n8n
n8n
Assessment labels are editorial guidance, not GDPR certifications. Validate the exact plan, lawful basis, DPA, subprocessors, retention, residency and feature settings. EU storage and no-training terms alone do not establish GDPR compliance. ¹ No training applies under the reviewed plan’s terms.
Pricing / Contract Route
Starter EUR20/month and Pro EUR50/month billed annually; self-hosted Business EUR667/month billed annually; Enterprise custom
Enterprise Features
EU-hosted Cloud, customer-selected self-hosting, DPA/SCC route, SSO/SAML, LDAP, Git version control, audit and security controls
Last Updated
September 10, 2026
Reviewed: 10 September 2026 - prepared by WAIMAKERS B.V.
1 Purpose
Conditional business route. n8n can support a GDPR-compliant workflow, but the product itself is not a blanket compliance outcome. The customer must establish a lawful basis, configure retention and access, assess every connected service, and document any international transfers.
n8n GmbH is based in Berlin. n8n Cloud is hosted on Microsoft Azure and its public pricing page says hosted-plan data is stored in Frankfurt, Germany. The current subprocessor list also identifies EU processing in Germany and Sweden, while optional AI providers can process in the EU or US. A self-hosted installation follows the infrastructure and integrations chosen by the customer.
2 Comparison of n8n Deployment Options (EU focus)
| Option | Hosting and control | Customer-content training | Contract and assurance | Public price at review date |
|---|---|---|---|---|
| Community Edition | Self-hosted; customer chooses location and operates security, backups and retention | n8n Cloud does not receive workflow content merely because the software is self-hosted; telemetry is a separate, configurable flow | Sustainable Use License; no managed-service assurance for the customer's environment | Free software; infrastructure and operations are extra |
| Cloud Starter | n8n-hosted in the EU; 1 shared project and 5 concurrent executions | Current Cloud and AI terms say Customer Content and AI Output are not used to train ML models | DPA applies under the Self-Serve Terms; SOC 2 report is restricted and SOC 3 is public | €20/month billed annually for 2,500 executions; check monthly price at purchase |
| Cloud Pro | n8n-hosted in the EU; 3 shared projects and 20 concurrent executions | Same contractual no-training commitment | Same DPA and cloud-security framework | €50/month billed annually for 10,000 executions; check monthly price at purchase |
| Business | Currently advertised as self-hosted | Same AI Terms; customer-selected LLMs have their own terms | SSO/SAML/LDAP, environments and Git version control; forum support | €667/month billed annually for 40,000 executions |
| Enterprise | n8n-hosted or self-hosted | Same AI Terms, subject to configured third-party services | Custom DPA/order, dedicated support/SLA, external secrets, log streaming and extended retention | Custom |
Prices exclude any customer infrastructure and may exclude tax. n8n bills by complete workflow executions and can change limits or prices.
3 Is n8n GDPR-Compliant?
Data use, AI and retention
- ✅ The current n8n AI Terms state that n8n will not use Customer Content or Output to train ML models and will not retain Customer Content beyond what is required to process an AI feature and return its output.
- ⚠️ The same AI Terms permit aggregated and de-identified usage data and prompts to be used to improve AI services. The general Cloud terms also permit Usage Data and de-identified datasets derived from Customer Content for service improvement. This is narrower than raw-content training, but it means “no use of any customer data” would be inaccurate.
- ⚠️ A customer that configures a third-party LLM instructs n8n to transmit data to that provider. Its location, retention and training policy must be reviewed separately. n8n's current subprocessor list includes AI providers with EU and US processing locations.
- ⚠️ Cloud execution history is retained according to plan limits and account retention settings. The current Self-Serve Terms say remaining Customer Content is usually deleted six months after account deactivation, subject to legal, accounting or regulatory retention.
- ⚠️ Self-hosted execution retention can be configured, but the operator remains responsible for pruning, encryption at rest, TLS, backups, access control and deletion. n8n's own telemetry can be disabled; connected nodes can still send data externally.
The earlier statement that AI context is always deleted after exactly 30 days is not used here: the current July 2026 AI Terms provide a processing-necessity rule instead, and provider-specific terms can differ.
Security and location
n8n says its Cloud service encrypts traffic in transit and uses Azure Storage server-side AES-256 encryption at rest. Its security programme aligns with SOC 2, undergoes annual independent audits, and offers a SOC 2 report to Enterprise customers and a public SOC 3 report. These controls support a risk assessment; they do not certify the customer's workflows as GDPR-compliant.
EU hosting does not mean every workflow remains in the EU. Data can leave the selected n8n environment through integrations, webhooks, support processes, affiliates or optional AI features. Where Chapter V GDPR applies, identify the actual transfer mechanism in the DPA/subprocessor record and assess whether supplementary measures are needed.
4 EU Rollout Checklist (Practical)
- Map the personal data, purpose, lawful basis, data subjects and every destination node.
- Choose Cloud or self-hosting from documented residency, security and operating requirements.
- Execute and archive the applicable DPA; record current subprocessors and transfer mechanisms.
- Configure the shortest workable execution-history retention and deletion process.
- For self-hosting, configure TLS, encryption at rest, secrets management, patching, backups and telemetry preferences.
- Restrict roles and credentials; use Business or Enterprise where SSO, environments or central governance are required.
- Review each AI model and integration separately. Do not assume n8n's commitments extend to a customer-selected provider.
- Complete a DPIA where the planned processing is likely to create a high risk, and keep the Article 30 record current where applicable.
5 Notes & Caveats
Open procurement questions
- Obtain the executed DPA and current annexes rather than relying on the public landing page alone.
- Confirm the exact Cloud retention limits for the purchased plan and the deletion path for backups and support data.
- Confirm processing locations for every optional AI feature and selected LLM.
- Ask for the current SOC 2 report if the assurance scope matters; the public site does not establish ISO 27001 certification.
- Confirm whether an air-gapped design is compatible with licensing checks and any enabled enterprise features.
6 References
- n8n pricing and hosted-data location
- n8n Self-Serve Terms
- n8n AI Terms
- n8n Data Processing Agreement
- n8n subprocessors
- n8n security
- n8n privacy documentation
- GDPR, official text
- EDPB recommendations on supplementary transfer measures
7 Disclaimer
This page is a practical procurement and data-risk overview, not legal advice. Suitability depends on the signed terms, deployment, configuration, connected services, data categories and the customer's own GDPR assessment.