AI agents and GDPR: a practical business guide

Whether an AI agent can be used in line with data protection requirements depends on the actual process. An EU server, a contract or disabled model training alone is not enough. Review the whole operation, from source documents and model providers to logs, connected tools and the final decision.

15 September 20263 min read
Slightly open glass vault door with data streams and a gold key

Checks before production

Plan privacy-conscious AI agents: check data flows, lawful basis, processor terms, permissions and deletion before deployment.

  • Define the purpose, people affected and necessary data; assess the lawful basis under Article 6. Special categories require additional consideration under Article 9.
  • Minimise data and establish responsibilities. For processing on behalf of a controller, assess Article 28 terms, subprocessors and instructions.
  • Document storage locations, remote access and disclosures. Assess Chapter V requirements separately for international transfers.
  • Set access controls, security measures, retention periods and deletion. Include inputs, outputs, search indexes, backups and logs.
  • Organise transparency information, individual rights and incident procedures. Assess whether likely high risk requires a data protection impact assessment before processing.

Three settings, three different questions

A provider example distinguishing training use, retention, application state and regional processing.

CheckEvidence to obtain
Data residencyWhich data is stored and processed where? Does the commitment cover subprocessors, support and connected tools?
Model trainingDoes the exclusion cover your product, contract and features? Check optional data sharing separately.
Retention and deletionHow long are content, application state and security logs kept? No training does not automatically mean no storage.

Example: an agent drafts support replies

Start with anonymised cases. Give the agent only necessary ticket fields and approved knowledge sources. Limit tool permissions; initially send sensitive replies and refunds for human approval.

Test with the accountable team: is access to another customer's data denied? Are deletion rules applied across systems? Can errors be detected and actions stopped? Record results and unresolved issues before release.

AI and privacy questions

Is a self-hosted model automatically GDPR-compliant?

No. Self-hosting can provide more control, but leaves operation, security, permissions and deletion with your team. External tools, telemetry or backups may still transmit data. The actual processing needs assessment.

Does an EU region automatically mean Zero Data Retention?

No. Region, training use and retention are separate properties. OpenAI, for example, requires approval for certain Zero Data Retention controls; some features may still retain application state. Check documentation for the specific endpoint.

How do we start selecting a system?

Describe one bounded use case without personal sample data. Compare operating models based on data flows, contract terms and demonstrable controls. Involve privacy and information security in the decision.

Sources for your assessment

In particular Articles 5, 6, 9, 28, 32, 35 and Chapter V. This checklist helps prepare an assessment of your use case.

Define your use case

The potential analysis captures tasks, data types and approvals to inform technical selection. Do not send confidential source data.

Start potential analysis

If you want to prioritize a real process, a few clear inputs are enough for a strong first assessment.

WhatsApp Kai