Building GDPR-Ready Agents with Mastra

Data residency, PII controls, and what GDPR means for the Mastra framework vs. the Mastra platform.

Brandon BarrosBrandon Barros·

Sep 28, 2026

·

6 min read

When we talk to European teams putting agents in front of customer data, GDPR usually comes up on the first call. The questions are pretty specific: can we host in the EU, will you sign a DPA, and what data leaves our system?

One team building an email-drafting agent told us they could move fast as long as everything was SOC 2 and GDPR compliant. Another pointed out that GDPR has "99 articles" and asked which ones Mastra covers. This guide covers how European teams are answering those questions on Mastra.

Working through HIPAA, SSO, or RBAC instead? See Building Secure, Governed Agents for Regulated Enterprise.

Background

The answer depends on which part of Mastra you're using.

Mastra framework is open-source and runs in your infrastructure. You choose the cloud, the region, the database, and the model provider. The only thing Mastra collects by default is anonymous CLI telemetry (OS, Mastra version, Node.js version), and you can turn that off with MASTRA_TELEMETRY_DISABLED=1.

Mastra platform hosts your Server, Studio, databases, and observability for you, with a dedicated EU region.

Compliance: Mastra is SOC 2 Type II audited. We publish a DPA with EU Standard Contractual Clauses, our subprocessor list, and our security controls in our Trust Center.

GDPR questions from our customers tend to fall into 4 buckets:

  1. Can our data stay in the EU?
  2. What personal data do our agents see?
  3. Can we handle retention, deletion, and access?
  4. What will you sign?

Everything inside the dashed box runs where you deploy it. Data only leaves when it goes to your model provider or your trace exporter.

1. Keep your data in the EU

If you self-host the framework, your agents run wherever you deploy them. If you deploy to an EU cloud region, your runtime, memory, and workflow state stay there.

A legal AI company we work with runs everything in a private European cloud because their contract review agents handle legal documents that need to stay in the region. A European construction software company also started out self-hosting for GDPR, and they're planning to move to our hosted EU platform once their customer DPAs are in place.

On the Mastra platform, you choose a region when you create an environment. If you pick eu, the hosted database and observability data are stored in the EU as well.

mastra deploy --env production --region eu

The region can't be changed after the environment is created, and the default is us, so pass --region eu on your first deploy.

You'll also want to think about your model provider. Prompts go from your server to whichever provider you choose, so teams with strict residency requirements usually use an EU-hosted model endpoint. Voice agents work the same way. Audio goes to the speech and realtime providers you configure, so choose ones that process data in the EU.

2. Minimize the personal data your agents see

Mastra's PIIDetector processor finds and redacts personal information like emails and phone numbers. You can run it on inputs before they reach the model, on outputs, or both.

const processor = new PIIDetector({
  model: "openrouter/openai/gpt-oss-safeguard-20b",
  threshold: 0.6,
  strategy: "redact",
  detectionTypes: ["email", "phone", "credit-card", "ssn"],
});

The email-drafting team asked whether Mastra still has the original data after it's been redacted. Redaction happens inside your own process, so the original is never sent to the model, your traces, or any hosted service.

For traces, SensitiveDataFilter removes the fields you specify from spans before they're exported. You can also use a configSelector to choose an observability config per request, so traces for EU customers go to an EU endpoint.

3. Handle retention, deletion, and access

A European SaaS company asked us how Mastra handles GDPR for "role based authentication, retention, deletion and retrieval of information." Mastra handles each of these through your storage and Studio:

  • Retention and deletion: Threads, working memory, workflow snapshots, datasets, and experiments are all stored in the database you configure, like your own Postgres. You set the retention policy and handle erasure requests directly in that database.
  • Retrieval: Since it's your database, you can look up and export a user's data when they ask for it.
  • Access: Studio supports SSO and role-based access control, so you can decide who can view traces, run agents, or delete datasets. You can also scope permissions to individual agents.

On the platform, your data stays in your environment's region, and we'll delete it on request if you leave.

4. What we commit to in writing

If you're using the platform, your legal team will want these commitments in a contract. Our DPA and security program include:

  • A signed DPA with Mastra as your processor, including EU Standard Contractual Clauses, the UK Addendum, and Swiss FADP terms
  • A SOC 2 Type II report (received October 2025), which you can request from our Trust Center
  • No training on your personal data, for us or for our subprocessors, including model gateways and providers
  • A public subprocessor list, with 30 days' notice and a right to object before we add a new one
  • Breach notification without undue delay, and within 72 hours where feasible
  • Help with data subject requests and DPIAs, plus annual audit rights (a recent SOC 2 report can be used in place of an on-site audit)

If you self-host the framework, most of this is handled on your end, since Mastra never has access to your data.

Working through a review

What GDPR asks of you depends on what data you process and who regulates you. If you have a security questionnaire, vendor review, or GDPR checklist, send it to us and we can go through it with you.

FAQ

Can our data stay in the EU?

Yes. Self-host in any EU region, or create a platform environment with --region eu. See Regions for details.

Will you sign a DPA?

Yes. Start from our published DPA. It includes the EU SCCs, so you won't need separate paperwork for data transfers.

Which parts of GDPR does Mastra cover?

Our DPA covers our obligations as your processor (Article 28), security measures (Article 32), and international transfers (Chapter V). As the controller, you're still responsible for your legal basis, privacy notices, and consent, including telling users when they're talking to AI. Mastra's redaction, EU hosting, and self-managed storage help you meet those requirements.

Do you have SOC 2?

Yes, SOC 2 Type II. Request the report from our Trust Center.

Share on X or LinkedIn
Brandon Barros
Brandon BarrosProduct Advocate

Brandon Barros is a Product Advocate at Mastra, helping teams scope, build, and ship AI agent systems.

All articles by Brandon Barros →