databases located?
- How are backups and log files cleaned up upon a deletion request?
To assess how you contractually anchor agreements on data retention and deletion with your vendor, read the advice on data retention at AI vendors.
5. Data Portability and Exit Strategy
When you decide to switch from an EU-hosted AI service to another facility, the hosted data must be easily exportable. Check whether the vendor supports open standards, what costs are charged for data transfers (egress fees), and within what period the vendor guarantees the destruction of all your data on all its systems after contract termination. To understand how to thoroughly vet a vendor on financial, organizational, and technical grounds before signing a contract, consult the overview on due diligence for AI vendors.
6. Demonstrable Certifications and Audit Reports
Poorly worded claims about "security according to the highest standards" have no legal value. Demand demonstrable and current certifications. The most important certifications for hosting on European soil are:
| Certification / Standard | What It Guarantees | How to Verify |
|---|---|---|
| ISO/IEC 27001 | Information security management (ISMS) of the data center and the organization. | Request the 'Statement of Applicability' (SoA) to check which locations fall under the scope. |
| SOC 2 Type II | Assessment of the operational effectiveness of security measures over an extended period. | Request the full audit report (under NDA) and read the findings of the independent auditor. |
| NEN 7510 | Specific Dutch standard for information security in the healthcare sector. | Required for healthcare-related applications in the Netherlands; check the validity date of the certificate. |
| GDPR Data Processing Agreement | Legally binding agreements on purposes, confidentiality, security, and data breach notification obligations. | Must be explicitly signed by both parties or form a binding condition of the contract. |
7. Support, Language, and Time Zone
In the event of incidents, data breaches, or security questions, it is important that the support department is reachable within European business hours and can handle communication in Dutch or English. This prevents delays in mandatory data breach notifications to the Dutch Data Protection Authority (AP) (which must take place within 72 hours).
8. Cost Models and the "EU Premium"
Offering dedicated infrastructure on European soil often brings higher operational costs for vendors than large-scale global rollout. It is important to take the following cost structures into account:
- Per-Token / Per-Request Model: Commonly used for cloud APIs. Local or EU-specific endpoints sometimes carry a surcharge compared to standard (US-hosted) endpoints.
- Per-Seat / License Model: Fixed price per user per month. Check whether the "EU Data Boundary" is an option only available in the more expensive Enterprise tier.
- Self-Hosted / Compute-Cost Model: No license costs per request, but ongoing costs for GPU infrastructure, energy, and management. This shifts the cost structure from operational variables to fixed infrastructure costs.
The Edge Cases: Nuances in Practice
Not every solution can be easily classified as "100% EU" or "100% foreign." In practice, organizations encounter three specific edge cases that require extra attention.
Edge Case 1: A European Company Hosting in the United States
A software company is registered with the Dutch Chamber of Commerce (KvK), has an office in Utrecht, and a Dutch-language helpdesk. However, to gain access to the most powerful GPU clusters, the developer uses a data center in the US. In this scenario, the company is indeed bound by the GDPR, but a transfer of personal data to a third country occurs with every AI request. The fact that the vendor is Dutch does not remove the obligations surrounding international data transfer.
Edge Case 2: An American Provider With Data in a European Region
Large international technology companies offer the option to store data exclusively within data centers in, for example, Amsterdam or Frankfurt (a so-called EU Data Boundary). The data remains physically within the EU. The legal risk here lies in the fact that the parent organization falls under the US legal system. If an American court issues an order under the CLOUD Act, the provider can be legally required to transfer data, regardless of where the servers are located. For organizations with strict confidentiality obligations (such as law firms, government, or financial institutions), this is a real consideration.
Edge Case 3: The Local LLM on Your Own Hardware
Running a model entirely locally on your own equipment (such as a local workstation or an internal server park) removes all external transfer risks. There are no third parties, no outbound network traffic, and no dependency on data processing agreements. The downside of this edge case is operational responsibility: the organization itself must ensure the physical security of the hardware, keep the software up to date, manage access control, and handle the capacity limits of the local GPUs. See the pros and cons in the guide on local LLM tools and the practical guide on running LLMs locally to see what this requires organizationally.
How to Choose: Decision Questions for Data Location
Use the decision questions below to determine, without external help, which type of hosting is necessary for your situation. Answer the questions in order:
- Nature of the Data: Does the AI system process personal data, trade secrets, or medical/legal information?
- No: You can use regular (global) AI services, provided you make agreements about not reusing data for model training.
- Yes: Proceed to question 2.
- Legal Framework: Is your organization bound by specific confidentiality obligations or the Wvbz/NEN 7510?
- Yes: Choose 'Self-hosting on your own hardware' or a 'Dutch/EU provider with adequate certification and exclusively EU subprocessors.'
- No: Proceed to question 3.
- Extraterritorial Legislation: Is the risk of data requests by third-country governments (such as the US CLOUD Act) acceptable for your risk profile?
- No: Choose a purely European cloud provider (EU headquarters and EU hosting) or your own hardware.
- Yes: An EU region of an international hyperscaler with a signed data processing agreement may suffice.
- Internal Management Capacity: Do you have the knowledge and hardware to maintain AI models in-house?
- Yes: Consider an open-source model on your own hardware or a dedicated EU private cloud.
- No: Choose a ready-made EU SaaS solution or a specialized privacy-friendly AI service.
Timeliness and Assurance of Data
The market for AI software, hosting solutions, and regional data centers is developing rapidly. New data centers are opened, acquisitions change the legal entity of vendors, and regulations surrounding international data transfer change regularly. An assessment of a vendor is therefore a snapshot in time.
To safeguard the reliability of this overview, the following validity statement applies: categories and examples verified on 2026-08-07.



