None of this is legal advice — talk to your counsel before launch, especially for anything customer-facing. What follows is the working checklist we point EU-based teams to when they're setting up their first AI phone agent.
Before the first call
- Decide what the caller is told at the start of the call — most teams add a short line disclosing that they're speaking with an AI agent, and that the call may be recorded
- Confirm where call recordings, transcripts and knowledge base documents are stored, and choose EU-based hosting if that's a requirement for your data
- List every third-party system the agent talks to — calendar, CRM, ticketing — and make sure each one has its own data processing agreement in place
What goes into the knowledge base
Knowledge bases built from documents or a website crawl are convenient, but convenient is how personal data quietly ends up somewhere it shouldn't be. Before uploading a document, check it for names, phone numbers or case details that don't need to be there — the agent only needs enough context to do its job, not a full customer record.
Retention and access
- Set a retention window for transcripts and recordings, and document why that window was chosen
- Decide who inside your team can read a transcript, and keep that list as short as the job allows
- Have a process ready for a caller who asks what data you hold on them, and how to delete it
A short pre-launch checklist
- Call disclosure line written and added to the opening of the flow
- Recording notice added where legally required
- Hosting region confirmed for calls, transcripts and knowledge bases
- Data processing agreements signed with every connected tool
- Retention period set and documented
- Deletion process defined for both individual requests and routine cleanup
Treat this as a starting checklist, not a finished audit — requirements vary by country, industry and what the agent is actually doing on the call, so loop in whoever handles compliance before you go live.