The difference between GDPR and the AI Act: two matte pillars facing off on a navy background, one with a coral data-protection shield and the other with a teal ring of EU stars, joined by a plate across the top
Guide10 min read

EU AI Act vs GDPR: What Each One Requires From Your Business

TL;DR

GDPR vs the EU AI Act is a matter of layers, not a choice: GDPR protects people's data (legal basis, consent, residency, rights) and the AI Act governs the AI system (transparency, risk, machine disclosure). Legitimate interest comes from GDPR, not the AI Act, and only works if it passes a balancing test and the channel allows it (TCPA, CAN-SPAM). Serve EU customers with a chatbot or voice agent and both apply at once.

The difference between GDPR and the EU AI Act isn't something you get to choose between, and that's exactly the first thing that confuses almost everyone. If you put an AI on your business phone or WhatsApp and you take calls from or handle data of anyone in the EU, both regulations apply to you at once, because they watch different things. GDPR protects your customers' data: what you collect, with what permission, where you store it, and what rights people have. The AI Act governs the artificial-intelligence system: whether it's transparent, what risk level it falls into, and whether the person knows they're talking to a machine. One looks after the person; the other watches the tool. And even if you serve only US customers today, these two are the strictest standard in the world—which is why Totem is built to them by default—and the good news is that, for a small business serving customers, the two checklists overlap almost completely.

What looks like a double audit boils down, in practice, to a handful of sensible things: ask permission for the data, keep it in the EU, respect your customers' rights, disclose that there's an AI behind the conversation, and always leave a door open to a person. Let's separate what each regulation asks for, put a clear table side by side, and see what a well-built tool checks off on its own.

Key takeaways

  • You don't pick between GDPR and the AI Act: if you serve EU customers with AI, you meet both at once (and they're the strictest standard anywhere).
  • GDPR protects the data (consent, residency, your customer's rights).
  • The AI Act governs the AI system (transparency, risk level, the "you're talking to a machine" notice).
  • "Legitimate interest" isn't from the AI Act: it's a GDPR basis, it takes a balancing test, and it doesn't skip each channel's own rules (TCPA, CAN-SPAM).
  • A support agent almost always lands in 'limited risk': its headline duty is to disclose that it's an AI.
  • In front of your customer and the regulator, you're the responsible party; the tool you pick is part of compliance.

GDPR and the AI Act aren't "either/or": they're two layers

The mental trap is thinking the AI Act came to replace GDPR, or that meeting one exempts you from the other. It doesn't work that way. They're two layers that stack. GDPR has been in force since 2018 and deals with personal data: it doesn't matter whether a person, a spreadsheet, or an AI collects it—the moment a customer's data is involved, GDPR is in charge. The AI Act is the new arrival, and it regulates something GDPR never looked at: artificial intelligence itself as a system, with its risk levels and its transparency duties. That's the difference between GDPR and the AI Act: one focuses on the data, the other on the tool.

That's why, the moment you plug in a chatbot or an AI voice agent for your customer service, you can trigger both at once. The chatbot handles personal data (name, phone number, whatever the customer shares), so GDPR comes in. And it's an AI system that talks to people, so the AI Act comes in. There's no way to touch one without touching the other.

two regulations, one conversation

What GDPR asks of you: the data

GDPR always looks at the same thing: the person's data. When your AI collects a phone number, listens to what a customer says, or stores a conversation, that's personal data, and the regulation asks you for four concrete things:

