Home/Articles/Trust and the buying decision
Is an AI email assistant GDPR and POPIA compliant?

Is an AI email assistant GDPR and POPIA compliant?

Short answer: An AI email assistant is not automatically GDPR- or POPIA-compliant as a product feature. Compliance depends on who controls each processing purpose, the lawful basis, processor contracts, data minimisation, security, individual rights, retention, international transfers and how the customer configures and uses the service. Assess the real data flow and obtain legal advice for regulated or high-risk use.

Is an AI email assistant GDPR and POPIA compliant? — Digital Hank

Compliance questions are often answered at the wrong level. A vendor displays “GDPR compliant” or “POPIA ready,” while the buyer processes client correspondence for a purpose the vendor cannot evaluate. Both laws allocate responsibilities across organisations and activities. The business may control why correspondence is processed; the service may operate on its instructions; cloud and model providers may be subprocessors; and the service may separately control account or security data. Lawfulness then depends on purpose, necessity, notice, contracts, safeguards, rights and transfers. This page is an operational checklist, not legal advice or certification. The current governance package adopts privacy and security policies aligned to both regimes, identifies roles and records US hosting. It also openly lists missing entity, Information Officer, privacy-contact, DPA and technical proof items. Until those close, public copy must not claim achieved compliance.

Who is responsible for each kind of personal data?

Assign controller/processor or Responsible Party/Operator roles per processing activity, because one company can hold different roles for different data. Contract labels do not override actual decisions.

For customer account data—name, sign-in, subscription and support—the service decides core purposes and is likely a controller or Responsible Party. For a business customer's connected emails, attachments and derived work records, the customer normally decides why the data is processed and the service operates on its instructions, making the service a processor or Operator. The model and hosting providers then process specified categories as subprocessors.

The adopted policy uses this split. It needs the operating legal entity confirmed so agreements, notices and rights requests identify a real accountable party. The customer's own obligations remain: a lawyer, broker or consultant must decide whether connecting client correspondence is lawful and proportionate, and whether professional confidentiality creates stricter requirements than general data protection law.

What lawful purpose and minimum data are required?

The business must define a legitimate, specific purpose and use only data necessary for that purpose; “we use AI” is not a lawful basis or purpose.

A defensible purpose might be: classify business requests, prepare replies and maintain source-linked tasks for the connected user. The data map can then ask whether full historical mail, every attachment, sent mail, calendar contents or persistent derived records are necessary. Different features may rely on contract, consent, legitimate interests or another basis depending on role and jurisdiction. Special personal information needs additional analysis.

The current policy states purpose limitation, no sale or advertising, no customer-content model training and least scope. The code nevertheless requests a combined Google read, send and calendar bundle. That may be necessary for the complete assistant, but a customer using only one feature should understand the access. Data minimisation must be demonstrated in configuration, retrieval and retention—not merely promised in a policy.

Which contracts and vendor records should exist?

A processor relationship needs a binding data-processing agreement, current subprocessor register and security commitments that match the deployed architecture. Marketing terms are not enough.

The contract should cover subject, duration, purpose, data types, data subjects, documented instructions, confidentiality, security, subprocessor approval or notice, rights assistance, incident support, deletion or return and audit information. The ICO's processor-contract checklist is a useful starting point for GDPR-style requirements.

The repository includes a subprocessor register naming Google Cloud/Firebase, Google Workspace APIs, Vertex AI, Cloudflare, Resend and conditional Sentry. It also says DPAs still need execution and Sentry use/configuration requires confirmation. The customer DPA is an open item. Those gaps prevent a completed-compliance claim even if the technical design is promising.

How should security and AI-specific risk be assessed?

Use risk-appropriate technical and organisational measures, then prove them with tests covering isolation, credentials, malicious content, approvals, deletion and incidents. A certification logo cannot describe the customer's exact workflow.

The security policy requires encryption, tenant isolation, least privilege, secrets separation, prompt-injection defence, audit, monitoring and human authority over consequential actions. The code encrypts connector credentials and scopes many routes to an authenticated user. Email sends are staged and missing attachments fail closed.

Important controls remain open or unproved: Firestore Rules and isolation tests, complete immutable audit logging, injection regression tests, monitoring configuration, administrative-access evidence, recovery targets and restore testing. The email-access safety page provides the product test. Higher-risk uses may also require a DPIA or comparable documented risk assessment before processing begins.

What rights, retention and deletion must the service support?

People must receive applicable transparency and rights, while the controller needs workable routes to access, correct, export, restrict and delete relevant data. Derived AI records are part of the problem.

