
Data Controller vs. Processor With AI: The Main Responsibility Is Yours (and the Vendor Answers for Its Own)
TL;DR
Use AI to serve your customers and your business is still the data controller: you carry the main responsibility and answer to the regulator — you can't pass it to the vendor (though the vendor answers for its own failures too). So choosing a tool is a compliance decision. Ask where the data lives (EU), demand a signed DPA, and check AI disclosure comes set up from the start.
When you bring in an AI to answer your customers, it's easy to assume you've outsourced the legal risk too. You haven't. Under privacy law, the key figure is the data controller, and that's you: your business determines the purposes and means of the processing, meaning it decides what customer data gets collected and why (GDPR art. 4(7)). The AI vendor is usually the "processor," the party that handles that data on your behalf and on your instructions (GDPR art. 4(8)). The uncomfortable consequence is direct: if something goes wrong because of a decision you made —processing with no legal basis, no data processing agreement, or without informing anyone— you're the one who answers to the regulator. Important nuance, though: the processor also answers for its own failures, and a regulator can penalize it too (GDPR art. 83(4)); the vendor isn't always off the hook. This framework applies whenever you handle the data of EU residents, and its logic mirrors the "business" vs. "service provider" split in US state laws like California's CCPA/CPRA. That's why choosing a tool isn't a marketing decision or a pricing one: it's a compliance decision. Here's how to get it right.
Data controller vs. processor: who answers for what
GDPR splits the roles. The data controller is the one who determines the purposes and the means: why data is processed and how. The processor is the one who handles it on your instructions. When you put an AI to work answering calls and saving leads, you decide the "why" (winning customers, booking appointments, following up), so you're the controller. The AI vendor executes on your behalf: it's the processor.
This isn't lawyer trivia. It means that, in an audit, you answer for your own decisions: the accountability principle falls on whoever decides the purposes and means. That said, the processor isn't off the hook: GDPR places direct obligations on it (art. 28) and a regulator can fine it for its own failures —say, a security lapse or acting outside your instructions— (art. 83(4)). On the penalty side there's no automatic joint liability: each party answers for its own duties. Civil liability is different: if a customer suffers harm, GDPR art. 82(4) lets them claim the full amount from either you or the vendor (joint and several liability), and whoever pays can then recover from the other for its share of the fault (art. 82(5)). You can't hand your legal responsibility to a tool. What you can do is choose one that helps you comply.
If you want the full picture of what the law expects from a conversational AI, we lay it out in is it legal to use an AI voice agent or chatbot for customer service?.

How to choose an AI vendor: the five questions to ask
Before you sign anything, put the vendor through a short interrogation. If it hesitates on any of these, you already know what to do.
The 5-question checklist for your AI vendor
- Where is my customers' data stored? The right answer is "in the EU." Anything else opens the can of worms that is international data transfers.
- Will you sign a data processing agreement (DPA)? If they don't have one drafted and ready, that's a bad sign. It should be standard, not a favor.
- Does the AI say it's an AI, and can I configure that? Disclosing that a caller is talking to an AI is a transparency duty under the EU AI Act (art. 50(1) of Regulation (EU) 2024/1689) if you serve EU customers —and a plain best practice, and an FTC expectation, everywhere else. It should adapt to your business, not sit buried.
- Can a customer ask to talk to a person, and does it actually happen? A support bot escalating to a human generally isn't a legal obligation —the right to human intervention in GDPR art. 22(3) only kicks in for solely automated decisions with legal or similarly significant effects— but it is a good trust practice: it should be one click away, not lost in a menu.
- What data is processed, how long is it kept, and how do I delete it? You want data minimization, a clear retention policy and a delete button, not a support ticket queue.
These five questions aren't a formality: they're the practical summary of GDPR article 28 (the processing agreement) and the transparency duties of AI Act art. 50. A vendor that answers them without breaking a sweat is the one you'll want beside you the day a complaint lands. For the detail on what the AI Act asks of you, we've got the list in the EU AI Act checklist for US businesses.
Red flags that give away a vendor that leaves you exposed
There are signals you shouldn't let slide.
The first: data outside the EU with no safeguards. Let's clear up a common misconception: GDPR does not require data to stay physically in the EU; its Chapter V (arts. 44–49) allows transfers outside the European Economic Area as long as valid safeguards are in place (an adequacy decision under art. 45 or the standard contractual clauses of art. 46). The problem isn't that data leaves, it's that it leaves without that transfer mechanism: at that point you've taken on a risk that shifts with every court ruling. Keeping data on European infrastructure is the cleanest route because it spares you that analysis; we explain it in detail in where is your chatbot's data stored?.
The second: no processing agreement. If the vendor doesn't offer you a DPA, the processing is improper from minute one —and a breach of GDPR art. 28 is attributable to both parties— no matter how pretty the demo is.
The third: no AI disclosure set up from the start. A bot that passes for human, or a vendor that leaves the notice in your hands with no support, pushes you toward falling short of the transparency the EU AI Act requires if you serve EU customers (art. 50(1)), and of the honest disclosure customers expect anywhere. At Totem we don't leave that piece loose: we set it up during onboarding and you approve the wording before you go live.