  1. Legal basis and consent. You need one of the six bases in Art. 6(1) GDPR to process that data; consent is only one of them, not the default rule. In customer service, legitimate interest (Art. 6(1)(f)) or the performance of pre-contract steps or a contract (Art. 6(1)(b)) is often enough. Recording calls doesn't always require consent either: the core duty is to inform people at the start (Art. 13 GDPR), and the basis can be legitimate interest or the contract depending on the case. (In the US, separately, call recording follows one-party or two-party consent depending on the state—so a clear notice at the start is the safe default.)
  2. Information and transparency. The customer must be able to know what you do with their data, ideally through an accessible privacy policy.
  3. International transfers. Here's a myth worth correcting: GDPR does NOT require the data to physically stay in the EU. Its Chapter V (Arts. 44–49) allows transferring it outside the EEA as long as an equivalent level of protection is guaranteed—through an adequacy decision (Art. 45) or appropriate safeguards such as standard contractual clauses (Art. 46). Keeping it in the EU simplifies compliance and skips that paperwork, which is why many tools choose it; we go deeper in where your chatbot's data is stored.
  4. The customer's rights. Access, rectification, erasure, objection. People must be able to exercise them. GDPR adds a narrow right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects the person—and, where applicable, to obtain human intervention (Art. 22 GDPR). Note: this is NOT a "general right to talk to a human"; it only kicks in for automated decisions with legal or similarly significant effects (denying credit, rejecting a job application), not when booking an appointment or answering a question.

Notice that none of these mentions "artificial intelligence." They talk about data. That's why GDPR would apply to you just the same if you served customers with an intern and a notepad. AI doesn't change the rules of the data; it just adds its own on top.

The missing piece: legitimate interest and contact lists

Here it pays to be very precise, because this is where everything gets mixed together. Legitimate interest is not an AI Act concept. The AI Act doesn't tell you which list you can write to or which contacts you can put into a cadence. That's decided by GDPR, in Art. 6(1)(f)—and, on top of it, by the specific rules of each channel. In the US, those channel rules are the ones that bite first: the TCPA for phone calls and text messages, CAN-SPAM for email, and each platform's own policies (WhatsApp) on top. (If you also serve EU customers, GDPR's channel-specific rules stack on as well.)

Legitimate interest means this: you can process personal data if you have a real, lawful, and proportionate interest, if using that data is necessary for that purpose, and if the person's rights don't outweigh it. The European Data Protection Board sums the test up in three steps: legitimate interest, necessity, and balancing. Translated for a small business: "I want to sell" doesn't cut it; you have to be able to explain why that person reasonably expected that contact, why that channel is proportionate, and how they can object or opt out.

The practical matrix looks like this:

List or contactCan it enter an automation?Reasonable channelsWhy
Lead who just asked for info via form, WhatsApp, call, or InstagramYes, to answer and follow up on that specific requestThe same channel they used and, if they left a phone/email for that purpose, proportionate direct contactThere's a request or a pre-contract step; don't automatically turn it into a newsletter or general campaign
Current or recent customerYes, with limitsCommercial email under CAN-SPAM with a clear unsubscribe; a text or live call only with the consent the TCPA requires for marketingAn existing relationship makes outreach about your own similar products more defensible—but the channel rule (TCPA consent for texts and calls) still governs
Business contact at a companyDepends, but can be valid if the use is strictly professionalBetter a call or one-to-one contact tied to their role; email/WhatsApp blasts without opt-in are a gray areaA B2B contact tied to someone's business role is more defensible than treating them as a consumer, not a license to autodial or mass-text without the consent the TCPA requires
Old lead with no live relationship or interaction in the last yearGray area leaning noBetter to re-activate only with clear consent; otherwise ask permission before adding to a cadenceWith no live relationship, request, or recent interaction, there's no reasonable expectation of contact
Purchased list, scraping (info gathered from the internet, even if public), directories, or randomly generated numbersNoNone for commercial automationNo traceability and no reasonable expectation; random-number and scraped-number outreach is exactly what the TCPA and FTC target
Person who opted out, said "don't contact me," is on a do-not-call/suppression list, or objectedNoNoneAn opt-out or Do-Not-Call registration stops marketing outreach. The automation must block them, not retry

The key word is purpose. Answering someone who asked you for a price is not the same as dropping them into a Black Friday campaign six months later. Calling a driving school's admissions lead to talk about an enrollment agent is not the same as texting her personal WhatsApp with a generic promo. The data can be the same; the purpose and the channel change the legal basis.

Valid channels: the quick rule

WhatsApp, SMS, email, Instagram/Messenger, and other electronic messages. If it's a conversation the person started, you can reply and continue the thread proportionately. If it's outbound promotion, treat it as commercial messaging: in the US, marketing texts need prior express written consent under the TCPA; commercial email is allowed under CAN-SPAM on an opt-out basis, provided you identify yourself and offer a clear unsubscribe; and WhatsApp additionally requires opt-in and approved templates under the platform's own policies.

