Is an AI receptionist GDPR-compliant in Ireland?

Plain-English answer for Irish businesses. Updated August 2026.

Handing your phone over to an AI can feel like a data-protection headache waiting to happen.

More so if you run a clinic, and callers tell you what's wrong with them.

It's a fair worry.

And most pages online either dodge it, or bury it in jargon.

So here's the straight version.

This page goes through what the GDPR and the new EU AI Act actually ask of you. In plain English. And it shows how Conversegy handles each part.

Who's responsible for what.
What callers have to be told.
Where the data goes, and how long it's kept.

Plus a checklist you can hold up against any provider. Not just us.

The short answer: the rules don't ban it.

Under the GDPR and the EU AI Act, using an AI to answer business calls in Ireland is lawful, once the normal duties are met.

A lawful reason to handle the call.
Telling callers what's happening, including that it's an AI.
Keeping details only as long as you need them.
A written agreement with your provider.

Your business stays the controller of the data.
The provider is the processor.

Is it even legal to use an AI to answer calls?

Yes. The GDPR doesn't ban AI from answering calls.

It sets conditions.

The main one: you need a lawful reason to handle a caller's details. A "lawful basis", in the wording of the rules. There are six of them to choose from. Which one fits depends on what your business is actually doing on the call.

The myth worth clearing up first: you do not always need consent.

It's the most repeated line online. Get the caller's consent, or you're breaking the law. And it's simply not true.

The GDPR gives you six lawful bases. Consent is one of them. It doesn't rank above the others, and it isn't the default. It's one option among six.

None of that makes consent wrong.

Plenty of businesses use it, and use it well. Especially where they're recording at scale, doing anything with a marketing angle, where separate rules do push you towards consent, or handling sensitive information. If your setup already runs on consent and it's working, there's no reason to tear it up.

For a lot of small businesses, though, there's a simpler fit.

If you're answering your own phone to help the person ringing and run your business, that's a fair and expected reason to handle their details. The basis that often suits this is legitimate interest. It saves you trying to collect proper, withdrawable consent from every single caller, which is hard to do well on a phone line.

It comes with one small task. You note down why your reason is fair, weighed against the caller's privacy. A short "balancing test", kept on file. A page, not a project.

Which basis is right is your call, and it depends on what you're doing. That's the honest answer. Any page that tells you there's one rule for everyone is selling you something.

What doesn't change is this.

The rules are the same whether a person answers the phone or an AI does. Handing the call to an AI doesn't add a new layer of law on top. The duties you already have as a business are the duties that apply. Nothing more exotic than that.

One flag before you settle it. If callers might mention their health, a symptom, a condition, a medication, there's an extra step, and consent can matter more there. That's its own topic, and we cover it further down.

We act on your instructions as your processor, under whatever basis you've set. We don't choose it for you. That stays yours to hold.

Who's responsible, you or Conversegy?

Both of you. But for different things.

Your business is the controller. You're the one in charge of the caller's data, because you decide the calls get answered and what happens to the details.

Conversegy is the processor. We handle that data on your instructions, and only on your instructions.

The GDPR asks the two of us to put that split in writing. A contract called a data processing agreement, or DPA.

This isn't unique to us, or to AI.

You're the controller for any tool that touches your data on your behalf. Your accountant. Your booking software. The people who print your appointment cards. Conversegy is one more processor on that list. The shape is familiar, even if the words are new.

Two roles, one contract

No tool can make you compliant on its own. You decide what happens to your callers' data. We carry it out. A written agreement holds the two halves together.

You, the controller

You decide what happens to the data.

  • Decide why and how data is used
  • Set the lawful basis and tell callers
  • Handle access and deletion requests
  • Keep your own record of processing

Data Processing Agreement

The contract that binds both sides.

Conversegy, the processor

We act only on your instructions.

  • Act only on your instructions
  • Keep the data secure
  • Help with data requests and audits
  • Flag any breach to you straight away

We use a small number of vetted suppliers to run the service. They are held to the same terms, and we stay answerable to you for them.

Being your processor means we're fenced in by that contract.

We only use your callers' data to run your service and keep it working properly. We don't sell it, and we don't use it to build profiles or for anything unrelated to answering your calls. And the tools we rely on behind the scenes, for the voice, the calls, your calendar and your records, each sit under their own data agreements with us.

Now the part a lot of providers won't say out loud.

Nobody can sell you compliance in a box.

A good provider can hand you a product built the right way, and a proper contract to go with it. That's real, and it matters. But it can't lift the legal responsibility off you. As the controller, the buck still stops at your desk.

