Updated 4 October 2026. This post is from March 2026 and names GPT-4 as current. The method and the advice still hold; today you would run it with:
- Gemma 4: Use Gemma 4 for local, privacy-focused tasks on your own hardware to avoid sending data to external APIs.
- Llama 4 Scout / Maverick: Deploy Llama 4 Scout or Maverick locally to maintain data sovereignty while processing sensitive documents.
- DeepSeek V4: Run DeepSeek V4 on your internal infrastructure to ensure compliance with GDPR and AEPD requirements.
Spanish businesses often worry about AI because of the data. You might ask where the data goes, who can see it, or what happens during an audit.
These concerns are valid. Under GDPR, any AI deployment processing personal data creates significant compliance obligations. There is a simple architectural choice to avoid most of them: run the AI on your own hardware.
It is much easier to manage what you can physically touch.

flowchart LR
subgraph Cloud["Cloud AI Path"]
direction TB
A1["Your Business Data"] --> B1["Cloud API\n(OpenAI, Google, etc.)"]
B1 --> C1["US/Ireland Servers"]
C1 --> D1["Result Returned"]
C1 -.-> E1["Data exposed to third parties\nCross-border transfer\nDPA + TIA + SCCs required"]
end
subgraph Local["Local AI Path (VORLUX AI)"]
direction TB
A2["Your Business Data"] --> B2["On-Premises Model\n(Mac Mini M4 / Jetson)"]
B2 --> D2["Instant Result"]
B2 -.-> E2["Data never leaves your network\nNo transfers\nGDPR compliance simplified"]
end
style Cloud fill:#FECACA,stroke:#B91C1C
style Local fill:#D1FAE5,stroke:#059669
style E1 fill:#FECACA,stroke:#B91C1C
style E2 fill:#D1FAE5,stroke:#059669The GDPR Problem with Cloud AI
With GDPR fines reaching EUR 7.1 billion between May 2018 and January 2026, according to DLA Piper’s annual survey, the stakes are real. Every time you send data to a cloud AI API (OpenAI, Google, Anthropic), you’re creating a data processing event that triggers GDPR obligations:
| Obligation | Cloud AI | Local AI |
|---|---|---|
| Data Processing Agreement (DPA) | Required with every provider | Not needed: you’re the sole controller |
| Transfer Impact Assessment (TIA) | Required if data leaves EU | Not needed: data stays in your office |
| Standard Contractual Clauses (SCCs) | Required for non-EU transfers | Not needed: no transfers occur |
| Record of Processing Activities | Complex: multiple processors | Simple: single internal processing |
| Data breach notification | Provider must notify you, you notify AEPD | You control the entire chain |
| Right to erasure compliance | Must verify provider deletes data | Delete locally: you have full control |
Source: GDPR Articles 28-30, 44-49. AEPD guidance on AI and data protection.
What the AEPD Says About AI
The Spanish Data Protection Authority (AEPD) has been clear: data minimization is a core principle. This aligns with GDPR Article 25 on data protection by design, which applies to any processing of personal data, AI included. If you can achieve the same AI capability without sending data to a third party, data minimisation weighs clearly in favour of the local option.
The AEPD has also issued specific guidance on:
- Automated decision-making (Art. 22): must provide human oversight
- Data Protection Impact Assessments for AI (Art. 35): required for high-risk processing
- Transparency: users must know when AI is processing their data
Local deployment simplifies ALL of these because you control the entire processing chain.
Practical GDPR Compliance Checklist for Local AI
Before Deployment
- Identify personal data processed: what data will the AI model see?
- Conduct DPIA if processing is “likely to result in a high risk” (Art. 35)
- Define lawful basis: legitimate interest, consent, or contract performance?
- Document in Record of Processing: add the AI system to your ROPA
- Update privacy notice: inform data subjects about AI processing
During Deployment
- Ensure data stays local: verify no telemetry or model phoning home
- Implement access controls: who can query the AI, who sees results?
- Enable audit logging: record what data the AI processed and when
- Test right to erasure: can you delete specific data from the system?
After Deployment
- Regular DPIA reviews: at least annually or when processing changes
- Monitor for model updates: new model versions may have different data handling
- Train staff: GDPR awareness for anyone interacting with the AI system
The EU AI Act Adds Another Layer
The EU AI Act adds requirements on top of GDPR, phased in over time. Transparency duties (Article 50) have applied since 2 August 2026, the date the Act became generally applicable (Commission timeline); after the Digital Omnibus, Annex III high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028:
| If your AI system is… | You must also… |
|---|---|
| High-risk (hiring, healthcare, law enforcement) | Full conformity assessment, technical documentation, human oversight |
| Limited risk (chatbot, content generation) | Transparency (Art. 50): if you built the chatbot, you are its provider and must design it so users know it is an AI; as a deployer you label deepfakes and AI text published to inform the public |
| Minimal risk (spam filter, recommendation) | No additional obligations |
Local deployment helps with EU AI Act compliance too: Article 10 (data governance) is inherently satisfied when you control the entire data pipeline.
Example Scenario: A Law Firm
Take a 15-person law firm that processes client case documents daily. Suppose it has considered sending documents to GPT-4 for summarization, and its compliance officer flags:
- Client documents contain sensitive personal data (Art. 9 special categories)
- Sending to OpenAI creates a cross-border transfer (US servers)
- Legal professional privilege could be compromised
Solution: A Mac Mini M4 running Qwen 3 8B locally. Documents never leave the office network. DPIA conducted, processing documented, staff trained. The hardware is a one-off purchase.
Result: The same summarization capability, no international transfer to document, no ongoing API costs.
Next steps
- Review the checklist for identifying personal data before your next deployment
- Check your AI system risk level using our interactive assessment
- Read about how local AI inference supports privacy by design
- Learn about the eight prohibited practices under the EU AI Act
Related Resources
- EU AI Act Interactive Assessment: classify your AI system’s risk level
- 17 compliance templates: DPIA, transparency notices, conformity assessments
- Compliance Hub: full EU AI Act and GDPR guide
- Hardware Catalog: 13 devices for private AI deployment
- ROI Calculator: compare local vs cloud costs
- Request Assessment: free 15-minute GDPR + AI evaluation
Sources
- GDPR, Regulation (EU) 2016/679: EUR-Lex
- GDPR Fines and Data Breach Survey, January 2026: DLA Piper
- EU AI Act Implementation Timeline
Related reading
- GDPR and AI Convergence in 2026: Why Local Deployment Is the Only Clean Answer
- GDPR Article 25: Why Local AI Inference IS Privacy by Design
- The 8 Prohibited AI Practices Under the EU AI Act (With Examples)
Work with us
We size the model and the machine by measuring, not by guessing. If you want to see your own task running on real hardware, book a 15-minute call or see how we work in consulting.