Skip to content
Anonix

Privacy & Law

AI use your data protection officer can approve.

This page is written for data protection officers, compliance and legal teams. No superlatives, just the articles that matter.

CLOUD Act and GDPR

Two legal systems, one contradiction.

US CLOUD Act (2018)

  • US authorities may require US companies to disclose stored data.
  • This applies regardless of where the data is physically stored.
  • No judicial review by EU standards is required.
  • It affects OpenAI, Google, Microsoft, Anthropic, AWS and other US providers.

EU GDPR

  • Transferring personal data to a third country requires a legal basis.
  • The CJEU’s Schrems II ruling invalidated the Privacy Shield.
  • The EU-US Data Privacy Framework only applies to certified companies.
  • Art. 48 GDPR prohibits disclosure without a mutual legal assistance treaty.

Why an EU data centre alone is not enough

Many organisations book AI models via AWS Bedrock or Microsoft Azure in a European data centre. Physically, the data never leaves the EU. But the CLOUD Act applies based on where the company is headquartered. AWS belongs to Amazon, Azure to Microsoft, both based in the US. This has been confirmed by the European Data Protection Board and the CJEU’s Schrems II ruling.

With Anonix, the AI provider, whether direct or via an EU data centre, only receives placeholders. The mapping to the original data never leaves your side. Even under a disclosure order, the text held by the provider contains no personal data in plain text.

The CLOUD Act, GDPR and AI in detail: read the whitepaper → (opens in a new tab)

1.2bn €

Meta, 2023, for third-country transfers

530m €

TikTok, 2025, for unlawful data transfers

45m €

highest fine in Germany (Vodafone, 2025)

4%

of worldwide annual turnover as the GDPR maximum

Sources: DLA Piper GDPR Fines Survey 2025, supervisory authority announcements, Art. 83 GDPR

An honest classification

Pseudonymisation or anonymisation?

Technically

Anonix performs pseudonymisation within the meaning of Art. 4(5) GDPR. Data is replaced so that it can no longer be attributed to a person without additional information. That additional information, the mapping, only exists in memory during processing.

From the AI provider’s perspective

The AI provider never receives the mapping. For the provider, the data is effectively anonymous. We phrase this precisely on purpose, because this is exactly the distinction your data protection officer will examine.

Whitepaper

US AI and data protection.All in 26 pages.

How your organisation can use ChatGPT, Claude and Gemini without giving away personal data. Prepared for management, data protection officers and IT.

  • CLOUD Act and GDPR: why an EU data centre alone is not enough
  • Practical examples from 12 industries, from public administration to software
  • Architecture, pricing and sample calculations
  • Compliance check under the GDPR, the EU AI Act and industry law

PDF, 26 pages, 1.3 MBDeutsche Version (opens in a new tab)

GDPR mapping

The technical measures, article by article.

  1. Art. 5(1)(c)Data minimisationOnly placeholders reach the AI provider. Personal data is reduced to the technically necessary minimum.
  2. Art. 25Data protection by designPseudonymisation precedes every AI call. Unprotected use through the proxy is not possible.
  3. Art. 28ProcessorsThe AI provider receives no personal data in plain text. The requirements for this processor are significantly reduced.
  4. Art. 30Records of processing activitiesComplete audit log of all requests, exportable as CSV.
  5. Art. 32Security of processingAES-256-GCM encryption, Argon2id password hashing, two-factor authentication and isolated tenant databases.

EU AI Act

Not a high-risk system.

Anonix is a data minimisation tool and does not fall into any high-risk category under Regulation (EU) 2024/1689. It makes no automated decisions about people, creates no profiles and affects no rights. Rather, it reduces the risks posed by the actual AI models.

Industry regulation

What applies to your industry.

RegulationIndustryHow Anonix helps
§ 203 StGBLawyers, tax advisers, doctorsProfessional secrecy is preserved because no client or patient data is transmitted.
DORA (EU 2022/2554)Banks, insurersICT risk management through controlled, logged AI use.
State data protection lawsPublic administrationCitizen data is replaced before any external processing.
SGB (social data protection)Social services, youth welfareSocial data is pseudonymised before external processing.

Security architecture

Security at every level.

  • AES-256-GCM

    Encryption of all stored API keys

  • Argon2id

    State-of-the-art password hashing

  • Isolated tenants

    Separate database per tenant

  • TOTP

    Two-factor authentication

  • Rate limiting & CSRF

    Protection against abuse and forged requests

  • Audit logging

    Structured, complete logging

  • EU hosting

    Operated exclusively on EU infrastructure

  • No stored mapping

    Placeholder mapping only in memory

Note: this page does not constitute legal advice. We are happy to provide your data protection officer with technical documentation for review.

Let’s talk abouthow you useAI.

In a short conversation we show you how Anonix fits your organisation: which providers, which data, which rules. No obligation.