To be clear up front: this article is practical orientation, not legal advice. For binding assessments, your data protection officer and, where needed, specialist counsel belong at the table.
The "Only Machine Data" Misconception
The sentence comes up in almost every digitalization project: "Data protection doesn't concern us — it's only machine data." It is wrong in two directions.
First, machine data is person-relatable more often than assumed. As soon as operator logins, shift schedules, manual inputs, or camera footage are part of the data stream — and they often are — machine behavior can be traced back to people. "Line 3 had many overrides at night" quickly becomes "employee M. had many overrides." At that point you are inside the GDPR with everything that entails — including works council co-determination, since systems that make employee behavior or performance observable are a classic case for it.
Second, the GDPR is not your only obligation. Non-disclosure agreements with your customers — the rule in automotive — often prohibit passing on process data regardless of any personal reference. A cloud transfer can be a breach of contract even when it is clean under data protection law.
The Question List for Every Cloud Offer
If a vendor wants to process your production data, you should have written answers to these questions before signing:
- Where exactly is processing happening? Data centre, country, jurisdiction. "In the EU" is a start, not an answer.
- Who is involved? The complete list of sub-processors — including the cloud infrastructure provider underneath and its corporate seat.
- Are there third-country transfers — including indirect ones, such as support access from non-EU countries or group structures with a foreign parent?
- What happens at contract end? Deletion concept, export format, deadlines — and what happens to the models trained on your data.
- Is your data used to train for other customers? If yes: your process knowledge is improving your competitor's product.
- Is there a data processing agreement under Art. 28 GDPR — and does it cover the actual processing chain, not just the direct contract partner?
Each of these questions produces effort, annexes, and reservations on the vendor side. That is not a sign of bad faith — it is the honest complexity of distributed processing.
The Simplest Answer: The Questions Disappear
There is one path on which most of this list becomes moot: the data never leaves your building.
With fully local processing — on-premise or air-gapped — there is no third-country transfer, no sub-processor chain for your raw data, and no conflict with customer NDAs through external processing. What remains are your internal duties (access concept, co-determination, purpose limitation) — which you have anyway, but you negotiate them with yourself instead of with a vendor chain across three jurisdictions.
That is the often-overlooked side effect of local AI: it is not only a security property — it is a massive simplification of compliance. Your data protection officer reviews an installation in your network instead of a transatlantic processing chain.
What fully local processing looks like in practice — including how updates work without internet — is something we show in a 30-minute conversation. Feel free to bring your data protection officer; we like those questions.