Skip to content
Prompt Consulting
de
privacyimplementation

AI vendor data privacy: 12 questions

Twelve questions to ask an AI vendor about data privacy before you sign, with what a good and a weak answer sound like and what to test in the demo.

Thilo Krause
AI vendor data privacy: 12 questions

The demo went well. The agent read a customer email, found the order and drafted a decent reply. Then somebody asks where that email went on its way to the reply, and the vendor's answer takes longer than the demo did.

Below are twelve questions to ask an AI vendor about data privacy. Each comes with why it matters and what a good and a weak answer sound like. I build agents for companies, so this is also the list I expect a client to put to me.

I wrote it for a company that falls under the GDPR. It is not legal advice, and your data protection officer or lawyer decides what your contract needs. The legal points come from the text of the GDPR, from the European Data Protection Board's Guidelines 07/2020 on controllers and processors and its Opinion 22/2024 on sub-processors, and from the European Commission's page on EU-US data transfers.

One piece of vocabulary first. When a vendor handles personal data for your purposes and on your instructions, the GDPR calls you the controller and the vendor a processor. Article 28 then requires a contract between you, usually called a data processing agreement or DPA. Most questions ask what that contract says and whether the product matches it.

Where does our data go, and who processes it?

1. Which companies touch our data between the input and the answer?

An AI product is rarely one company. A typical agent runs on a cloud host, calls a model from a second company and may use a third for reading scanned documents. Each holds a copy of your customer's data, at least for a moment.

A good answer is a list with every company's name, what it does and where it runs. A weak answer is "everything stays in our secure cloud".

2. In which country is the data processed and stored, and does the contract say so?

A region chosen on a settings page can change with a product update, or when an overloaded data centre hands traffic elsewhere. A region written into the DPA is a commitment the vendor has to keep or renegotiate.

A good answer names the region for storage and for the model calls, and points to the clause. A weak answer is "our servers are in Frankfurt" with no word on where the model runs.

Does the vendor train AI models on our data?

3. Do our inputs and outputs train or improve any model, yours or your model provider's?

Under Article 28(3)(a) GDPR a processor handles personal data only on your documented instructions. A vendor that uses your customers' messages to improve its own product follows a purpose of its own, which is a different arrangement from the one the DPA describes.

A good answer is "No, neither we nor the model provider, and both contracts say so." A weak answer is "only to improve the service". If there is an opt-out, ask what the default is.

4. Does a person at your company or at the model provider ever read our prompts and outputs?

Some model providers keep inputs for a period to check for abuse, and some products let staff sample conversations for quality review. Either can be acceptable. You want to know before a customer's complaint sits in someone's review screen.

A good answer says who can read what, for how long, and whether you can switch it off. A weak answer is "our staff are bound by confidentiality". Article 28(3)(b) requires that anyway, and it does not tell you who reads.

How long is our data kept, and can it be deleted?

5. How long do you keep prompts, outputs, logs and backups, each counted separately?

An agent leaves copies in more places than the product screen shows. Think of the request log, the debugging trace, a cache, perhaps a search index, and the backups. One retention figure for "your data" rarely covers all of them.

A good answer is a table with a period for each location and the job that deletes it. A weak answer is "we keep data as long as necessary".

6. When a customer asks us to delete their data, how do we do that in your system?

The request reaches you, because you are the controller. Article 28(3)(e) GDPR obliges the processor to help you answer it. Help can mean an API call that takes a minute or a support ticket that takes three weeks.

A good answer shows deletion by customer ID, covering logs and any search index, with a confirmation. A weak answer is "send us an email".

Who can see our data, and what gets logged?

7. Which of your employees can open our data, and is each access recorded?

Support engineers need access sometimes. You want to hear that it is the exception and that it leaves a record.

A good answer names the roles, ties access to a support case you opened, and offers you the access log. A weak answer is "only authorised personnel".

8. If there is a breach, how fast do we hear about it, and from whom?

Article 33 GDPR gives you 72 hours after becoming aware of a breach to notify the supervisory authority, where a notification is required. The processor has to tell you "without undue delay" under Article 33(2), and that phrase is not a number. The EDPB's Guidelines 07/2020 say the contract can set a timeframe in hours and name a contact point.

A good answer is a number of hours and a named channel. A weak answer is "in line with applicable law".

Which sub-processors are involved, and does data leave the EU?

9. Can we have the current sub-processor list, and how do we learn about a new one?

Under Article 28(2) GDPR a processor may not bring in another processor without your prior written authorisation. If you gave a general authorisation, the vendor must tell you about intended changes so that you can object. The EDPB goes further in Opinion 22/2024. A controller should have the name, address and contact person of every processor and sub-processor at hand at all times, and the processor should supply them without being asked.

