From the current Vapi documentation, the EU dashboard is positioned to support GDPR compliance, but full compliance still depends on how your agents are configured and which providers you use.
For the strongest EU/GDPR setup, most teams usually bring their own EU-hosted LLM, STT, TTS, and storage providers to ensure regional control over processing and retention. I couldn’t find a clear confirmation that every default model available in the agent settings is strictly EU-hosted, so it would be best for Vapi support to confirm exactly which providers guarantee EU-only processing and data residency.
You’ll also want to review subprocessors, retention policies, recordings/transcripts handling, and DPA coverage to make sure everything aligns with your compliance requirements.
@Lajna