Live commercial call with a person, or with real human involvement. It can rest on consent or on documented legitimate interest, but you have to document the balancing. Live telemarketing has to respect the Do-Not-Call registry, identify who's calling and the commercial purpose at the start, and honor any objection immediately. Having a real person dial avoids the stricter rule for prerecorded or autodialed calls, but it doesn't turn a purchased, random, or untraceable list into a valid one.

Automated commercial call with no human involvement. Don't use legitimate interest as a shortcut here. In the US, the TCPA requires prior express written consent for prerecorded or autodialed marketing calls to cell phones. If you want to do commercial outbound with an AI voice, treat it as an explicit prior-consent case and review it with counsel before you launch.

Web chat or inbound support on your site. This is the cleanest case: the person comes in and asks. You can help them, qualify, and store what's needed for that request, informing them in the privacy policy and disclosing when they're talking to an AI. To turn that chat into future campaigns, ask for a specific opt-in.

Clear cases and gray areas

Clearly yes: a clinic gets a form: "I'd like a price for a dental cleaning," and the person leaves a phone number and WhatsApp. The AI can reply, answer questions, and offer an appointment on that channel, disclosing that it's an AI. If it later wants to put that person into monthly cosmetic-dentistry campaigns, it needs marketing consent or a basis and channel that genuinely fit.

Clearly yes, with limits: a driving school calls former students of a course they paid for to offer a very similar new session. If the data was collected lawfully, they didn't object, the commercial purpose is disclosed, and opting out is allowed, legitimate interest can fit. If the former student hasn't had a relationship or any interaction in years, it's no longer so clear.

Gray area: a list of "clinic directors" scraped from LinkedIn to send automated WhatsApps. Even if they're professional profiles, WhatsApp is a very intrusive channel, and reasonable-expectation rules weigh heavily. Better to ask permission through a less invasive channel, make very contextual one-to-one contact, or not automate that list at all.

Outbound with a real person: if a salesperson calls an admissions lead using a business number obtained lawfully, to talk to the school about a service related to its activity, that can fit better than a cold AI voice. Even so, it's not an open bar: first check the Do-Not-Call registry where it applies, have your legitimate-interest balancing or consent, explain at the start who's calling and why, and cut the cadence the moment the person says they don't want more calls.

No: buying a database of restaurant phone numbers and setting an AI voice to cold-call them. If it's an automated call with no human involvement, you need prior consent. If they're random numbers, that's exactly what the TCPA and FTC target for marketing calls. And if someone says "stop" or "don't call me again," they come out of every cadence.

The operating rule for Totem—or for any serious tool—should be simple: every contact enters with an origin, a purpose, a legal basis, a permitted channel, proof of consent or balancing, and an objection/opt-out status. If any one of those boxes is empty, that contact shouldn't enter a commercial automation.

What GDPR requires: a matte vault on a navy background holding a coral personal-data token, with a teal EU flag sealing the entrance for data residency
GDPR watches the data: where it lives, who processes it, and—as a product choice—keeping it in the EU.

What the AI Act asks of you: the system

The AI Act regulates exactly where GDPR didn't reach: the AI tool itself. And the first thing it does is classify it by risk level. The vast majority of a small business's uses (answering, informing, booking an appointment) aren't in Annex III of the Regulation, so they fall into limited risk, a category whose central obligation is transparency (Regulation (EU) 2024/1689—the AI Act—, Art. 50(1)). High risk exists, but it's reserved for Annex III uses like screening résumés, assessing creditworthiness for a loan, or managing critical infrastructure. An agent that picks up your clinic's phone and offers a slot Thursday at five is not on that list.

For that limited risk, the obligation the AI Act places on you is, at its core, that the person knows they're talking to an AI (Art. 50(1)). On top of that comes AI literacy for your staff, already applicable since February 2, 2025 (Art. 4), and not using the tool for the prohibited practices in Art. 5 (e.g., subliminal manipulation or social scoring). For a small business that books appointments and follows up, those prohibited practices are a non-issue: you're not deciding anything the Regulation bans.

