- gdpr
- privacy
- compliance
- trend
AI and GDPR: using customer data without getting it wrong
Your AI agent reads customer messages, so it handles personal data. What the GDPR actually asks of you, what to ask your vendor, and what not to automate.
There's a question that comes up in nearly every first meeting, usually half-whispered, as if it were slightly embarrassing to ask: "This AI thing… is it actually legal with my customers' data?" The short answer is yes. The longer answer is that it depends entirely on how you set it up — and the decisions that matter get made before you switch anything on. This guide is for small-business owners already using (or about to use) AI on customer messages, emails or records. By the end you'll know what the GDPR really requires, what to ask your vendor, and the three things you're better off not automating.
Start with the uncomfortable bit: yes, you're processing personal data
A name is personal data. So is a mobile number. And "hi, this is Marta, I'm calling about the service on my car, plate 1234 ABC" is personal data wrapped around three other pieces of it.
Which means that the moment an AI agent reads your WhatsApp Business messages, sorts your inbox or drafts a quote from what a customer told you, you are processing personal data. This isn't a grey area or a novel legal question — it's exactly what was happening when an intern read those same messages. The GDPR applied then and it applies now.
That's actually good news: nothing has to be invented, the existing rules still work. What changes is that AI works faster and with more "memory", which amplifies the mistakes you were already making. If you kept customer conversations for seven years in an uncontrolled shared folder, AI didn't create that problem. It just made it visible.
Spain's data protection authority has been saying this for years in its guidance on processing that incorporates AI, and in February 2026 it published specific guidance on agentic AI — systems that don't just answer but act — hammering the same point home: accountability stays with the controller. That's you.
Your vendor doesn't own your data — they're a processor
This is the most important conversation you'll have about any of this, and it takes under ten minutes.
When you hire someone to handle your customers' data on your behalf — an AI tool, an agency, a CRM — that company is a processor. You remain the controller. The relationship gets documented in a data processing agreement (Article 28 of the GDPR). This isn't decorative paperwork: it defines what that company may and may not do with what you hand over.
Four questions worth asking any AI vendor before you sign:
- Do you train your models on my conversations? The answer you want is "no". Plenty of consumer tools do it by default; business tiers usually don't, but check. If they say "you can turn it off", ask whether it ships turned off.
- Where is the data processed and stored? Inside the EEA is the easy path. Outside isn't forbidden, but it needs additional safeguards — and you need to be able to explain them.
- Who are your sub-processors? Almost no AI tool is a single company: behind it sits a model provider, a hosting provider, possibly a transcription service. You're entitled to that list.
- How long do you keep conversations, and how do I delete them? If nobody can answer, you have your answer.
A serious vendor handles these without breaking a sweat and sends you a DPA before you've asked twice. If they start improvising, that's not a technical problem. That's a risk problem.
Minimise: your agent doesn't need to know everything
This is where most small businesses make life harder than it needs to be. The temptation is to hand the agent everything: the full CRM history, the contracts folder, the customer spreadsheet with ID numbers and bank details. Just in case.
Bad idea, and not only because of the GDPR. The data minimisation principle says you should only process the data necessary for a specific purpose. And it turns out minimisation and quality pull in the same direction: an agent answering questions about opening hours, prices and availability doesn't need anyone's bank details to do that well. It actually does it better with less noise.
In practice:
- Separate what the agent reads from what the agent can look up. Knowing the catalogue doesn't require access to the billing system.
- Sensitive data out by default. Health, political views, union membership, sexual orientation, children's data: if your business handles these (a clinic, say), they demand an extra level of protection and shouldn't pass through an agent without a deliberate, documented decision.
- Set retention periods. "Forever" is not a retention period. Decide how long it makes sense to keep a support conversation — six months, a year — and actually delete it.
- Anonymise where you can. Working out "what are people complaining about this month" doesn't require knowing who is complaining.
When you should NOT let the machine decide
This is the part nobody tells you, so here it is straight. Three situations where the agent should stop and call you:
Automated decisions with significant effects. Article 22 of the GDPR gives people the right not to be subject to a decision based solely on automated processing where it produces legal effects or similarly significantly affects them. Translated: if your agent decides on its own, with no human looking, who gets financing, who gets refused a service, or who gets hired, you're on thin ice. An agent tidying your inbox is nowhere near that line. An agent rejecting applications is well past it.
Sensitive data without a prior assessment. If you're going to process health data, biometrics or children's data at scale, the GDPR will likely require a Data Protection Impact Assessment before you start. It's not an impossible hurdle, but it is a hurdle — better not to discover it after the fact.
When you can't explain what the agent did. If a customer asks "why did you tell me that?" and the only honest answer is "no idea, the AI said so", you have an accountability problem. Keep a record of what the agent does. A boring log is worth more than a thousand vendor promises.
None of these three force you to give up automation. They force you to design it with a human at the decision point — which, as it happens, is how well-built agents work anyway: you approve, they execute.
The one thing with a deadline: say it's an AI
Something concrete and dated. The transparency obligations of the EU AI Act apply from 2 August 2026: if a customer is talking to an AI system, they have a right to know. That part of the law was not pushed back by this year's simplification package.
Complying costs you one line:
Hi, I'm the virtual assistant for [your business]. I'm here to help, and I'll hand you to a person whenever you need one.
And while you're at it, do yourself a favour and revisit your privacy policy. If you've added AI to your customer service and the policy hasn't changed since 2021, it no longer describes reality. One paragraph will do: what the assistant does, why, and how a customer exercises their rights. For the full picture of the law, we covered it in this piece on the EU AI Act for small businesses.
The ten-minute review
Pour a coffee and answer these in writing. Six for six and you're in decent shape:
- What customer data does my agent actually see, and why does it need each piece?
- Do I have a signed data processing agreement with the vendor?
- Is anything trained on my conversations? (It should be "no".)
- How long is data kept, and who deletes it?
- Does the customer know they're talking to an AI, and how do they reach a human?
- Is there any decision the agent makes alone that it shouldn't?
Not one of these questions is technical. All of them are business questions. And that's the encouraging part: compliance here doesn't depend on understanding how a language model works. It depends on thinking clearly about what you let it do.
At Yaqbot we build agents this way from day one: minimum access, everything logged, and a human approving what matters. If you want to see what that looks like day to day, take a look at the receptionist agent — the one that handles your customers — and the limits you can put on it.
