Is Lambda Labs GDPR compliant?
Lambda's privacy policy includes GDPR provisions for users located in the EEA, UK and Switzerland, meaning Lambda contractually commits to honouring data-subject rights such as access, deletion and portability. That is the legal compliance floor every US SaaS provider has met since 2018. It is not the same as architectural GDPR enforcement: Lambda does not operate any EU compute region for GPU workloads as of May 2026, the legal operator is Lambda, Inc. (a US Delaware corporation with full administrative access to the host), and the platform does not offer Intel TDX, GPU TEEs, or any hardware attestation that could back the technical-measures clause of a GDPR Article 28 Data Processing Agreement for sensitive-data workloads. VoltageGPU is operated by a French entity (VOLTAGE EI, SIREN 943 808 824), runs workloads inside Intel TDX guests under a French controller, and delivers DCAP attestation as cryptographic evidence the operator cannot read the data. For high-sensitivity workloads under GDPR Article 9, the latter is what European auditors now expect.