“Your data is hosted in Europe”: why that statement does not mean very much
Every serious AI provider now offers a European hosting option. OpenAI, Anthropic, Google and Microsoft all operate regions in the EU, highlight GDPR compliance and reassure customers about where their data is located.
Yet the question of sovereignty remains unresolved. “Where is the data stored?” and “who can legally access it?” are two distinct questions. The latter does not depend on the geography of the servers, but on the law governing the company that operates them.
This distinction is not an experts-only debate. For a public body, teaching hospital or university sending learner data to an AI service, it determines what it can guarantee to its users and what it must record in its processing register.
Data residency, hosting and sovereignty: three different things
Let us first untangle the vocabulary, which marketing has carefully blurred.
Data residency means the physical location where data is stored. This is what a cloud provider's “European region” guarantees. It is verifiable, contractual, and the minimum.
Hosting adds the question of who operates the infrastructure. Data stored in a Frankfurt data centre operated by a subsidiary of a US group does not have the same legal status as the same data held by a European operator.
Sovereignty asks the question that really matters: which authority can compel the provider to hand over that data, regardless of where it is located?
At this third point, geography stops being relevant.
What the law says, and why geography is not enough
The Clarifying Lawful Overseas Use of Data Act, enacted in the United States in 2018 and codified at 18 U.S.C. § 2713, establishes a simple principle: a service provider subject to US jurisdiction must comply with a judicial order for data it controls, regardless of where that data is stored.
Server location is not the criterion. The criterion is control by an entity subject to US law. A US company operating a data centre in Ireland is still required to comply with a US order concerning that data.
Two intelligence mechanisms are added to this: Section 702 of the Foreign Intelligence Surveillance Act, which authorises the collection of non-US persons' data from US providers, and Executive Order 12333, which governs foreign intelligence activities.
In Europe, the Court of Justice of the European Union invalidated the Privacy Shield in July 2020 in the Schrems II ruling (case C-311/18), specifically finding that those surveillance mechanisms did not guarantee a level of protection equivalent to European law. Chapter V of the GDPR has since governed transfers outside the EU, and the European Data Protection Board has issued recommendations on the supplementary measures to implement.
The Data Privacy Framework, adopted in 2023, restored a framework for transfers to certified US companies. It is under challenge before the CJEU. A prudent data controller does not base an architecture on a framework whose legal durability is disputed: they have already seen it fall twice.
In practical terms: a US provider offering European hosting remains subject to US law. This is not an opinion about the quality of its service; it follows from its legal status.
Why this is more critical in education than elsewhere
Learning data may appear harmless. It is not.
An exchange between a learner and an AI tutor reveals what they do not understand. Repeated across a learning journey, this information creates a profile of cognitive difficulties, learning pace and, sometimes, personal vulnerabilities. In vocational training, it can affect skills assessment and therefore a career.
Three sectors concentrate this exposure. Higher education handles student data, often belonging to young people, within a public-service framework. Healthcare combines continuing education with data potentially covered by professional secrecy. The public sector is subject to traceability requirements that the private sector does not always face, while ANSSI's SecNumCloud standard, which explicitly requires immunity from extraterritorial laws, is becoming a common procurement criterion in public tenders.
The AI Act, fully applicable since 2 August 2026, adds its own transparency and traceability obligations to those of the GDPR.
The Mistral case: what can be verified, and what needs attention
Mistral AI is a French company, subject to French and European law. It is not within the scope of the CLOUD Act. This is a difference in nature, not degree.
Its documentation is explicit about hosting: “By default, your data is hosted in the European Union.” It is equally explicit about the limitations, and that deserves credit: “Depending on the feature you use, your data can be temporarily transferred outside of the European Union, to the locations listed in the Subprocessors tab of our Trust Center.” Transfers outside the EU are governed by safeguards compliant with Article 46 of the GDPR.
In other words, Mistral does not claim that no data ever leaves Europe. It documents its subprocessors and publishes the list. For a DPO, that is actionable information. Indeed, it is the only approach that makes it possible to complete a processing register properly.
There are two points to watch, however.
Using a marketplace changes everything. Using a Mistral model through AWS Bedrock or Azure AI does not place you under the framework described above. Data residency then follows the cloud provider's region, and that US provider becomes your processor. The model is French; the processing is not.
Not all Mistral models are open-weight. The company does release several models under open licences, which allows a fully internal deployment. But its most capable commercial models are not open-weight. Saying “Mistral is open-weight” without specifying which model would be inaccurate.
Our architecture, described precisely
We prefer to describe our processing chain rather than wave labels around.
PimenkoAI's application infrastructure is hosted by Scaleway, a French operator and subsidiary of the Iliad group. Scaleway holds HDS certification for hosting health data. On SecNumCloud, let us be precise: Scaleway is engaged in the ANSSI qualification process and is therefore listed publicly among providers currently seeking qualification. It has not yet obtained the qualification. We state this because ANSSI's list is public and you will check it.
Inference is provided by Mistral's API, a French company. Messages are therefore not processed on our Scaleway infrastructure, but by Mistral under the conditions described above. We prefer to state this plainly rather than place two French names side by side and imply an integrated chain.
Learner identities never leave Moodle. A pseudonymised identifier is substituted before every external call. What is transmitted is limited to the message, the course context and that identifier.
Scaleway now offers models as a service, which could make inference possible on French infrastructure. This is the direction we want to take, and it requires reaching a volume we have not yet achieved. We present it as an intentional trajectory, not as a current product capability.
Three questions to ask any provider
Which legal system governs the entity processing the data? Not where the servers are. What is the company's legal nationality, and that of its parent company? A European subsidiary of a US group remains within the scope of the CLOUD Act.
What is the list of subprocessors, and is it public? A provider that documents its subprocessors and reports changes allows you to maintain your register. A provider that remains vague puts you out of compliance without you knowing it.
What happens if the transfer framework falls? The Privacy Shield was invalidated, and before it the Safe Harbor. A provider whose architecture depends entirely on the validity of the Data Privacy Framework exposes you to a disruption risk. Ask for its contingency plan.
These questions do not call for a perfect answer. They call for a precise one. A provider able to describe exactly what leaves, who receives it, under which legal regime and with which safeguards lets you make an informed decision. That is all a DPO asks for.
See PimenkoAI's processing architecture in detail →
References
-
18 U.S.C. § 2713,
Clarifying Lawful Overseas Use of Data Act (2018)
Online: https://www.govinfo.gov/app/details/USCODE-2024-title18/USCODE-2024-title18-partI-chap121-sec2713 -
Regulation (EU) 2016/679 (GDPR), Chapter V, Articles 44 to 50
Online: https://eur-lex.europa.eu/eli/reg/2016/679/ -
Regulation (EU) 2024/1689 laying down harmonised rules on
artificial intelligence
Online: https://eur-lex.europa.eu/eli/reg/2024/1689/