GDPR check

Is ATLAS.ti GDPR compliant? What universities should check

ATLAS.ti is one of the most widely used tools for coding interviews and field notes, and its AI coding features have made DPOs and ethics boards look at it again. The answer differs for the desktop app, ATLAS.ti Web and the AI features. This page sets out what ATLAS.ti publicly documents about each and what a university should check before researchers use it with participant data.

Published 7 October 2026 · Sources checked 7 October 2026

Short answer

ATLAS.ti is published by ATLAS.ti Scientific Software Development GmbH in Berlin, now part of Lumivero's product portfolio. The desktop app keeps projects on the researcher's computer, and ATLAS.ti Web is documented as hosted on AWS in Frankfurt. Its public DPA expressly covers research participants and special category data, and its licence terms address the EU AI Act directly. The AI features (coding, summaries, conversational analysis, transcription) are opt-in and send content to OpenAI and Deepgram in the US under a no-training clause, with an AI Regions option for Europe whose scope a DPO should confirm.

Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers qualitative analysis of interviews with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data

What ATLAS.ti documents publicly

All sources were read on 7 October 2026. "Not found publicly" means we did not find it in the sources listed at the end of this page; it does not mean the safeguard does not exist.

TopicWhat the vendor statesSource
Company and establishmentDocumented ATLAS.ti Scientific Software Development GmbH, Berlin, Germany, is the controller for account data. The external data protection officer is Compliance.One GmbH. ATLAS.ti appears as a product on Lumivero's website and in Lumivero's trust centre.[1] [2] [8]
Products and where data sitsProduct-dependent ATLAS.ti Desktop runs locally; online updates send an encrypted serial number, version and seat count. ATLAS.ti Web is "hosted with Amazon Web Services in Germany" (Frankfurt) through two German service providers, and data processed as a processor "is processed in the EU only". The white paper stating this is dated August 2023.[1] [4]
Data processing agreementDocumented Public DPA (07 July 2026) under Article 28 GDPR, incorporated by the licence terms and governed by German law. Appendix 1 names "research participants or interviewees" and special categories including medical, genetic and biometric data. It states that voice recordings are used for transcription only, with "no speaker identification and no biometric analysis".[3] [5]
SubprocessorsPartly documented The DPA names OpenAI LLC (generative AI analysis) and Deepgram, Inc. (transcription), both in the US, "and/or other AI provider". The privacy policy names further providers, including mailjet (Germany) for system mails and Mixpanel (US) for usage analysis based on consent. Not found publicly A single consolidated subprocessor list.[1] [3] [4]
International transfersDocumented Transfers to AI sub-processors rely on the Standard Contractual Clauses, with the EU-U.S. Data Privacy Framework as an alternative where a sub-processor is certified. ATLAS.ti itself is an EU company, so DPF certification of ATLAS.ti is not relevant; whether each AI sub-processor is certified should be confirmed with ATLAS.ti.[3]
AI features and regionsOpt-in AI coding, code suggestions, summaries, conversational document analysis and transcription. AI features are used only "upon your request through an opt-in or other sign-up process". An AI Regions setting lets users choose "the United States or Europe" for AI processing.[4] [5]
AI model trainingDocumented Neither ATLAS.ti nor its AI sub-processors "use such content to train, retrain or improve artificial intelligence models". AI sub-processors keep content only temporarily, for service delivery and abuse detection; ATLAS.ti will state the current retention periods on request.[3]
Retention and deletionDocumented ATLAS.ti Web data is blocked when a contract ends or an account is deleted and erased three months later, unless immediate deletion is requested. Under the DPA, data is returned or deleted at the end of the contract, with proof on request.[1] [3]
SecurityPartly documented AES-256 encryption at rest and TLS in transit; hosting providers with ISO 27001 and ISO 27018 certifications. Lumivero's trust centre offers a HECVAT and a CAIQ for ATLAS.ti. Not found publicly An ISO 27001 certificate or SOC 2 report specific to ATLAS.ti itself.[4] [8]

ATLAS.ti deserves credit for several things DPOs and ethics boards look for: an EU-based controller, EU hosting for the web app, a DPA written with research participants in mind, a contractual no-training clause that extends to its AI sub-processors, an explicit opt-in for AI features, a choice of AI region, and licence terms that set out provider and deployer roles under the AI Act.

