14 September 2026 · Law, privacy and artificial intelligence
Where the model runs decides which law applies: on-device processing, cloud processing, and what each requires
The decision whether a model runs on the device or in the cloud looks like an engineering one, and it settles whether personal data has been transferred to a third party. That distinction changes which documents are required, which transfer rules apply, and what is said to a client or an employee.
What counts as processing
The General Data Protection Regulation, Regulation (EU) 2016/679, defines processing in Article 4(2) as almost any operation performed on personal data, including collection, storage, use, retrieval and disclosure. Where a prompt contains a name, a file number, transaction details or the content of a document, the personal data in it is processed. The legal question is not whether processing occurs, but who carries it out and where.
A model running on the device
Where the model runs on the device itself and the text never leaves it, there is no disclosure to a third party, no provider processing the data on behalf of the organisation, and no cross-border transfer. The organisation remains the controller and its ordinary duties continue to apply, among them a lawful basis, information duties, security and erasure. What is saved is the contractual layer with the provider and the transfer rules.
A model running in the cloud
Where the text is sent to a provider server, the provider processes personal data on behalf of the organisation. Article 28 of the Regulation requires a written arrangement under which the provider acts only on the instructions of the organisation, undertakes confidentiality and security, engages no sub-processor without authorisation, and deletes or returns the data at the end of the engagement. Where the server sits outside the European Union, the transfer rules in Chapter V apply as well. A separate question, answered in the terms of service themselves, is whether the material sent is used to train the model.
Israel and the adequacy decision
The European Commission recognised Israel as providing an adequate level of protection by a decision of 31 January 2011. On 15 January 2024 the Commission published a report reviewing eleven adequacy decisions adopted before the Regulation, Israel among them, and found that personal data transferred to Israel continues to receive an adequate level of protection, including as regards the limitations and safeguards on access to personal data by public authorities. The Commission stated that it will continue to monitor the decisions and developments in national law. The practical effect is that a transfer from the Union to Israel needs no further transfer mechanism. An onward transfer from Israel to a provider in a third country is assessed on its own.
Amendment 13 to the Privacy Protection Law
Amendment 13 to the Israeli Privacy Protection Law came into force on 14 August 2025. It aligned definitions in the law with European usage, replaced the registration of databases with a duty to notify certain databases, imposed a duty to appoint a privacy protection officer and an information security officer on the categories of bodies it lists, and widened the enforcement powers of the Privacy Protection Authority together with the financial sanctions. The Authority deferred enforcement of the information security officer duty to 31 October 2025 and published forms and guidance for implementation.
What is checked before a tool is put to work
| Subject | What is checked |
|---|---|
| The data | Which personal details the prompt contains, and whether they can be reduced before it is sent |
| The processor | Who operates the model, and who its sub-processors are |
| The contract | Whether a processor arrangement exists, the deletion terms, and notice of a change of sub-processor |
| Location | Where the servers are, and whether processing can be confined to a region |
| Training | Whether the material sent is used for training, and whether that can be switched off |
| Retention | How long prompts and outputs are kept by the provider |
Further reading
The economics behind the move of part of the processing onto the device are set out in the article on conversion efficiency and the AI race.
Sources
Regulation (EU) 2016/679, Articles 4(2), 28 and Chapter V · European Commission decision of 31.1.2011 concerning Israel · Commission report of 15.1.2024 on eleven adequacy decisions · Privacy Protection Law, 1981, as amended by Amendment 13, in force 14.8.2025 · publications of the Israeli Privacy Protection Authority
General overview. Correct as at the date of writing, 14 September 2026.
