Is Consensus GDPR compliant? What universities should check
Consensus is an AI search engine that answers questions from peer-reviewed papers. Libraries and research offices are often asked whether staff and students may use it. This page sets out what Consensus publishes about data protection, what is missing, and what to ask before you approve it.
Short answer
Consensus is run by Consensus NLP, Inc., a US company, and its privacy policy says all its servers are in the United States. It offers Free, Pro and Deep plans for individuals, plus Teams, Enterprise and sitewide library licences for institutions. A real strength is a plain, plan-wide commitment that user content is never used to train AI models, by Consensus or by the AI providers it uses (OpenAI, Anthropic, Google and Baseten). We found no public DPA, subprocessor list, security certification or GDPR transfer mechanism. Whether you can use it depends on what Consensus will put in an institutional contract and on what personal data your users would enter.
Prefer a tool built in the EU? Kahubi, from Avidemic AB in Sweden, covers AI research assistance with EU hosting and, for institutions, only European subprocessors. See how Kahubi handles research data
What Consensus documents publicly
All sources were read on 7 October 2026. "Not found publicly" means we looked in the places listed under Sources and did not find it; it does not mean the safeguard does not exist.
| Topic | What the vendor states | Source |
|---|---|---|
| Company and establishment | Documented Consensus NLP, Inc., headquartered in the United States; the terms are governed by Delaware law. Privacy contact: privacy@consensus.app. Not found publicly An EU representative under GDPR Article 27 or a named DPO. | [1], [2] |
| Where data is stored and processed | Documented The privacy policy says "all our servers are located in the United States". The cloud provider is not named. No EU hosting option found. | [1] |
| Data processing agreement | Not found publicly No public or self-serve DPA. The help centre says Consensus is "prepared to document any specific handling requirements" for organisations in the contract. | [1], [3] |
| Subprocessors | Partly documented No public subprocessor list. The privacy policy names the AI model operators: OpenAI, Anthropic, Google and Baseten. They receive queries, conversation history, paper content and the text of uploaded documents, but not the user's name, email or account identifier. They "may apply their own automated safety checks and retain content briefly under their own terms". Voice dictation audio is sent to OpenAI for transcription. | [1] |
| International transfers | Not found publicly The policy relies on the user's consent to storage and processing in the United States. It does not mention Standard Contractual Clauses or the EU-US Data Privacy Framework. On the official DPF list we found no entry for Consensus NLP, Inc. (the only "Consensus" match is an unrelated company in Atlanta). | [1], [9] |
| AI model training on customer content | Documented "Your queries, content, and personal information are never used to train AI models", neither Consensus's own nor any third party's. No plan distinction is made. The terms grant Consensus a broad licence to user materials but state it is not intended to conflict with the privacy policy. | [1], [2], [7] |
| Retention and deletion | Partly documented Data is kept "for as long as it is reasonably necessary for a legitimate business purpose"; no fixed periods. Users can clear thread history, delete their account and search in incognito mode. For organisations, Consensus says it can flag and immediately delete searches by the organisation's users, and offers a paid custom option with separate or no query logging. | [1], [3], [6] |
| Security certifications | Not found publicly No ISO 27001 or SOC 2 claim on consensus.app or its help centre. The policy says data is encrypted in transit and at rest. Note: certifications listed online for "Consensus" often belong to goconsensus.com, a different company. | [1], [3] |
| Institution and enterprise controls | Plan-dependent Teams (up to 200 seats) adds seat and user management and central billing; Enterprise (over 200 users) adds library integrations. Sitewide library licences authorise all university email domains and give partners quarterly usage reports (accounts, searches per user, papers clicked and saved). SSO or SAML: not found publicly. | [4], [5], [6] |
What this means for a university
Validemic's analysis
What personal data is involved. Most Consensus use is a researcher typing a question about published literature. The papers themselves are rarely personal data. The account (name, email, payment details), search history and usage reports are personal data, and the questions can be too: a clinician asking about a rare condition in a named setting, or a student pasting a draft, puts more into the prompt than a literature query needs. The upload feature is the bigger point. Consensus's own help article suggests uploading "dissertations, clinical protocols, private research reports", and the privacy policy says the text of uploaded documents goes to the AI model operators. Interview transcripts, patient material or unpublished student work should not go in without an institutional agreement.
Controller or processor. For an individual on a Free or Pro account, Consensus acts as its own controller under its privacy policy. If the university licenses Consensus for staff or students, the university is likely to be the controller for that use and needs a processor agreement under GDPR Article 28. Because no public DPA exists, that has to be negotiated; the help centre's offer to document handling requirements in the contract is the starting point.
Transfers. All servers are in the US and the model operators are US companies. The public policy relies on consent, which is generally a weak basis for routine transfers in an employment or teaching relationship. An institution would normally expect SCCs or DPF certification in the contract, plus information on the onward transfers to OpenAI, Anthropic, Google and Baseten.
DPIA. A short screening is sensible for any AI tool. A full DPIA becomes more likely if staff or students would upload unpublished or sensitive material, or if the library would receive per-user search reports, which can amount to monitoring of reading behaviour.
