Grok (SpaceXAI)
SpaceXAI
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Business/Enterprise and API pricing varies; verify current order form
Enterprise Features
DPA with SCCs, business/API no-training, ZDR, custom retention, regional processing/data-residency options, SOC 2 Type II assurance
Last Updated
September 10, 2026
Reviewed on 10 September 2026 by WAIMAKERS B.V.
🚨 Executive summary
Grok has distinct consumer, X-platform, API and enterprise routes. SpaceXAI's current business documentation now offers controls that older “US-only/no DPA” descriptions miss: a DPA with SCCs, no-training commitments for business/API data, Zero Data Retention for eligible API use, and enterprise regional-processing/data-residency options. The exact EU region and feature coverage still need contractual confirmation.
Comparison of Grok offerings (EU focus)
| Route | Training and retention | Practical assessment |
|---|---|---|
| Grok consumer service | SpaceXAI may use content and interactions for training. Users can opt out; Private Chat is excluded from training. Deleted chats and Private Chat are generally deleted within 30 days, subject to stated exceptions. | Do not approve for confidential organisational data. |
| Grok on X | Governed by X's terms and privacy policy, not automatically by SpaceXAI's business terms. | Assess X separately, including its training controls and regulatory proceedings. |
| xAI API standard retention | API inputs/outputs are not used for training without explicit permission. Encrypted request/response data is retained for 30 days for audit by default. | Viable only after the DPA, region, stateful features and deletion are confirmed. |
| xAI API with ZDR | SpaceXAI says covered request/response data is not retained. ZDR is team-wide and disables incompatible stateful features. | Stronger privacy route; verify activation and endpoint/feature coverage. |
| Enterprise | No training is advertised, with custom retention and regional processing/data-residency controls. | Conditional business route; name the actual region and commitment in the order form. |
Is Grok GDPR-compliant?
SpaceXAI's privacy policy, effective 24 August 2026, identifies SpaceXAI LLC as the operator and states that X Corp is separate and X use is governed by X's policies. It says consumer content may be used to improve and train models and gives Europe-specific rights and representatives.[1]
Its consumer FAQ says users can opt out of training and use Private Chat, while submitted feedback can be a separate training case. It says business and enterprise data is not used for training. Deletion is generally completed within 30 days, subject to security, legal and de-identification exceptions.[2]
Consumer, business and API controls
The xAI API security page says API data is not used for training without explicit permission, is encrypted, and is retained for 30 days for audit by default. It documents team-wide ZDR and says ZDR prevents use of stateful features. SpaceXAI also reports SOC 2 Type II assurance for its enterprise platform; obtain the report and scope.[3]
The current DPA covers SpaceXAI acting as processor, incorporates the EU Standard Contractual Clauses, addresses subprocessors and contains deletion/security provisions. Contract documents and the configured service determine whether it applies.[4]
The xAI API page advertises enterprise data residency and regional-processing options, but its public wording does not itself identify an EU region for every product or feature. Record the region, backup/support access and exclusions in the order form.[5]
Regulatory evidence involving X
The Irish Data Protection Commission opened an inquiry in April 2025 into X's use of public EU/EEA posts to train Grok.[6] In February 2026 it opened a separate inquiry into X's processing connected with Grok-generated sexualised images, including images of children.[7]
These notices describe investigations into X; they are not final GDPR judgments on every SpaceXAI API or Enterprise deployment. The European Commission's DSA investigation into X is also a different legal regime from GDPR.[8]
Recommendations and EU rollout checklist
- ✅ Separate consumer Grok, Grok on X, API and Enterprise in policy and technical controls.
- ✅ Execute the DPA and verify SCC module, subprocessors and controller/processor roles.
- ✅ Contract the exact EU/EEA processing and storage region, including backups and support.
- ✅ Enable and test ZDR where stateful features are not required; otherwise define the 30-day or custom retention route.
- ✅ Disable training and control feedback channels.
- ✅ Restrict sensitive data and monitor outputs, abuse controls and human review.
Prices, model names, context windows and product bundles change and do not determine GDPR compliance. Confirm them in the current order form.[9]
Verdict summary
Grok/SpaceXAI merits a deployment-specific review, not a provider-wide rejection. Enterprise and API routes publish meaningful privacy controls, while the consumer and X routes have different training terms and regulatory exposure. Regional processing is advertised, but exact EU residency remains a contract question.
Disclaimer
This is an editorial procurement assessment, not a legal determination or legal advice.