Using AI in a business is not new territory from a GDPR standpoint; most requirements are the same as for any other data processing. This checklist maps out what matters in practice when phone AI, a chatbot or agents process personal data.

Data processing agreements (DPAs)

Every provider whose infrastructure processes personal data needs a data processing agreement under Art. 28 GDPR: this applies to the language model used just as much as to hosting, voice synthesis or the automation platform. Check before deploying each tool whether a DPA is in place, not afterward.

Ensuring EU processing

Where possible, personal data processing should take place in the EU. Many AI providers now offer EU data centers; that’s standard, not a special request, and should be explicitly guaranteed by contract, not just advertised.

Processing customer data via an AI phone assistant or chatbot needs a legal basis, usually performance of a (pre-)contractual relationship (Art. 6(1)(b) GDPR) or a legitimate interest. Document which basis applies to which use case.

Setting up Art. 15 and Art. 17 processes

Data subjects have a right to access (Art. 15) and erasure (Art. 17). Your AI system should be able to represent both technically: on request it must be possible to trace which data is stored about a person, and deletion must happen completely and with a log, not just “removed from the interface”.

Logging

Every answer an AI gives on behalf of your company should be logged: who (which system), what, when, from which source. This serves not only traceability in the event of complaints but also proof of accountability under Art. 5(2) GDPR.

Defining retention periods

Set out how long transcripts, chat histories and logs are stored, and make sure deletion afterward happens automatically, not manually and not “whenever someone remembers”.

Staff training

The biggest practical risk is rarely the official AI system, but the informal use alongside it: employees copying customer data into a private chat tool because it’s faster. A clear, short internal policy (which tools are allowed, what data must not go into them) plus a one-time training session noticeably lowers this risk.

EU AI Act: transparency duties (as of July 2026)

The EU AI Act requires transparency for chatbots and voice AI in customer contact: users must be able to recognize at the start of the interaction that they’re talking to an AI system, not a human. This applies to text chatbots on the website as much as to voice assistants on the phone. This disclosure requirement should be firmly built into the conversation script or the first chat prompt, not added later as a disclaimer somewhere in the fine print.

Checklist to work through

ItemDone?
DPA in place with every AI provider involved
Processing demonstrably in the EU
Legal basis documented per use case
Access process (Art. 15) technically implemented
Deletion process (Art. 17) technically implemented, with a log
Logging of every AI answer active
Retention periods defined and automated
Staff trained on allowed/forbidden AI tools
AI disclosure to customers at the start of the conversation (EU AI Act)

This checklist doesn’t replace legal advice for your specific case, but it gives you a practical starting point for the conversation with your data protection officer or lawyer. At meine-bots, every one of these points is built firmly into the architecture of the AI operating system, not bolted on afterward.