If you run a clinic, salon, or trades business in Ireland and an AI receptionist answers your calls, you are the data controller under GDPR. The AI provider is your processor, acting under your documented instructions. That means you carry the compliance obligation, and choosing the wrong infrastructure or skipping the right agreements puts you in the Data Protection Commission's crosshairs. Each call an AI receptionist handles contains personal data, and by August 2026 the new AI Office of Ireland will be live as the national enforcement point for the EU AI Act, stacking a second regulatory layer on top of GDPR.
EU data residency is the safe default, and transfers add work you probably do not want
For Irish businesses, the safest operational choice for AI receptionist call data is EU-based infrastructure, because data leaving the EU triggers transfer-safeguard obligations under Chapter V of GDPR. If your AI provider stores call recordings or transcripts in the United States, you need a valid transfer mechanism: Standard Contractual Clauses, adequacy decisions, or binding corporate rules. Most small businesses do not have the legal budget to audit those mechanisms, and the Data Protection Commission has shown it will challenge big-tech transfers. Ask your provider where call data lives at rest and in transit. If the answer is AWS us-east-1 or Azure US Central, you are accepting compliance risk for convenience.
AskAndBook processes and stores call data within EU data centres, so Irish businesses avoid the transfer-safeguard burden. That is architectural, not a marketing claim. The platform routes inbound calls through EU infrastructure, transcribes them in-region, and holds recordings and transcripts on EU-resident servers. You still need an Article 28 Data Processing Agreement, but you do not need to defend a transatlantic data flow to the DPC.
Disclosure to callers is now mandatory under the EU AI Act, and recording notice must come upfront
If callers interact with an AI system, EU AI Act Article 50 requires clear disclosure in good time before the interaction continues, unless it is obvious. For a voice call, "obvious" is a high bar; most callers assume they are speaking to a person until told otherwise. The compliant pattern is a short greeting that names the AI: "Hi, this is the AskAndBook assistant for [your business name]. How can I help?" That sentence satisfies Article 50 and sets expectations.
If you record calls, callers must be informed before recording begins, and the notice should be upfront rather than buried in a privacy policy. A second-sentence disclosure works: "This call is recorded for booking accuracy." GDPR Article 6(1)(f) gives you a legitimate-interest basis for recording when it is necessary to fulfil the booking or answer the caller's question, but you still owe transparency. AskAndBook plays a configurable disclosure message at call start, and every call log shows whether the recording was active.
You might think disclosure will make callers hang up. It does not, and I have seen the call-completion data. Callers care whether their question gets answered and their appointment gets booked. Naming the AI upfront reduces mid-call friction because the caller adjusts their phrasing and stops expecting small talk.
You might think disclosure will make callers hang up. It does not, and I have seen the call-completion data.
Data minimisation and retention schedules are where most small businesses quietly fail GDPR
GDPR Article 5(1)(c) requires you to collect only the personal data adequate, relevant, and limited to what is necessary. For an AI receptionist, that means capturing the caller's name, phone number, appointment time, and the reason for the call. It does not mean logging their home address, date of birth, or payment-card details unless your service requires them. Current guidance for local businesses emphasises data minimisation: collect only the minimum form fields needed, such as name, email, and message.
Retention is the other silent failure point. GDPR Article 5(1)(e) says personal data must be kept no longer than necessary. Most Irish businesses I have spoken to have no documented retention schedule; they keep call recordings forever because storage is cheap and deletion feels risky. That is a GDPR violation waiting for an audit. One Irish AI receptionist provider publishes a clear schedule: call recordings retained up to 30 days, call transcripts up to 12 months or as directed by the client, and website enquiry data up to 24 months. You need a schedule that matches your operational need, and you need to enforce it with automated deletion.
AskAndBook enforces a 30-day rolling deletion window for call recordings and a 12-month window for transcripts unless you configure a shorter period. The system does not wait for you to remember; it deletes on schedule. That is data minimisation by design, and it is one fewer compliance task you have to track manually.
Most small businesses I have spoken to have no documented retention schedule; they keep call recordings forever because storage is cheap and deletion feels risky.
The Article 28 Data Processing Agreement is not optional, and the AI Office will check
Under GDPR Article 28, you must have a written Data Processing Agreement with any processor that handles personal data on your behalf. The agreement must specify the subject matter, duration, nature and purpose of processing, the type of personal data, the categories of data subjects, and your obligations and rights as controller. Most SaaS terms-of-service pages bury a DPA link in the footer; you need to find it, read it, and confirm it covers your use case.
The AI Office of Ireland opens on 2 August 2026 as an independent statutory body, and it will coordinate AI regulation and serve as the national point of contact under the EU AI Act. That office will have enforcement powers, and it will ask to see your DPA when it audits your AI systems. If you cannot produce one, you are in breach of Article 28, and the fines for GDPR non-compliance run to €20 million or 4% of worldwide annual turnover, whichever is higher. For EU AI Act non-compliance, fines reach €15 million or 3% of worldwide annual turnover.
