LATYNEX

What to check before your AI agent goes live in the EU

GDPR applies based on what data you process and in what context — not because a system is described as "AI." An AI sales agent, chatbot, or lead-automation workflow adds some genuinely new considerations (like whether people know they're talking to a machine, which is an EU AI Act question, not a GDPR one) on top of the same data-protection basics any form or CRM already has to get right. This is an operational checklist, not legal advice — use it to find gaps before you launch, not as a substitute for a data protection lawyer or your DPO.

Not legal advice. This checklist is a practical starting point built from EU primary sources (EUR-Lex, EDPB) — it is not a substitute for qualified legal counsel, and completing it does not certify or guarantee compliance. Each item is labeled Requirement (literally mandated by GDPR/AI Act text), Good practice (sound but not itself a legal mandate), or Depends (depends on your specific data, scale, or use case) — so you can tell the difference.
0 of 10 sections fully reviewed
0 of 30 operational checks reviewed — 30 still need attention

Loading your saved progress…

Data inventory

What the agent actually collects, before anything else.

Lawful basis

Every processing purpose needs one of six legal bases — consent is not the default.

Transparency & privacy notice

What people must be told, and when.

AI disclosure

A separate obligation from GDPR transparency — don't conflate the two.

Data minimisation & retention

Collect only what the purpose needs, and don't keep it forever by default.

Processors, subprocessors & DPAs

Every vendor touching the data needs a real contract, not just a ToS.

International transfers

Sending data outside the EEA needs its own legal mechanism.

Data subject rights

People can ask, and you need a real way to find and act on their data.

Automated decision-making & human escalation

Most lead-scoring agents fall outside Article 22 — but the line matters.

Security, DPIA & breach response

Risk-appropriate measures, an honest look at whether a DPIA is needed, and a real breach process.

What this checklist does not prove

  • Completing this checklist does not mean your AI system is GDPR-compliant — it's a starting point for your own review, not a certification.
  • This is not legal advice — it doesn't replace a qualified data protection lawyer or your DPO, especially for anything marked "Depends."
  • It doesn't assess your specific contracts, vendor terms, or actual data flows — those need to be checked directly, not inferred from a checklist.
  • It doesn't cover every EU member state's additional national requirements, which can vary beyond the GDPR baseline.
  • It doesn't replace a formal DPIA where one is actually required.

Sources

Next step

LATYNEX Digital doesn't offer legal or compliance certification services — but we do build and review the technical side of AI agent deployments. If this checklist surfaced gaps in how your setup actually works, these are the concrete next steps:

See also