Data protection and AI agents: what to settle before switching the bot on

The company running the service remains the data controller. The automation vendor is a processor. Before switching the bot on you need an updated privacy notice, a contract with a data processing agreement, control over where the data lives, and a working path to delete it when someone asks.

When a conversational agent takes over customer service, nothing changes in the structure of responsibility under Brazil’s LGPD, or under the GDPR for that matter. That is exactly why people get it wrong. The temptation is to think “the AI is the one talking”. In the eyes of the law, it is your company.

Who is what in this relationship

The company serving the customers decides why and how the data is processed, so it is the controller. Whoever built and maintains the automation processes data on its behalf, so they are the processor. The language model provider comes in as a sub-processor, and that has to be declared somewhere.

The practical consequence shows up fast. If a customer asks for deletion or complains about the processing, the company under contract is the one who answers. It needs to be able to comply, which means having access to and control over the database rather than depending on a vendor’s goodwill.

The legal basis is usually simpler than people fear

When the customer starts the conversation asking to be served, processing the data needed to answer rests on performance of a contract or on steps taken prior to entering one. You do not need formal consent to reply to someone who asked what a service costs.

The care belongs to the additional uses. Using that contact for a marketing campaign later, enriching a customer record, or training a model on the conversation content. Those uses have their own legal basis and some require specific consent. That is where problems get created, not in the service itself.

Sensitive data needs extra care

Clinics are the clearest case. A message like “I need to move my physiotherapy session” contains health data, which carries reinforced protection. That does not rule out automation, but it does require a few things:

  • Collect the minimum. The agent does not need a diagnosis to book a slot.
  • Restrict who inside the company can read the conversation, with individual accounts and access logs.
  • Define how long the history is kept, and delete automatically when that period expires.

What has to be in the vendor contract

Ask for it and check it:

  1. A data processing agreement stating plainly that the client is controller and the vendor is processor, with the purpose described.
  2. A list of sub-processors. Which language model provider, which hosting, which messaging provider.
  3. Where the data lives and what happens to it when the contract ends, including export and a deletion deadline.
  4. A commitment not to train models on your data. Enterprise API plans offer that guarantee. Confirm it is actually switched on.
  5. An incident procedure. Who tells whom, how fast, and who notifies the authority and the data subjects if it comes to that.

Telling the customer is simple and non-negotiable

Two things. The person has to know they are talking to an automated system, and they need a route to a human. One line in the first message covers the first. An “agent” option that actually works covers the second.

Beyond that, your privacy notice needs to mention automated service over WhatsApp, which data is processed and for how long. It is half a page of editing, and it is usually the piece that is missing.

Checklist before going live

  • Privacy notice updated and reachable.
  • Contract with a data processing agreement signed.
  • Dashboard access with one account per person, no shared passwords.
  • Retention period defined and the deletion routine actually running.
  • A tested path for handling a deletion request.
  • Backups with a restore you have verified, because losing customer data is an incident too.
  • Human handover working and visible.

Automating well improves compliance

It is worth saying the other half of this. The previous arrangement, where conversations lived on each employee’s personal phone, with no logging, no access control, no retention period, and walking out of the company when someone resigns, is far worse from a data protection standpoint.

Centralised service with individual accounts, access logs, a defined retention period and automated deletion is easier to audit and easier to defend. Automation done properly is a compliance gain, not a new risk.

Need this solved at your company?

A twenty minute call is usually enough to tell whether it makes sense, and you talk straight to the engineer who builds it.

Talk to the studio ↗