Get your regular legal insights

Subscribe to our newsletter to learn more about legal management and be the first to hear about news at GAIA

Request a demo

Take the first step towards uncomplicated and efficient legal management. Request a demo today and discover how GAIA can transform the way you handle legal affairs, saving you time and stress.

Sign up

Introducing: GAIA Agentic AI Contract Extractions

Read more

Data Residency vs Data Sovereignty: Choosing an LLM Provider for EU Contract Data

EU data residency and EU data sovereignty aren't the same thing. Under the US CLOUD Act, who controls your LLM provider — not where its servers sit — decides who can reach your contract data. A practical guide for in-house legal teams, plus the honest trade-off of going fully European.

At a Glance

Most legal teams evaluating AI can tell you where their data is stored. Far fewer can tell you whose law can reach it. Why this matters: Under the US CLOUD Act, exposure follows who controls the provider, not which city the servers sit in, which is why EU data residency and EU data sovereignty are not the same thing. This piece unpacks the legal conflict beneath that distinction, why a European provider can offer something a US provider with EU data centres cannot fully match, and the honest trade-off if you go fully European.

Why the nationality of your LLM provider matters more than where its servers sit

A practical guide for in-house legal teams choosing the AI that reads their contracts.

The question you should ask: Whose Law can reach your Data?

When a legal team evaluates an AI tool for contract work, the first question is almost always: where is our data hosted? It feels like the responsible question, and vendors are ready for it. "Data stays in the EU." "Frankfurt region." "Sovereign cloud." These sound like reassuring answers, but hide an important distinction you should know about.

The harder question is whose law can reach your data? And that is a question about the provider's nationality, not the server's postcode. For contract data specifically — among the most sensitive commercial information a company holds, and routinely subject to strict confidentiality obligations — getting this distinction right enables an informed decision.

The legal issue at hand

Two bodies of law collide here, and the collision has never been cleanly resolved.

On the European side, the GDPR treats any transfer of personal data outside the EU as something you may only do under defined conditions (Chapter V, Articles 44–49), the baseline principle being that the data may leave the EU only if it will enjoy protection essentially equivalent to European standards. Contracts are full of personal data — signatories, employees, beneficial owners, counterparties — so almost any contract workflow touches this. The cleanest way to satisfy that rule is an adequacy decision: a formal finding by the European Commission (under Article 45 GDPR) that a particular country protects personal data well enough for it to flow there freely, without each company having to put its own extra safeguards in place. The mechanism that currently supplies that finding for the United States is the EU-US Data Privacy Framework, the adequacy decision the Commission adopted in 2023.

The problem is that the Framework is standing on shaky ground. It is the third attempt at a transatlantic data deal; its two predecessors were both struck down by the Court of Justice of the European Union — Safe Harbor in 2015 (Schrems I, Case C-362/14) and Privacy Shield in 2020 (Schrems II, Case C-311/18). In both cases the Court reached the same conclusion:

US surveillance law let government agencies reach Europeans' data too broadly, and EU individuals had no effective way to challenge it in a US court. So the protection on offer was not "essentially equivalent" to the GDPR's.

It cleared its first legal test in September 2025 — the EU's General Court dismissed the challenge and upheld the adequacy decision in full — but the Court judged it only on the situation as it stood in 2023, expressly declining to weigh later developments, and that narrow framing is now the strongest ground of the appeal pending before the CJEU (Case C-703/25 P). The US foundations underneath have kept shifting since: the oversight body the Commission had relied on lost its quorum, and Section 702 of FISA — the surveillance authority at the centre of the dispute — lapsed in mid-2026 without reauthorization, with only existing court certifications keeping collection running into 2027. Privacy campaigners have already signalled the next challenge — the one commentators are calling "Schrems III." Nobody serious treats the current Framework as permanent.

On the US side sits the CLOUD Act. Passed in 2018, it lets US authorities compel a US-based provider to hand over data it controls — regardless of where that data is physically stored. Its reach follows corporate control, not geography. A legal demand served on a US company's headquarters can compel production of data sitting on its servers in Frankfurt, Amsterdam, or Dublin. The data centre's location is legally irrelevant; what matters is that the entity holding it answers to US law.

Complying with a CLOUD Act order can put a company in breach of GDPR Article 48. That article says a judgment or order from a third-country court or authority is not, on its own, a valid basis to transfer or disclose EU personal data — it can be recognised or enforced only where it rests on an international agreement between that country and the EU or a member state, such as a mutual legal assistance treaty (MLAT). A CLOUD Act warrant is exactly the kind of unilateral foreign order the article is meant to catch, so unless it runs through an MLAT or is backed by another lawful basis under the GDPR, complying with it means making an unlawful disclosure. This isn't just a literal reading of the text: in a 2019 joint assessment with the EDPS — since reaffirmed in the EDPB's dedicated Guidelines 02/2024 on Article 48 — the European Data Protection Board took the view that a CLOUD Act warrant cannot, by itself, make such a transfer lawful. The result is a genuine conflict of laws that leaves US providers and their European subsidiaries in an impossible position: comply with the US order and breach the GDPR, or refuse and breach US law. For a European company, that may be a dilemma it isn't willing to accept — and either way, the point is to make the choice knowingly, rather than discover it after a warrant has already landed.

