HR Tech

Conversational AI and GDPR: An HR Buyer Checklist

Evaluate conversational AI for HR with a practical evidence checklist covering data flows, access, retention, international transfers, and employee trust.

By Rachel FosterAutomated, source-grounded editorial method5 min read
Share
Conversational AI and GDPR: An HR Buyer Checklist

Short answer

Assess a conversational AI tool against the specific employee-data use case, rather than a compliance badge. Map what it collects, where information travels, who can access it, and when it is deleted. Ask your privacy and security leads to assess the legal basis, transfer arrangements, and risks before inviting employees. A hosting location or consent screen alone is not proof of compliance.

Start with the work decision

A tool answering a benefits question, a conversation preparing a manager review, and a system used to evaluate workers have different purposes and consequences. Write down the intended use before comparing vendors. The conversational AI for HR guide separates these categories.

Use this article as a procurement worksheet. Your data protection lead or counsel should assess the applicable rules for the deployment; it is not a legal opinion or a certification of any vendor.

Ask the project owner to complete this sentence: “We need employees to describe ___ so that ___ can decide ___.” If the blanks remain vague, the project is not ready for a meaningful data review.

Four assumptions to challenge

EU hosting is not a complete compliance assessment. The European Commission describes adequacy decisions that permit transfers to destinations outside the EU within their scope. Check the actual parties and processing, rather than treating every overseas transfer as prohibited.

The UK needs its own transfer assessment. The ICO's international transfer guidance covers adequacy, appropriate safeguards, and exceptions. Ask which route applies to each relevant transfer, including access by a separate overseas provider. Do not assume an EU arrangement automatically answers the UK question.

A consent checkbox does not settle the lawful basis. The ICO's worker-monitoring guidance explains that employment power imbalances often make consent unsuitable. It also calls for a justifiable retention schedule, not a universal deletion period measured in hours.

A small pilot can still need careful assessment. The ICO's DPIA guidance requires an impact assessment for processing likely to result in high risk. Use its screening approach with the privacy lead; participant count alone does not decide the question.

The evidence worksheet

The table below is a suggested working record. The roles are starting points to adapt to your organisation, and the evidence is something to request and verify, not a claim about any particular product.

Review questionEvidence to requestSuggested owner
What decision will the conversation support?A written purpose, intended outputs, and uses excluded from the pilotHR or Operations
What information enters and leaves the system?A diagram covering input, transcription if used, inference, storage, logs, and support accessSecurity and vendor
Who processes it, and in which locations?Named providers, sub-processors, processing locations, and the relevant agreementsPrivacy and procurement
What does each role actually see?A demonstration using fictional employee, manager, and HR accountsProduct owner
What remains after deletion?Settings and an explanation of deletion across outputs, logs, backups, and exportsSecurity and vendor
What might an employee disclose unexpectedly?A documented route for sensitive information and complaintsPrivacy and HR
Can a person correct or challenge an output?A worked example of correction, review, and escalationHR and vendor
What will the employee be told?A short notice checked against the demonstrated behaviourPrivacy and communications

Record each answer as verified, unresolved, or outside scope, together with the document or demonstration that supports it. A polished answer without evidence should stay unresolved. Where a gap matters to the proposed use, narrow the pilot or resolve it before collecting real employee information.

A fictional UK-and-EU pilot

Imagine a company evaluating a guided conversation to prepare an upcoming manager check-in in one UK team and one EU team. Procurement receives a statement that storage is in Europe, but no explanation of transcription, model processing, or support access.

The team uses fictional conversations for the first demonstration. Security asks the vendor to complete the data-flow map. The privacy lead reviews the two deployment contexts and records the required assessment. HR checks the manager view and discovers that its draft employee notice described access differently from the demonstration.

The useful result is a list of concrete gaps to close. The company corrects its notice, confirms the intended access settings, and assigns owners for the unresolved processing questions. The example does not establish that a particular country, provider, or design is compliant; it shows how procurement can replace assumptions with evidence.

Make the employee explanation testable

Before invitations go out, rehearse the explanation with someone outside the project:

  • What is the conversation for?
  • Who can see the original response and the resulting brief?
  • What happens if the output is incomplete or wrong?
  • Which subjects belong in a separate support or reporting channel?
  • Where can the employee ask questions about their information?

Avoid promising anonymity simply because names disappear from a summary. Describe the actual access arrangement. Treat a small-group threshold as one safeguard to examine, not an automatic guarantee that a person cannot be identified.

Where Lontra belongs in the evaluation

Lontra is relevant when the operational need is to prepare a human conversation from current work context or capture a practice for expert review. It should go through the same evidence worksheet as any other vendor. This article makes no claim about a specific hosting configuration, certification, retention period, or transfer arrangement.

For a concrete product scenario, view the fictional manager-preparation example. Use it to frame the desired outcome, then ask for the documentation and product demonstration needed for your own deployment.

Frequently asked questions

Does GDPR require conversational AI to run only in the EU?

There is no blanket EU-only hosting rule. International transfers need an applicable legal route and assessment of the actual processing. EU hosting alone does not establish compliance.

Does an employee consent screen make an HR AI tool compliant?

No. The organisation must assess the lawful basis and the use case. In employment, a power imbalance can make consent inappropriate. The employee notice and actual product behaviour must also agree.

What should HR request before a pilot?

Request the data-flow map, processing agreement, sub-processor information, access rules, retention settings, and an explanation employees can understand. Assign privacy, security, and operational owners to review the evidence.

Apply this question to your organization

Choose one team and a concrete work question. Explore how Lontra can help prepare conversations and review what people describe before deciding on an action.

More from Blog