Customer service SaaS GDPR: How to choose and use a truly compliant tool?

Customer service software probably holds some of the most sensitive personal data in your organization after payroll.

Customer service software probably holds some of the most sensitive personal data in your organization after payroll: contact details, purchase histories, conversations, attachments, complaints, and sometimes health or financial information volunteered by a customer in a free-text field. And one misconception is widespread: choosing a "GDPR-compliant" vendor does not transfer your responsibility to that vendor. Here is what you need to check in the product, the contract, and your own practices.

 

Customer service SaaS GDPR: Who is responsible for customer data?

 

The user company is generally the data controller.

 

This is the starting point for the entire process and the one procurement teams most often underestimate. In its guidance published on 28 May 2026 on the qualification of cloud computing actors, the CNIL sets out the following principle: as a general rule, the customer is the controller for the processing it carries out on the cloud service, because it determines the purposes and essential means. It chooses its provider and decides what data is processed, how the service is configured, what is deleted, and what is backed up.

 

The example given by the CNIL applies directly to customer service: a company that uses a CRM to track its customers is the data controller, while the CRM provider is its processor.

 

The SaaS vendor is a processor, except for its own processing

 

The vendor acts as a processor when it performs operations on your data according to your instructions. But the qualification is not monolithic: the same provider may be a controller for certain operations it decides on alone, for example, using usage data to improve its product, or a joint controller when the improvement benefits both parties and the arrangements are defined jointly.

 

The CNIL also points out that qualification depends on the facts, not on a contractual choice: signing a DPA that designates the vendor as a processor is not enough if the reality of the relationship is different.

A picture of a lock on a keyboard picturing data security through GDPR

Customer service SaaS GDPR: what data should you map before deployment?

What actually flows through a customer service tool?

 

  • last name, first name, contact details, and customer ID;
  • conversations by email, chat, WhatsApp, social media, or phone;
  • tickets, internal notes, and advisor comments;
  • attachments provided by the customer;
  • order, contract, or subscription history;
  • technical data, connection logs, and metadata;
  • call recordings or transcripts, where applicable;
  • information volunteered in a free-text field.

The last point is the most delicate and is specific to support. A dissatisfied customer may voluntarily mention a health issue, financial difficulty, or family situation that you never intended to collect. This data still falls within your scope of responsibility. Provide explicit instructions for advisors and a procedure for purging free-text fields.

Customer service SaaS GDPR: clauses to check in the contract and DPA

 

The processing agreement required by Article 28

 

The relationship between controller and processor must be governed by a written contract or another legally binding act. The CNIL also recommends paying particular attention to the choice of cloud provider and considering the entire chain of processing providers, not just direct processors.

 

Check point by point: subject matter, duration, nature and purposes of the processing, categories of data and data subjects, obligation to act on documented instructions, staff confidentiality, security measures, assistance with data subject rights requests and impact assessments, breach notification, audit rights, and the fate of data at the end of the contract.

 

Subprocessors, the most common blind spot

 

A customer service SaaS almost always relies on other providers: a cloud host, email delivery service, file storage provider, analytics tool, AI model provider, voice transcription provider, or outsourced technical support.

 

Three minimum requirements: an accessible, up-to-date list of subprocessors, a prior-notification mechanism for changes, and a reasonable right to object on your side. An evasive answer on this point is sufficient reason to reject a provider.

 

Checklist: 10 points to check in customer service SaaS DPA

 

  1. Is the DPA provided by default, or do you have to request it?
  1. Do the documented instructions match your actual use?
  1. Is the list of subprocessors public and dated?
  1. How are you informed of a change of subprocessor?
  1. Is the hosting location contractually guaranteed, or only stated on the website?
  1. What transfers outside the EU exist, including for support and maintenance?
  1. How quickly does the vendor notify you of a personal data breach?
  1. What concrete assistance is provided for data subject rights requests?
  1. What audit arrangements are actually practical, beyond an annual questionnaire?
  1. What happens to the data upon termination: format, timeline, cost, and deletion of copies?

 

Customer service SaaS GDPR: Where is your data hosted and transferred?

 

Hosting location and absence of transfers are not the same thing.

 

"Our servers are in Europe" is an incomplete answer. European hosting does not rule out remote access from a third country for maintenance, a technical subprocessor established outside the EU, or a data flow to a tool integrated into the product.

 

Map four distinct things: the location of primary storage, the location of backups, administrator and support access, and outbound flows to third-party components of the product, including AI engines.

 

Transfers outside the EU: Where does the Data Privacy Framework stand?

 

This topic deserves an up-to-date answer rather than a position of principle. The adequacy decision of 10 July 2023 remains legally in force, and the General Court of the European Union rejected the action for annulment against it on 3 September 2025. However, an appeal was filed with the Court of Justice of the European Union on 31 October 2025 and remains pending, while several analyses place a decision in late 2026 or in 2027.

