GDPR-compliant AI in support: what really matters
Assess AI providers for customer service with confidence. How to make sure that the DPA, EU hosting and deletion periods stand up to GDPR requirements.
Martin Semmele

Contents
- 01The DPA: the legal basis
- 02Hosting region: where the data physically sits
- 03Model training: the red line for customer data
- 04Sub-processors: who is reading along in the background?
- 05Deletion periods: when data has to disappear
- 06Rights of access: transparency for your customers
- 07The checklist: seven questions for the provider
- 08Frequently asked questions
Key takeaways
- A data processing agreement (DPA) is mandatory for every AI tool in support.
- The biggest risk is third-party AI models being trained on your sensitive customer data unnoticed.
- Watch the core criteria: EU hosting, exclusion of training and full transparency about sub-processors.
- Before you choose, also settle deletion periods and the procedure for access requests.
The DPA: the legal basis
When you use AI in customer service, the software provider you choose processes personal data of your customers: names, email addresses, order numbers or the specific issue at hand. In legal terms, this makes the software provider a processor under Art. 28 GDPR. Without a legally valid data processing agreement (DPA), you simply may not operate the system in Germany. A missing or incomplete DPA is a direct breach of data protection law: for infringements of the obligations under Art. 25 to 39 GDPR, Art. 83(4) GDPR provides for fines of up to 10,000,000 euros or, in the case of an undertaking, up to 2 % of its total worldwide annual turnover for the preceding financial year, whichever is higher1.
Purpose limitation and technical measures
The DPA governs two essential safeguards: strict purpose limitation and the technical and organisational measures (TOMs). Purpose limitation states that the provider may process your data solely to carry out the support task in question. Any further use for its own business purposes is legally excluded. The TOMs describe concrete protective arrangements such as end-to-end encryption, access controls and separation requirements. Standard terms and conditions without an individual DPA are never enough for B2B SaaS solutions.
- Strictly bound by instructions: the provider may process data only on your direct instruction.
- Guaranteed TOMs: documented encryption, access restrictions and continuous data security.
- Inspection and audit rights: verifiable certificates and ways for your business to run checks.
Before you start, make sure the DPA can be concluded digitally during onboarding, without lengthy paper processes. The data processing agreement documentation from CITO GmbH gives you an advance look at contract templates that work in practice.
Hosting region: where the data physically sits
The physical place where servers stand and AI models process requests determines the legal effort your customer service takes. Many established US tools host their infrastructure in North America. Under the GDPR, however, data transfers to third countries outside the European Economic Area (EEA) require additional safeguards and risk assessments.
Third-country transfers and legal certainty
Since 10 July 2023 the EU-U.S. Data Privacy Framework (DPF) has been in place as an adequacy decision of the European Commission. Even so, the legal situation with US servers remains complex because of foreign access powers. A data centre in the European Union removes that risk entirely. If conversations, knowledge bases and vector stores stay in the EU, the standard of European data protection law applies without complicated transfer impact assessments.
| Hosting location | GDPR classification | Relevant legal basis and evidence |
|---|---|---|
| EU-only regions | Direct GDPR compliance | DPA under Art. 28(3) GDPR only, no transfer instrument |
| USA with DPF certification | Adequacy decision under Art. 45 GDPR | DPA plus a check of the provider's current DPF certification |
| Third country without DPF | Transfer only with appropriate safeguards | DPA plus standard contractual clauses and a transfer impact assessment |
Transparent providers do not just use abstract terms such as cloud, they name concrete data centres. You will find an overview of strictly European storage locations and data paths in the Security & privacy section.
Model training: the red line for customer data
In the support chat, customers type in sensitive details: home addresses, invoice numbers, complaints or account data. The biggest risk when using generative artificial intelligence is that these inputs flow, unasked, into the general training of the language models involved.
No opt-out: why contracts need clear exclusion clauses
Some software providers reserve the right in their general terms of use to use customer data to improve their models. Often all that is offered is a hidden opt-out option. For support that complies with data protection law, that is not enough. What is needed is a contractual agreement that strictly excludes any use of your knowledge base and customer chats for training their own or third-party foundation models.
- Strict exclusion of training: conversations and documents stay isolated in your workspace.
- No passing of data to third-party models: API requests to language models run without the model operator storing data.
- Guaranteed tenant separation: your business's vector embeddings stay strictly separate from other systems.
A reliable partner makes it clear: your data serves only to produce accurate answers for your customers. Nothing flows back into global algorithms.
Sub-processors: who is reading along in the background?
An AI support tool rarely consists of a single software component. The platform often uses external service providers for parts of the job: hosting, email delivery, payment processing or vector search. For your business, the entire chain of these sub-processors is relevant under data protection law.
