GDPR-compliant AI in customer support: what to check
A practical checklist for using AI in customer support under the GDPR. Hosting, data retention, sub-processors, and the questions to ask any AI support vendor before you connect your inbox.
Connecting an AI tool to your support inbox means handing it your customers' personal data. Names, order numbers, sometimes far more. Under the GDPR that's a real responsibility, not a checkbox. This is a practical guide to what matters, written for a support lead, not a lawyer. (It's guidance, not legal advice: check your specifics with counsel.)
Why support inboxes are sensitive
A support message is often full of personal data: the sender's identity, their problem, account details, occasionally health or financial information they volunteer. Any tool that reads, stores, or drafts from those messages is processing personal data on your behalf. That triggers concrete obligations.
The questions to ask any AI support vendor
- Where is the data hosted? EU hosting keeps you clear of many transfer complications. Ask for the region, not a vague "cloud."
- Who are the sub-processors? The AI model provider, the mail provider, the hosting company, each is a sub-processor you must be able to name and account for.
- How long is data retained? There should be a clear default retention period and a way to shorten or delete it.
- What happens on disconnection? Removing a channel should delete its data, not orphan it somewhere.
- Is there a Data Processing Agreement (DPA)? You need one in place with any processor. No DPA, no deal.
- Is customer data used to train models? For most B2B use, the answer you want is no. Your customers' messages shouldn't become training data.
"The AI is GDPR-compliant" is not a meaningful claim on its own. Compliance depends on hosting, retention, sub-processors and contracts. Ask for specifics, and get them in writing.
Data minimization in practice
The GDPR's minimization principle says: process only what you need. For AI support that means the tool should work with the message content required to draft a reply, and not quietly hoover up more, or keep it longer than necessary. A shorter retention window is both safer and simpler to defend.
How SupportWunder approaches this
SupportWunder is built for the DACH market, so these aren't afterthoughts:
- EU hosting for the application and its data.
- A 90-day default retention window, not indefinite storage.
- Disconnection means deletion: remove a channel and its data goes with it.
- Grounded answers, not model guesswork: replies come from your knowledge base, and the system flags a case rather than inventing an answer.
You can read the specifics on the security and data help page, and the privacy policy covers the legal detail.
A short pre-launch checklist
- Confirm EU hosting and get the region in writing.
- Get the sub-processor list and a signed DPA.
- Confirm the retention period and the deletion-on-disconnect behaviour.
- Confirm customer data is not used for model training.
- Document your own lawful basis and update your privacy notice.
Handled well, AI support and the GDPR are not in tension. The same discipline that keeps you compliant (minimal data, clear retention, grounded answers) is also what makes the AI trustworthy. For the wider view, see our guide to AI in customer service.