Why your customer feedback platform might be creating a GDPR compliance gap you didn't know about.
“EU region” is not the same as EU jurisdiction
A US-headquartered provider operating an EU datacentre remains subject to US lawful-access requests for data under its control. The physical location of the disk is one input to a transfer impact assessment, not the answer to it.
What to ask your vendor
Four questions surface almost every gap:
- Who controls the encryption keys, and where are they held?
- Which sub-processors touch the data, and in which jurisdictions?
- Where do the models run, and are prompts retained?
- Do you publish a transfer impact assessment?
Want to try this on your own data? Run a free VOC health check — no credit card, EU-processed.
Start freeKey takeaways
- Jurisdiction attaches to corporate control, not server location.
- Ask about model hosting and prompt retention, not only storage.
About the author
Sofia Keller
Compliance Lead, InsightNarrator
Advises European CX teams on GDPR, transfer impact assessments and hosting architecture. Based in Zurich.
Connect on LinkedIn