Search AI and GDPR are not a contradiction, if you ask the right questions. We see three traps that many setups walk into, and show how to avoid them.
Trap 1: US hosting despite an EU office
Many well-known search vendors have an EU subsidiary and advertise “GDPR-compliant”. In the fine print: data is processed on US servers, often with sub-processors in third countries. The EU subsidiary is the billing address, not the place of processing.
What to check concretely:
- Where is the data actually processed? (not “where the company is registered”)
- Which sub-processors are used? Request the list.
- Are there EU Standard Contractual Clauses (SCC) for every third-country transfer?
Trap 2: end-customer tracking
Many search vendors collect tracking data at the end-customer level: IP, user ID, browser fingerprint. It’s part of the “personalization promise”. From a GDPR perspective: consent-required and to be declared in the cookie banner.
At Eywora, personalization is anonymous: no user tracking, no cookies, no IP storage. Personalized re-ranking runs per session, anonymously. What is not collected cannot become a data-protection issue.
Trap 3: black-box AI without explainability
Art. 22 GDPR allows automated decisions only under certain conditions, and demands transparency. If you cannot explain why a product ranks at position 1, that is legally risky as soon as personalization is involved.
Solution: Search Debugger. For every result, you see which factors contributed at which weight to the ranking. That makes the AI decision explainable, including towards supervisory authorities.
- US hosting in the background
- IP and user tracking
- Black-box ranking
- Hosted in Germany only
- Anonymous personalization
- Search Debugger explains everything
What truly GDPR-compliant search AI looks like
- Hosting in the EU, ideally in Germany. No data transfers to third countries.
- DPA (Data Processing Agreement) included, without extra cost or pro-forma contracts.
- Anonymous personalization, no user IDs, no tracking cookies.
- Explainability through Search Debugger or comparable transparency tools.
- Clear sub-processor list, documented and changeable with advance notice.
- 30-day deletion after contract end, with confirmation.
Eywora’s position
We built Eywora from practice. “Eywora collects no customer data” is not a marketing slogan, it’s a technical design principle: the system is built so it doesn’t need customer data at all to perform.
Hosted in Germany, DPA included, ISO 27001 in preparation, TISAX on request. Details on the privacy page and in the DPA standard text.
Three questions to ask any vendor
- “Where is my data actually processed?” Server locations should be clearly documented, not just the company address.
- “Which personal data do you collect about my end customers?” Ideal answer: none. Reality: often IP, user ID or session tracking. Get the list in writing.
- “Can you explain to me why a specific result ranks where it does?” If the answer is “that’s the black-box AI”, you are exposed under Art. 22 GDPR.