So if a provider tells you their product makes you compliant, full stop, be wary. That's not how the law works. And it's usually a sign they're glossing over the bits that are actually your call.

What about health information?

Health details get extra protection under the GDPR.

A symptom, a condition, a medication, even mentioned in passing, counts as "special category" data.

For that, a lawful basis on its own isn't enough. You need a second condition on top, just for the sensitive part. And for most businesses that means explicit consent, or keeping the detail out of your records in the first place.

This is the part that keeps clinic owners up at night, and fairly so.

The GDPR treats information about your health differently from your name or your number. It sits in a protected group the rules call special category data, alongside things like religion and biometrics. The bar for handling it is higher.

So the sums change.

For ordinary details, you need one lawful basis. For health details, you need two things. That lawful basis, and a second condition on top, specifically for the sensitive part.

The condition most businesses can actually rely on is explicit consent. Clear, specific, spelled-out agreement from the person. Which is hard to get cleanly from someone ringing in a panic about a sore tooth.

So the cleaner route, and the one Conversegy is built around, is simpler.

Don't capture it in the first place.

The job of the phone line is to book the appointment and take a message. Not to build a medical record. So we take what's needed to do that. The name, the callback number, roughly what it's about, and no more. We don't prompt callers for health detail. And if someone volunteers "it's my chest again", that stays as a passing note to you. It doesn't get promoted into a tidy health field in your records.

Two honest caveats.

We can't stop a caller saying what they say. If someone describes a symptom, it may sit in the call recording or the summary for the short time we hold it. Minimising isn't a magic filter. What it does is keep the sensitive stuff to a minimum, and out of your permanent records.

And the clinical side of your work, the notes, the files, the actual care, has its own footing under the health-care rules. That's your world, and your own basis to set. The phone line is the front door, not the filing cabinet.

Conversegy answers calls for dental practices, physio clinics and vets across Ireland, with this same light-touch approach to sensitive details.

Where does your call data go?

The GDPR doesn't require your data to stay in the EU. It requires that any trip outside the EU is covered by an approved safeguard.

So the real question isn't "does any data leave Ireland?". It's "is every transfer properly covered?".

Here's how it works.

Personal data can move outside the EU, but only under one of a set of recognised safeguards. The two that matter most here are an "adequacy decision", a formal EU ruling that a country protects data well enough, and "standard contractual clauses", a set of binding legal terms that travel with the data wherever it goes.

For the United States, there's a scheme called the Data Privacy Framework that many well-known providers sign up to. It's valid today. It has also been challenged in the courts, more than once, so sensible providers back it up with the standard clauses as well. Belt and braces.

So be a little wary of a bold "your data never leaves the EU" badge.

Sometimes it's true, and it's a fine thing to offer. But often the tools underneath, the voice, the phone network, the software, are run by international companies, and the data does travel. Lawfully, under those safeguards. A provider claiming a fully EU stack is either genuinely running one, which is rarer than the badges suggest, or stretching the truth.

Here's where Conversegy's data actually sits. The calls, the voice and your records run on established providers, some based in the United States. Every one of those transfers is covered by the Data Privacy Framework, and by standard contractual clauses where they apply, with a data processing agreement behind each. Where a provider offers EU-based processing, we use it.

How long is the data kept?

The GDPR doesn't set a fixed period. It says keep it only as long as you actually need it, and be able to say why.

At Conversegy, the call recording and transcript we hold are set to delete automatically after 30 days. Long enough to sort out any query about a call. Short enough that nothing lingers.

There's no magic number in the law.

The GDPR won't tell you "keep calls for 30 days" or "delete after a year". It sets a principle instead. Hold personal data only for as long as you have a real reason to, then let it go. And be able to explain your reason if anyone asks.

So the job is to pick a sensible period for your purpose, write it down, and stick to it.

Here's what Conversegy does.

The recording of a call and its transcript are set to delete on their own after 30 days. You don't have to remember to clear anything. It just happens. That window is there so you can settle a "what did they say on Tuesday?" query, and no longer.

One thing worth being clear on, so there's no surprise.

The 30 days covers our copy. The text summary we send you the moment a call ends is now sitting in your phone. And if a booking went into your calendar, or a detail into your records, that's in your systems too. Those copies are yours. They live as long as you decide they should, under your own retention.

We can only auto-delete what we hold. The rest is your call. Which is exactly as it should be, since you're the controller.

