Every field is source-linked and dated.See the rubric behind the grades.

How we grade
Sovereign AI Registry
ExploreBlogGov accessCertsCountries

Footer

Sovereign AI Registry

The compliance registry for AI vendors. Data residency, training defaults, retention, subprocessors and EU AI Act posture — one row per vendor, product and deployment, every claim linked to its source.

Registry

  • Explore vendors
  • Deployment models
  • Categories
  • Countries

Compliance

  • Gov access exposure
  • EU AI Act roles
  • Certifications

Resources

  • FAQ
  • Methodology
Built with ShipMore·Build yours →

© 2026 Sovereign AI Registry. All rights reserved.

Line drawing of five pipes carrying data away from servers inside a dashed boundary; one pipe is broken, one is wrapped in a contract scroll, one in two scrolls, one passes under an arch with a hanging seal, and one loops back inside the boundary.

Analysis

SCCs, adequacy or nothing: how to read a vendor's transfer mechanism

By Marta Reinders

Published on August 10, 2026

Somewhere in every AI vendor's data processing agreement is a short clause naming the legal instrument that lets your data leave the European Economic Area: standard contractual clauses, an adequacy decision, the EU-US Data Privacy Framework, or nothing at all. Most buyers skim past it. The registry records that clause for all 83 products it now tracks, and it turns out to be one of the most predictive single fields we hold. Products that name no transfer mechanism have a median sovereignty score of 36. Products that need no mechanism at all, because their data never crosses a border, have a median of 86.

This explainer covers what each answer means, what it actually protects you from, and why the scores fall the way they do.

What the field records

Chapter V of the GDPR restricts moving personal data out of the EEA. A transfer needs a legal basis, and in practice a vendor's paperwork names one of three:

  • Standard contractual clauses (SCCs) are contract terms approved by the European Commission, signed between the data exporter and the importer. They are an Article 46 safeguard: the importer promises, contractually, to protect the data to EU standards.
  • An adequacy decision is a Commission finding that a third country's own law already protects personal data essentially as EU law does. Switzerland and the United Kingdom hold one. Data can flow there without further paperwork.
  • The EU-US Data Privacy Framework (DPF) is an adequacy decision limited to US companies that certify against its principles. Its two predecessors, Safe Harbour and Privacy Shield, were both invalidated by the Court of Justice of the European Union, which is why careful buyers treat a DPF certification as something to verify rather than a settled fact.

The registry reads each vendor's published DPA, privacy policy and trust pages and records the instrument the vendor itself names. Five answers come back, and they sort the registry cleanly:

Mechanism named

Products

Median score

None stated

17

36

SCCs

24

52

SCCs plus DPF

12

56.5

Adequacy decision

6

75.5

No transfer to cover (intra-EU)

24

86

The registry-wide median is 56. Grades come from weakest-link scoring across the whole data path, explained on the methodology page.

Nothing stated

17 products name no mechanism anywhere in their public record. That does not necessarily mean data is moving unlawfully. It means the question cannot be answered from anything the vendor publishes, and for a procurement review an unanswerable question is a failed one.

The pattern is not confined to thin, careless paperwork. Otter.ai publishes one of the best sub-processor pages we have graded, every entity named with its activity and country, and still names no Chapter V mechanism for its European customers. DeepInfra states that prompts live only in memory during the request, with the exceptions written down rather than buried, and pairs that with no published DPA, no named Article 46 mechanism and no EU residency option. Disclosure and lawful transfer are different jobs, and a vendor can do one well while ignoring the other.

No product that leaves this line blank scores above 56, which is exactly the registry median. Naming a mechanism is close to the price of entry for the upper half of the table.

SCCs, alone or with the framework

SCCs are the workhorse: 24 products name them alone and another 12 pair them with a DPF certification. The Schrems II judgment shapes how much weight they can bear. The clauses bind the vendor by contract, but they cannot bind the vendor's government, so the exporter is expected to assess whether the importer's local law undermines the promise before relying on them. A signed SCC annex is the start of the check, not the end of it.

The mechanism also follows the data flow, not the marketing. Happy Scribe is an Irish company with an EU data centre and a sub-processor list that is mostly European, and it still records SCCs, because Slack sits in its corporate stack for internal communications and Slack is American. That is the benign version of the pattern: the mechanism covers a peripheral flow, not your audio. The version to watch for is Fathom, which holds a genuine DPF certification, correctly credited by our methodology, while every sub-processor it discloses is American and each one handles the meeting recording or the transcript. The transfer is lawful. The data still sits in the United States, under United States jurisdiction, at every hop.

That is why these two groups cluster near the middle of the table, at medians of 52 and 56.5. The mechanism makes the flow lawful and changes nothing about where the flow goes.

Adequacy: lawful is not the same as local

6 products rest on an adequacy decision, at a median of 75.5, the strongest score of any mechanism that involves an actual transfer. In this registry the group is anchored by Swiss vendors. Infomaniak runs its AI services in its own data centres and commits, in its GDPR terms, to "Store your data in our data centers based exclusively in Switzerland, and never transfer your data outside our own infrastructure". Proton pairs a no-logs policy and zero-access encryption on saved chats with a DPA that confines transfers to Switzerland, the Union and adequacy-covered countries.

Two limits matter. An adequacy decision makes a transfer lawful; it does not place the data under EU jurisdiction, and it does not bind the third country's future legislature, which is why the Commission reviews these decisions periodically. Adequacy works as well as it does in these rows because the vendors built almost everything else right, so the decision is a short final hop rather than the load-bearing wall.

The strongest mechanism is not needing one

The remaining 24 products record no transfer because there is nothing to cover: either the vendor's whole supply chain sits inside the Union, or there is no vendor in the data path at all. Their median of 86 is the highest of the five groups. STACKIT is the registry's highest-scoring hosted service at 88, serving open-weight models from group-owned data centres in Germany and Austria, with no transfer out of the Union to need a mechanism for. At the far end of the same group, self-hosted Whisper transcribes audio on the operator's own machine and transmits nothing to anyone.

This is the real lesson of the field. The mechanism a vendor names is a proxy for the architecture it chose. Under weakest-link scoring, a single American sub-processor in the inference path drags the grade toward that hop no matter how strong the rest of the chain is. A vendor that needs no Chapter V instrument has already done the structural work that the instrument only papers over: it put the compute, the storage and the sub-processors where your data protection regime actually reaches. The paperwork gradient in the table is really an architecture gradient.

What to check in your own stack

  • Pull the DPA or privacy policy for each AI product you run and find the transfer clause. If no instrument is named, treat that as an open question to put to the vendor, and expect the rest of the record to be thin: in our data, no such product scores above 56.
  • Read the mechanism against the sub-processor list, not on its own. An EU vendor naming SCCs for a peripheral corporate tool is the Happy Scribe pattern and is usually fine. A DPF badge or SCC annex covering every model provider in the inference path is the Fathom pattern: the transfer is lawful, and it happens on every request.
  • If a vendor claims the DPF, verify the certification is current on the framework's public list and note which corporate entities it covers.
  • Ask which flows the mechanism covers: account data, support tickets, or the prompts and outputs themselves. Vendor documents often blur these, and the difference is where the risk lives.
  • If your requirement is that content never leaves the Union, shortlist from the group that needs no mechanism at all: EU supply chain hosts and self-hosted deployments. Their median of 86 is not an accident.

This article was researched and written by an automated pipeline from the Sovereign AI Registry's own data, then published without human review. Every figure is computed from the registry's live records. Corrections: open an issue.