All articles

Compliance

GDPR and AI call handling in the EU: a practical compliance checklist

ยท 7 min

This article is practical guidance, not legal advice โ€” have your final setup reviewed by a qualified adviser. That said, most of what EU businesses need to get right when an AI agent answers their phone line is straightforward and can be handled once, properly.

1. Tell the caller

Callers should know, early and clearly, that they are speaking with an automated assistant, and whether the call is recorded or transcribed. A single opening sentence covers both. Never design an agent that claims to be a human being.

2. Establish your lawful basis

For taking a service request, a callback or an appointment, contract performance or legitimate interest usually applies. For recording audio, you generally need a stronger justification, so many businesses keep the transcript and summary and skip storing audio entirely. Whatever you pick, document it in your records of processing.

3. Minimise what you capture

  • Ask only for data you need to call the person back and serve them.
  • Instruct the agent not to request payment card details, ID numbers or health details beyond what is necessary.
  • Prefer structured fields over long free-text notes where possible.

4. Set a retention period and enforce it

Pick a window โ€” for example 90 days for transcripts and shorter for audio โ€” write it in your privacy notice, and delete automatically rather than manually. Unbounded retention is one of the most common findings in practice.

5. Get your processor chain in order

An AI phone setup usually involves a telephony provider, a speech/voice provider and your application. Each is a processor or sub-processor. You need a data processing agreement with your vendor, a list of sub-processors, and clarity on where data is stored and whether any transfer leaves the EEA.

6. Be ready for data-subject requests

  1. 1Access: be able to export every call, transcript and note relating to one phone number or person.
  2. 2Erasure: be able to delete them, including any audio, within your stated timeframe.
  3. 3Rectification: be able to correct wrong contact details captured during a call.
  4. 4Objection: have a route for a caller who does not want to speak to an automated system.

7. Security basics that auditors actually check

  • Access control per organisation, so one customer can never see another's calls.
  • Recordings in private storage behind short-lived signed links, never public URLs.
  • API keys held server-side only, never in the browser.
  • An audit log of who accessed or changed what.
  • EU data residency for your database, storage and, where available, your voice provider.
Compliance is mostly configuration: disclose, minimise, delete on schedule, and keep everything server-side and isolated.

Receply is built around these defaults: EU-hosted database and storage, per-organisation row-level isolation, private recording storage with expiring links, server-side-only provider credentials, an audit log, and export and deletion of an organisation's call data on request.

Let the next call be answered.

Create a workspace, publish an agent and point your line at it. Covered by the 30 day money back guarantee.

Set up your AI agent