And if a caller ever asks you to delete what you have on them, that's a right they have. You handle the request as the controller. We help by wiping our copy on your say-so. Recordings, transcripts and summaries all count as their data, so all of it is in scope.

What are callers told?

Two things, and both up front. That they're speaking to an AI, and that the call is being handled, and why.

Telling callers it's an AI isn't just good manners anymore. Since August 2026, the EU AI Act makes it the law. And the older GDPR rule still stands: people should know a call is being recorded before it starts, not after.

Start with the new one, because it's caught a lot of people out.

The EU AI Act came into force on the 2nd of August 2026. One of its plainest rules: if an AI is talking to a person, that person has to be told they're dealing with an AI. Not buried in small print. Up front, at the start of the conversation.

There's a narrow let-off, for cases where it's already obvious. But here's the catch. The better and more natural an AI voice sounds, the less it can lean on "obvious". A voice good enough to be mistaken for a person is exactly the voice that has to own up to being one. So for a modern phone assistant, the honest answer is simple. Just say it.

The duty is shared, which works in your favour.

The company that builds the AI has to bake the disclosure in. The business that uses it has to make sure it happens. So this isn't a job that lands on your desk. A properly built assistant tells callers what it is on its own, and you inherit that.

Then the older rule, the one that's been there all along.

If a call is recorded, people should be told before it starts. Quietly recording and mentioning it later doesn't cut it. And the tired line "this call may be recorded for quality purposes" is wearing thin, because it doesn't really say what's happening. The rules increasingly expect the notice to match the truth.

Which is how Conversegy has always done it.

Callers hear, at the start, in plain words, that they're speaking to an AI answering for the business, and what that means. No "for quality purposes" fog. No pretending to be a person and hoping nobody notices. Just a straight, short notice up front.

It used to be the decent thing to do. As of August 2026, it's also the required thing. We're glad those line up.

The checklist: what to look for in any provider

You don't have to take anyone's word for this. Including ours.

So here's a checklist you can hold up against any AI phone provider, us included. If they can answer these plainly, they've done the work. If they go vague, that tells you something too.

  • A clear reason for handling calls. A lawful basis, with a short note on file explaining it.
  • Callers told before recording starts. Not a line slipped in afterwards.
  • Callers told they're speaking to an AI, up front. Since August 2026, that's the law, not a nicety.
  • Sensitive details kept to a minimum. Health and the like stay out of stored records, unless there's a proper consent step for them.
  • A signed data processing agreement between you and the provider.
  • A straight answer on where your data goes. And how any trip outside the EU is covered.
  • A set retention period, written down, with old data deleted automatically.
  • A simple way to handle a caller who asks to see or delete their data.
  • A written risk check, a "DPIA", where the setup needs one. Higher-risk or larger operations especially.

That's it. Nine things. A provider worth trusting can tick all nine without breaking a sweat.

Common questions

Do I need a caller's consent to record?

Not necessarily. Consent is one of six lawful bases under the GDPR, and for everyday business calls, legitimate interest often fits instead. Consent is the right choice in some settings, like marketing or sensitive data. What matters is that you pick a basis, note down why, and tell callers before recording starts.

Is a DPIA required?

Sometimes. A data protection impact assessment is a short written risk check. It's expected where a setup is higher-risk, for example new technology handling sensitive data at scale. Many small phone setups won't need one. A busy clinic might. If in doubt, doing one is rarely wasted effort.

Does my data leave the EU?

It can, and that's allowed if it's done properly. Many providers use international tools for the voice, the calls or the software, and the data travels under approved safeguards like standard contractual clauses or the Data Privacy Framework. Ask any provider for a straight answer on where data goes, and how each transfer is covered.

What if a caller mentions a health condition?

Health details are "special category" data, held to a higher bar. The safest approach is not to store them: take what's needed to book or pass on the message, and keep the sensitive part out of your records. A well-built assistant won't prompt for it, and won't file it away.

Can a caller ask to have their data deleted?

Yes. People have a right to ask you to delete what you hold on them. As the business, you handle the request, and your provider deletes its own copy on your instruction. Recordings, transcripts and summaries all count, so all of it is covered.

Still weighing it up?

The honest test of any phone assistant isn't a compliance page. It's the call itself.

Ring the Conversegy demo line and hear exactly what your callers would hear. The notice, the manner, the way it takes a message. Then judge for yourself.

Call our demo line

This page is general information about the rules, not legal advice. It reflects our understanding as of August 2026, and the law here is moving quickly, especially the new AI Act. Check your own obligations for your own business.

Last updated: August 2026.