Back to Insights
AI & Technology

AI Data Processing Agreements: Where Is Data?

October 2, 20266 min read0 viewsID 1166

An AI data processing agreement (DPA) is the contract between a business and an AI provider that sets out how the provider may process the business's data: for what purpose, under what security controls, by which sub-processors and, crucially, in which countries. As AI becomes embedded in operations, organisations rely more and more on third-party AI services, and knowing where business data is actually processed is not a technical detail. It is a legal, regulatory and security requirement.

Why data location matters in AI processing

AI data processing is rarely a single-location operation. AI services run on distributed cloud infrastructure that can span several countries or continents, which makes it hard to know exactly where data is held, processed or analysed. The location of processing determines which data protection rules apply, including the UK GDPR, the EU GDPR and other national regimes.

Data sovereignty matters too. Countries differ in their legal powers to access data and their rules on transfers, which affects the confidentiality of business data. When AI providers use cloud services hosted in several jurisdictions, the risk picture becomes more complex.

What an AI data processing agreement should cover

1. Explicit clauses on data location

The DPA should state clearly where data will be processed and stored. Vague wording such as "data may be processed outside the UK" is not enough. Insist on precision about processing jurisdictions and data centre regions, and on notice before they change.

2. International data transfers

International transfers are tightly controlled. Where an AI provider processes UK personal data outside the UK, a valid transfer mechanism is required: UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment. For EU data, the equivalents are EU adequacy decisions, Standard Contractual Clauses or Binding Corporate Rules. The DPA should say which mechanism applies.

3. Sub-processor transparency and control

AI providers often rely on sub-processors, including the cloud platforms and model providers underneath their service. Insist on a published list of sub-processors, advance notice of changes and a right to object.

4. Security matched to location risk

Security requirements should reflect the risks of the processing locations, including government access and cyber threat. The DPA should specify encryption in transit and at rest, access controls, logging and monitoring wherever the data is processed.

5. Use of your data for model training

Many AI services reserve the right to use customer inputs to improve their models unless the customer opts out or buys an enterprise tier. The DPA should state plainly whether your prompts, files and outputs can be used for training, how long they are retained, and how they are deleted.

Challenges specific to AI data processing

  • Replication and backup: AI workloads often replicate large datasets across many nodes for performance and resilience. That replication must be covered so data does not end up in jurisdictions outside your compliance framework.
  • Training versus inference locations: a model may be trained in one place while live requests are processed somewhere else. Both locations should be transparent in the DPA.
  • Hyperscale cloud dependency: most AI applications sit on a small number of global cloud providers. Understand how those providers handle data residency and compliance, not only the AI vendor in front of them.
  • Shadow AI: staff using unapproved AI tools bypass the DPA entirely. Our article on the risks of sharing your data with AI models covers this exposure.

Practical steps for businesses

  • Carry out due diligence: assess each AI provider's infrastructure, processes and compliance posture on data location before signing.
  • Negotiate precise DPAs: avoid generic templates and insist on clauses that reflect your regulatory environment and risk appetite.
  • Involve legal and technical experts: review agreements for both regulatory compliance and technical feasibility.
  • Monitor and audit: check that processing locations and practices stay compliant over the life of the contract.
  • Plan for incidents: understand how a breach or regulatory investigation would play out in each jurisdiction and build the response into the contract.

Choosing between AI platforms often comes down to these terms as much as to features; our comparison of Microsoft Copilot and Claude looks at the decision from a business perspective. Intology is independent of AI vendors, and its AI governance framework work and fractional CISO support help boards put these controls in place.

Conclusion

As AI and data protection evolve, knowing where business data is really processed is essential. Data processing agreements must move beyond boilerplate to define processing locations, controls and legal safeguards explicitly. A rigorous approach lets organisations use AI with confidence while staying compliant and protecting their data.

Frequently asked questions

What is a data processing agreement for AI?

It is the contract, required under the UK GDPR when a provider processes personal data on your behalf, that defines how an AI provider may use your data, where it is processed, which sub-processors are involved, the security controls applied and what happens to the data at the end of the contract.

Do AI providers process UK data outside the UK?

Often, yes. Many AI services run on global cloud infrastructure, and processing may take place in the US, the EU or elsewhere unless you contract for UK or EU data residency. The DPA should say where processing happens and which transfer mechanism covers it.

Can an AI provider use my business data to train its models?

It depends on the service and the contract. Consumer and some business tiers allow training on inputs by default, while enterprise agreements usually exclude it. Check the DPA and terms of service, and make sure the position is written down.

What should a business check before signing an AI DPA?

Processing locations, the international transfer mechanism, the sub-processor list and change process, security controls, whether data is used for training, retention and deletion, audit rights, and breach notification terms.

ai data processingdata processing agreementuk gdprdata residencyai governance

Found this useful? Share it.

Continue reading

All insights