Which plan. The no-training commitment covers every plan, which is helpful. The contractual safeguards (DPA, deletion on request, logging options) appear only through Teams, Enterprise or a sitewide licence. Staff use on personal Free or Pro accounts leaves the university without those safeguards.
Students. The terms allow users from age 13, with parental consent below the age of majority. For a licence that covers students, check how the domain-based sign-up works, what the usage reports show about individual students, and whether students are told about them.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
Questions to ask Consensus before approving it
- Will you sign a data processing agreement under GDPR Article 28 for our Teams, Enterprise or sitewide licence? Please share the template.
- What is the transfer mechanism for EU personal data (SCCs, DPF certification of Consensus NLP, Inc., or another)? Does it cover the onward transfers to OpenAI, Anthropic, Google and Baseten?
- Can you provide a full subprocessor list, with locations, and notify us of changes?
- What do OpenAI, Anthropic, Google and Baseten retain, and for how long? Do you have zero data retention terms with any of them?
- Do you hold, or plan, an independent security attestation such as SOC 2 Type II or ISO 27001? If not, can you complete a security questionnaire?
- What are the concrete retention periods for search history, uploaded documents and account data, including backups?
- What exactly do the library usage reports contain, at what level of detail, and can they be aggregated or switched off?
- Do you support SSO (SAML, or eduGAIN through our national research and education federation)?
- Your help centre security article says you do not collect personally identifiable information, while the current privacy policy lists name, email and payment data. Which applies to institutional accounts?
- Who is your EU representative under GDPR Article 27, and who handles data subject requests from EU users?
The EU AI Act angle
Using Consensus to search and summarise literature is normally not a high-risk use under the AI Act, Regulation (EU) 2024/1689. Annex III, point 3 lists the education uses that are high-risk: AI used to decide admission or access, to evaluate learning outcomes, to assess the level of education a person will receive, or to monitor students for prohibited behaviour during tests. Using any tool for those purposes would change the assessment.
A university that uses an AI system under its authority is a deployer (Article 3(4)). Article 4 on AI literacy has applied since 2 February 2025. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, replaced that article: deployers must now "take measures to support the development of AI literacy" of their staff and others using AI on their behalf, without having to guarantee a specific level for each person. The same regulation moved the application date for Annex III high-risk obligations to 2 December 2027.
Obligations for general-purpose AI models (Article 53, applying since 2 August 2025) fall on the model providers, such as the companies whose models Consensus uses, not on the university.
Sources
- Consensus, Privacy Policy (dated 18 August 2026), retrieved 7 October 2026
- Consensus, Terms of Service (last updated 25 June 2025), retrieved 7 October 2026
- Consensus Help Center, "Security", retrieved 7 October 2026
- Consensus Help Center, "Subscription Plans", retrieved 7 October 2026
- Consensus, "Consensus for University Libraries", retrieved 7 October 2026
- Consensus Help Center, "Account Settings", retrieved 7 October 2026
- Consensus, "For Research Organizations", retrieved 7 October 2026
- Consensus Help Center, "How to Upload and Chat With Documents", retrieved 7 October 2026
- Data Privacy Framework List (searched for "Consensus" and "Consensus NLP", active and inactive participants, via the list's search service), retrieved 7 October 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 3(4), 4, 53, 113 and Annex III, Official Journal text read via the Publications Office, retrieved 7 October 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal text read via the Publications Office, retrieved 7 October 2026
About this page
We read Consensus's privacy policy, terms, help centre and institutional pages, and searched the official Data Privacy Framework list, on 7 October 2026. We also checked for a trust centre, DPA and subprocessor page at the usual addresses and found none. This page describes public documentation only. It is not legal advice and not a verdict on whether Consensus complies with the GDPR; that depends on your contract and your use. Vendors change their documents often, so check the sources before relying on them.
If you work at Consensus and something here is out of date or incomplete, please contact us and we will review it promptly.
Frequently asked questions
Does Consensus train AI models on my data?
Its privacy policy (dated 18 August 2026) says queries, content and personal information are never used to train AI models, neither Consensus's own nor any third party's. The policy presents this as applying to all users, with no plan distinction.
Where does Consensus store data?
The privacy policy says all Consensus servers are located in the United States. We found no EU hosting option in its public documentation (checked 7 October 2026).
Does Consensus sign a data processing agreement (DPA)?
We found no public DPA. Consensus's help centre says it is prepared to document specific handling requirements for organisations in the contract, so an institution should ask for a DPA during procurement.
Which AI providers does Consensus use?
The privacy policy names models operated by OpenAI, Anthropic, Google and Baseten. It says these providers receive queries, conversation history, paper content and the text of uploaded documents, without the user's name, email address or account identifier.
Can students use Consensus under GDPR?
The terms set a minimum age of 13, with parental consent below the age of majority. Whether a university can recommend or license it for students depends on a DPA, the transfer basis and the data students would enter, which the institution should settle first.