Using AI in a business is not new territory from a GDPR standpoint; most requirements are the same as for any other data processing. This checklist maps out what matters in practice when phone AI, a chatbot or agents process personal data.
Data processing agreements (DPAs)
Every provider whose infrastructure processes personal data needs a data processing agreement under Art. 28 GDPR: this applies to the language model used just as much as to hosting, voice synthesis or the automation platform. Check before deploying each tool whether a DPA is in place, not afterward.
Ensuring EU processing
Where possible, personal data processing should take place in the EU. Many AI providers now offer EU data centers; that’s standard, not a special request, and should be explicitly guaranteed by contract, not just advertised.
Clarifying the legal basis
Processing customer data via an AI phone assistant or chatbot needs a legal basis, usually performance of a (pre-)contractual relationship (Art. 6(1)(b) GDPR) or a legitimate interest. Document which basis applies to which use case.
Setting up Art. 15 and Art. 17 processes
Data subjects have a right to access (Art. 15) and erasure (Art. 17). Your AI system should be able to represent both technically: on request it must be possible to trace which data is stored about a person, and deletion must happen completely and with a log, not just “removed from the interface”.
Logging
Every answer an AI gives on behalf of your company should be logged: who (which system), what, when, from which source. This serves not only traceability in the event of complaints but also proof of accountability under Art. 5(2) GDPR.
Defining retention periods
Set out how long transcripts, chat histories and logs are stored, and make sure deletion afterward happens automatically, not manually and not “whenever someone remembers”.
Staff training
The biggest practical risk is rarely the official AI system, but the informal use alongside it: employees copying customer data into a private chat tool because it’s faster. A clear, short internal policy (which tools are allowed, what data must not go into them) plus a one-time training session noticeably lowers this risk.
EU AI Act: transparency duties (as of July 2026)
The EU AI Act requires transparency for chatbots and voice AI in customer contact: users must be able to recognize at the start of the interaction that they’re talking to an AI system, not a human. This applies to text chatbots on the website as much as to voice assistants on the phone. This disclosure requirement should be firmly built into the conversation script or the first chat prompt, not added later as a disclaimer somewhere in the fine print.
Checklist to work through
| Item | Done? |
|---|---|
| DPA in place with every AI provider involved | ☐ |
| Processing demonstrably in the EU | ☐ |
| Legal basis documented per use case | ☐ |
| Access process (Art. 15) technically implemented | ☐ |
| Deletion process (Art. 17) technically implemented, with a log | ☐ |
| Logging of every AI answer active | ☐ |
| Retention periods defined and automated | ☐ |
| Staff trained on allowed/forbidden AI tools | ☐ |
| AI disclosure to customers at the start of the conversation (EU AI Act) | ☐ |
This checklist doesn’t replace legal advice for your specific case, but it gives you a practical starting point for the conversation with your data protection officer or lawyer. At meine-bots, every one of these points is built firmly into the architecture of the AI operating system, not bolted on afterward.