Antek Automation GDPR & AI ACT · UK + EU
Download the PDF ↓ → Brand guide

GDPR & the EU AI Act — The Plain-English Guide

What Antek Automation actually needs to do, in normal words. Not legal advice — a practical map.

The one-paragraph version

Two separate EU rulebooks touch AI voice agents and chatbots. GDPR is about personal data — names, numbers, call recordings, transcripts. The EU AI Act is about the AI system itself. For a normal reception bot, lead-qualifier or website chatbot, the AI Act mostly just says "tell people they're talking to a robot." GDPR is the one with real day-to-day teeth — because every call and chat is full of personal data.


Part 1: GDPR in plain English

What it is: EU law on handling people's personal data — names, phone numbers, emails, addresses, call recordings, transcripts, CRM notes.

Why it applies to us: Every AI receptionist call and every chatbot conversation captures someone's personal data. That's GDPR's whole territory.

The key roles:

What we need to be able to hand a client, in plain terms:

  1. A Data Processing Agreement (DPA) — the contract that says how we handle their data.
  2. A subprocessor list — who else touches the data (OpenAI, Twilio, ElevenLabs, etc.).
  3. A transfer mechanism if data leaves the EU (Standard Contractual Clauses).
  4. Retention settings — how long we keep recordings, transcripts, logs.
  5. A deletion/export process — client can ask for their data back or gone.
  6. A security summary — how it's protected.
  7. Privacy notice wording they can put on their site/phone script.

Rule of thumb: minimise what you capture, delete it when you no longer need it, and never let it silently end up in a model you're training on.


Part 2: The EU AI Act in plain English

What it is: EU law on the AI system itself — what it's allowed to do, and what it has to disclose.

Who it applies to: Anyone whose AI system is used in the EU, sold into the EU, or affects someone in the EU — even if Antek itself isn't based there.

The one rule that matters for us — Article 50 (transparency):

People must be told they're talking to AI. That's it, for a normal bot.

Suggested disclosure wording:

Don't hide that it's AI behind a human-sounding name/persona.

The three risk tiers (only matters if you stray outside normal use):

TierWhat it meansWhere a normal Antek bot sits
Limited / transparencyJust disclose it's AI Receptionist, chatbot FAQ, lead capture, booking, reminders — this is us
High-riskHeavy compliance regime Only if used for HR/recruitment, credit scoring, insurance pricing, education access, emergency dispatch, law enforcement, biometrics
ProhibitedBanned outright Manipulative/deceptive AI, exploiting vulnerable people, social scoring, scraping faces into a database, emotion-reading at work/school

Bottom line: a standard AI receptionist or chatbot that answers FAQs, takes messages, qualifies leads and books appointments is not high-risk. It becomes a problem only if it starts making real decisions about someone's job, credit, insurance, education, or safety.


Part 3: ePrivacy — the quiet third rulebook

Covers call recording notices and marketing consent. Two practical points:


Part 4: What this means for Antek, practically

Build these into every deployment as default settings, not extras:

Have a standard "compliance pack" ready to hand any EU client:

  1. What the product does / doesn't do (explicit exclusion list: no HR screening, credit, insurance, emergency dispatch, biometrics).
  2. AI disclosure scripts (voice + chat).
  3. Human escalation design.
  4. Data flow diagram (caller → bot → AI/voice provider → CRM/calendar).
  5. Subprocessor list + hosting regions.
  6. Retention defaults.
  7. DPA + SCC reference.
  8. Security summary.
  9. Incident process (what happens if the bot hallucinates, misroutes, or leaks data).

Sales line that's actually true:

"AI Act-ready voice and chat automation for small businesses: clear AI disclosure, human fallback, GDPR-aware data handling, and no risky automated decisioning."

Objection handling, if a prospect worries about "the AI Act":

"It doesn't ban business chatbots or AI receptionists. For ordinary reception, FAQs, lead capture and booking, the only real requirement is telling people they're dealing with AI. The heavy rules are for hiring, credit, insurance, education, biometrics, law enforcement and emergency dispatch — categories we deliberately stay out of."

Part 5: UK version — what's different

Big point: there's no UK AI Act. UK doesn't have an EU-style horizontal AI law for ordinary receptionist/chatbot use. The real UK compliance burden is UK GDPR + PECR + Ofcom + consumer protection, not an AI-specific statute. Don't sell "UK AI Act compliant" — it doesn't exist for this use case.

Sell instead: "UK GDPR, PECR, and telecoms-aware AI receptionist implementation."

Still disclose AI at the start — not legally mandated the way the EU AI Act does it, but it's the safest default and matches EU practice.

PECR — the UK's sharpest edge (marketing calls/emails/SMS):

Data (Use and Access) Act 2025: updated UK data law — makes automated decision-making somewhat more permissive, but big/solely-automated decisions still need safeguards. Doesn't change the core rule: don't let the bot make final calls on anything legally significant.

Call recording notice (UK wording):

"Calls may be recorded and transcribed so we can handle your enquiry, keep accurate records, and improve service."

