Where your data actually goes: UK residency and GDPR for ChatGPT, Claude, Gemini, Grok and Muse

Checked 12 Sep 2026: ChatGPT Business has no UK data residency and Claude has no first-party EU or UK region. Nine vendor tiers in one table.

John Kelleher
John Kelleher

Last checked: 12 Sep 2026. Every cell in the table below was read from the vendor's own documentation, trust page or help centre on that date. Where a vendor does not publish an answer, the cell says so rather than guessing. This is not legal advice. It is a record of what the vendors state, and what to put in writing before you sign.

"Data residency" is the question UK buyers ask most often and the one vendors answer least clearly. It is really three questions. Where is your data stored at rest? Where does the model actually run when it processes a prompt? And which contract makes either of those binding? A vendor can answer yes to the first and no to the second, and most marketing pages will not tell you which.

Two results below are worth knowing before you read the table. ChatGPT Business is excluded from OpenAI's data residency programme entirely: the eligible products are Enterprise, Edu, Healthcare and the API platform. And Anthropic's first-party Claude has no EU or UK region at all: the documentation states that workspace geo has one available value, "us", and that inference geo accepts only "us" or "global".

UK and EU data residency by vendor and tier, checked 12 Sep 2026

Vendor and tier Trains on your data by default Retention UK residency EU residency How to get residency DPA and certifications What to ask the vendor
ChatGPT Business No. OpenAI states it does not use Business, Enterprise, Edu, Healthcare or API data, inputs or outputs, for training by default. Retention controls are offered to "qualifying organizations". Zero data retention is an API platform option, not a ChatGPT one. No. Business is not among the products listed as eligible for residency. No. Not available on this tier. Move to Enterprise, Edu or Healthcare, or build on the API. DPA available. CSA STAR, SOC 2 Type 2, ISO/IEC 27001, 27017, 27018 and 27701. Whether residency can be added to an existing workspace later, or only set when the workspace is created.
ChatGPT Enterprise No, by default. Configurable retention for qualifying organisations. Yes, at rest. UK is on OpenAI's list of at-rest residency locations. In-region inference is offered in the US or Europe only, so UK processing is not. Yes. At-rest storage in Europe plus opt-in in-region GPU inference in Europe. Eligibility is granted by OpenAI and configured on the workspace. Raise it before the workspace exists. DPA available. Same certifications as above. Enterprise Key Management for customer-held keys. Whether your UK residency covers processing or only storage at rest, in the contract, not the sales call.
OpenAI API No. "Data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in)." Abuse-monitoring logs are retained 30 days by default. Modified Abuse Monitoring or Zero Data Retention removes that, subject to approval. Storage only. The UK endpoint (gb.api.openai.com) supports regional storage; regional processing is listed as not supported. Yes, storage and processing. The EU region covers the EEA and Switzerland. You must be approved for abuse monitoring controls to use any non-US region. Residency endpoints carry a 10% uplift for models released on or after 5 Mar 2026. DPA available. Certifications as above. Which specific models and endpoints are residency-eligible today, since the eligible list is per model and changes with each release.
Claude Team and Enterprise No. "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." Chat, file and project content follows the retention policy your admin sets in organisation settings. The compliance activity feed is retained for six years, as are session transcripts by default. No. Workspace geo has one available value, "us", and cannot be changed after a workspace is created. No, not on the first-party product. Not available on Claude Team or Enterprise seats. Regional routing exists only for API traffic through Amazon Bedrock or Google Cloud, which is a separate contract with that cloud provider. DPA available through the Trust Centre. ISO 27001:2022, ISO/IEC 42001:2023, SOC 2 Type I and Type II, HIPAA-ready configuration with a BAA. Whether any first-party EU or UK region is on the roadmap, and what the interim contractual safeguards are.
Claude API No, by default. Prompts and outputs are not retained by default. The exception is Covered Models (Fable 5.1, Mythos 5.1, Fable 5, Mythos 5), which require 30-day retention and are not available under zero data retention unless Anthropic expressly authorises it. No. Inference geo accepts only "us" and "global". No, not first-party. Amazon Bedrock or Google Cloud regional and multi-region endpoints, at a 10% premium over global endpoints. US-only first-party inference carries a 1.1x multiplier and is not an EU or UK answer. As above. Whether the model you have standardised on is a Covered Model, because that decides whether zero data retention is even available to you.
Gemini in Google Workspace No. Google commits "not to use customer data to train or fine-tune any of Google's generative artificial intelligence models supporting the Google Workspace Generative AI Services without our customer's prior permission or instruction". Not stated on the privacy hub. Governed by your Workspace agreement. Not stated by the vendor for Gemini. Note that Google states file sharing and data region settings do not apply to data in Gemini Notebook. Not stated by the vendor for Gemini specifically. Ask Google to confirm in writing which Gemini surfaces your existing Workspace data region settings actually cover. Workspace agreement including the Cloud Data Processing Addendum. Content is "not human reviewed or otherwise used for Generative AI model training outside your domain without permission". Which Gemini features sit inside your data region and which sit outside it.
Gemini via Vertex AI Not stated on the locations documentation. Governed by the Google Cloud Data Processing Addendum. Not stated on the page checked. No for Gemini 3.8, 3.7 and 3.6 Flash. They are available only in the global region for in-country regions, including the UK (europe-west2). Gemini 3.5 Flash supports UK in-country residency and processing. Yes. At-rest residency and processing in the EU multi-region for 3.8, 3.7 and 3.6 Flash. Pin to the EU multi-region, or stay on 3.5 Flash if you need UK in-country. Documentation updated 3 Sep 2026. Google Cloud Data Processing Addendum. What happens to your UK in-country guarantee the next time you upgrade model version, because upgrading is what breaks it.
Grok API and Enterprise "No training" is listed as a feature of the Business and Enterprise tiers. The default for lower tiers is not stated on the pricing page. "Custom data retention" is listed on Business and Enterprise. No default period is published. Not stated. Enterprise lists "Data residency: control where your data lives" without naming a single region. Not stated. Enterprise contract only. Get the regions named in the agreement. A DPA and a sub-processors page are published. SOC 2 Type I and II listed across tiers, plus SSO, SCIM, advanced audit controls, customer-managed encryption keys and a dedicated data plane on Business and Enterprise. The named regions, and the current status of the ICO investigation opened on 3 Feb 2026 into X and xAI.
Muse (Meta) Depends on the endpoint. Meta's developer documentation states muse-spark-1.3 data is "not used to improve our products", while the cheaper muse-spark-1.3-contributor tier is "used to improve our products". Not stated by the vendor. Not stated. Meta's help centre (updated 11 Sep 2026) says Muse subscriptions are "in limited testing and aren't available in all locations yet" and requires you to be "located in a country where Muse is available". No country list is published. Not stated. Not procurable in the UK today. No business or enterprise tier identified. 18 or the age of majority to subscribe. Nothing yet. Treat Muse as a market development, not a shortlist candidate.

