GDPR-Compliant AI — Use ChatGPT & Claude Without Breaking EU Rules

ChatWall lets European companies use the best AI models on the market — ChatGPT, Claude, Gemini, Copilot — while keeping personal data inside the EU and out of US-based LLM providers. Masking is performed locally, so no personal data ever crosses a border.

Try the Sandbox Talk to Sales
The GDPR problem with public LLMs: sending personal data to OpenAI, Anthropic or Google involves an international transfer to the US, a third-party processor, an unclear lawful basis, and a real risk that personal data ends up in training sets. DPAs and works councils increasingly flag this.

How ChatWall makes GDPR work for LLMs

GDPR snapshot

GDPR concernPublic LLM aloneWith ChatWall
Personal data sent to a US providerYesNo (tokens only)
International transfer (Ch. V)Yes — requires SCCs / TIANot for personal data
New sub-processor for extensionNone (local)
Right to erasure feasibleDepends on providerTrivial — never stored
EU-only deployment optionNoYes (ChatWall Box)

For DPOs and security leads

ChatWall is built by an EU team. The code is source-available on GitHub so DPOs can include it in a DPIA without relying on vendor claims. The on-premise ChatWall Box ships as a Docker image you run inside your own VPC — no data, logs or telemetry ever leave your infrastructure.

FAQ

Does tokenized text count as personal data under GDPR?

If the mapping table that links tokens back to real identifiers is held only on the user's device (extension) or inside your own VPC (Box), then the third-party LLM sees pseudonymized text it cannot re-identify — significantly reducing GDPR exposure on that processor. Your DPO should confirm based on your specific setup.

Do we still need an EU AI Act assessment?

Yes — the EU AI Act applies to your use case, not to ChatWall. But masking personal data before it reaches the model materially reduces the risk profile of many use cases (especially "limited" or "high" risk processing of personal data).

Can we deploy ChatWall entirely on EU soil?

Yes. ChatWall Box is a Docker container that runs in your own infrastructure — OVH, Scaleway, Outscale, German sovereign cloud, on-prem datacenter — your choice.

What about the Schrems II / TIA requirement?

The TIA exists because personal data crosses to the US. If you mask personal data on-device first, the data sent to the US-based LLM is pseudonymized and no longer identifies an EU data subject — which materially changes the TIA outcome.