compliancegdpr
AI automation and GDPR: a checklist for Hungarian companies
Seven things to settle before an AI system touches customer data: lawful basis, DPAs, data minimisation, residency, retention, disclosure and records.
Published: 5 min read
Written by: The Cégsegítő AI teamThe seven-point checklist
Work through these in order during scoping. Each takes hours, not weeks.
- 01Lawful basis: name it for each data flow, usually contract performance or legitimate interest.
- 02Data processing agreements: one with every provider that sees personal data, including the model API.
- 03Data minimisation: send the model the fields the task needs, not the whole record.
- 04Residency: choose EU regions where offered; otherwise rely on standard contractual clauses and document it.
- 05Retention: define how long logs and transcripts are kept, then delete automatically.
- 06Disclosure: tell people at the start of a call or chat that they are speaking with an AI.
- 07Records: add each AI processing activity to your records of processing and, for higher-risk uses, run a DPIA.
Where companies usually slip
Two places: using a consumer AI account instead of a business API with a DPA, and keeping call recordings indefinitely 'just in case'. Both are easy to fix before launch and hard to explain afterwards.
Frequently asked questions
Do I need a DPIA for a voice agent?
Often yes if it records calls or processes health, financial or other sensitive data at scale. For a booking agent at a hair salon, usually no, but documenting the assessment is still good practice.
Related terms
Related services
Have a process like this? Tell us about it.
Book a callFurther reading