+33 (0)1 87 66 00 65 · Monday to Friday, 9am–6pm Free audit (15 min)
AI law, explained

AI agents and the GDPR: the rules for processing personal data

An AI agent often processes personal data without that data sitting in a conventional file: voice, emails, prompts, call notes, tickets, customer history or a score can identify a person. The GDPR requires a purpose, a legal basis and safeguards to be defined before collection — and then proved to work.

Law verified as at 16 August 2026. This page is not individualised legal advice.

The short answer

The GDPR applies to an AI agent as soon as it collects or uses information that makes a person identifiable, even indirectly: voice, email address, telephone number, prompt, history, ticket or score. The organisation must define each purpose and its legal basis, minimise the data, inform the individuals, set clear terms with its suppliers, secure the processing and check the transfers. A determining score can fall under Article 22. Source: GDPR(opens in a new tab).

Quotable legal markers

What you need to be able to cite

When does the GDPR apply?

As soon as a person is identifiable, directly or indirectly, in the data processed by the agent.

Source : GDPR, Articles 4 and 5(opens in a new tab)

Is AI itself a legal basis?

No. Each purpose must rest on a basis in Article 6 and, for special category data, on a condition in Article 9.

Source : GDPR, Articles 6 and 9(opens in a new tab)

Is a score an automated decision?

It can be, where the score produces legal effects or significantly affects the person and a third party follows it in a determining way.

Source : CJEU, SCHUFA, C-634/21(opens in a new tab)

The essentials in 30 seconds

What to remember

  • The GDPR applies as soon as a person is identifiable, directly or indirectly.
  • AI is not a legal basis. Each purpose must rest on Article 6 GDPR(opens in a new tab) and, for special category data, on an exception in Article 9.
  • Collecting less is an obligation. An agent must ask only for what the announced task requires.
  • The roles must be written down: controller, processor, joint controllers and sub-processors.
  • A score can be an automated decision. Article 22 GDPR(opens in a new tab) can apply where a third party follows the score in a determining way.
  • European hosting helps but is not enough. Every actual access and transfer must be checked.
Our sources

Our official sources

Every statement on this page links to the text or decision it rests on. The links go straight to the official document.

Editorial author and publisher: Blue Lemon Agent, a brand of LINDBERGH FORMATION. Method: texts and decisions verified on EUR-Lex, Légifrance, the CNIL, the courts and the competent authorities. Legal review: Mohamadou Hamady DIA, juriste, on 18/08/2026. Updated on 10/09/2026.

The detail, rule by rule

Start with the purpose, not with the tool

Before connecting a model or an agent to a CRM, a mailbox or a document repository, the organisation must describe each purpose: answering a request, summarising a call, routing a ticket, detecting fraud, carrying out direct marketing, assessing a candidate or training a model. A broad formula such as “improving AI” does not make the use of the data foreseeable.

For each purpose, document:

  • the categories of individuals and of data;
  • the source of the data;
  • the legal basis;
  • the recipients and processors;
  • the retention period;
  • transfers outside the European Economic Area;
  • the applicable rights and the channel to exercise them;
  • whether a data protection impact assessment is needed.

Choose a genuine legal basis

Under Article 6 GDPR(opens in a new tab), six legal bases are available. For a business AI agent, the most frequent are performance of a contract or of pre-contractual measures requested, a legal obligation, a public interest task, consent and legitimate interests.

What legitimate interests can support

Legitimate interests can support certain necessary and proportionate processing, for example security or some B2B direct marketing operations. They do, however, require a three-part test: the legitimate interest pursued, the necessity of the processing, and the balancing against the rights and reasonable expectations of the individuals.

What legitimate interests cannot support

Data revealing in particular health, political opinions, religion, sexual orientation, trade union membership, and biometric data used to identify a person, fall under Article 9 GDPR(opens in a new tab). A chatbot must not ask for such information out of convenience. Where it may receive it spontaneously, filtering, compartmentalisation, a short retention period and an escalation scenario must be provided for.

Inform at the right time — Articles 13 and 14

Where the data is collected from the user, Article 13 GDPR(opens in a new tab) applies. Where it comes from a CRM, a directory, a data broker, a professional network or a public source, Article 14 applies.

The information must state in particular the identity of the controller, the purposes, the legal bases, the recipients, the transfers, the retention periods, the rights and the source of the data. It is normally provided within one month at the latest; where the data is used to contact the person, at the latest at the time of the first communication; where it is disclosed to another recipient, at the latest at the time of that first disclosure.

The disproportionate effort exception in Article 14 GDPR(opens in a new tab) is not an automatic exemption for web scraping. It must be demonstrated, documented and offset by appropriate measures, including publicly available information. The CNIL, the French data protection authority, recommends layered information, with the essentials immediately accessible.

Minimise the data and the retention periods

The minimisation principle in Article 5 GDPR(opens in a new tab) requires data that is adequate, relevant and limited. An agent tasked with booking an appointment does not need access to every client file. An agent tasked with extracting an invoice reference must not keep the whole content of the email for an indefinite period.

Practical measures:

  • restrict connectors to the folders and fields that are necessary;
  • mask the data before sending it to the model where identity serves no purpose;
  • separate technical logs from business content;
  • switch off the use of conversations for training where that use is not provided for;
  • set retention periods by category and automate erasure;
  • test the risks of memorisation, extraction and re-identification.

