AI and GDPR: what Italian companies need to know (and what the EU AI Act is)
An Italian company that uses artificial intelligence to manage customers and communications has to comply with two regulations: the GDPR, which governs the processing of personal data, and the EU AI Act, the European regulation that classifies AI systems by risk level and imposes proportionate obligations. In practice this means choosing tools that process data transparently, store it in the EU and are designed to respect these rules. Let’s look at what you need to know, without unnecessary jargon.
Note: this article is for informational purposes only and does not constitute legal advice. For the specific obligations of your company, consult a professional.
Why AI and GDPR have to be considered together
An AI assistant that answers customers processes personal data: names, phone numbers, emails, the content of conversations. That places it squarely within the scope of the GDPR. The key principles to respect are the same as always:
- lawfulness and transparency: the user must know they are interacting with an automated system and how their data is used;
- minimization: collect only the data you need;
- storage limitation: do not keep data longer than necessary;
- security: protect data with adequate measures;
- place of processing: pay attention to where data is processed and stored (ideally in the EU).
The most common sticking point with AI is where the data ends up: many tools process it outside the European Union, which requires additional safeguards.
What the EU AI Act is
The EU AI Act is the European Union’s regulation on artificial intelligence, the first comprehensive legal framework in the world for this technology. Its logic is risk-based: the more an AI system can impact people’s rights, the more obligations it carries. The main categories are:
| Risk level | Examples | Consequence |
|---|---|---|
| Unacceptable | Social scoring, manipulation | Banned |
| High risk | AI in healthcare, recruitment, credit | Strict obligations |
| Limited risk | Chatbots and AI assistants | Transparency obligations |
| Minimal risk | Spam filters, AI in video games | No specific obligations |
Most AI assistants for customer care fall under limited risk: the main obligation is transparency, that is, informing the user that they are talking to an automated system.
What changes in practice for a company that uses AI
In practical terms, a company that adopts a virtual assistant or a customer care software with AI should:
- Inform users that the conversation may be handled by an AI.
- Update the privacy notice to include processing via AI.
- Check where the provider processes the data (EU vs non-EU).
- Ensure human intervention where needed (escalation to an operator).
- Keep data only for as long as necessary and in a secure way.
Many of these points depend on the choice of tool: a provider designed for the European market makes compliance much simpler.
How to choose an AI that is compliant with GDPR and the EU AI Act
When you evaluate a platform, these are the right questions to ask:
- Is the data stored in the EU?
- Is the provider transparent about how it processes and protects data?
- Is there escalation to a human operator?
- Is the architecture explicitly aligned with the EU AI Act?
- Is the data exportable, with no lock-in?
These criteria apply to any company, but they are especially relevant for those operating in regulated sectors or handling sensitive data, like many B2B professional services.
Humassistant’s approach to privacy and compliance
Humassistant is designed for the European market from the ground up. Concretely:
- GDPR-native: data is stored in the EU, on Google Cloud, in the Milan data center;
- EU AI Act ready: architecture compliant with the European regulation on AI;
- transparency and escalation: the AI assistant hands the conversation over to a human operator when needed;
- no lock-in: data exportable at any time;
- Made in Italy: development, support and billing in Italian.
For the formal details you can consult the legal area and the privacy policy.
Frequently asked questions about AI and GDPR
Does using an AI assistant violate the GDPR?
No, provided you respect its principles: transparency toward the user, data minimization, security and compliant data processing (preferably in the EU). Compliance depends heavily on the tool you choose.
What is the EU AI Act in plain terms?
It is the European regulation on artificial intelligence that classifies AI systems by risk level and imposes proportionate obligations: the more a system impacts people’s rights, the more rules it has to follow.
Does an AI chatbot have to declare it is not human?
Yes. For limited-risk systems, like conversational assistants, the EU AI Act sets a transparency obligation: the user must know they are interacting with an AI.
Where must data be stored to be compliant?
The GDPR does not flatly prohibit transfers outside the EU, but it makes them subject to specific safeguards. Storing data in the EU – as Humassistant does in Milan – is the simplest and safest choice.
Want an AI for your customers that is born compliant with European rules? Discover Humassistant → – GDPR-native, data in Milan, Made in Italy. Or talk to us.
Scritto da
Francesco Sganga
Francesco Sganga is one of the founders of Humassistant, the Italian platform that centralizes email, WhatsApp, phone, chat and social into a single inbox. He writes about artificial intelligence applied to business communication, customer care and automation, always focused on the real needs of Italian SMEs.