Data controller vs. processor with AI: a coral figure carries a controller's seal while another holds an AI toolbox, on a navy background
Guide8 min read

Data Controller vs. Processor With AI: The Main Responsibility Is Yours (and the Vendor Answers for Its Own)

TL;DR

Use AI to serve your customers and your business is still the data controller: you carry the main responsibility and answer to the regulator — you can't pass it to the vendor (though the vendor answers for its own failures too). So choosing a tool is a compliance decision. Ask where the data lives (EU), demand a signed DPA, and check AI disclosure comes set up from the start.

When you bring in an AI to answer your customers, it's easy to assume you've outsourced the legal risk too. You haven't. Under privacy law, the key figure is the data controller, and that's you: your business determines the purposes and means of the processing, meaning it decides what customer data gets collected and why (GDPR art. 4(7)). The AI vendor is usually the "processor," the party that handles that data on your behalf and on your instructions (GDPR art. 4(8)). The uncomfortable consequence is direct: if something goes wrong because of a decision you made —processing with no legal basis, no data processing agreement, or without informing anyone— you're the one who answers to the regulator. Important nuance, though: the processor also answers for its own failures, and a regulator can penalize it too (GDPR art. 83(4)); the vendor isn't always off the hook. This framework applies whenever you handle the data of EU residents, and its logic mirrors the "business" vs. "service provider" split in US state laws like California's CCPA/CPRA. That's why choosing a tool isn't a marketing decision or a pricing one: it's a compliance decision. Here's how to get it right.

Data controller vs. processor: who answers for what

GDPR splits the roles. The data controller is the one who determines the purposes and the means: why data is processed and how. The processor is the one who handles it on your instructions. When you put an AI to work answering calls and saving leads, you decide the "why" (winning customers, booking appointments, following up), so you're the controller. The AI vendor executes on your behalf: it's the processor.

This isn't lawyer trivia. It means that, in an audit, you answer for your own decisions: the accountability principle falls on whoever decides the purposes and means. That said, the processor isn't off the hook: GDPR places direct obligations on it (art. 28) and a regulator can fine it for its own failures —say, a security lapse or acting outside your instructions— (art. 83(4)). On the penalty side there's no automatic joint liability: each party answers for its own duties. Civil liability is different: if a customer suffers harm, GDPR art. 82(4) lets them claim the full amount from either you or the vendor (joint and several liability), and whoever pays can then recover from the other for its share of the fault (art. 82(5)). You can't hand your legal responsibility to a tool. What you can do is choose one that helps you comply.

If you want the full picture of what the law expects from a conversational AI, we lay it out in is it legal to use an AI voice agent or chatbot for customer service?.

Data controller vs. processor with AI: a coral figure holds the controller's seal while receiving an AI toolbox from the processor, on a navy background
You outsource the operation, not the responsibility: to a regulator, you're the data controller.

How to choose an AI vendor: the five questions to ask

Before you sign anything, put the vendor through a short interrogation. If it hesitates on any of these, you already know what to do.

The 5-question checklist for your AI vendor

  • Where is my customers' data stored? The right answer is "in the EU." Anything else opens the can of worms that is international data transfers.
  • Will you sign a data processing agreement (DPA)? If they don't have one drafted and ready, that's a bad sign. It should be standard, not a favor.
  • Does the AI say it's an AI, and can I configure that? Disclosing that a caller is talking to an AI is a transparency duty under the EU AI Act (art. 50(1) of Regulation (EU) 2024/1689) if you serve EU customers —and a plain best practice, and an FTC expectation, everywhere else. It should adapt to your business, not sit buried.
  • Can a customer ask to talk to a person, and does it actually happen? A support bot escalating to a human generally isn't a legal obligation —the right to human intervention in GDPR art. 22(3) only kicks in for solely automated decisions with legal or similarly significant effects— but it is a good trust practice: it should be one click away, not lost in a menu.
  • What data is processed, how long is it kept, and how do I delete it? You want data minimization, a clear retention policy and a delete button, not a support ticket queue.