The policy commits to those rights, deletion from live systems within 30 days of account closure or request, backup purge on normal rotation within 90 days and a 30-day transient-original-attachment window. It distinguishes copied files from extracted text and durable business records. That distinction is essential because deleting a PDF does not correct a false contact or task derived from it.

No production privacy address, self-service export or full-account deletion workflow is evident. The storage lifecycle configuration is not checked into this repository. These must be implemented or supported by documented, tested operations. The related training-versus-storage explanation prevents a no-training statement from hiding retained application data.

How should international transfers be handled?

Map the primary region and every onward transfer, then apply the mechanism and safeguards required by the relevant law and customer context. “Cloud hosted” is not a location answer.

The governance files record Firebase App Hosting and Firestore in us-east4 in the United States, with global cloud services elsewhere. They say transfers rely on Standard Contractual Clauses and provider safeguards. Model code defaults the Vertex location to global, so the actual deployed processing location and applicable data residency settings need confirmation.

For GDPR, assess Chapter V transfer requirements and subprocessor terms. For POPIA, assess section 72 and whether the recipient is subject to adequate law, binding rules or agreement, or another permitted condition. Retain executed documents and a current transfer map. A policy statement that SCCs apply is not equivalent to filed agreements and a customer-facing explanation.

Who it is not for

This service is not ready for a use that requires completed contractual, residency, rights or security evidence which the vendor cannot yet provide. The correct response to a compliance gap is not a broader disclaimer.

Health, children's, biometric, criminal, employee-monitoring, legal-privilege and high-risk financial use may require additional law, consent, professional rules or sector controls. Organisations with mandated local residency, customer-managed encryption or formal records schedules should verify those features explicitly. A sole professional is not exempt merely because the business is small.

The current product should remain on synthetic or appropriately low-risk data until its entity, Information Officer, privacy route, DPAs and release-blocking tests are complete. Independent legal advice is appropriate before sensitive production use.

Conclusion: is the assistant compliant today?

No responsible vendor can make GDPR or POPIA compliance a context-free product adjective. The buyer and provider must map roles, purposes, data, lawful basis, contracts, security, rights, retention, subprocessors and international transfers for the actual use. Hank's adopted policies establish a serious direction: processor-style handling of connected content, no model training, stated retention, human approval and named security controls. They also record unresolved foundations, including the legal entity, Information Officer, public privacy contact, customer and subprocessor DPAs, transfer evidence and several technical tests. Ask for those items in writing, and treat any vendor unwilling to put them in writing as having answered the question. The honest acquisition value is the checklist itself: it lets a professional reject vague badges and ask for the evidence their own accountability requires.

Frequently asked questions

Is a GDPR-compliant AI tool enough to make my use compliant?

No. The customer normally remains responsible for its purposes, lawful basis, notices, access decisions and treatment of clients or employees. A capable processor supports compliance through contracts and controls, but cannot choose every lawful use for the customer. Document the intended workflow, data categories, people affected, necessity, risks and configuration before deployment.

Who is the controller or responsible party for client emails?

Usually the professional or business decides why client email is processed and is therefore the GDPR controller or POPIA Responsible Party. The assistant provider may act as processor or Operator for connected content, while acting as controller or Responsible Party for its own account, billing and security data. Determine roles per processing activity, not brand label.

Do I need a data processing agreement for an AI email assistant?

A business using a processor for personal data generally needs a binding agreement covering documented instructions, confidentiality, security, subprocessors, rights assistance, deletion, audits and breach support. GDPR Article 28 is prescriptive, while POPIA requires the Responsible Party and Operator relationship to address security safeguards. Have the agreement reviewed for the actual service and jurisdiction.

Can email data be processed outside South Africa or Europe?

Cross-border processing may be lawful when the applicable transfer conditions and safeguards are satisfied, but it is not automatic. Identify every destination and onward processor, then document the transfer mechanism, contractual safeguards and local risks. POPIA section 72 and GDPR Chapter V require a real basis; a globally distributed cloud logo is not that analysis.

Does no model training make an AI email assistant compliant?

No. A no-training term supports purpose limitation, but compliance also covers inference, application storage, derived records, security, transparency, rights, retention, subprocessors and transfers. The customer still needs a lawful purpose for processing correspondents' information. Treat training as one line in a wider data map, not a substitute for the full assessment.

Stop working for your inbox.

Hank turns the work arriving in your email into tasks, records, drafts and proposed actions, while you stay in command.

Start 14 days free — no card