Ofcom / Calling Line ID: use real, assigned caller IDs. Never spoof numbers. Displayed number must be callable back.

Consumer protection / GEO claims: no fake reviews, no hidden incentivised reviews, no "guaranteed ChatGPT ranking" claims. CMA is actively enforcing on fake reviews.

Online Safety Act: only a real risk if a chatbot allows user-to-user content, search, or open-ended public chat. Ordinary single-business FAQ/lead-capture bots are low risk — keep them scoped that way on purpose.

UK risk table (same shape as EU, different flavour):

Use caseUK riskObligation
Inbound AI receptionistLow-mediumAI disclosure, call-recording notice, UK GDPR, human escalation
Website FAQ/lead chatbotLow-mediumAI disclosure, privacy notice, scope discipline
Appointment bookingLow-mediumLawful basis, transparency
Lead scoring for sales priorityMediumProfiling transparency, no protected-trait inference
Unsolicited outbound AI sales callsHighAvoid unless explicit consent + PECR review
Solicitor/legal chatbot giving adviceHighIntake/admin only unless legally supervised
HR screening, credit/insurance decisions, health triage, emergency dispatchHighAvoid for Antek's ICP

UK compliance pack — same 16-item shape as the EU one, plus: controller/processor role matrix, UK IDTA/UK SCC Addendum for transfers, PECR checklist, TPS/CTPS suppression-list process.

UK sales line:

"UK-ready AI receptionist and chatbot automation: clear AI disclosure, human fallback, UK GDPR-aware data handling, PECR-safe outreach, and no risky automated decisioning."

UK objection answer:

"The UK doesn't have a broad EU-style AI Act for standard business receptionists and chatbots. The real compliance issues are UK GDPR, PECR, call-recording transparency, telecoms caller-ID rules, and consumer protection. We design around clear AI disclosure, human escalation, limited data capture, sensible retention, and no high-stakes automated decisions."

If selling to both: keep EU and UK compliance packs separate — EU clients still need the EU AI Act pack even if Antek is UK-based; UK clients don't need "AI Act" language at all.


Part 6: The baseline documentation everyone needs — even "we don't really use AI"

There's a lot of fearmongering doing the rounds about the AI Act right now. One thing is genuinely true and worth taking seriously: you don't need a "certified AI Officer," but you do need baseline documentation — and "we're not sure which AI tools we use" stops being a defensible answer.

Article 4 — AI literacy (already in force, not a future date):

Why 2 August 2026 matters on top of that:

The GDPR angle the post makes well: an AI system can be low-risk under the AI Act while still being a real GDPR problem. AI phone assistants, chatbots, meeting transcription tools, CV-screening tools, and generative AI tools are the textbook examples — exactly Antek's product category. Low AI Act risk tier does not mean low data protection risk. Treat them as two separate checklists, not one.

Minimum baseline documentation every company (including Antek) should have — proportionate, not hundreds of pages:

  1. An AI tool inventory — which AI tools/models are used, by whom, for what purpose (including vendor tools like OpenAI, ChatGPT, Retell, transcription tools — not just custom-built systems).
  2. Staff AI-literacy records — evidence people using/configuring AI tools understand what they do and their risks (Article 4).
  3. Risk classification per use case — a one-line note on why each AI use sits in "limited/transparency" and not "high-risk" (see Part 2 table).
  4. Supplier/vendor due diligence — even if Antek's own system is low-risk, the upstream model/voice providers (OpenAI, Anthropic, Retell, Twilio, ElevenLabs) need to be assessed and listed. This is the "assessment and control of suppliers" point — it applies even to companies that think they "don't use AI directly."
  5. Data flow note — tied to the GDPR data flow diagram already recommended in Part 4/5.

Penalties — why this isn't optional admin:

Violation tierMaximum fine
Prohibited practices (Article 5)€35m or 7% of global turnover, whichever is higher
Other operator obligations (e.g. missing/incomplete documentation, governance failures)€15m or 3% of global turnover, whichever is higher
Misleading information to authorities€7.5m or 1% of global turnover, whichever is higher

SME/start-up fines use the same tiers but the lower of the fixed amount or percentage applies — still real money, not a rounding error.

What Antek should actually do with this:


Quick reference checklist


Key dates

DateWhat happens
2 Aug 2026EU AI Act Article 50 transparency duty (AI disclosure) becomes active
2 Dec 2026Deadline for EU-facing bots already live before Aug 2026 to add disclosure
19 Jun 2025UK Data (Use and Access) Act 2025 received Royal Assent
2 Feb 2025EU AI Act Article 4 (AI literacy) already in force — applies to every risk tier, not just high-risk

Sources (official — EU)

Sources (official — UK)

Confidence: High on the legal facts and dates (official EU and UK sources). Medium-high on how this plays out client-by-client — exact needs vary by sector, data flow, and (for UK) evolving ICO/Ofcom guidance on automated decisions and Online Safety Act scope.