Hugging Face
Hugging Face
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Team/Enterprise and inference pricing varies; verify current order form
Enterprise Features
EU Hub storage for eligible organisations, EU-region dedicated endpoints, Enterprise DPA, SOC 2 Type II assurance
Last Updated
September 10, 2026
Reviewed on 10 September 2026 by WAIMAKERS B.V.
Purpose and context
Hugging Face is a platform with several materially different routes. The Hub, routed Inference Providers, dedicated Inference Endpoints and self-hosting cannot share one GDPR answer. A compliant deployment is possible, but only after the chosen storage, compute and provider chain is documented.
📊 Service route comparison
| Route | Documented handling | EU control | Practical assessment |
|---|---|---|---|
| Hub repositories, datasets and Spaces | Hugging Face stores the content and account data covered by its terms. | Team and Enterprise organisations can choose EU storage for supported Hub resources; other accounts use US storage. | Verify resource type, storage region, collaborators and whether a Space calls external services. |
| Routed Inference Providers | Hugging Face says it does not store routed request/response payloads and does not use them for training. Operational logs can be kept for up to 30 days without user data or tokens. The external provider's policy also applies. | Provider-dependent. | Review both Hugging Face and the named inference provider. |
| Dedicated Inference Endpoints | Hugging Face says payloads and authentication tokens are not stored; endpoint logs are retained for 30 days. | The customer selects an available cloud and region, including documented AWS Ireland availability. | Good control when the region, network mode, logging and model repository are configured correctly. |
| Self-hosted model or runtime | Hugging Face does not receive prompts merely because software or weights were downloaded. | Operator-controlled. | The operator owns security, licence, logging, lawful basis, deletion and model governance. |
✅ GDPR compliance assessment
For routed inference, Hugging Face's security documentation says requests and responses are not stored when Hugging Face routes them, and are not used for training. It also says the external provider's own security and data-use policy governs that provider's handling.[1] The pricing documentation confirms that this service sends requests to the selected provider, whether billing goes through Hugging Face or the customer supplies a provider key.[2]
For dedicated endpoints, Hugging Face says request payloads and tokens are not stored, while endpoint logs are kept for 30 days. Its documentation lists TLS, private-link options and an Enterprise DPA.[3]
🌍 Infrastructure, data residency and security
Hugging Face's privacy policy identifies a US company and says personal data may be processed in the United States and other countries with applicable safeguards.[4] Hub storage-region documentation says Team and Enterprise organisations can store supported repositories, datasets, Spaces and storage buckets in the EU or US; free and Pro storage remains in the US. A selected Hub storage region does not automatically set the processing region of an external inference provider.[5]
Hugging Face reports SOC 2 Type II assurance for Hub and Inference Endpoints and says Enterprise customers can execute a DPA. Obtain the report, DPA and exact product scope for procurement rather than treating a platform-wide badge as coverage for every third party.[6]
In May 2024 Hugging Face disclosed unauthorised access to its Spaces platform and said a subset of Spaces secrets may have been accessed. It revoked affected tokens and recommended key rotation. The notice does not establish that every Space or all chat data was exposed.[7]
EU business rollout checklist
- Name the exact route and every organisation that receives prompts, files, metadata or logs.
- For Hub storage, select the supported EU region on an eligible plan and verify the resource actually uses it.
- For routed inference, review the selected provider's DPA, region, training policy, retention and subprocessors.
- For dedicated endpoints, select the region and private networking, restrict repository access, and define deletion of the 30-day logs.
- Execute the applicable DPA and record transfer safeguards, access roles and incident procedures.
- Treat community models and Spaces as third-party code/content: inspect licences, cards, secrets, dependencies and outbound calls.
Current plan pages list Team and Enterprise features and prices, but prices and included usage change and do not prove a privacy property. Confirm the live order form.[8]
📋 Verdict summary
Hugging Face merits a deployment-specific review. EU Hub storage and EU-region dedicated endpoints are available on eligible routes, while free Hub content is US-stored and routed inference inherits the selected provider's terms. There is no platform-wide retention or training answer.
Disclaimer
This is an editorial procurement assessment, not a legal determination or legal advice.