AI and the GDPR: what you as an SME owner actually need to arrange
You remain the controller: the AI vendor is a processor acting on your instructions. You need a data processing agreement, a lawful basis for the processing, and a threshold above which a human decides. That last one is not a courtesy but article 22 GDPR.
Published on
Who is responsible for what?
The first question that often gets answered wrongly: who is in charge of the data? The answer is almost always you, not your vendor. You determine why and how the data is processed — that makes you the controller. The vendor carries out what you instruct and is therefore the processor.
That is not a formality. It determines who must report a data breach, who answers a customer requesting their data, and who is held to account when something goes wrong. In all three cases, that is you.
| What | Who | What that means in practice |
|---|---|---|
| Determining purpose and means | You (controller) | You decide what work the AI does and with which data |
| Carrying out the processing | Vendor (processor) | Only within your instruction, recorded in a processing agreement |
| Reporting a breach to the regulator | You | Within 72 hours; the processor notifies you without undue delay |
| Answering a data subject request | You | The processor must be able to help you do so |
| Engaging sub-processors | Vendor, with your authorisation | Ask which parties those are and where they run |
The line above which a human must decide
An AI that drafts answers and schedules appointments is doing executing work. The moment it makes decisions that affect someone, that changes. Article 22 GDPR prohibits, as a rule, decisions based solely on automated processing that significantly affect someone.
The Dutch implementation act carves out an exception in article 40, but only in narrowly described cases: where the decision-making is necessary to comply with a legal obligation or for a task carried out in the public interest, and explicitly not on the basis of profiling. For most SME use cases that means: let the AI prepare and complete the work, and keep a human in the loop the moment a decision genuinely affects someone.
In practice this is manageable. Cancelling an order, changing an address or booking an appointment are not decisions within the meaning of article 22 — that is carrying out what was already agreed. Rejecting a request or prioritising someone based on a profile is.
How long may you keep it?
Two retention rules run into each other and that causes most of the confusion. The GDPR says: no longer than necessary for the purpose. The tax retention obligation says: some records you must in fact keep for years. Those two do not contradict each other; they concern different data.
The Dutch Tax Administration states that to determine the start of the retention period you use the current value of a record: as long as records remain current they belong to the administration, and only once that current value lapses does the period begin. So a four-year contract is kept for four years plus seven.
That does not apply to the messages an AI processes: that is customer contact, not administration. Those may — and should — have a much shorter retention. The invoice arising from that contact does stay in your books.
What you concretely need to arrange
Four things, and none of them is a big job:
- A data processing agreement with your vendor, setting out what is processed, for what purpose, for how long and with which sub-processors.
- A lawful basis for the processing. For customer contact that is usually performance of a contract or legitimate interest — record which one you rely on.
- A recorded limit on what the AI may decide on its own, with a human above it.
- A retention period for the messages themselves, separate from your tax administration.
This article is not legal advice and does not replace an assessment of your own situation. What it does do: sharpen the questions you should be asking a vendor before switching anything on.