12 June 2026 · 7 min read

GDPR-compliant AI phone assistant: the checklist for businesses

An AI phone assistant processes voice, names and often sensitive requests – in other words, personal data. This checklist shows what businesses need to look for so that using one is GDPR-compliant.

Why privacy is critical in AI telephony

Every call with an AI assistant is data processing: the caller's voice is captured and transcribed, name and phone number are recorded, the request is stored and summarised. All of this is personal data under the GDPR – and for medical practices or law firms, special categories such as health data are quickly involved.
German criminal law adds another layer: Section 201 of the Criminal Code protects the confidentiality of the spoken word. Recording calls without consent is a criminal offence. A serious AI phone assistant must therefore make transparent from the start that an AI is speaking and whether the call is recorded.

The checklist: 7 points for GDPR-compliant AI telephony

  • EU data processing: speech recognition, language model and speech synthesis should run on servers in the EU – not via US endpoints.
  • Data processing agreement (DPA): the provider must offer a DPA under Art. 28 GDPR naming all sub-processors involved.
  • Transparent AI announcement: callers must learn at the start of the call that they are talking to an AI – the EU AI Act requires this too.
  • Recording only with information: whether and what is stored must be announced clearly; covert recording violates Section 201 of the German Criminal Code.
  • Storage limits and deletion concept: call audio should not be stored at all, or only briefly; transcripts need defined retention periods and a delete function.
  • Data subject rights: access, rectification and erasure must be practically feasible – ideally directly in the dashboard.
  • Data minimisation: the assistant should only ask for what the request requires and must not build profiles across callers.

The legal bases in brief

For customer contact, processing is usually based on Art. 6(1)(b) GDPR (contract or pre-contractual steps) or (f) (legitimate interest in reachability). The information duty under Art. 13 is key: callers must know who is responsible and what happens to their data – in practice solved via the announcement plus the privacy policy.
Since 2024 the EU AI Act has been entering into force in stages. Most relevant for AI phone assistants are the transparency obligations: people must be able to tell they are interacting with an AI. These obligations become binding on 2 August 2026 – anyone introducing an assistant now should meet them from day one.

Be careful with US providers

Many voicebot platforms route speech through US services for speech recognition or language models. That means every conversation leaves the EU – including voice and content. Even with standard contractual clauses this remains risky after the Schrems II ruling and hard to justify, especially with health or client data.
The safe option: a provider that demonstrably runs the entire speech pipeline in the EU and guarantees it contractually. Ask specifically where speech recognition and the language model are hosted – not just where data is “stored”.

How Empfango implements these requirements

Empfango is built for the European legal framework from the ground up: speech processing runs on EU servers, every conversation starts with a fixed announcement about AI use and recording, call audio is not stored permanently and transcripts can be deleted at any time. That turns the AI phone assistant from a compliance risk into a compliance advantage.
← Back to the blog