GDPR vs the AI Act: the side-by-side

Placed next to each other, the difference between GDPR and the AI Act is crystal clear: they don't compete, they split the work. One covers the data; the other, the system. Here's the quick comparison you can take into the meeting with your DPO.

DimensionGDPR (the data)AI Act (the AI system)
What it protectsThe customer's personal dataThe artificial-intelligence system
Key questionDo you handle the data well?Is the AI transparent and safe?
Headline dutyLegal basis and safeguards for transfersDisclose that it's an AI
Customer's rightAccess, erasure, objectionKnowing they're talking to a machine
In forceSince 2018General application from August 2, 2026
Who answersThe data controller (you)The deployer (you)

The "who answers" row is the one that costs the most to misread: for data you're the data controller, and for the AI's use you're the deployer, so you answer for your own decisions. But that doesn't mean the vendor is off the hook: as the processor, it also answers for its own failures and can be penalized by a data-protection authority (Art. 82(2) and Art. 83(4) GDPR). Each party answers for its role. If you want the full list of AI Act duties, we go through them one by one in the EU AI Act checklist for US businesses.

What the AI Act requires: a coral matte agent headset on a navy background with a teal tag reading AI hanging from the cord, a symbol of the transparency notice
The AI Act watches the system: that the customer knows they're talking to an AI and has a way out to a person.

Myth

The AI Act replaces GDPR; meeting one is enough.

Reality

They're two layers that stack: GDPR covers the data and the AI Act covers the AI system.

Myth

GDPR doesn't affect me because I serve customers with an AI, not people.

Reality

GDPR is in charge the moment personal data is involved, no matter who collects it.

Myth

If the AI slips up, the software vendor always pays.

Reality

You answer for your decisions (as data controller/deployer); the vendor answers for its own as processor and can also be penalized. Each for its own role.

How to meet GDPR and the AI Act at once, without running two projects

Here's the reassuring part. Even though they're two regulations, the points where they overlap are so many that, well built, meeting both is a single move. Disclosing that it's an AI satisfies the Art. 50 transparency duty of the AI Act; keeping the data in the EU spares you GDPR's transfer-safeguards paperwork; and informing people well and leaving a trail of every interaction gives you transparency for both. Offering a handoff to a person is, above all, a good UX and trust practice: Art. 22 GDPR only requires human intervention for automated decisions with legal or significant effects, and a booking agent normally doesn't make that kind of decision. Even so, having that exit ready covers you in case some flow ever brushed that threshold. That turns two lists of obligations into a single service routine.

This is exactly what we designed in TotemAI: compliance that comes built in instead of being a to-do list for you. The AI introduces itself as an AI when it picks up, offers to pass you to a person when needed, and that handoff is warm, with the full context of the conversation. On voice, the human joins the same call; on chat, they join the same thread. The data stays in the EU, recordings carry their notice and retention, and every call and every chat is logged with sentiment analytics, so the trail exists without you building it.

  1. The customer gets in touch

  2. It helps and books

  3. It asks for a person

  4. The trail stays

GDPR answers "do you handle the data well?" and the AI Act answers "is the AI transparent?" A well-built tool says yes to both without you drafting a single clause.

The result is that compliance stops being a toll and becomes part of how you serve people better. It's not theory: it's the same flow your customers respond to faster and miss fewer appointments with.

~1 s

to pick up the phone, 24/7, before handing off to a person

1 click

for a human to take over the conversation with context

0

lock-in: flat monthly plan with minutes and messages included

A couple of honest limits are worth remembering. This guide is informational and not legal advice; if in doubt, consult your DPO or a lawyer, especially if your case brushes against sensitive decisions like candidate screening, scoring, or health. And choosing the right tool doesn't exempt you from your legal basis or your privacy policy: that's yours. But a good part of the rest (AI disclosure, data in the EU, handoff to a person, the audit trail) can come solved out of the box, and that's where a small business saves the bulk of the work.

