2026-07-30 · TokenBridge Blog

EU AI Vendor Compliance Checklist (Berlin & Frankfurt Edition)

A procurement-grade checklist for evaluating Chinese-AI vendors in the EU: GDPR baseline, data residency, the Data Processing Agreement, and audit-log expectations your DPO will ask for.

If you buy AI for a Berlin or Frankfurt-headquartered company, you probably already know that the procurement questionnaire for "AI API access" looks nothing like the one you ran three years ago. The DPA subsection is longer. The sub-processor table has a column you have never seen before ("country of origin of the model"). Your DPO asks the same five questions every time — and the answers usually end up in front of the Berlin Datenschutzbehörde or the BfDI before a single API call is made.

This post walks through the four items your DPO will inspect line-by-line, and ends with a checklist you can lift directly into your vendor evaluation form. It is written for the procurement, legal, and security teams on the buying side — not for vendor engineering. Where TokenBridge is the working example on a given item, we link to the page where the evidence actually lives: the Trust & Compliance hub and transparent EUR pricing.

Why EU procurement teams are asking harder questions

Three things changed in the last 18 months. First, the European Data Protection Board's guidance on AI models and personal data has hardened the de facto expectation that any API call which can ingest personal data gets a DPA review — not just vendors that "process" data in the legal sense. Second, the Chinese upstream-model market consolidated — three providers (DeepSeek, ByteDance Doubao, Alibaba Qwen) now handle the majority of low-cost inference, and each one sits behind a data-protection question that US hyperscaler vendors never had to answer. Third, the Berlin and Frankfurt Datenschutzbehörden have started publishing enforcement priorities that name vendor due-diligence gaps as a recurring theme.

The net effect: a "yes, we have a privacy policy" answer is no longer enough. Procurement teams now expect a written response on each of the four pillars below before approval.

1. GDPR: the legal baseline

GDPR Article 28 is the part your DPO will read first. The minimum a vendor has to be able to produce on request:

If the vendor cannot produce all four in a signed PDF within a few days of the request, the rest of the technical due-diligence is moot. See the Trust & Compliance hub for what TokenBridge ships on this front, and the full DPA text for the actual prose your DPO will read.

2. EU data residency and the China-transfer question

"EU data residency" is the most-misused phrase in AI procurement. The honest answer for any vendor that calls a Chinese model is: account and infrastructure data stays in the EU; prompt content crosses the EU border to reach the upstream model, because that is where the model runs. No middleware will change that.

What you need on paper for that hop:

If a vendor tells you "all data stays in the EU" while routing to a model that runs in Beijing, the answer is wrong on the facts. The right answer is "yes it crosses, and here are the safeguards for that hop."

3. The DPA: what "good" looks like

A thin DPA is a red flag. The sections your DPO will look for in a working DPA:

A DPA that is silent on any of these is a DPA that the Berlin Datenschutzbehörde will read aloud in an enforcement hearing.

4. Audit logs and observability

Two layers of "audit log" usually come up:

1. Security audit log. Who logged in, when, from which IP, what API key they used. Required for your ISO 27001 readiness work, even if the vendor is not yet certified.
2. Billing/usage log. Per-request: timestamp, model, input tokens, output tokens, EUR cost, request ID. This is the record your finance team audits against the monthly wallet top-ups, and the record your DPO cites when a data subject asks "what did you send to an AI model about me?"

The TokenBridge customer dashboard surfaces both layers at /dashboard: the security side via login history, and the per-request log via the detailed usage history with CSV export. For the operator-side audit trail on administrative actions (manual wallet credits, key rotations) see the Refund Policy for the surrounding commercial controls.

5. Procurement checklist (Berlin/Frankfurt edition)

Drop these items into your standard vendor-evaluation form. "No" or "TBD" on any of them is a fail.

How TokenBridge answers each item

We sit down near the bottom of the page in this article because the more useful pattern is to run your checklist against any vendor and then come here to compare. For the items above:

For SOC 2 / ISO 27001 status specifically: we don't currently claim either certification. We will say so before your DPO finds it from a vendor questionnaire surprise — see the SOC 2 & ISO 27001 readiness section for the current roadmap.

Final note for Berlin/Frankfurt readers

If your company is in scope for the Berlin Datenschutzbehörde's AI vendor due-diligence framework (most RegTech, HealthTech, and PublicSector-adjacent teams are), reach out before signing — we can put the DPA and the data-residency transfer map on your desk within one business day via the contact form. If you are evaluating TokenBridge specifically, the Trust & Compliance hub is the page to start from.

Ready to verify? Read the Trust & Compliance hub · See pricing

← All posts