Practical guide

A GDPR checklist for AI in customer service

Using AI in customer service means personal data is processed by a third party, which sets clear requirements under GDPR. This checklist covers what you actually need to have in place before launch.

05 stepsA sequence to use before and after launch

The sequence

Work through the important decisions

Keep the scope narrow, test with real questions and expand when the workflow is reliable.

01

Sign a data processing agreement (DPA)

Required under GDPR when a vendor like Aveexia processes personal data on your behalf. Confirm the agreement exists in writing before going live.

02

Confirm where data is stored and transferred

Ask for written confirmation of storage region, any transfers and safeguards – not just a verbal promise.

03

Define the legal basis and retention period

Determine why you're collecting the data (for example contract or legitimate interest) and how long it should be kept before deletion or anonymisation.

04

Give visitors clear information

Update your privacy policy to mention the AI receptionist and link to it where the chat widget is displayed.

05

Have a process for deletion and access requests

Customers have the right to request deletion or an extract of their data – confirm you (and your vendor) can handle such requests within the statutory timeframe.

Review before launch

Common pitfalls

  • 01Assuming a vendor's general GDPR page on their website replaces an actual signed DPA.
  • 02Letting the AI collect more information than necessary, in violation of GDPR's data minimisation principle.
  • 03Forgetting to update the privacy policy after launch, so it no longer matches reality.

From the Aveexia blog