So the next time someone frames it as "GDPR or the AI Act," you've got the answer: neither one nor the other—both. But it's not twice the work. It's the same customer service done well, seen from two angles, and with the right tool the bulk of the work is already well underway.

Official sources

  • Regulation (EU) 2024/1689 (AI Act) — Arts. 4, 5, 50, and 113 (transparency, prohibited practices, and timeline) — EUR-Lex
  • Regulation (EU) 2016/679 (GDPR) — Arts. 6, 13, 22, 28, 44–46, 82, and 83 (legal bases, information, automated decisions, processor, transfers, and penalties) — EUR-Lex
  • Guidelines 1/2024 of the European Data Protection Board on GDPR Art. 6(1)(f) — legitimate interest, necessity, and balancing — EDPB
  • Telephone Consumer Protection Act (TCPA) — consent for marketing calls and texts; robocall and Do-Not-Call rules — FTC Do Not Call Registry
  • CAN-SPAM Act — commercial email: identify yourself and honor opt-outs — FTC compliance guide
  • CCPA/CPRA — California consumer data rights, the de-facto US baseline — California Attorney General

Frequently asked questions

What's the real difference between GDPR and the EU AI Act?

GDPR looks at the data: what you collect, on what legal basis, where you store it, and what rights the person has. The AI Act looks at the system: whether the AI is transparent, what risk level it falls into, and whether the person knows they're talking to a machine. One protects the person; the other watches the tool.

Do I have to choose between complying with GDPR or the AI Act?

It's not a choice: if you use AI with EU customers, both apply at once. GDPR has been in force for years and protects personal data. The AI Act is new and regulates the artificial-intelligence system. They're distinct layers that stack, not options to pick between.

Is my small business's chatbot or voice agent 'high-risk' under the EU AI Act?

Almost always no. Answering, informing, and booking aren't in Annex III of the AI Act, so they fall into 'limited risk,' whose central obligation is transparency: disclosing that it's an AI (Art. 50(1) of Regulation (EU) 2024/1689). High risk is reserved for Annex III uses like screening candidates or assessing creditworthiness. Confirm it with your DPO if your case brushes sensitive decisions.

Does the AI Act govern legitimate interest?

No. Legitimate interest is a GDPR legal basis (Art. 6(1)(f)), not an AI Act one. The AI Act requires transparency when an AI interacts with people; whether you can put a contact into an automation depends on GDPR and, depending on the channel, on rules like the TCPA (calls and texts) or CAN-SPAM (email).

Which contacts can I put into a marketing automation?

As a rule of thumb: leads who contacted you about that specific request, customers with a prior relationship for your own similar products or services, and business contacts when the use stays within their professional role. Don't add purchased lists, random numbers, contacts with no traceability, people who opted out, or old leads with no recent interaction. And always check the channel: in the US, marketing texts and prerecorded or autodialed calls generally need prior express written consent under the TCPA, commercial email is opt-out under CAN-SPAM, and WhatsApp needs opt-in and approved templates.

Who's liable if something goes wrong—me or the software vendor?

As the business that decides to use the AI, you're the data controller and answer for your own decisions (legal basis, information, rights). But the vendor, as the processor, also answers for its own failures (security, acting outside instructions) and can be penalized by a data-protection authority (Art. 28 and Art. 83(4) GDPR; Art. 82(2) GDPR). It's not that the vendor 'never' answers: each party answers for its role, and the data processing agreement (DPA) allocates the internal cost.

Since when do GDPR and the AI Act apply?

GDPR has been in force since May 2018. The AI Act applies in phases and, since August 2, 2026, much of the regulation is now generally enforceable, including the Art. 50 transparency duty for systems that talk to people (Art. 113 of Regulation (EU) 2024/1689).

Can one tool cover both GDPR and the AI Act?

Largely yes. The overlap is so extensive that, set up well, a single tool covers the AI disclosure, EU data residency, the handoff to a person, and the trail of every interaction. What stays yours is the legal basis and the privacy policy; the rest can come built in.

Ready to activate your agent?

Launch your TotemAI pilot

Book a 20-minute call. Within 24 hours we’ll map your flows, analyze your tools, and scope a tailored pilot.

Arrow Book a demo

Made with by Totem Studio