Service · GDPR-compliant AI

GDPR-compliant AI. Your data never leaves the building.

There are three solid ways to run AI in a company in line with data protection law: a properly configured enterprise subscription, EU-hosted models, or your own LLM in your own datacenter. We build and operate all three and tell you which one fits your case.

Talk to an engineer

01

What GDPR concretely means for AI

Four technical questions decide compliance, long before it gets legal: where is the data processed, in the EU or a third country? Is there a data processing agreement with the provider? Are your inputs used for training, and is that contractually excluded? And does your use case require a data protection impact assessment?

We are engineers, not lawyers. The legal assessment belongs to your legal department or law firm. Our part is the technical side: building systems so the answers to these four questions exist in writing and hold up in operation.

02

Three paths to GDPR-compliant AI

The first path is an enterprise subscription from a US provider, properly configured: data processing agreement, processing in the EU, training on your data excluded. ChatGPT is usable in a GDPR-compliant way for many use cases this way, and anyone claiming otherwise is usually selling fear. The limit lies with particularly sensitive data and with dependence on the vendor’s prices and model changes.

The second path is models hosted in the EU, such as Mistral or open models on European infrastructure. Data never leaves the EU, the contractual situation is simpler, and the models are now close to the American frontier models.

The third path is your own LLM on-premise: in your own datacenter or on our bare metal in Germany, completely without cloud, with no outside connection at all if you want. No token leaves the building, no vendor can change prices or retire models. That is the most expensive entry and the cheapest operation beyond a certain size.

03

When your own LLM pays off

The threshold is lower than most vendors suggest. From roughly fifty to a hundred intensive users, running costs tip in favour of owned infrastructure, and every case with high requirements on confidentiality, client separation or evidentiary duties belongs in-house anyway.

Run both sides over three years: license costs per user per month on one side, hardware, hosting, power and operations on the other. The advantage of an owned system is rarely price alone. It is that you can assure your own customers in writing where every sentence is processed, and that no vendor can retire a model a process was built on.

04

AI without cloud is operable

Open models like Llama or Mistral run today on hardware that fits into a server cabinet, and with quantization even on off-the-shelf GPUs. The technical part is solved. What makes a local LLM fail is the same point as with any infrastructure: nobody updates models, checks answer quality and picks up the phone when something sticks.

That is why operations are part of our offer: model updates, evaluation of answer quality, monitoring, on-call. If you want the technical background, running LLMs offline covers it in detail.

Common questions about GDPR-compliant AI.

Can ChatGPT be used in a GDPR-compliant way?
Yes, in the Business and Enterprise plans: with a data processing agreement, processing in the EU and training on your data contractually excluded. For many use cases that is sufficient. For particularly sensitive data, client separation or evidentiary duties we recommend an owned system.
Can we run an LLM completely offline?
Yes. After setup a local LLM needs no outside connection. We apply updates in a controlled way, after answer quality has been checked against your cases.
What does an owned LLM cost compared to licenses?
Entry costs are higher, running costs lower. From roughly fifty to a hundred intensive users, operating your own infrastructure undercuts the license costs of comparable subscriptions over three years. We run the numbers for your case concretely before anything gets built.
Do you also handle the legal review?
No. We are engineers, not lawyers. We deliver the technical evidence your legal department or law firm needs for the assessment: processing locations, contract states, logging, access concepts.

Thirty minutes with an engineer.

No sales, no slide decks. We reply within one business day.

Email

info@liermann.engineering

Phone

shown via JavaScript

Haan, Germany

Book a slot

30 minutes, video call, English or German.