GDPR & the EU AI Act: the legal side of AI telephony
Few topics create as much uncertainty for businesses as the legal situation around AI on the phone: is the assistant allowed to hold conversations? What about callers’ data? The good news: AI telephony is clearly permitted in Austria and the EU – provided a few obligations are met. This overview summarises the most important ones.
Note: this article is general orientation and does not replace legal advice.
1. Transparency: callers must know they’re talking to AI
The EU AI Act requires that people are informed when they interact with an AI system. For a phone assistant this means concretely: it introduces itself as a digital assistant at the start of the call. That’s not a formality – it also builds trust. Callers respond noticeably more relaxed when they know what they’re dealing with.
2. GDPR: handling personal data properly
As soon as the assistant records names and callback numbers, it processes personal data. The usual GDPR rules apply:
- Legal basis: usually pre-contractual measures (Art. 6(1)(b) GDPR) – the caller wants to book or enquire about something.
- Data processing agreements: every service involved – telephony platform, speech recognition, automation tool – requires a DPA.
- Information duty: the website’s privacy policy must describe the phone processing: which data, for what purpose, for how long.
- Data minimisation: the assistant should capture what’s needed for the callback – and nothing more.
3. Call recording: be careful with audio
A common misconception: an AI assistant does not need permanent audio recording to work. Speech recognition processes the audio in real time. Anyone who wants to record calls beyond that needs a separate legal basis and must inform callers clearly. For most businesses the rule of thumb is: transcript or structured summary instead of audio recording – it’s entirely sufficient for the callback and avoids legal complexity.
4. Where the data lives
Pay attention to where the services involved process their data. Providers with EU data centres or recognised transfer mechanisms (such as the EU-US Data Privacy Framework) simplify the GDPR assessment considerably. And: callback lists and call data should contractually belong to the business – not to the technology provider.
Rule of thumb: with transparency, DPAs and an up-to-date privacy policy in place, the three biggest construction sites of AI telephony are already done.
Checklist for your business
- Assistant introduces itself as a digital assistant
- DPAs concluded with all services involved
- Privacy policy extended to cover AI telephony
- No audio recording without its own legal basis and clear information
- Retention periods defined (e.g. delete callback list once handled)
- Contractually agreed: the data belongs to the business
Bottom line
The legal framework is not an obstacle to AI telephony – it’s a quality requirement. Seriously built solutions meet these points from day one, and callers notice the difference. If a provider dodges questions about DPAs or transparency obligations, that evasion is the real warning sign.
Sounds like your business?
In a free 30-minute discovery call we’ll work out what’s possible for you.