"Fable 5 / Opus 4.8 / GPT are stronger, but they run in someone else's cloud, so we cannot use them" is a common conclusion, and it is wrong for two reasons. First, GDPR regulates neither the workflow nor the model, but personal data - those that identify a person.
A foreign model and GDPR are not an either-or choice
Most of the text you send to an LLM does not contain personal data. Second: between "everything in a foreign cloud as-is"
between "everything on your own hardware" there is an intermediate setup - a privacy gateway that anonymizes data before sending and restores it in the response. GPU for self-hosted inference is the most expensive and latest step, not the first. Start with what is cheaper and faster: a privacy gateway in front of a foreign model or CIS cloud. Buy hardware only if the setup truly requires it - and that decision should be calculated in the calculator for your configuration, not guessed.



