Skip to content
fiveleaf
Answers/

Compliance

·

2 min read

Is conversational AI GDPR compliant?

Silviu Major·Founder, Fiveleaf·

The technology is neither compliant nor non-compliant. Your deployment is one or the other, and it comes down to decisions you make rather than to conversational AI as a category.

This is not legal advice. It is the set of questions I would want answered before putting an agent in front of customers, and the ones a serious partner should answer without being chased.

Where is the data processed

The first question, and the one with the clearest practical consequence.

UK or EU processing is materially simpler to reason about than US processing. Not impossible either way, but the paperwork and the internal argument are different, and it is worth knowing before you are three weeks from launch.

Ask specifically where the model runs, where transcripts are stored, and whether either changes depending on load.

What is retained, and by whom

There are usually two separate answers here and people conflate them.

What your agent platform stores, meaning transcripts, customer records, conversation history. And what the model provider stores, which is a different company with different terms.

Enterprise tiers from the major providers offer zero-retention modes built for exactly this concern, where prompts are not stored and not used for training. Consumer tiers often do not. That distinction matters more than almost anything else in this list, and it is settled in a contract rather than in a settings panel.

What the agent is allowed to say

An agent with read access to your CRM can, in principle, read out anything in the record.

So identity verification is not a nice touch, it is the control that stops someone getting another person's details by claiming to be them. What does the agent require before it discusses an account. What does it refuse to say even after verification. Is there a category of data it simply never touches.

Those should be explicit rules, not emergent behaviour.

Can you delete it

If a customer exercises their right to erasure, you need to find every trace of that conversation and remove it.

That means knowing where transcripts live, what the retention period is, and whether the model provider holds a copy. If nobody can answer that in a sentence, it has not been designed for.

The practical read

Most of this is settled in the contract and the architecture rather than in the conversation design, which is why it should be discussed early rather than at legal review.

A partner who talks fluently about hosting, retention, verification flows and deletion without being prompted has done it before. One who gets vague precisely where the specifics live has not, and that hesitation is the most useful thing you will learn in the call.

Get your own legal advice on your specific situation. What I would push back on is the idea that this is a blocker. It is a set of decisions, and they are all answerable.

Frequently asked

Does customer data get used to train the model?
It depends entirely on the provider and the tier you are on. Enterprise tiers from the major model providers offer zero-retention modes precisely for this, where prompts are not stored or used for training. Consumer tiers frequently do not. This is a contract question, and it should be answered in writing before anything goes live.
Do we need to tell customers they are talking to AI?
Disclosure is good practice and increasingly expected, and there is a practical case for it beyond compliance: customers who work it out themselves feel handled. Whether it is strictly required in your situation is a question for your own legal advice, not for a vendor.
What happens to a conversation if a customer requests erasure?
You need to be able to find and delete it, which means knowing where transcripts live, how long they are kept and whether the model provider holds a copy. If a vendor cannot answer that quickly, they have not thought about it, and that is the useful signal.

If you want help building this

Building AI agents into a mid-market business is what Fiveleaf does.

Bespoke build, fully integrated, continuously optimised. A 30-minute discovery call is enough to tell you honestly whether AI agents fit your team right now, or whether you’re better off waiting six months. No pitch.

About the author

Silviu Major, Founder, Fiveleaf

Silviu Major

Founder, Fiveleaf

10+ years building automation systems inside enterprise SaaS, now applying that same operational rigour to AI implementation for mid-market businesses. Writes about what works (and what doesn’t) from inside live deployments, not from the outside looking in.

Connect on LinkedIn →

Keep reading