Updated on 28 Sep 2026

You're a plumber on a job. Phone rings. Your AI receptionist picks up, takes the caller's name, grabs their postcode, books them in for Thursday. Useful, efficient, and from a data protection standpoint, it just processed personal information on your behalf.

That's the tension with AI and GDPR. The technology is fast, convenient and increasingly good at sounding human, but every call your AI receptionist answers involves data – names, phone numbers, email addresses, and sometimes health details or financial queries. UK data protection law has clear rules about how that data is collected, stored and used.

The good news? Using an AI receptionist is entirely GDPR-compliant. The regulations don't ban AI from answering your phone – they just require you to handle the data properly. This means understanding what your provider does with caller information and making sure the right safeguards are in place.

What counts as personal data on a phone call?

More than you'd think. Under UK GDPR, personal data is any information that can identify a living person, directly or indirectly. On a typical business call, that includes the caller's name, their phone number, their email address and any details they share about their situation.

Voice recordings add another layer. A person's voice is considered biometric data, which falls under the GDPR's "special category" rules and requires stronger protections. If your AI receptionist records calls, that voice data needs explicit handling.

Even a post-call summary that pairs a name with a query ("Sarah called about a leak at 14 Elm Street") counts as personal data. The moment information can be traced back to a specific person, GDPR applies.

The 6 GDPR rules that apply to AI receptionists

UK GDPR is lengthy, but when it comes to an AI receptionist handling your business calls, 6 requirements do most of the work. Get these right and you're covering the ground the ICO expects.

You need a lawful basis for processing

Every time your AI receptionist collects personal information, you need a legal reason for doing so. Article 6 of the UK GDPR lists the options, and for most businesses answering customer calls, "legitimate interests" is the most appropriate basis. You're running a business, customers are calling you and you need to handle their enquiries. That's a legitimate interest.

If your AI receptionist records calls, the picture changes. Call recordings often require explicit consent as the lawful basis, because you're capturing voice data that goes beyond what's strictly necessary to handle the enquiry. Providers that don't record calls sidestep this issue entirely.

Callers need to know they're speaking to AI

The ICO is clear on this. If a caller is interacting with an AI system rather than a human, they should be told. Transparency is shown in Articles 13 and 14 of the regulation.

This usually means the AI identifies itself at the start of the call. A short, natural statement is enough.

Only collect what you need

Data minimisation sounds bureaucratic, but the principle is straightforward – don't collect information you have no reason to hold. If your AI receptionist is booking a plumbing callout, it needs the caller's name, contact details and a description of the problem. It doesn't need their date of birth.

Good AI receptionist platforms let you configure exactly what information the AI asks for. That control is worth using, because collecting less data means less data to protect and worry about if something goes wrong.

Define how long you keep data

UK GDPR doesn't set a fixed retention period. It requires you to define one, document your reasoning and stick to it. Call summaries, contact details and any other personal data your AI receptionist collects should have a clear expiry date.

For many businesses, 6 to 12 months is a sensible baseline for call records. The point is to avoid holding data indefinitely "just in case". If you don't need it, delete it.

Sign a data processing agreement with your provider

Your AI receptionist provider is a data processor because they handle personal data on your behalf. Article 28 of UK GDPR requires a written agreement between you (the data controller) and them, covering what data is processed, how it's secured, what happens to it when you stop using the service and whether any sub-processors are involved.

Reputable providers supply this as standard. If a provider can't produce a data processing agreement, that's a red flag worth paying attention to.

Carry out a data protection impact assessment

A data protection impact assessment (DPIA) isn't always legally required, but the ICO recommends one whenever you're deploying new technology that processes personal data at scale. An AI receptionist answering your business calls fits that description.

A DPIA doesn't have to be complicated. It documents what data the system collects, the risks to callers, the safeguards you've put in place and whether the processing is proportionate to what you're trying to achieve. Think of it as a written record showing you've thought this through.

Where most businesses get it wrong

The regulations themselves aren't especially complicated. The mistakes tend to happen around the edges.

Not checking where data is stored is a common one. If your AI provider routes caller data through servers outside the UK, you may need additional safeguards like Standard Contractual Clauses. Ask the question before you sign up.

Ignoring retention policies is another. It's easy to assume call summaries will be handled automatically, but if your provider stores data indefinitely by default and you haven't set a retention window, you're holding personal data longer than you can justify.

Then there's the training data question. Some AI providers use customer interactions to train their models. If caller data from your business is being fed into a third-party AI model without callers' knowledge, that raises serious GDPR concerns. It's worth asking your provider directly – do you use my customers' data to train AI models?

And finally, skipping the paperwork. A surprising number of businesses adopt AI tools without updating their privacy policy, without completing a DPIA and without signing a data processing agreement. These aren't optional extras. They're the documentation the ICO expects to see.

What to ask your AI receptionist provider before you sign up

Before committing to any provider, put these questions to them. The answers will tell you whether they've built their product with GDPR in mind or bolted compliance on as an afterthought.

  • Does the AI identify itself as non-human at the start of each call? 
  • Are calls recorded, and if so, how is consent handled? 
  • Where is caller data stored? In the UK, within the EEA or elsewhere? 
  • How long is data retained, and can you configure the retention period? 
  • Will you provide a data processing agreement? 
  • Do you use customer data to train AI models? 
  • What happens to data when a business cancels the service?

If any of those questions get a vague answer, keep shopping. Providers that take GDPR seriously tend to answer them upfront, often before you even ask. You can compare the best AI receptionists in the UK to see how leading providers stack up on security and compliance alongside features and pricing.

How Fasthosts AI Receptionist handles GDPR

Fasthosts AI Receptionist is designed with GDPR compliance built in. Calls are not recorded, and only the call summary and basic metadata are retained after a call completes. Customer data is also not used to train AI models.

Because there are no voice recordings, the complications around biometric data and explicit consent for recording don't apply. The AI identifies itself during calls, and businesses can configure what information the receptionist collects from callers, supporting the data minimisation principle.

Fasthosts is a UK-based company with data centres in the UK, which simplifies the question of international data transfers. And for businesses that want to understand how the product works before making a decision, a 1-month free trial is available across all packages.

Frequently asked questions

Yes. GDPR doesn't prohibit AI from handling phone calls or processing personal data. It requires that you do so lawfully, with a valid legal basis, appropriate transparency and proper safeguards in place. Choosing a provider that handles data responsibly puts you on solid ground.

Not necessarily. For answering business calls, "legitimate interests" is typically the appropriate lawful basis rather than consent. However, if your AI receptionist records calls, you’ll likely need explicit consent for the recording itself. Providers that don't record calls, like Fasthosts, avoid this requirement.

Do callers have to be told they're talking to AI?

Yes. The ICO expects businesses to be transparent about the use of AI in communications. In practice, this means the AI should identify itself near the start of each call. Most well-designed AI receptionists do this automatically.

Can the ICO fine me for using an AI receptionist?

The ICO doesn't fine businesses for using AI technology. It fines businesses for failing to comply with data protection law. If you process caller data lawfully, with proper documentation and appropriate safeguards, the technology you use to do it is not the issue.

How long can I keep data from AI receptionist calls?

UK GDPR doesn't specify a fixed period. You need to define a retention window that's proportionate to your business needs, document your reasoning and ensure data is deleted when the period ends. For many businesses, 6 to 12 months is a reasonable starting point for call records.