Do you want more insights like this? Subsribe to our Newsletter:

Why "EU data centres" doesn't close the gap

This is where the marketing and the law part ways.

A US hyperscaler or AI provider can truthfully tell you your data lives in an EU region. That genuinely reduces some risks: lower latency, cleaner data-residency posture, fewer cross-border transfer headaches in day-to-day operation. It is not nothing.

But it does not remove US jurisdiction. If the provider is a US entity, or is ultimately controlled by one, the CLOUD Act still reaches the data — Frankfurt or not. "Sovereign cloud" branding does not change who the company answers to when a US order lands. Data sovereignty, in other words, cannot be delivered by a contractual promise or a hosting region alone; it is a function of which legal system the provider sits inside.

That is the real reason a European team might prefer a European provider over a US provider with EU data centres. It isn't a preference for European companies as such, and it isn't flag-waving. It's that a provider outside US jurisdiction addresses the CLOUD Act exposure at its root rather than merely managing it. Everything else — encryption, EU hosting, strong contracts, no-training guarantees — mitigates the risk; a provider with little or no US jurisdictional hook reduces it structurally. That isn't an absolute: the CLOUD Act reaches any provider subject to US jurisdiction, so a European company with US subsidiaries, staff, or substantial US business is not automatically beyond reach, and the statute has a comity mechanism for conflicting foreign law. The point is that jurisdiction is the lever that actually moves this risk — not the server's location.

For most workloads, mitigation is fine. For your most sensitive contracts — M&A, litigation-adjacent agreements, anything strategically explosive if disclosed — the difference between merely mitigating the exposure and removing its root cause is exactly the kind of distinction a GC is paid to notice.

The honest trade-off of going fully European

So the clean answer is "use a European model like Mistral for everything," right?

Not so fast — and any vendor who tells you it's that simple is selling, not advising.

A genuinely European provider like Mistral gives you real advantages beyond jurisdiction: European data residency by default, open-weight models — many released under permissive licences — that you can self-host whenever you want full control rather than only in the most regulated corner cases, strong multilingual coverage across EU languages, and typically lower cost per token. For a European legal team, that's a serious package.

The trade-off is capability. On published reasoning and long-context benchmarks, the frontier US labs — Anthropic's Claude, OpenAI's GPT — have tended to hold a lead on the hardest tasks, which matters most precisely where contract review is unforgiving, since a confidently wrong extraction is worse than no extraction at all. But the gap has narrowed sharply — on general tasks a European model like Mistral is now competitive — and "narrowed" is not "closed."

So the real decision isn't European or American. It's a spectrum of positions, each with a different balance of capability and sovereignty:

  • US model, US hosting — maximum capability, maximum jurisdictional exposure. Fine for low-sensitivity, non-personal tasks.
  • US model, EU hosting — top-tier capability with better data residency. Depending on the provider and route, this may cost the same as global hosting or carry a modest premium. Either way the catch is identical: the CLOUD Act reach remains because the provider is still US-controlled — so EU hosting can add cost without fully solving the problem it appears to solve.
  • European model (e.g. Mistral) — full jurisdictional sovereignty, with a capability trade-off you should measure against your actual workload, not against a benchmark leaderboard.

Where this leaves your AI decision

The uncomfortable truth is that there is no single correct model for a legal team. There is a correct framework: know which jurisdiction each option sits in, know what each one can and can't reach, and route each type of contract to the option whose risk profile fits.

That's the logic behind keeping the model choice open rather than locking your team to whatever a single vendor happened to build on. GAIA works with most of the leading AI providers — including the major US models through their European-based data centres, as well as Mistral as a fully European option — so an organisation can align the model behind its contract work with its own risk appetite. And because that choice carries real compliance weight, it sits where it belongs: as an organisation-level decision owned by the people accountable for data governance, not something left to chance.

Ask your AI vendor a simple question: if a US court ordered it, could your provider be compelled to produce our contract data — yes or no? If the honest answer is yes, EU hosting hasn't solved your problem. It has postponed it until someone asks the right question.

GAIA works with most of the leading AI providers — including the major US models through their European-based data centres, as well as Mistral as a fully European option — so your organisation can align the model behind its contract work with its own balance of capability and data sovereignty.

Written by

Simona Sopova

on

August 25, 2026