These five questions aren't a formality: they're the practical summary of GDPR article 28 (the processing agreement) and the transparency duties of AI Act art. 50. A vendor that answers them without breaking a sweat is the one you'll want beside you the day a complaint lands. For the detail on what the AI Act asks of you, we've got the list in the EU AI Act checklist for US businesses.

Red flags that give away a vendor that leaves you exposed

There are signals you shouldn't let slide.

The first: data outside the EU with no safeguards. Let's clear up a common misconception: GDPR does not require data to stay physically in the EU; its Chapter V (arts. 44–49) allows transfers outside the European Economic Area as long as valid safeguards are in place (an adequacy decision under art. 45 or the standard contractual clauses of art. 46). The problem isn't that data leaves, it's that it leaves without that transfer mechanism: at that point you've taken on a risk that shifts with every court ruling. Keeping data on European infrastructure is the cleanest route because it spares you that analysis; we explain it in detail in where is your chatbot's data stored?.

The second: no processing agreement. If the vendor doesn't offer you a DPA, the processing is improper from minute one —and a breach of GDPR art. 28 is attributable to both parties— no matter how pretty the demo is.

The third: no AI disclosure set up from the start. A bot that passes for human, or a vendor that leaves the notice in your hands with no support, pushes you toward falling short of the transparency the EU AI Act requires if you serve EU customers (art. 50(1)), and of the honest disclosure customers expect anywhere. At Totem we don't leave that piece loose: we set it up during onboarding and you approve the wording before you go live.

And the fourth: no real path to a person. Even though escalating to a human generally isn't a legal obligation in customer service, a vendor that doesn't make it easy leaves you without a trust route customers value highly. In voice, a real path means your team can pick up the same call; in chat, that they step into the same thread with the context right there.

What you checkA vendor that protects youA vendor that leaves you exposed
Where the data livesIn the EU, by defaultOutside the EEA, or you don't know
Processing agreement (DPA)Signed and standardNonexistent or grudging
AI disclosureSet up by Totem and approved with youHidden, missing, or left to you
Handoff to a personSame call in voice; same thread in chatNonexistent or trapped in a menu
Data retention and deletionClear and under your controlOpaque; you depend on support

The data processing agreement (DPA): why it's non-negotiable

The data processing agreement, or DPA, is the document GDPR article 28(3) requires between controller and processor. It's not decorative paperwork: it's what defines, in writing, what data the vendor processes on your behalf, for what purpose, for how long, with what security measures, and what happens to that data when the relationship ends. Without it, both parties are in breach, not just the vendor (art. 28).

Without a signed DPA, it's not that you have a risk: it's that the processing is improper from day one, whatever you do afterward.

A vendor that takes compliance seriously hands you the DPA without your having to ask twice. If they present it as an extra, as something to "figure out later," or as a generic PDF nobody has read, that attitude tells you a lot about how they'll treat your data when no one's watching. The DPA is the documentary proof that you acted with due diligence in choosing a processor: exactly what protects you the day someone asks.

Data processing agreement (DPA) under GDPR article 28, sealed with a teal padlock and signed between controller and processor, on a navy background
The article 28 DPA: without it, the processing is improper from day one.

What many people believe

If the bot messes up with the data, the blame and the fine are always the vendor's.

What the rule actually says

Each party answers for its own: you, for your decisions as controller; the vendor, for its failures as processor, which a regulator can also penalize (GDPR art. 83(4)). Choosing the wrong processor is your risk.

What many people believe

Hiring an AI tool outsources compliance too.

What the rule actually says

You outsource the operation, not the responsibility. Accountability can't be delegated; you only manage it by choosing well and signing a DPA (GDPR art. 28).

What many people believe

A tiny 'this is a bot' notice covers you.