AskAndBook provides a signed Article 28 DPA as part of onboarding. It is not an optional add-on; it is built into the account setup flow. The agreement names AskAndBook as processor, you as controller, and specifies that call data is processed solely to answer calls, book appointments, and capture leads. You get a countersigned copy before the first call goes live.
A compliant AI receptionist setup has six components you cannot skip
According to published guidance from AI receptionist providers, a GDPR-compliant setup should include EU data processing, a written Article 28 Data Processing Agreement, AI disclosure to callers, recording notice, data minimisation, and an enforced deletion schedule. Those six components are the minimum; they are not best-practice extras.
AskAndBook ships all six by default. Call data stays in the EU. The DPA is signed at onboarding. The AI introduces itself by name at call start. Recording disclosure plays in the greeting. The system captures only the fields you configure in your knowledge base and booking forms. Deletion runs on a 30-day schedule for recordings and 12 months for transcripts, or shorter if you set it. You do not have to build compliance; you configure the business logic (your FAQ, your calendar, your transfer rules) and the platform handles the regulatory layer.
The platform answers your inbound calls in a natural voice, in English or switching mid-call to other languages. It answers questions from your knowledge base, books appointments into Cal.com or Google Calendar (on the Pro and Business plans), captures and qualifies leads, and transfers to a human when needed. The Pro plan includes analytics, email summaries, sentiment analysis, and smart transfer. The Business plan adds webhook integration so bookings post directly into your CRM. There is no per-user fee; you pay one monthly plan plus any minutes used beyond your included pool.
AskAndBook will not replace a human for empathy-heavy calls where a caller is distressed or needs reassurance beyond facts. It will handle the 80% of inbound calls that are appointment requests, FAQ questions, and lead capture, and it will do that work while keeping your data inside the EU and your compliance file ready for the AI Office.
Frequently Asked Questions
Do I need a Data Protection Impact Assessment for an AI receptionist?
GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to individuals' rights and freedoms. For most small businesses, an AI receptionist answering calls and booking appointments does not meet that threshold because you are not processing special category data (health, biometric, genetic), you are not doing large-scale monitoring, and you are not making automated decisions with legal or similarly significant effects. If you run a medical practice and the AI captures symptoms or medical-aid numbers, you should complete a DPIA because health data is special category under Article 9.
Can I use a US-based AI receptionist provider if they have Standard Contractual Clauses?
Legally, yes, if the provider has signed the European Commission's Standard Contractual Clauses and you have completed a transfer impact assessment under Schrems II. In practice, that assessment requires you to evaluate whether US surveillance laws allow your provider to protect the data adequately, and most small businesses do not have the legal resources to do that analysis credibly. EU-based infrastructure removes the problem.
What happens if a caller asks me to delete their call recording?
Under GDPR Article 17, individuals have a right to erasure when the data is no longer necessary, the individual withdraws consent, or the data was unlawfully processed. If a caller asks you to delete their recording, you must honour the request unless you have an overriding legitimate interest (for example, the call contains evidence of a contract dispute). Your AI receptionist platform should let you delete individual call recordings on demand; if it does not, you cannot comply.
Does the EU AI Act classify an AI receptionist as high-risk?
No. The EU AI Act Annex III lists high-risk AI systems, and they include biometric identification, critical infrastructure management, educational or vocational training scoring, employment decisions, and law enforcement. An AI receptionist that answers calls and books appointments does not fall into those categories. You still owe the Article 50 transparency obligation (disclosing that the caller is interacting with an AI), but you do not face the conformity assessment, registration, and monitoring requirements that high-risk systems carry.
If I use AskAndBook, who is responsible if there is a data breach?
You are the data controller, so you carry the primary obligation to notify the Data Protection Commission within 72 hours of becoming aware of a breach (GDPR Article 33) and to notify affected individuals if the breach is likely to result in a high risk to their rights (Article 34). AskAndBook, as processor, is required under Article 28 to notify you without undue delay after becoming aware of a breach. The DPA specifies the notification procedure. In practice, if the breach originates in AskAndBook infrastructure, the AskAndBook team will notify you immediately and provide the details you need for your DPC notification.
Can I record calls without asking for consent every time?
Yes, if you have a legitimate interest under GDPR Article 6(1)(f) and you disclose the recording upfront. Booking accuracy, quality assurance, and dispute resolution are recognised legitimate interests. You do not need explicit opt-in consent for every call, but you must tell the caller the call is recorded before recording starts, and you must document your legitimate-interest assessment. If the caller objects, you should stop recording or offer to continue the call unrecorded.
The AI Office of Ireland goes live in five weeks, and it will ask to see your Data Processing Agreement, your retention schedule, and your disclosure scripts. If you are running an AI receptionist today without those three documents, you are exposed. AskAndBook gives you all three by default, processes your call data inside the EU, and enforces deletion on schedule. Hear it answer your calls.



