If you buy AI for a Berlin or Frankfurt-headquartered company, you probably already know that the procurement questionnaire for "AI API access" looks nothing like the one you ran three years ago. The DPA subsection is longer. The sub-processor table has a column you have never seen before ("country of origin of the model"). Your DPO asks the same five questions every time — and the answers usually end up in front of the Berlin Datenschutzbehörde or the BfDI before a single API call is made.
This post walks through the four items your DPO will inspect line-by-line, and ends with a checklist you can lift directly into your vendor evaluation form. It is written for the procurement, legal, and security teams on the buying side — not for vendor engineering. Where TokenBridge is the working example on a given item, we link to the page where the evidence actually lives: the Trust & Compliance hub and transparent EUR pricing.
Why EU procurement teams are asking harder questions
Three things changed in the last 18 months. First, the European Data Protection Board's guidance on AI models and personal data has hardened the de facto expectation that any API call which can ingest personal data gets a DPA review — not just vendors that "process" data in the legal sense. Second, the Chinese upstream-model market consolidated — three providers (DeepSeek, ByteDance Doubao, Alibaba Qwen) now handle the majority of low-cost inference, and each one sits behind a data-protection question that US hyperscaler vendors never had to answer. Third, the Berlin and Frankfurt Datenschutzbehörden have started publishing enforcement priorities that name vendor due-diligence gaps as a recurring theme.
The net effect: a "yes, we have a privacy policy" answer is no longer enough. Procurement teams now expect a written response on each of the four pillars below before approval.
1. GDPR: the legal baseline
GDPR Article 28 is the part your DPO will read first. The minimum a vendor has to be able to produce on request:
- A signed Data Processing Agreement (DPA) that names TokenBridge as processor, you as controller, and covers subject matter, duration, nature, and purpose of processing.
- A list of sub-processors with country of origin and the legal basis for any cross-border transfer (typically EU Standard Contractual Clauses Module 2 for controller-to-processor flows).
- A breach-notification SLA measured in hours, not "promptly."
- Audit rights that survive termination — so you can verify what happened to data after the contract ends.
If the vendor cannot produce all four in a signed PDF within a few days of the request, the rest of the technical due-diligence is moot. See the Trust & Compliance hub for what TokenBridge ships on this front, and the full DPA text for the actual prose your DPO will read.
2. EU data residency and the China-transfer question
"EU data residency" is the most-misused phrase in AI procurement. The honest answer for any vendor that calls a Chinese model is: account and infrastructure data stays in the EU; prompt content crosses the EU border to reach the upstream model, because that is where the model runs. No middleware will change that.
What you need on paper for that hop:
- EU Standard Contractual Clauses (SCCs) Module 2 for the controller-to-processor transfer (EEA → China).
- Transfer Impact Assessment (TIA) that names the destination country's surveillance laws and the supplementary measures the processor applies (data minimisation, no PII required, pseudonymisation encouraged, no persistence by the processor).
- A sub-processor list where you can see, for each sub-processor, what data crosses which border and on what legal basis. See TokenBridge's data residency page for the working example.
If a vendor tells you "all data stays in the EU" while routing to a model that runs in Beijing, the answer is wrong on the facts. The right answer is "yes it crosses, and here are the safeguards for that hop."
3. The DPA: what "good" looks like
A thin DPA is a red flag. The sections your DPO will look for in a working DPA:
- Sub-processor management. General prior authorisation with a 30-day notice window for new sub-processors and a 15-day objection period. TokenBridge's DPA matches both numbers — see the Trust & Compliance sub-processor section.
- International transfers. Identifies the legal mechanism (SCCs Module 2 plus the UK Addendum for UK GDPR) and lists the supplementary measures.
- Security measures. Names specific controls (encryption at rest, TLS in transit, key management, access logging) at a level your auditor can verify.
- Breach notification. Specific clock window (TokenBridge: 72 hours from becoming aware) and a fixed contents list for the notification.
- Audit clause. Not less than once per calendar year, on no less than 30 days' notice.
- Data return and deletion on termination. TokenBridge commits to 30 days with written certification on request — see the data residency detail.
A DPA that is silent on any of these is a DPA that the Berlin Datenschutzbehörde will read aloud in an enforcement hearing.
4. Audit logs and observability
Two layers of "audit log" usually come up:
1. Security audit log. Who logged in, when, from which IP, what API key they used. Required for your ISO 27001 readiness work, even if the vendor is not yet certified.
2. Billing/usage log. Per-request: timestamp, model, input tokens, output tokens, EUR cost, request ID. This is the record your finance team audits against the monthly wallet top-ups, and the record your DPO cites when a data subject asks "what did you send to an AI model about me?"
The TokenBridge customer dashboard surfaces both layers at /dashboard: the security side via login history, and the per-request log via the detailed usage history with CSV export. For the operator-side audit trail on administrative actions (manual wallet credits, key rotations) see the Refund Policy for the surrounding commercial controls.
5. Procurement checklist (Berlin/Frankfurt edition)
Drop these items into your standard vendor-evaluation form. "No" or "TBD" on any of them is a fail.
- [ ] Signed Article 28 DPA on file, version-dated, names both parties.
- [ ] Public sub-processor list with country of origin per sub-processor.
- [ ] EU SCCs Module 2 in force for every non-EEA sub-processor.
- [ ] TIA on file naming the legal mechanism for the EEA → China hop.
- [ ] Breach-notification SLA at or below 72 hours.
- [ ] DPA audit clause permitting no less than one annual audit on 30 days' notice.
- [ ] Data return / deletion clause with a fixed window (TokenBridge: 30 days) and written certification.
- [ ] Billing/usage log downloadable per request, per model, with EUR cost per row.
- [ ] Customer-visible history of who logged in and which API key was used.
- [ ] Public, transparent EUR pricing — no FX exposure on the invoice (see pricing).
- [ ] DPA available without an NDA so your procurement team is not blocked on legal review.
How TokenBridge answers each item
We sit down near the bottom of the page in this article because the more useful pattern is to run your checklist against any vendor and then come here to compare. For the items above:
- DPA. A standard Article 28 DPA ships with every paid TokenBridge account. The full text is public so procurement can review it before a sales call.
- Sub-processors and data residency. The sub-processor table lists each sub-processor with country of origin, the purpose, and the legal basis for any cross-border transfer. The data residency page walks through the EU → China hop and the supplementary measures in place.
- Breach SLA. 72 hours from becoming aware of a Personal Data Breach — see the Trust & Compliance breach SLA section.
- Audit-log expectations. The per-request usage ledger is downloadable from the dashboard; the operator-side audit trail on administrative actions is summarised in the Refund Policy.
- Pricing transparency. EUR pricing with no FX exposure, monthly EUR invoice with VAT on every charge — see pricing.
- Refunds and commercial recourse. The Refund Policy documents how a wallet top-up can be reversed if a charge was made in error.
For SOC 2 / ISO 27001 status specifically: we don't currently claim either certification. We will say so before your DPO finds it from a vendor questionnaire surprise — see the SOC 2 & ISO 27001 readiness section for the current roadmap.
Final note for Berlin/Frankfurt readers
If your company is in scope for the Berlin Datenschutzbehörde's AI vendor due-diligence framework (most RegTech, HealthTech, and PublicSector-adjacent teams are), reach out before signing — we can put the DPA and the data-residency transfer map on your desk within one business day via the contact form. If you are evaluating TokenBridge specifically, the Trust & Compliance hub is the page to start from.
Ready to verify? Read the Trust & Compliance hub · See pricing