The technology is neither compliant nor non-compliant. Your deployment is one or the other, and it comes down to decisions you make rather than to conversational AI as a category.
This is not legal advice. It is the set of questions I would want answered before putting an agent in front of customers, and the ones a serious partner should answer without being chased.
Where is the data processed
The first question, and the one with the clearest practical consequence.
UK or EU processing is materially simpler to reason about than US processing. Not impossible either way, but the paperwork and the internal argument are different, and it is worth knowing before you are three weeks from launch.
Ask specifically where the model runs, where transcripts are stored, and whether either changes depending on load.
What is retained, and by whom
There are usually two separate answers here and people conflate them.
What your agent platform stores, meaning transcripts, customer records, conversation history. And what the model provider stores, which is a different company with different terms.
Enterprise tiers from the major providers offer zero-retention modes built for exactly this concern, where prompts are not stored and not used for training. Consumer tiers often do not. That distinction matters more than almost anything else in this list, and it is settled in a contract rather than in a settings panel.
What the agent is allowed to say
An agent with read access to your CRM can, in principle, read out anything in the record.
So identity verification is not a nice touch, it is the control that stops someone getting another person's details by claiming to be them. What does the agent require before it discusses an account. What does it refuse to say even after verification. Is there a category of data it simply never touches.
Those should be explicit rules, not emergent behaviour.
Can you delete it
If a customer exercises their right to erasure, you need to find every trace of that conversation and remove it.
That means knowing where transcripts live, what the retention period is, and whether the model provider holds a copy. If nobody can answer that in a sentence, it has not been designed for.
The practical read
Most of this is settled in the contract and the architecture rather than in the conversation design, which is why it should be discussed early rather than at legal review.
A partner who talks fluently about hosting, retention, verification flows and deletion without being prompted has done it before. One who gets vague precisely where the specifics live has not, and that hesitation is the most useful thing you will learn in the call.
Get your own legal advice on your specific situation. What I would push back on is the idea that this is a blocker. It is a set of decisions, and they are all answerable.
