GDPR compliance in an AI project is not a checkbox added at the end. It shapes where data is hosted, which vendors are involved, and what happens to a conversation once it is over. Here is what a decision-maker should actually be asking a vendor.
Where does the data actually live?
The first question is hosting location, not just legal terms. A GDPR-compliant setup keeps data on EU or German servers, and, for businesses that need the strongest guarantee, a fully on-premise deployment is possible on request, so data never leaves the client's own infrastructure at all. That option matters most for anything touching customer conversations directly, which is exactly what an AI phone agent or chatbot does.
What paperwork should actually exist
A data processing agreement (Auftragsverarbeitungsvertrag, AVV) should exist between the business and any vendor processing personal data on its behalf. This is a GDPR requirement, not an optional extra a vendor can skip for a smaller client. For a chatbot specifically, any third-party channel involved (WhatsApp Business, for instance) has its own data-transfer implications worth understanding: WhatsApp Business API usage involves a connection to WhatsApp's own infrastructure, which is a separate consideration from the AI system itself.
Who is accountable, and for how long is data kept
Accountability should be a named point of contact, not a generic support address, and retention periods should be defined and enforced rather than open-ended: data kept only as long as the purpose it was collected for requires. A vendor that cannot answer "how long do you keep this, and who deletes it" specifically has not actually built the compliance structure it is claiming.
The questions worth asking before signing anything
Where does the data get processed, physically? Is an AVV in place, and can it be reviewed before the project starts? Is on-premise deployment available if the answer to the first question is not good enough? What is the retention period, and is it enforced automatically or does it depend on someone remembering? A vendor with a real compliance structure answers all four without hesitation.
Takeaway
GDPR compliance in an AI deployment comes down to four checkable things: hosting location, a signed AVV, clear accountability, and an enforced retention period, with on-premise deployment as the strongest option where the data is sensitive enough to warrant it.