GuideGDPR and compliance
Mailatio

GDPR and AI at the firm: the documents to demand before signing.

Plugging an AI into a firm's email means entrusting the processing of personal data — often sensitive — to a processor. The GDPR regulates this situation precisely, and a serious vendor must be able to produce three documents before signature.

1. The data processing agreement (Article 28)

This is the central document: it defines what the provider is allowed to do with the firm's data, the security measures, the retention period, what happens to the data at the end of the contract and the audit conditions. Without a signed data processing agreement, the firm is at fault — not just the vendor.

2. The record of processing activities (Article 30)

The vendor must describe the processing it carries out on your behalf: which data, for which purposes, which recipients, for how long. This record feeds into your own — the firm remains the data controller for its own record.

3. The impact assessment (Article 35)

A firm's email contains data covered by legal professional privilege, often health, criminal or financial data. Large-scale automated processing of these categories warrants a data protection impact assessment (DPIA). Ask for it: its quality says a lot about how serious the vendor is.

The awkward questions — ask them anyway

At Mailatio, these three documents are handed over at signature, hosting is in the European Union and firms' data never trains models.

The complete GDPR pack, handed over at signature.