Back to Insights
AI & Compliance

Can an AI Agent Process Customer Data? GDPR and Liability

7 min read
Can an AI Agent Process Customer Data? GDPR and Liability — practical AI guide for SMEs

Yes, an AI agent may process customer data, as long as you follow the GDPR (AVG) the way you would for any other software. The sharp line isn't in the data but in the autonomy: may the agent make a meaningful decision about a person on its own? That's where Article 22 of the GDPR draws the line.

Many SME owners only ask this question once the build is already under way: 'But is that thing even allowed to process our customer data on its own?' The GDPR doesn't forbid an AI agent from seeing or processing customer data. Your CRM, your mail server and your accounting package have been doing that for years. What the level of autonomy does decide is whether your agent project sails through the compliance check or sits for months at 'we first need to sort out the legal side'.

(This article is a practical explanation, not legal advice. If you're unsure about a specific case, put it to a privacy lawyer.)

Can an AI agent make decisions about people on its own?

Article 22 GDPR gives people the right not to be subject to a decision based solely on automated processing that has legal effects or similarly significant effects. It's a narrow, specific provision, and that narrowness is good news for most SME agents.

An agent that writes a draft reply that an employee approves before it's sent? Not Article 22. An agent that categorises incoming support tickets and routes them to the right colleague? Not Article 22. An agent that rejects a credit application on its own, filters out a job applicant or sends a customer a binding decision with no one stepping in? That is Article 22 territory, and stricter requirements apply.

You can capture the practical difference in one decision table:

What the agent doesAutonomyArticle 22 applies?Recommended set-up
Draft a replyHuman approvesNoHuman-in-the-loop as the default
Route and label ticketsFullNo (no significant decision)Logging + spot checks
Enrich or summarise dataFullNoData minimisation
Send a quote or price autonomouslyFullBorderlineBring in a person for exceptions
Reject an applicant or credit applicationFullYesHuman review mandatory

Most administration and customer service agents in SMEs, such as email handlers, reminder bots and ticket routers, fall in the top half of that table. Human-in-the-loop (the agent proposes, a person decides) takes Article 22 out of the picture in almost all cases. Want to see what such an agent looks like in practice? Take a look at the AI implementation page.

Who is liable when the agent gets it wrong?

This is where most of the confusion starts. Under the GDPR, you, the company that deploys the agent, are the controller. The party that builds and runs the agent for you is your processor. The provider of the underlying language model (Anthropic, OpenAI or Microsoft, for example) is a sub-processor. That chain decides who pays for what.

Three scenarios make it concrete:

  • The agent emails data to the wrong customer. This is a data breach. As controller, you have to report it to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours, not your builder. In the contract you can require the processor to inform you immediately and cooperate.
  • The agent sends incorrect advice on its own. Towards the person concerned, you remain liable under civil and privacy law. That's why human-in-the-loop where the content carries risk isn't a luxury but a way to limit liability.
  • The model trains on your customer data. Without the right data processing agreement and settings, data can end up in a training set. That's a violation for which you, as controller, are held accountable.

The stakes aren't symbolic: GDPR fines go up to 20 million euros or 4% of worldwide annual turnover, whichever is higher. For SMEs the realistic risks are usually reputational damage and recovery costs, but that upper limit shows why you should close the chain tightly in your contracts. You can read how to set down roles, responsibilities and controls on the security and governance page.

What does the EU AI Act require of your agent?

Alongside the GDPR, the EU AI Act applies. The good news, which scare stories often skip: most SME agents are not a high-risk system. In the law, high risk is reserved for things like recruitment screening and credit scoring (Annex III). An email assistant or ticket router falls under low or minimal risk.

There is a transparency obligation (Article 50), though: if your agent communicates directly with customers, they need to know they're dealing with AI. The law comes into force in phases, so check the current dates before you plan around a specific moment.