What this means for research with participants

Validemic's analysis

Interview data is usually sensitive. Transcripts and field notes often contain special category data under Article 9(1) GDPR, such as health, religion or sexual orientation [6]. Universities usually rely on Article 9(2)(j) for research, with Article 89 safeguards such as pseudonymisation [6], and ethics approvals describe where data will be stored. ATLAS.ti offers three quite different answers to that question.

Desktop, Web and AI are three processing set-ups. A local desktop project keeps content on university equipment; on our reading of the privacy policy, only licence, update, crash and optional usage data reach ATLAS.ti. ATLAS.ti Web places the project with a German processor on AWS in Frankfurt under the DPA, which suits most EU institutions' storage rules. AI features add a third step: selected content goes to OpenAI or Deepgram, which the DPA locates in the US. That last step is the one most likely to need explicit mention in participant information sheets and ethics applications.

The AI Regions setting needs a precise answer. The AI page says users can choose Europe for AI processing, while the DPA names US entities as sub-processors and relies on the Standard Contractual Clauses. Both can be true if the European option processes data in EU data centres under a US provider's contract. A DPO should ask exactly which data stays in the EU when Europe is selected, including logs and abuse-monitoring copies, and whether an institution can enforce the setting for all users.

One older FAQ answer should be clarified. The AI data security page, dated August 2023 in the Legal Center, includes an answer on human review that mentions fine-tuning on user-submitted data "unless you have opted out". This appears to describe OpenAI's general practice rather than ATLAS.ti's arrangement, and it conflicts with the no-training clause in the 2026 DPA. The DPA is the contractual document, but asking ATLAS.ti to update the FAQ is reasonable.

Transcription and voice data. The DPA's statement that voice recordings are not used for speaker identification or biometric analysis is useful, because biometric data processed to identify a person is a special category under Article 9 [6]. Deepgram as a US transcription sub-processor still needs to be covered in the transfer assessment.

The MCP server route. Lumivero describes an ATLAS.ti MCP server that connects tools such as Claude Desktop to a project and runs locally [8]. The connection is local, but the AI assistant the researcher connects will process project content under that assistant's own terms, which the ATLAS.ti DPA does not cover.

DPIA likelihood. Using AI features on special category interview data with a US sub-processor will often meet the criteria for a DPIA under Article 35 GDPR [6]. Our DPIA screening tool gives a first view. Desktop-only use without AI is usually a much smaller assessment.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

Questions to ask ATLAS.ti before approving AI features

  1. When the Europe AI Region is selected, where are prompts, outputs and abuse-monitoring copies processed and stored, and by which legal entity?
  2. Can a campus or multi-user licence administrator enforce the Europe AI Region, or disable AI features, for all users?
  3. What are the current retention periods at OpenAI and Deepgram for content from ATLAS.ti, and is zero data retention available?
  4. Can you provide a complete, current subprocessor list for ATLAS.ti Web and the AI features, with notification of changes?
  5. Is the August 2023 white paper still accurate for ATLAS.ti Web hosting, and which German providers operate it?
  6. Will you update the AI FAQ answer about fine-tuning to match the no-training clause in the DPA?
  7. Does ATLAS.ti, as distinct from its hosting providers, hold an ISO 27001 certificate or SOC 2 report?
  8. Does the Lumivero group DPA or the ATLAS.ti DPA apply to our licence, and which takes precedence?
  9. Is telemetry for the desktop app consent-based for all users, and can an institution turn it off centrally?