What the rule actually says

The notice has to be clear and unambiguous: disclosing that it's an AI is a transparency duty under AI Act art. 50(1). Burying it means failing that duty.

What makes Totem a safe choice from day one

We're not going to sell you absolute guarantees: compliance always depends on how you use the tool. What we can do is make it easy to comply. In TotemAI, your leads, calls and conversations are hosted in the EU by default, so you never have to wrestle with international transfers. The notice that people are talking to an AI is part of the setup: we get it ready and you approve the wording before you go live. The handoff to a person is real and warm: in voice, your team joins the same call; in chat, they step into the same thread, always with the full context. And we sign the data processing agreement because it's the right thing to do, not as a favor.

That built-in compliance design is deliberate, and we go under the hood in how Totem handles AI disclosure, consent, EU data residency and handoff. The idea is simple: the legal box comes checked from the factory so you can focus on serving customers, not putting out regulatory fires.

And since compliance and selling aren't at odds, it's worth remembering what you're hiring all this for. According to our clients, answering well and on time translates into concrete things.

60%

less response time by answering the phone in ~1s, 24/7

+40%

more demos booked by answering instantly

−35%

fewer no-shows with WhatsApp and voice reminders

The takeaway is the usual one, but this time with a legal twist: speed and 24/7 coverage win you customers, and a vendor that complies out of the box spares you the headache. Choose your tool the way you'd choose a partner, because you answer for your own decisions, and the vendor for its own.

Official sources

  • GDPR (Regulation (EU) 2016/679), arts. 4, 22, 28, 44–46, 82 and 83 — EUR-Lex
  • AI Act (Regulation (EU) 2024/1689), arts. 50 and 113 — EUR-Lex
  • CCPA/CPRA (California Civil Code §1798.100 et seq.), the US analog of the controller/processor split (business vs. service provider) — California OAG

Frequently asked questions

Who is the data controller if I use a vendor's AI?

Your business. You decide why you process your customers' data and to what end, so you're the data controller. The AI vendor is the processor: it handles the data on your behalf. When a regulator acts, the primary penalty falls on the controller — that is, on you.

If the bot makes a mistake with the data, is it the vendor's fault?

Not entirely. The processor answers for its own obligations, but the controller is still the one accountable to the authority. Choosing a vendor that doesn't host data in the EU or won't sign a processing agreement exposes you, not it. That's why the choice of tool is, at bottom, a compliance decision.

What is a data processing agreement (DPA) and why do I need one?

It's the contract GDPR article 28 requires between controller and processor. It sets out what data is processed, for what purpose, for how long, and with what security measures. Without it, the processing is improper from day one. A serious vendor offers it to you signed, not as a favor.

Where should my customers' data be stored?

GDPR doesn't require it to stay physically in the EU: its Chapter V allows transfers outside the EEA with valid safeguards (an adequacy decision under art. 45 or the standard contractual clauses of art. 46). That said, keeping it on European infrastructure is the simplest path, because it spares you the slippery ground of international transfers and mechanisms that change with every court ruling. At Totem, your leads, calls and conversations are hosted in the EU by default.

What's the difference between a data controller and a processor?

The data controller decides why and how data is processed: that's you, the business hiring the AI. The processor handles it on your behalf, following your instructions: that's the AI vendor. To a regulator, the controller is the one held accountable, even when a third party runs the operation.

How do I choose an AI vendor that won't leave me exposed to a fine?

Ask five questions before you sign: where it stores the data (the right answer is "in the EU"), whether it will sign a data processing agreement (DPA), whether the AI disclosure is configurable, whether a customer can ask to talk to a person, and how you control retention and deletion. If it hesitates on any of them, you're the one taking on the risk.

Ready to activate your agent?

Launch your TotemAI pilot

Book a 20-minute call. Within 24 hours we’ll map your flows, analyze your tools, and scope a tailored pilot.

Arrow Book a demo

Made with by Totem Studio