And the fourth: no real path to a person. Even though escalating to a human generally isn't a legal obligation in customer service, a vendor that doesn't make it easy leaves you without a trust route customers value highly. In voice, a real path means your team can pick up the same call; in chat, that they step into the same thread with the context right there.
| What you check | A vendor that protects you | A vendor that leaves you exposed |
|---|---|---|
| Where the data lives | In the EU, by default | Outside the EEA, or you don't know |
| Processing agreement (DPA) | Signed and standard | Nonexistent or grudging |
| AI disclosure | Set up by Totem and approved with you | Hidden, missing, or left to you |
| Handoff to a person | Same call in voice; same thread in chat | Nonexistent or trapped in a menu |
| Data retention and deletion | Clear and under your control | Opaque; you depend on support |
The data processing agreement (DPA): why it's non-negotiable
The data processing agreement, or DPA, is the document GDPR article 28(3) requires between controller and processor. It's not decorative paperwork: it's what defines, in writing, what data the vendor processes on your behalf, for what purpose, for how long, with what security measures, and what happens to that data when the relationship ends. Without it, both parties are in breach, not just the vendor (art. 28).
Without a signed DPA, it's not that you have a risk: it's that the processing is improper from day one, whatever you do afterward.
A vendor that takes compliance seriously hands you the DPA without your having to ask twice. If they present it as an extra, as something to "figure out later," or as a generic PDF nobody has read, that attitude tells you a lot about how they'll treat your data when no one's watching. The DPA is the documentary proof that you acted with due diligence in choosing a processor: exactly what protects you the day someone asks.

What many people believe
If the bot messes up with the data, the blame and the fine are always the vendor's.
What the rule actually says
Each party answers for its own: you, for your decisions as controller; the vendor, for its failures as processor, which a regulator can also penalize (GDPR art. 83(4)). Choosing the wrong processor is your risk.
What many people believe
Hiring an AI tool outsources compliance too.
What the rule actually says
You outsource the operation, not the responsibility. Accountability can't be delegated; you only manage it by choosing well and signing a DPA (GDPR art. 28).
What many people believe
A tiny 'this is a bot' notice covers you.
What the rule actually says
The notice has to be clear and unambiguous: disclosing that it's an AI is a transparency duty under AI Act art. 50(1). Burying it means failing that duty.
What makes Totem a safe choice from day one
We're not going to sell you absolute guarantees: compliance always depends on how you use the tool. What we can do is make it easy to comply. In TotemAI, your leads, calls and conversations are hosted in the EU by default, so you never have to wrestle with international transfers. The notice that people are talking to an AI is part of the setup: we get it ready and you approve the wording before you go live. The handoff to a person is real and warm: in voice, your team joins the same call; in chat, they step into the same thread, always with the full context. And we sign the data processing agreement because it's the right thing to do, not as a favor.
That built-in compliance design is deliberate, and we go under the hood in how Totem handles AI disclosure, consent, EU data residency and handoff. The idea is simple: the legal box comes checked from the factory so you can focus on serving customers, not putting out regulatory fires.
And since compliance and selling aren't at odds, it's worth remembering what you're hiring all this for. According to our clients, answering well and on time translates into concrete things.
60%
less response time by answering the phone in ~1s, 24/7
+40%
more demos booked by answering instantly
−35%
fewer no-shows with WhatsApp and voice reminders
The takeaway is the usual one, but this time with a legal twist: speed and 24/7 coverage win you customers, and a vendor that complies out of the box spares you the headache. Choose your tool the way you'd choose a partner, because you answer for your own decisions, and the vendor for its own.
Official sources
- GDPR (Regulation (EU) 2016/679), arts. 4, 22, 28, 44–46, 82 and 83 — EUR-Lex
- AI Act (Regulation (EU) 2024/1689), arts. 50 and 113 — EUR-Lex
- CCPA/CPRA (California Civil Code §1798.100 et seq.), the US analog of the controller/processor split (business vs. service provider) — California OAG
Frequently asked questions
Who is the data controller if I use a vendor's AI?
Your business. You decide why you process your customers' data and to what end, so you're the data controller. The AI vendor is the processor: it handles the data on your behalf. When a regulator acts, the primary penalty falls on the controller — that is, on you.
If the bot makes a mistake with the data, is it the vendor's fault?
Not entirely. The processor answers for its own obligations, but the controller is still the one accountable to the authority. Choosing a vendor that doesn't host data in the EU or won't sign a processing agreement exposes you, not it. That's why the choice of tool is, at bottom, a compliance decision.
What is a data processing agreement (DPA) and why do I need one?
It's the contract GDPR article 28 requires between controller and processor. It sets out what data is processed, for what purpose, for how long, and with what security measures. Without it, the processing is improper from day one. A serious vendor offers it to you signed, not as a favor.
Where should my customers' data be stored?
GDPR doesn't require it to stay physically in the EU: its Chapter V allows transfers outside the EEA with valid safeguards (an adequacy decision under art. 45 or the standard contractual clauses of art. 46). That said, keeping it on European infrastructure is the simplest path, because it spares you the slippery ground of international transfers and mechanisms that change with every court ruling. At Totem, your leads, calls and conversations are hosted in the EU by default.
What's the difference between a data controller and a processor?
The data controller decides why and how data is processed: that's you, the business hiring the AI. The processor handles it on your behalf, following your instructions: that's the AI vendor. To a regulator, the controller is the one held accountable, even when a third party runs the operation.
How do I choose an AI vendor that won't leave me exposed to a fine?
Ask five questions before you sign: where it stores the data (the right answer is "in the EU"), whether it will sign a data processing agreement (DPA), whether the AI disclosure is configurable, whether a customer can ask to talk to a person, and how you control retention and deletion. If it hesitates on any of them, you're the one taking on the risk.