The EU AI Act angle

ATLAS.ti's licence terms are unusually explicit on the AI Act, Regulation (EU) 2024/1689. They say ATLAS.ti is the provider of the AI features under Article 3(3), the customer is the deployer under Article 3(4), and the intended purpose is to assist trained users with qualitative analysis "subject to full human review" [5]. The terms prohibit use for practices banned under Article 5, and require prior written agreement before the features are used in a high-risk system under Annex III, for example "the evaluation of learning outcomes or examination conduct" [5]. Coding research interviews is not one of the Annex III education uses [7].

Under Article 4, deployers must take measures to support the AI literacy of staff using AI on their behalf. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, reworded that duty, and it moved the application date of the Annex III high-risk obligations to 2 December 2027 [9]. The DPA also commits ATLAS.ti to give customers the information they need for their own AI Act transparency obligations [3]. For researchers, the practical step is to record which AI features were used and how outputs were reviewed in the methods section.

Sources

  1. ATLAS.ti, Privacy Policy (effective 7 July 2026), retrieved 7 October 2026
  2. ATLAS.ti, Imprint (effective 25 December 2025), retrieved 7 October 2026
  3. ATLAS.ti, Data Processing Agreement (Legal Center date 07.07.2026), retrieved 7 October 2026
  4. ATLAS.ti, White Paper Data Security and Privacy Compliance (Legal Center date 14.08.2023), and AI Data Security and Privacy at ATLAS.ti, retrieved 7 October 2026
  5. ATLAS.ti, Licensing Conditions and Terms of Use (EULA), last modified 7 July 2026, section 11, retrieved 7 October 2026
  6. Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4(14), 9, 28, 35 and 89, retrieved 7 October 2026
  7. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3, 4, 5 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
  8. Lumivero Trust and Compliance Center, and Lumivero, Official Information About Lumivero, retrieved 7 October 2026
  9. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026

About this page

We read ATLAS.ti's privacy policy, imprint, DPA, licence terms, data security white paper and AI data security page, Lumivero's trust centre listing and AI information page, and searched the official Data Privacy Framework list, all on 7 October 2026. We did not download the Legal Center archive or the trust centre questionnaires. "Not found" means we could not find the information in public documentation; it does not mean ATLAS.ti lacks it. Products, terms and features change, so confirm the current position with ATLAS.ti before relying on it.

This page describes public documentation and gives our own analysis. It is not legal advice and it is not a statement that the tool is or is not GDPR compliant, which depends on your contract, configuration and use. If you work at ATLAS.ti or Lumivero and see an error, please contact us and we will correct it.

Frequently asked questions

Where does ATLAS.ti store my data?

ATLAS.ti Desktop projects are stored on your own computer. For ATLAS.ti Web, ATLAS.ti's data security white paper (August 2023) says the service is hosted with Amazon Web Services in Frankfurt, Germany, and that data it processes as a processor stays in the EU. The AI features are an exception: they use OpenAI and Deepgram, which the DPA locates in the United States.

Does ATLAS.ti send interview data to OpenAI?

Only if AI features are used. ATLAS.ti says its AI features are opt-in and use OpenAI's GPT models through the API, and transcription uses Deepgram. Its DPA (07 July 2026) says neither ATLAS.ti nor its AI sub-processors may use the content to train AI models, and that AI sub-processors keep content only temporarily.

Does ATLAS.ti have a data processing agreement?

Yes. ATLAS.ti publishes a Data Processing Agreement under Article 28 GDPR, governed by German law and incorporated into its licence terms. Its description of processing expressly covers research participants, interviewees and special category data such as health and genetic data.

Can I choose EU processing for ATLAS.ti AI features?

ATLAS.ti's AI data security page describes an AI Regions feature that lets users choose the United States or Europe for AI processing. The DPA still names OpenAI LLC and Deepgram, Inc. in the US as sub-processors, so ask ATLAS.ti what the Europe setting covers.

Who owns ATLAS.ti?

The legal entity is ATLAS.ti Scientific Software Development GmbH in Berlin. ATLAS.ti is listed as a product of Lumivero on Lumivero's website and trust centre, which also hosts ATLAS.ti's HECVAT and CAIQ questionnaires.