A good answer is a list with name, function and location for each company, notice of changes some weeks ahead, and a stated consequence if you object. A weak answer is a list that leaves out the model provider.

10. For anything processed outside the EU, which transfer mechanism applies?

Chapter V of the GDPR allows a transfer to a third country on the basis of an adequacy decision or of safeguards such as standard contractual clauses. For the United States, the European Commission adopted its adequacy decision for the EU-US Data Privacy Framework on 10 July 2023. In the Commission's words it covers companies in the United States "that participate in the Data Privacy Framework", so a vendor has to be on the list at dataprivacyframework.gov.

The General Court of the EU dismissed a challenge to that decision on 3 September 2025 (Latombe v Commission, T-553/23). An appeal was lodged at the Court of Justice in October 2025 as case C-703/25 P. The two earlier frameworks ended in that court, so ask every vendor what happens to the transfer if this one does too.

A good answer names the mechanism for each sub-processor outside the EU and has standard contractual clauses in place as a fallback. A weak answer is "the data is encrypted, so that doesn't apply".

What can the AI agent do on its own?

11. Which actions can the agent take without a person approving them, and where is that limit enforced?

An agent that emails one customer's order history to another customer has disclosed personal data, however well the storage was encrypted. Ask whether the limit sits in the instructions the model receives or in the permissions of the account the agent uses. I explain the difference in a prompt is a request, a guardrail is a wall.

Article 22 GDPR matters here too. A person has the right not to be subject to a decision based solely on automated processing if it has legal or similarly significant effects. If the agent could reject a claim or an application, ask how a person makes that decision. A review queue that people trust is part of the answer.

A good answer lists the agent's actions, shows write permissions narrower than read permissions, and sends anything external past a person at first. A weak answer starts with "the agent is instructed not to".

What happens to our data when the contract ends?

12. When we leave, what do we get back, in which format, and when is the rest deleted?

Article 28(3)(g) GDPR gives you the choice. After the service ends, the processor deletes or returns all personal data and deletes existing copies, unless the law requires it to keep them. The contract should say how many days that takes.

Ask about what is not personal data as well. The prompts, rules and test cases make the agent work, and you want them when you leave. More on that in what a ninety-day handover contains.

A good answer is an export in an open format, a deletion date that includes backups, and a written confirmation. A weak answer is "your account is deactivated".

What to ask for in the demo

A demo runs on sample data, so the answers above cost the vendor nothing to give. Ask to see them. These five requests take about ten minutes.

  1. Open the admin screen with the region and training settings, and show their defaults on a new account.
  2. Run one request, then open its log entry and show what was stored.
  3. Delete a test customer, then search for them in the product and in the logs.
  4. Ask the agent to send an email in a read-only setup, and watch what stops it.
  5. Put the DPA and the sub-processor list on the screen during the call.

Keep real customer data out of demos and trials until the DPA is signed. A free trial fed with last week's support tickets is processing of personal data like any other. After signing, the next test is a shadow run on live inputs, where the agent works on real cases and changes nothing.

The checklist to copy

AI vendor data privacy checklist

1.  Every company touching our data is named, with function and location
2.  Region for storage and model calls is in the DPA
3.  No training on our inputs or outputs, by vendor or model provider
4.  We know who can read prompts and outputs, and for how long
5.  Retention period per location: prompts, outputs, logs, caches, backups
6.  Deletion by customer ID covers logs and indexes and is confirmed
7.  Staff access is tied to a support case and recorded
8.  Breach notice within a stated number of hours, to a named contact
9.  Current sub-processor list, notice of changes, right to object
10. Transfer mechanism named for every sub-processor outside the EU
11. Permissions limit the agent's actions, a person approves the rest
12. Exit: export format, deletion date including backups, confirmation

Twelve answers give your data protection officer something to assess. Whether the system is compliant is still their call.

The AI agent examples show which systems and data each kind of agent touches. To put these questions to me, book a thirty-minute scoping call and bring the list.

All notes

Next step

Tell us what your team still does by hand.

Thirty minutes on a call. You describe the work that eats the week. We tell you whether an agent can take it and what building it would cost, including when the answer is that it cannot.

  • Built on your current stack
  • Nothing to migrate
  • Three clients at a time

Analytics and spam protection

We would like to count visits with Google Analytics, and to load Google's spam check on the contact form. Both load only if you accept. Either way we store one entry in your browser so this does not ask again, and the contact form works the same whichever you press.

What we collect, in full