Home›Blog›Article 28 GDPR: What Irish Businesses Must Check Before Using an AI Receptionist
GDPR & Compliance

Article 28 GDPR: What Irish Businesses Must Check Before Using an AI Receptionist

SO
By AI Receptionist Ireland
·October 2026·10 min read

Article 28 of the General Data Protection Regulation is one of the most practically important provisions for Irish businesses using cloud-based services, yet it remains one of the least understood. It deals specifically with the relationship between a Data Controller, which is your business, and a Data Processor, which is any external supplier that handles personal data on your behalf. Any automated call answering service that captures caller names, phone numbers, and messages is a Data Processor. Article 28 sets out exactly what must be in place before you hand them that data.

The core requirement is a written Data Processing Agreement. Not a vague reference to privacy practices buried in terms and conditions, but a specific, legally binding contract that addresses a defined list of obligations. Getting this right protects your business from both regulatory scrutiny and the practical consequences of a supplier relationship that goes wrong.

What Article 28 Requires

The regulation specifies that the contract between you and your Processor must address several mandatory elements. The Processor must only process data on your documented instructions. They must ensure that all staff authorised to process the data are bound by confidentiality obligations. They must implement appropriate technical and organisational security measures. They must assist you in responding to data subject rights requests, such as when a caller wants to know what data was captured about them. They must delete or return all personal data at the end of the service relationship. And critically, they must make available all information necessary to demonstrate compliance with these obligations.

Sub-Processor Obligations Under Article 28(2) and 28(4)

Articles 28(2) and 28(4) extend the requirements beyond the immediate supplier relationship. Your Processor is not permitted to engage a Sub-Processor without your prior written authorisation. When they do engage Sub-Processors, they must flow down the same data protection obligations to those Sub-Processors by contract.

In the context of an automated call answering service, Sub-Processors are the underlying technology providers: the platform that handles voice transcription, the telephony infrastructure that routes the call, and the automation tools that deliver the transcript to your inbox. Each of these must be named in a Sub-Processor Schedule, and the same Article 28 obligations must flow down to each of them through their own contractual agreements with your primary provider.

This chain of contractual accountability is not a technicality. If a Sub-Processor suffers a breach and your primary provider cannot demonstrate that adequate flow-down protections were in place, the compliance failure lands back at your door as the Data Controller.

Compliance Checklist for Article 28

Before using any AI call answering service, confirm that a written DPA is executed, a complete Sub-Processor Schedule is available, flow-down obligations are contractually in place, and the Processor can provide documentation on request. Missing any one of these creates a structural gap in your compliance posture.

Practical Steps for Irish Businesses

Before deploying an automated receptionist, request and review the Data Processing Agreement from your provider. Check that it explicitly addresses each of the mandatory Article 28 elements rather than referencing them generically. Ask for the Sub-Processor Schedule and verify that every platform in the chain is named along with their location and the transfer mechanism in use for any non-EEA processing.

If your provider cannot produce a complete DPA and Sub-Processor Schedule on request, that itself is a significant red flag. A provider that processes personal data on behalf of Irish businesses and cannot demonstrate Article 28 compliance is not a provider that should be trusted with your customers' call data.

The No-Training Confirmation

One element that goes beyond the strict text of Article 28 but is increasingly expected by Irish businesses, particularly those in regulated sectors, is a No-Training Confirmation. This is a written assurance from the provider that no call data processed through their service is used to train, fine-tune, benchmark, or improve any AI model, whether belonging to the provider itself or any of its Sub-Processors.

Without this confirmation, you cannot guarantee that sensitive caller conversations are not contributing to the development of AI systems you have no visibility into. The GDPR's purpose limitation principle under Article 5 strongly supports obtaining this assurance as a matter of routine.

Want to see our Article 28 documentation?

We provide a full compliance pack including our DPA, Sub-Processor Schedule, and No-Training Confirmation to all clients on request. Book a call and we will walk you through it.

Book a Free Demo

Article 28 compliance is not optional. It is a baseline requirement that applies to every Irish business using any form of cloud-based data processing. Understanding what must be in your Data Processing Agreement, what Sub-Processor obligations must flow down, and what additional assurances like a No-Training Confirmation provide gives you the practical foundation to deploy an automated receptionist confidently and compliantly. Review our full compliance documentation on our GDPR compliance page, or book a free demo to speak directly with the team.

This article provides general educational information about Article 28 of the GDPR and Data Processing Agreements. It does not constitute legal advice. Please consult a qualified data protection advisor for guidance specific to your business circumstances and regulatory obligations.