Hidden interfaces and the duty of transparency
Even if a main provider is based in Germany, external AI APIs may be embedded in the background. Under Art. 28(2) GDPR, a processor may engage further processors only with the prior written authorisation of the controller, and must inform you of any intended change so that you can object4. If a sub-processor fails to meet its data protection obligations, the main provider remains liable to you for those obligations.
| Task in the system | Requirement for the sub-processor | Checking duty for customers |
|---|---|---|
| AI generation & LLM | Contractual waiver of training & EU endpoint | Disclosure of the provider in the DPA |
| Semantic vector search | Encapsulated databases in the EU | Check of the storage location |
| Email & messaging delivery | GDPR-compliant data processing | Access to the sub-processor list |
A transparent list of service providers prevents nasty surprises during audits. A traceable list of all sub-processors is a precondition for any GDPR-compliant architecture.
Deletion periods: when data has to disappear
Customer service logs contain personal data that may not sit on servers indefinitely. The principle of storage limitation under Art. 5(1)(e) GDPR requires that data be kept in a form which permits identification only for as long as is necessary for the respective purpose of processing5.
Automatic routines and manual control
A professional support platform has to support two deletion paths: automated deletion rules after defined intervals and manual deletion at the press of a button. If customers request the erasure of their personal data, the ticket including all chat histories and file attachments has to be removed without residue.
- Configurable retention periods: automatic anonymisation or deletion of old tickets after defined periods in months.
- Immediate deletion in the Inbox: deletion of individual conversations by support agents with a click.
- Clean-up without residue: removal from vector stores and caches when knowledge sources are deleted.
Clean deletion concepts protect your business from legal legacy problems and make sure you meet your obligations to respond on time.
Rights of access: transparency for your customers
Under Art. 15 GDPR, data subjects have the right to find out which personal data a business processes about them. In AI-supported support, that covers not only stored master data but also the histories of automated chat conversations.
Straightforward data export in day-to-day support
When an access request comes in, the support software must not slow your processes down. The system has to let your team export all stored conversations of a data subject quickly, in a common, machine-readable format.
| Requirement under Art. 15 GDPR | Function of the support software | Benefit for your team |
|---|---|---|
| Completeness of the information provided | Capture of all chat and email logs | No manual searches in databases |
| Common export format | Export as a structured file | Direct hand-over to the applicant |
| Answering within the deadline | Central search function for customer data | Time saved in running support |
A well-structured inbox architecture turns GDPR requests from a time sink into a routine click. Detailed questions about data use are answered by the official Privacy policy.
The checklist: seven questions for the provider
Marketing promises are not enough to gain clarity before deciding on an AI support provider. Use this hard set of questions in the evaluation call:
- 1. Is there a ready-made DPA under Art. 28 GDPR that we can conclude digitally straight away?
- 2. In which specific EU regions are our conversations and knowledge data processed?
- 3. Is it contractually guaranteed that our data will not be used to train AI models?
- 4. Are all sub-processors disclosed without gaps, and where are their servers?
- 5. Can retention periods and automatic deletion routines be set flexibly?
- 6. Does the software offer an export function for access requests under Art. 15 GDPR?
- 7. Are there clear fallback rules so that the AI hands over seamlessly to human support agents when it is unsure?
A reliable partner answers every one of these questions without evasion. ComLayer is built on exactly this basis: the platform brings the support widget, the Help Centre and a shared inbox together in a single interface. Data stays in European regions, model training on customer data is excluded, and a matching DPA is ready.
Whether in the flexible entry-level Free plan, in the Pro package from €49 per month or in the Scale tier for higher volumes: transparent structures keep your support safe. You will find all details of what each plan includes in the Pricing overview.
Frequently asked questions
Is using AI in customer service allowed under the GDPR at all?
Yes, the use is legally permissible. It does, however, require a clear legal basis, often legitimate interest or the performance of a contract. In addition, a valid data processing agreement (DPA) has to be concluded with the AI provider.
What is the biggest data protection risk with support AI?
The biggest risk lies in the covert training of AI models. If a provider uses chat logs to improve its own language model, customer data drains away uncontrolled. Training on your data has to be excluded by contract.
Do the servers for the AI have to be in the EU?
A location in the EU is not required by law, but it reduces the legal effort enormously. As soon as data flows to third countries such as the USA, strict checking duties apply. With European hosting you avoid these complex hurdles.
Is my business liable for the AI provider's data protection breaches?
Towards its own customers, the commissioning business is always liable. That is why it matters that the AI provider discloses all sub-processors transparently and guarantees the level of protection across the entire chain of service providers by contract.
How do I handle sensitive information in chat logs?
Customers often type in account numbers or health data without thinking. Your AI provider has to let you define clear deletion periods. Data that is no longer needed for the support case has to disappear automatically.
Do customers have to be told that they are talking to an AI?
Yes. Transparency is a core principle of the GDPR. Customers must learn from the privacy policy that AI is used for processing. The European AI Act also requires that interaction with an AI system be clearly marked.