Skip to content
Novot AI
NLBook a call

REFERENCE

Knowledge base

What the GDPR and the AI Act ask of you when you deploy AI in your business. In plain language, with the legal articles and the source included, so you can check everything yourself. Grouped by theme, with the date each article was published or last revised.

Starting with the GDPR

If you let AI handle customer contact, you are processing personal data. These articles cover what has to be in place for that: a lawful basis, a processing agreement, a record and sometimes a DPIA.

Customer rights and incidents

A customer requests their data, wants it erased, or something goes wrong. What is expected of you then, and within which deadline.

The AI Act

The European AI Act arrives in stages. Which part applies from when, which risk category your system falls into, and what you have to tell your customers.

Retention and deletion

How long you may keep customer conversations, and how the retention obligation fits with the duty to store as little as possible.

By channel: email, WhatsApp and phone

Every channel has its own rules. What is allowed by email is therefore not automatically allowed on WhatsApp or over the phone.

By sector

Professional secrecy, consumer law and supervision differ per industry. Find the sector you work in here.

Staff and security

What your staff need to know, what an AI may and may not see of their conversations, and what has to be in place technically before you go live.

Figures

How many Dutch SMEs use AI and what for, with the CBS and Eurostat figures included.

See what Novot AI can do for your business.

Book a call