Quick Verdict: A HIPAA business associate agreement (BAA) and a GDPR data processing agreement (DPA) are different contracts for different legal regimes. A BAA addresses PHI handled for a covered entity or business associate. A DPA addresses personal data processed for a controller under GDPR. One document does not replace the other, and neither document proves that the GPU environment is isolated or HIPAA-ready by itself.
A BAA vs a GDPR DPA is a contract-instrument comparison for teams that host or process regulated AI data. Security questionnaires, SOC reports, and architecture diagrams are parallel evidence. They are not substitutes for the instrument that your counsel says the regime requires.
Privacy, security, and platform owners should map data classes before they ask a provider to “send the standard paper.” Prompt logs, fine-tune corpora, and RAG chunks can be PHI, personal data, both, or neither. This page compares the two instruments. It is not legal advice and it is not a BAA-scope encyclopedia.
What does each instrument actually do?
| Dimension |
HIPAA BAA |
GDPR DPA |
| Primary regime |
U.S. HIPAA when PHI is involved |
GDPR when personal data is processed |
| Typical parties |
Covered entity or business associate and a downstream associate |
Controller and processor, plus processor-to-subprocessor flow-down |
| Core job |
Permit and constrain PHI use, safeguards, breach notice, and return or destruction |
Set processing instructions, confidentiality, assistance, deletion, and audit rights |
| Does not prove |
That a GPU is single-tenant or that a model is clinically safe |
That U.S. hosting is lawful without a transfer mechanism, or that training is fair |
| When teams need it |
A vendor will create, receive, maintain, or transmit PHI for you |
A vendor will process personal data on your documented instructions |
If the same provider stores clinical notes for a U.S. health system and EU customer chat logs for a product team, counsel may require both instruments, plus a transfer story for the EU data. Do not let procurement collapse that into one PDF.
When is a BAA the wrong paper?

A BAA is the wrong paper when the dataset is not PHI and no HIPAA party is in the chain. Forcing a BAA onto a purely commercial EU workload wastes cycle time and still leaves the GDPR processor clauses unaddressed. It is also the wrong paper if you only need a vendor to host anonymized weights with no PHI in logs or prompts.
A BAA is also not a substitute for residency evidence. Signing one does not move GPUs on shore and does not freeze subprocessors. Ask where inference logs, checkpoints, and support copies live, then attach that map to the BAA packet.
Existing articles that explain BAA scope or whether a GPU host needs a BAA answer those narrower questions. Use them for coverage and trigger tests. Use this comparison when you must choose or sequence BAA and DPA work.
When is a DPA the wrong paper?
A DPA is the wrong paper when the only regulated class is PHI under HIPAA and GDPR does not apply to that processing. A DPA will not satisfy a covered entity that asked for a BAA. It also will not, by itself, authorize a restricted U.S. transfer. Transfer tools sit beside the DPA, not inside a marketing sentence.
Watch AI-specific gaps. Many template DPAs still talk like a SaaS ticketing tool. You need instructions for training versus inference, for human review of prompts, for model-improvement opt-out, and for deletion of vectors and checkpoints, not only of database rows.
How should AI teams sequence the work?
Classify the data path first: source system, prompt store, embedding index, training cache, and admin access. Mark each hop as PHI, personal data, both, or neither. Then assign instruments per hop and per vendor, including subprocessors that see logs.
Run contract review in parallel with technical isolation. Dedicated GPUs, U.S. residency, and access control make the paper believable. Paper without isolation is a future incident. Isolation without paper is a procurement fail. Healthcare AI infrastructure reviews should keep both tracks visible.
OneSource Cloud can be evaluated when you need U.S. private AI infrastructure for sensitive workloads. OneSource does not replace counsel, does not issue a blanket HIPAA certification, and does not publish a universal BAA-or-DPA product claim. Ask for the environment design and the contract path that match your data classes.
FAQ
Can a GDPR DPA replace a HIPAA BAA?
No. The regimes define different data classes, parties, and notice duties. If PHI is in scope for a HIPAA entity, counsel will look for a BAA or an equivalent HIPAA mechanism. A DPA may still be required for EU personal data on the same platform. Treat them as a pair when both classes exist, not as aliases.
Do we need a BAA if we only run inference?
Possibly. Inference prompts, retrieved chunks, and traces can be PHI even when you never fine-tune. The trigger is whether the vendor creates, receives, maintains, or transmits PHI for you, not whether the job type is training. Map the logs before you decide the paper is “training-only.”
What if the GPU provider lists many subprocessors?
The DPA path usually needs flow-down and a current list. The BAA path needs to know who can see PHI. Ask which subprocessors touch prompts, support copies, or backups. A long list is not automatically a fail. An undocumented list is.
Does a signed BAA mean the cluster is HIPAA compliant?
No. A BAA allocates duties. It does not prove encryption, access review, or clinical safety. Use HIPAA-ready language for infrastructure posture and keep shared-responsibility items explicit. Guaranteed HIPAA compliance is not a claim this page, or a hosting brochure, should make.
Who should own the comparison inside the company?
Counsel owns instrument selection. Security owns evidence. The AI platform owner owns the data-path map. Procurement should not pick “the vendor’s standard DPA” because it arrived first. The three roles meet on one worksheet: data class, instrument, evidence, residual risk.
Summary
A HIPAA BAA and a GDPR DPA are not interchangeable wrappers for “AI vendor legal.” Match the instrument to the regime and the data class. You may need both. Neither signature proves isolation, residency, or model quality. Sequence contract work with a hop-by-hop data map.
For U.S. dedicated environments that healthcare or other regulated teams want to evaluate alongside counsel’s paper, review healthcare AI and private AI infrastructure as architecture options, not as legal substitutes.