Checklist: how to set up an AI agent GDPR-proof

Go through this checklist before going live:

  1. Data minimisation: give the agent access only to the data the task really needs. Not your whole CRM, but the one mailbox or the one ticket field.
  2. Data processing agreement: sign one with your builder (Article 28 GDPR) and check that the sub-processors (the LLM provider) are named in it.
  3. Data location and training: put in writing that your data isn't used to train models, and choose EU hosting where possible (for example Azure OpenAI in an EU region or AWS Bedrock EU).
  4. Human-in-the-loop for meaningful decisions: see the table above; this covers Article 22.
  5. Logging and audit trail: record what the agent did, so you can reconstruct an incident and show that you're in control.
  6. Transparency: when the agent deals directly with customers, say that it's AI.
  7. DPIA for high risk: if you process sensitive data on a large scale or make significant decisions, carry out a data protection impact assessment (DPIA).

What does a safe set-up look like in practice?

The starting point at UnifyAI is human-in-the-loop, unless it's demonstrably safe to do otherwise. The agent does the heavy lifting: reading, looking things up, proposing. A person keeps a hand on the button for anything that goes to a customer or amounts to a decision. That isn't only sensible under the GDPR, it also helps quality in the first weeks, while you're still fine-tuning.

An example for illustration: an accountancy firm wants an email responder that handles frequently asked client questions. Those emails contain personal data and sometimes financial details, exactly the kind of data you need to be careful with. A sensible set-up: the agent gets access only to that one mailbox (data minimisation), drafts a reply and an employee approves it before it's sent (no Article 22). The language model runs under a data processing agreement with no training on the data, and every action is logged.

The GDPR work on top of the build consists of having the data processing agreement checked, mapping the data flows and configuring human-in-the-loop. That removes the biggest legal uncertainty before the agent goes live. Want to know where in your processes agents can safely run? An AI scan gives you a first picture.

The language model and the agent platform (such as AgentWorks) are tools. The responsibility for setting things up properly lies with the party that applies them, and you remain ultimately responsible as controller.

What is a good next step?

The fear that an AI agent will run off with customer data is understandable, but with a good set-up it can largely be solved: limit the data, keep a person in the loop for decisions and put the chain down in contracts. Then an agent is no riskier than the software you already use, and often easier to audit, because every step is logged.

Want to set this up properly for your situation? Talk it through via AI consultancy: together we look at which agents can safely run at your company, how you cover the GDPR and the EU AI Act, and what the first concrete step is.

FAQ

Frequently asked questions

Short, clear answers so you can decide faster.

May an AI agent process customer data without consent?

Processing always needs a legal basis under the GDPR (Article 6), but that is far from always consent. For most SME agents the basis is performing a contract or a legitimate interest. More important than consent are data minimisation and a data processing agreement.

Is an AI agent a high-risk AI system under the EU AI Act?

Usually not. Administration and customer service agents fall under low or minimal risk. High risk is reserved for things like recruitment screening and credit scoring. A transparency obligation does apply: customers must know they're communicating with AI.

Who is liable if the agent makes a mistake with personal data?

The company that deploys the agent is the controller and therefore primarily liable towards the person concerned. You also report a data breach to the Dutch Data Protection Authority, not your builder. In the contract you set down with your processor who does what in an incident.

May the agent deal with customers completely on its own?

For meaningful decisions about a person, not completely on its own and without human involvement (Article 22 GDPR). Drafts that an employee approves, or routing tickets, are allowed. Human-in-the-loop is therefore the safe default for SMEs.

Do ChatGPT or Claude train on my customer data?

On the business API and enterprise plans of OpenAI and Anthropic that doesn't happen by default, provided you have a data processing agreement and the settings are right. You arrange EU data location through, for example, Azure OpenAI in an EU region or AWS Bedrock EU. Put it in the contract.

Erwin Berkouwer

Erwin Berkouwer

AI consultant and architect, your single point of contact

Book an intro call.

30 minutes to an hour, online or by phone. Within 2 working days a proposal is ready in your personal environment.

Email:
connect@unify-ai.nl
Phone:
+31 6 41 53 93 66
Loading calendar