---
title: "AI and GDPR"
description: "Using AI on customer data in the EU falls under the GDPR like any other processing: you need a lawful basis, a data processing agreement with every provider, da"
canonical: https://automataai.hu/en/glossary/ai-and-gdpr
language: en
publisher: Automata AI
updated: 2026-09-19
---

# What is AI and GDPR?

Using AI on customer data in the EU falls under the GDPR like any other processing: you need a lawful basis, a data processing agreement with every provider, data minimisation and the ability to delete. The EU AI Act adds transparency duties, such as telling people when they interact with an AI. Neither prohibits AI automation; both shape how it is built.

## The practical checklist

Choose providers that offer EU data residency or at least no-training terms. Send the model only the fields it needs. Keep logs for a defined period, then delete. Add an AI disclosure to calls and chats. Document all of it in your records of processing. Done well, this takes days, not months.

## FAQ

**Can customer data leave the EU when using AI APIs?**

It can be kept in the EU with the right provider settings, and where it cannot, standard contractual clauses apply. We set this per project and record it in the DPA.

Related: https://automataai.hu/en/glossary/ai-voice-agent, https://automataai.hu/en/glossary/llm, https://automataai.hu/en/glossary/human-in-the-loop
