All articles

AI phone calls and GDPR: what companies really need to cover

A voice agent listens, understands and stores. That puts every call under the GDPR. The good news: the requirements are clear — and with the right setup they are met in a matter of days.

7 min readJuly 27, 2026Rufori

Why AI telephony is a data protection topic at all

The moment an AI phone assistant answers a call, it processes personal data: the number, the name, the request, often an address or appointment details too. The voice itself is a biometric feature. So every call falls under the same rules as any other customer record in your company — except that it is created in seconds and processed automatically.

Under the GDPR you are the controller, not the technology provider. The provider acts as a processor on your instructions. That is exactly why a marketing claim is not enough: you need to know where processing happens, what is stored and for how long.

The effort involved is manageable. Most requirements concern things a properly built system brings anyway: a data processing agreement, processing inside the EU, clear retention periods and a transparent notice at the start of the call. This article puts the points in order but does not replace legal advice for your specific case.


The six obligations at a glance

Have these points settled before the first real call runs through the AI:

  1. 01

    Establish a legal basis

    For inbound calls, pre-contractual steps or legitimate interest usually apply. Outbound marketing is stricter: there you generally need documented consent.

  2. 02

    Inform transparently

    Callers must learn at the start that an automated system is speaking and whether the call is recorded. A short, clear notice is enough — a buried line in the privacy policy is not.

  3. 03

    Handle recording properly

    Recordings are not automatically permitted. Either you obtain consent, or you work with a transcript and summary only, without storing audio.

  4. 04

    Sign a data processing agreement

    Without a DPA under Art. 28 GDPR, no provider may process your caller data. The agreement must also name the sub-processors involved — language models and telephony providers included.

  5. 05

    Update your record of processing

    AI telephony is a processing activity in its own right. It belongs in your Art. 30 record with purpose, data categories, recipients and retention periods.

  6. 06

    Define and enforce retention

    Call data may only be kept as long as the purpose requires. Set concrete periods and check that your system actually enforces them.


How to spot a privacy-friendly provider

The difference rarely shows in the marketing. It shows in the contract and the architecture:

CriterionCriticalUnproblematic
Server locationProcessing in the US or unclearProcessing in Germany or the EU, contractually guaranteed
Sub-processorsNot named or changeable at any timeFully listed, changes announced in advance
Training on your dataCalls feed into model trainingContractually excluded
RecordingOn by default, without noticeCan be switched off, with notice and documented consent
DeletionIndefinite storage, no self-serviceConfigurable periods, deletion on request
Access requestsNo process, manual searchCalls findable and exportable per person

What a clean setup gets you

01

No surprises under review

Record, DPA and retention concept are in place. A request from an authority or a customer can be answered in minutes instead of weeks.

02

Trust on the caller side

An open notice costs two seconds and takes the uncertainty out of the call. Starting transparently gets you more usable information.

03

Sign-off from procurement and privacy

In larger companies a pilot rarely fails on technology — it fails on missing paperwork. A complete DPA package removes that loop.

04

Less data clutter

Taking retention seriously leaves you with clean data instead of years of recordings nobody can attribute anymore.


Common pitfalls in practice

These points are most often overlooked during rollout:

Outbound without consent

Marketing calls to consumers require explicit, documented consent. The fact that an AI is calling changes nothing — violations carry fines.

Health data in the call

Practices and clinics handle special categories under Art. 9. That requires additional safeguards and tighter purpose limitation.

Privacy policy not updated

Telephony is missing from many policies entirely. Add a dedicated section on automated call handling and recording.

The CRM as a shadow archive

Transcripts land in the CRM automatically and are never deleted there. Retention has to apply along the whole chain, not just in the phone system.

No route to a human

Callers should always be able to reach a person. That is good practice, defuses complaints and is mandatory for sensitive matters.

Live calls used as test data

Using real conversations for tuning is only permitted if purpose and retention cover it. Otherwise work with anonymised examples.


Going live compliantly in four steps

The order saves time: paperwork first, then the technology, then live operation.

01

Describe the processing

Write down which calls the AI handles, which data that produces and who sees it later. This description is the basis for your record, your privacy policy and internal sign-off.

02

Put contracts and documents in place

Sign the DPA, review sub-processors, extend the record of processing and add a section on automated telephony to your privacy policy.

03

Configure for data minimisation

Enable the AI disclosure, switch recording on only if you genuinely need it, set retention periods and decide which fields are passed to the CRM at all.

04

Set up processes for data subject rights

Clarify internally who handles access and deletion requests and how calls are located for a given person. A short dry run shows whether the path works in practice.


Frequently asked questions about AI telephony and GDPR

Is AI telephony allowed in Germany?

Yes. There is no ban on automated call handling. What matters is that processing has a legal basis, happens transparently and meets the usual obligations such as a DPA, a record of processing and retention periods.

Do I have to tell callers that an AI is speaking?

Yes, and at the start of the call. Transparency is a core GDPR obligation, and when asked directly the system must answer truthfully. Rufori never pretends to be human.

Am I allowed to record calls?

Only on a solid basis, usually the caller's consent obtained before recording starts. Without consent, the route is a transcript and summary without stored audio.

Where does Rufori process the data?

On servers in Germany. Data stays in the EU, a data processing agreement is signed, and calls do not feed into the training of public models.

How long is call data stored?

As long as the purpose requires — you set the period. Short periods for raw data are common, with longer retention only for what you actually need for contracts or accounting.

Do I need a data protection impact assessment?

Not in every case. It becomes relevant with systematic large-scale processing or special categories of data, for example in healthcare. When in doubt, check briefly with your data protection officer.

Conclusion

GDPR compliance is not an obstacle to AI telephony — it is a matter of preparation.

Clarify the legal basis, disclose transparently, sign the DPA, process in the EU, set retention. Do that and you can automate without second thoughts.

AI telephony built for European requirements.

15 minutes, a real call, your own use case. Processing in Germany, DPA included.