What the table changes about a shortlist

Three things follow from it that are worth more than any vendor's security page.

First, the tier matters more than the brand. A buyer who says "we are on ChatGPT, so we have residency" is usually on Business, which has none. The gap between Business and Enterprise is not a feature list, it is a different compliance position.

Second, storage and processing are separate promises. OpenAI's UK region stores at rest in the UK and processes elsewhere. If your control objective is that UK personal data is never processed outside the UK, the UK region does not meet it and the EU region is the closer answer.

Third, model upgrades break residency. Google's newer Flash releases dropped UK in-country support that 3.5 Flash still has. Anthropic's newest models carry a mandatory 30-day retention that rules out zero data retention. Both are cases of a buyer's compliance position changing because a vendor shipped, not because the buyer did anything. We cover the Anthropic side of this in more detail in is Claude safe for business, and the retention mechanics in OpenAI zero data retention.

The regulatory position, with dates

EU AI Act, Article 50, from 2 Aug 2026. Transparency duties now apply to AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text. Providers must disclose that the content is artificially generated or manipulated. If you sell into the EU and your product writes copy, generates images or speaks to customers, this is a live obligation, not a forthcoming one.

Commission enforcement powers over GPAI providers, from 2 Aug 2026. The AI Act's obligations for general-purpose AI model providers applied from 2 Aug 2025, but the Commission's enforcement powers in respect of those providers came into force on 2 Aug 2026. The grace period has ended. Providers of models placed on the market before 2 Aug 2025 must be compliant by 2 Aug 2027.

Data (Use and Access) Act 2025, section 80, in force 5 Feb 2026. Section 80 replaced UK GDPR Article 22. The old default was prohibition: solely automated decisions with legal or similarly significant effects were barred unless an exception applied. The new default is permission, subject to safeguards: information about the decision, an opportunity to make representations, human intervention and the ability to contest it. Special category data remains more tightly restricted. This matters if you are building agents that decide anything about a person, because the UK position has now diverged from the EU one, and a single policy written to Article 22 no longer describes both.

ICO investigation into Grok, opened 3 Feb 2026. The ICO opened formal investigations into X Internet Unlimited Company and X.AI LLC over the processing of personal data in relation to Grok and its potential to produce harmful sexualised image and video content. The investigation examines whether personal data was processed lawfully, fairly and transparently and whether appropriate safeguards were built into Grok's design and deployment. Maximum UK GDPR exposure is £17.5m or 4% of global annual turnover. This is a fact to weigh in procurement, not a verdict: the investigation is open and no finding has been made.

Transatlantic transfers: the foundation is contested

On 29 Jun 2026 the US Supreme Court decided Trump v. Slaughter (No. 25-332), holding that Federal Trade Commission commissioners are removable at will. That is a ruling about the FTC's independence, not about data transfers. The connection is indirect but real: the European Commission's 2023 adequacy decision for the EU-US Data Privacy Framework rests in part on the FTC's independent enforcement role, and noyb wrote to the Commission the same day asking it to withdraw adequacy. Skadden's analysis of 28 Jul 2026 says the decision "could increase the risk" that European courts annul the adequacy decision.

