GDPR
The General Data Protection Regulation (GDPR) is the European Union data protection law that governs how organizations collect, use, share, secure, retain, and delete personal data.
The GDPR applies through defined territorial and processing rules, including to some organizations outside the European Union. It distinguishes between a controller, which determines why and how personal data is processed, and a processor, which handles data on the controller's instructions. A business can hold different roles for different processing activities.
Personal data is broader than a name or email address. In a phone workflow, it can include a number, voice recording, transcript, account identifier, call metadata, or any combination that identifies or can be linked to a person. Information about health and certain other sensitive subjects can fall into special categories with additional conditions.
What the GDPR requires in practice
An organization needs a valid lawful basis for each processing purpose and clear information for the people whose data it handles. Consent is one possible basis, but it is not the only one and should not be presented as the automatic answer for every call. The organization must also address data minimization, accuracy, security, retention, individual rights, processor oversight, and applicable rules for international transfers.
For an AI phone agent, this starts with a data-flow map. Teams should identify what the agent collects, which call artifacts are created, what tools and integrations receive them, where people can exercise their rights, and when each copy is deleted. The purpose should be specific: data collected to schedule an appointment should not silently become an unrestricted marketing profile.
A Data Processing Agreement commonly governs a processor's handling on the controller's behalf. That contract does not replace the controller's lawful basis, privacy notice, or instructions, and it does not resolve every cross-border transfer question. Recording and automated-interaction disclosures may create separate obligations under other rules.
In practice on ThunderPhone
ThunderPhone's public posture is GDPR and HIPAA compliant. Customers remain responsible for configuring their workflows, data handling, recordings, integrations, and notices for their own obligations.