Loading the catalogue…
Loading the catalogue…
Databricks is a privately-held, US-incorporated data and AI platform company with substantial EU R&D and sales presence (Amsterdam, London EMEA HQ). It offers mature enterprise security and privacy tooling (ISO 27001/27017/27018, SOC 2 Type II, GDPR DPA with 2021 SCCs) but, as a US entity, remains subject to the CLOUD Act and FISA 702. Its open-weights models (DBRX, MPT) carry a custom, non-OSI licence with usage restrictions, and Databricks is currently defending an active copyright class action over training data used in both model families.
Active federal class-action lawsuit alleging Databricks' DBRX and MosaicML/MPT foundation models were trained on approximately 196,000 pirated copyrighted books; a motion to dismiss the DBRX claims was denied in April 2026, so litigation and potential damages exposure is ongoing.
Databricks is a US-incorporated, California-headquartered company and therefore subject to US CLOUD Act and FISA 702 government access mechanisms regardless of where EU customer data is contractually processed.
No public evidence that Databricks has signed the EU GPAI Code of Practice, unlike several peer model providers (OpenAI, Anthropic, Google, Microsoft, Amazon, Mistral, Aleph Alpha, IBM).
Full SOC 2 Type II report, ISO certificates, and annual pen-test confirmation letters are gated behind an account-team due-diligence package rather than being publicly downloadable in full.
Stav’s assessment
Editorial assessment, not legal advice. Stav's risk ratings, scores, and verdicts are our own analysis of publicly available information and may be incomplete or out of date. Verify independently before making compliance or procurement decisions.
Documented, multi-framework security program (ISO 27001/27017/27018, SOC 2 Type II, PCI-DSS, HIPAA BAA support) aligned to NIST 800-53, plus a formal vulnerability response and disclosure program following RFC 9116 / ISO 29147 / ISO 30111.
Published, downloadable Data Processing Addendum incorporating the 2021 EU Standard Contractual Clauses, plus a dedicated transfer-impact-assessment FAQ addressing Schrems II/EDPB recommendations, UK and Swiss data transfers.
Publishes model cards, a technical blog post, and an Acceptable Use Policy for its DBRX foundation models, documenting training data scale, architecture, and known risks.
Continued, growing EU investment: Amsterdam is described as Databricks' largest R&D centre in EMEA, and the company is establishing a new, larger London EMEA headquarters.
Published safeguards & certifications