The position today is straightforward. The adequacy decision remains in force. Its foundations are contested. A UK firm relying on the UK Extension to the Data Privacy Framework should hold Standard Contractual Clauses or the International Data Transfer Agreement as a fallback, so that a change in adequacy is a paperwork event rather than an outage.

Ten questions to put to a vendor before you sign

  1. Which tier am I actually buying, and is that tier eligible for data residency at all?
  2. Does residency cover storage at rest, processing, or both? Answer each separately.
  3. Is residency set at workspace creation, or can it be added to the workspace we already run?
  4. Which specific models and endpoints are residency-eligible today, and what is the uplift in price?
  5. What is the default retention period, in days, for prompts and outputs, and what changes it?
  6. Do any of your current models carry a mandatory retention term that overrides our retention setting?
  7. What happens to our residency and retention position when you release the next model version?
  8. Can we block new models from being enabled in our tenant until we have approved them?
  9. Which transfer mechanism applies to us: adequacy, SCCs, the IDTA, or the UK Extension, and what is the fallback if adequacy changes?
  10. Show us the sub-processor list, the DPA, the certification scope and the audit report, not the marketing page.

Question six and question eight are the ones buyers skip and then regret. A retention term that appears with a model update is not hypothetical: it is a pattern we have seen bite a regulated firm that had done everything else correctly.

If you are in a regulated sector

Regulated firms we speak to want three things that generic AI governance advice does not give them.

An evidence pack, not a policy. The regulator and the auditor want to see the decision, the basis for it and the controls, mapped line by line: data classification, model governance, retention, transfer mechanism, records export, and a data protection impact assessment. A policy document that asserts good practice is not the same artefact.

Model approval as a configuration control. "We will only use approved models" is a sentence. Blocking unapproved models in the tenant admin console is a control. If your platform cannot enforce it, that is a finding, and you should know it before the auditor does.

Retention terms that survive a model update. The realistic failure mode is not a breach, it is a vendor shipping a model whose terms differ from the one you assessed, and nobody noticing for a quarter. Put a named owner on re-checking the retention and residency position after every vendor release, and keep a dated record of what you checked.

None of this requires a favourite vendor. It requires knowing which of the nine rows above you are actually on, and holding the vendor to the specific sentence rather than the category.

Frequently asked questions

Does ChatGPT Business keep our data in the UK?

No. OpenAI's business data page lists ChatGPT Enterprise, Edu, Healthcare and the API platform as eligible for data residency. ChatGPT Business is not on that list. Business does get the no-training-by-default commitment, but not residency.

Can Claude run in the UK or the EU?

Not on the first-party product. Anthropic's data residency documentation states that inference geo accepts only "us" and "global", and that workspace geo has one available value, "us", which cannot be changed after the workspace is created. Regional routing exists for API traffic through Amazon Bedrock or Google Cloud regional endpoints, at a 10% premium over global endpoints, and that is a contract with the cloud provider rather than with Anthropic.

Does Gemini support UK data residency?

It depends on the model version. Google's locations documentation, updated 3 Sep 2026, shows Gemini 3.8, 3.7 and 3.6 Flash as available only in the global region for in-country regions including the UK (europe-west2), while 3.5 Flash supports UK in-country residency and processing. All four support the EU multi-region.

Should the ICO investigation into Grok stop us using it?

That is your risk decision, not ours to make for you. The facts are that the ICO opened formal investigations into X Internet Unlimited Company and X.AI LLC on 3 Feb 2026 concerning Grok, that the investigation is open with no finding made, and that xAI publishes a DPA, a sub-processors page and SOC 2 Type I and II, with no training, custom retention and unnamed data residency on its Business and Enterprise tiers. Weigh the open investigation alongside the absence of named regions.

Can we use Muse in the UK?

No. Meta's help centre, updated 11 Sep 2026, says Muse subscriptions are "in limited testing and aren't available in all locations yet" and requires you to be located in a country where Muse is available, without publishing a country list. There is no business or enterprise tier and no DPA we could find.

Is UK GDPR now easier than EU GDPR for AI?

On automated decision-making, it is different rather than uniformly easier. Section 80 of the Data (Use and Access) Act 2025 came into force on 5 Feb 2026 and replaced UK GDPR Article 22, moving from a default prohibition to a safeguards regime for most personal data, with special category data still treated restrictively. If you operate in both jurisdictions you now need a policy that describes both positions.

Where to go from here

If you are choosing a platform, or discovering that the one you already pay for does not sit where you assumed, the useful next step is an assessment of what you hold, where it goes and which controls you can actually enforce. Our AI implementation work starts there, and the AI and Data Readiness Assessment on that page is the shortest route to a written position. If you would rather go straight to scope and cost, request a quote.

SpotDev is an AI and digital transformation consultancy that builds real software. We are a HubSpot Diamond Solutions Partner, an OpenAI Select Partner and a Claude Registered Partner, and we hold Cyber Essentials Plus. We do not recommend a house model. We recommend the one whose written terms fit the obligations you are carrying.

John Kelleher

John Kelleher

Author
John is the founder and the Chief Executive at SpotDev.

Stay Updated with Our Latest Insights

Get expert HubSpot tips and integration strategies delivered to your inbox.