The checklist at a glance
- Data processing agreement (DPA) under Art. 28 GDPR signed with the provider.
- Processing on servers in Germany or the EU – no third-country transfer without a basis.
- Legal basis clarified (e.g. pre-contractual steps or legitimate interest); consent where required.
- Transparent information for customers in your privacy policy.
- Record of processing activities updated.
- Deletion and retention periods defined.
- For messenger channels: documented consent so you can use WhatsApp in the dealership, GDPR-compliant.
- Technical and organisational measures (encryption, access control) documented.
This checklist is guidance, not legal advice. Confirm your specific use case with your data protection officer.
The data processing agreement: the most important element
As soon as a provider processes personal data on your behalf – which any AI answering customer inquiries does – you need a data processing agreement. It governs what happens to the data and records that you, the dealership, remain the controller.
Ask every provider whether they supply a DPA under Art. 28 GDPR. If they don't, use in the dealership isn't legally sound.
Processing location and subprocessors
Where the data is processed is a decisive point. Processing on servers in Germany avoids the uncertainties of a third-country transfer. Also ask to be shown which subprocessors are involved – transparency here is a good sign of a reputable provider.
For a practical example, see the GDPR-compliant AI chatbot for dealerships; the technical details are documented in the Velyx Trust Center.



