Groq
GDPR Compliance
Data Handling
All customer data retained in Google Cloud Platform (GCP) buckets in the United States. No EU data residency option. Groq has a designated EU GDPR representative (DP-Dock GmbH, Hamburg) but no EU-based infrastructure.
By default, Groq does not retain customer data for inference requests. Data may be temporarily retained up to 30 days only for reliability troubleshooting or abuse investigation. Zero Data Retention available to all customers via self-service Data Controls settings.
ZDR is self-service for all customers, not enterprise-only. Batch processing files retained 30 days. Fine-tuning data retained until deleted by customer.
Certifications & EU AI Act
No public EU AI Act documentation. Groq hosts third-party open-weight models (Llama, Qwen, Whisper, etc.) rather than developing frontier models. As a deployer of others' models, direct GPAI provider obligations may be limited — but this is unconfirmed.
Verification
Headquartered in Mountain View, CA. DPA is publicly available without NDA and covers GDPR, UK GDPR, Swiss FADP, CCPA, and Saudi PDPL — more transparent than most competitors. ZDR is self-service for all customers. Runs third-party open-weight models on proprietary LPU hardware; does not develop frontier models. No ISO 27001 confirmed as of verification date.