 

A new factor has been added: a U.S. Supreme Court decision issued on 29 June 2026 concerning the independence of the Federal Trade Commission has led several law firms to recommend that companies prepare a fallback solution in case the adequacy decision is eventually annulled, since that decision relies in part on the FTC's role as an independent supervisory authority.

 

What this means for your choice of tool

 

Three practical consequences:

  • The Data Privacy Framework covers only self-certified entities, whose status must be checked at each contract renewal.
  • An adequacy decision never removes the need for the Article 28 contract or security measures;
  • Any strategy relying exclusively on this framework carries a continuity risk. Providing standard contractual clauses as a fallback, or choosing European hosting, is not an ideological stance but a risk-management measure.

A picture of a laptot opened on a website's RGPD

Customer service SaaS GDPR: What security guarantees should you require from the provider?

 

Distinguish security of the cloud from security in the cloud

 

This is the most useful distinction to keep in mind during a procurement process. Security of the cloud is the provider's responsibility: infrastructure, hypervisors, network, and physical resilience. Security in the cloud is your responsibility: role configuration, permission management, choice of the data you place there, and control of exports.

 

The CNIL also warns against several common assumptions, including assuming that the security obligation lies solely with the provider or overlooking telemetry and usage data collected by the provider in the risk analysis.

 

Technical measures to have documented

 

Encryption in transit and at rest, identity management and strong authentication, granular roles and permissions, logging of access and exports, backups at geographically separate sites, incident management procedure, regular security testing, business continuity, and a disaster recovery plan.

 

Ask for evidence rather than statements: audit reports, current certifications, and a description of the vulnerability management process.

 

Apply least privilege to support teams

 

Six questions to review within your own organization, independently of the provider:

  • Does a first-line advisor need to see the customer's entire file?
  • Are attachments visible to all teams?
  • Can administrators read conversations without traceability?
  • Are bulk exports restricted and logged?
  • How quickly are the accounts of departed employees disabled?
  • Do outsourced providers have the same level of access as your internal teams?

Most incidents observed in customer service operations do not come from a vendor vulnerability but from overly broad permissions left in place for years.

 

Customer service SaaS GDPR: customer rights, incidents, and reversibility

 

Enable access, rectification, and erasure

 

Your tool must allow you to respond to data subject requests within the required time limits. Features to test in a demonstration, rather than merely read about in a brochure: searching for a person across all channels, structured export of their data, rectification, deletion, restriction of processing, and anonymization when complete deletion is not possible.

Watch out for data scattered across tickets and attachments

 

Deleting a contact record is not enough if the same information remains in an archived ticket, the body of an email, an attachment, an export created by a team, a backup, or a connected tool. A poorly handled erasure request is a frequent reason for complaints, precisely because the company genuinely believes it has fulfilled the request.

 

Test the full scenario before production: a fictitious erasure request followed by a search across all channels and all storage locations.

 

Organize the response to a personal data breach

 

The contract and your internal procedures must specify who detects the breach, who alerts whom, within what timeframe, what information is transmitted, how evidence is retained, and what assistance the vendor provides so that you can meet your own obligations. A vague notification deadline in the DPA is a serious warning sign.

 

Prepare reversibility before signing, not at termination

 

Export format, scope of what can actually be exported (tickets, conversations, attachments, internal notes, metadata), return timeline, possible cost, migration support, and deletion timeline for residual copies and backups. These points cost little to negotiate before signing and become almost impossible to obtain afterward.

A picture of a cloud collection informations respecting rgpd

 

Alcmeon, a customer service SaaS designed for demanding requirements

Sovereign hosting and control of data flows

Alcmeon is the conversational platform used by major B2C brands and French public services, including SNCF Connect, Carrefour, Fnac Darty, and Le Bon Marché. Hosting is provided in France and the European Union, which significantly simplifies the international-transfer portion of your analysis and reduces your exposure to the uncertainty currently affecting transatlantic adequacy frameworks.

 

Governance of processing and AI

 

The platform anonymizes sensitive data before it is sent to AI engines, and AI features can be configured use case by use case rather than being activated globally. Native CRM connectors make it possible to expose to advisors and automated systems only the information necessary to handle the request. To go further on this topic, see our guide to customer service AI governance.

A single console, a practical condition for compliance

Responding to an erasure request is simple when all of a customer's conversations live in one place and very difficult when they are spread across an email inbox, an Instagram account, a chat tool, and a spreadsheet. Alcmeon's single console brings together more than fifteen channels, making search, export, and deletion practical across the entire journey. See our guide to centralizing customer conversations.

Request an Alcmeon demo and have our teams test your GDPR checklist.

Grazie! La tua richiesta è stata ricevuta!
Ops! Qualcosa è andato storto durante l'invio del modulo.

Alcmeon, Il Vostro Fornitore Conversazionale, in Piena Trasparenza

Supportiamo i CIO e i team di sicurezza durante tutto il ciclo di qualificazione, dal questionario per i fornitori alla firma del DPA.