Allocate the roles and set clear terms with suppliers

The client that determines why and how the agent uses its data is generally the controller. The supplier may be a processor for running the service, but a controller for its own purposes — independent security, improvement reusing the data, or product development — depending on the facts. Contractual labels do not prevail over reality.

A contract compliant with Article 28 GDPR(opens in a new tab) must set out the subject matter, the duration, the categories of data, the instructions, confidentiality, security, sub-processors, assistance with rights and incidents, the fate of the data and audits. Joint controllership requires the arrangement provided for by Article 26 and access for the data subject to the essence of that arrangement.

Security, confidentiality and impact assessment

Under Articles 24, 25 and 32 GDPR(opens in a new tab), the organisation owes accountability, data protection by design and security appropriate to the risk. For a conversational agent, this means in particular authentication, fine-grained access management, encryption, separation between clients, prevention of prompt injection, output filtering, exfiltration testing, backup and incident management.

A data protection impact assessment is required where processing is likely to result in a high risk, in particular in the case of systematic evaluation producing significant effects, large-scale processing of special category data, or systematic monitoring. The innovative nature of AI can strengthen the case for an assessment, without on its own triggering an automatic obligation.

Automated decisions and the right to an explanation

Under Article 22 GDPR(opens in a new tab), a person has the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them. The exceptions — contract, law or explicit consent — are strict and call for safeguards, including human intervention, the possibility of expressing a point of view and of contesting the decision.

A “human in the loop” is not a form of words. The person must have real authority, time, information and the ability to depart from the output. A reflex approval does not remove the automated character of the decision.

Transfers outside the EEA

Mapping where the data is hosted is not enough. Administration, support, telemetry, backups, sub-processors and remote access must all be checked. A transfer may rest on an adequacy decision, on standard contractual clauses accompanied by an assessment and, where necessary, by supplementary measures, or on an exceptional derogation under Article 49 GDPR(opens in a new tab).

Presenting a solution as “sovereign” therefore calls for verifiable facts: location, law applicable to the providers, keys, access, sub-processors and ability to migrate.

Leading case law

CJEU, 7 December 2023, SCHUFA, C-634/21

Official judgment(opens in a new tab) The Court holds that the automated establishment of a probability of creditworthiness can amount to a “decision” within the meaning of Article 22 GDPR where the third party receiving the score gives it a determining role in its own decision. A provider therefore does not sidestep Article 22 by calling its output a mere recommendation if the downstream client follows it in practice.

CJEU, 16 July 2020, Schrems II, C-311/18

Source : Official judgment (opens in a new tab)

The Court upholds standard contractual clauses in principle, but requires an assessment of whether the protection is essentially equivalent, and the suspension of the transfer where it cannot be ensured. It invalidates the Privacy Shield. The ruling supports a disciplined approach to controlling transfers, not a geographical slogan.

CNIL, 5 December 2024, KASPR, SAN-2024-020

Source : Official decision (opens in a new tab)

The CNIL accepts that a direct marketing or recruitment objective can amount to a legitimate interest, but rules that basis out for contact details whose visibility the individuals had restricted. Limit: the decision does not impose consent on all B2B direct marketing; it penalises one specific processing operation and specific sources.

Penalties

Breaches of the GDPR can give rise to corrective measures and to fines reaching, depending on the provision infringed, 10 million euros or 2%, or 20 million euros or 4% of total worldwide annual turnover, whichever is higher. To that are added erasure requests, restrictions, litigation and reputational harm.

Integration checklist

To check before putting the agent into service

  • Record of purposes, data, sources, legal bases and retention periods.
  • Written legitimate interests test wherever that basis is used.
  • Contracts under Article 28 GDPR(opens in a new tab) and an up-to-date list of processors.
  • Notices under Articles 13/14 GDPR(opens in a new tab) available at the right moment.
  • Agent access limited to the data that is necessary.
  • No reuse to train a model without a purpose and a legal basis of its own.
  • Map of transfers and the measures attached to them.
  • Procedure for exercising rights tested end to end.
  • DPIA carried out where a high risk is likely.
  • Effective human intervention for significant decisions.
Frequently asked

What we get asked most

Does a prompt contain personal data?

Yes, as soon as it identifies a person or makes it possible to identify them indirectly, including through the professional context, the voice or the combination of several items of information.

Can conversations be used to improve the model?

Only if that purpose is specified, lawful, transparent and compatible with what the individuals expect. A provider’s contract does not create the client’s legal basis.

Are legitimate interests enough for B2B direct marketing?

They can suit some marketing connected with the recipient’s occupation, provided that information is given, that objecting is made simple, that reasonable expectations are respected and that deliberately hidden data is not used.

Does hosting in France rule out any transfer?

No. Support access, group companies, backups, logs and processors must also be checked.

Does a human clicking “approve” take the case outside Article 22?

Not if the review is purely formal. The reviewer must examine the file, understand the relevant factors and be able to change the decision.

Is a DPIA always required for an AI agent?

No. It is required where a high risk is likely. The purpose, the scale, special category data, monitoring and the effects on individuals are the decisive factors.

Does your agent follow these rules?

The free audit runs your project against the applicable obligations, before it goes live.