The checklist at a glance

  • Data processing agreement (DPA) under Art. 28 GDPR signed with the provider.
  • Processing on servers in Germany or the EU – no third-country transfer without a basis.
  • Legal basis clarified (e.g. pre-contractual steps or legitimate interest); consent where required.
  • Transparent information for customers in your privacy policy.
  • Record of processing activities updated.
  • Deletion and retention periods defined.
  • For messenger channels: documented consent so you can use WhatsApp in the dealership, GDPR-compliant.
  • Technical and organisational measures (encryption, access control) documented.

This checklist is guidance, not legal advice. Confirm your specific use case with your data protection officer.

The data processing agreement: the most important element

As soon as a provider processes personal data on your behalf – which any AI answering customer inquiries does – you need a data processing agreement. It governs what happens to the data and records that you, the dealership, remain the controller.

Ask every provider whether they supply a DPA under Art. 28 GDPR. If they don't, use in the dealership isn't legally sound.

Processing location and subprocessors

Where the data is processed is a decisive point. Processing on servers in Germany avoids the uncertainties of a third-country transfer. Also ask to be shown which subprocessors are involved – transparency here is a good sign of a reputable provider.

For a practical example, see the GDPR-compliant AI chatbot for dealerships; the technical details are documented in the Velyx Trust Center.