GDPR and your help desk
A help desk holds names, addresses, complaints and occasionally something a customer would rather nobody read. This guide sets out what GDPR asks of you and what to check before choosing a product.
Why a help desk is a data protection question
Every ticket is personal data. The name and the email address are obvious; less obvious is what accumulates around them – what someone complained about, how often they got in touch, and occasionally health or financial information they volunteered without being asked.
That makes the help desk one of the more sensitive systems in the company, and it is usually chosen with less scrutiny than the accounting software.
The four things to check
- A data processing agreement. Any vendor processing personal data on your behalf needs one. Ask for it before you sign, not after.
- Where it runs. Hosting inside the EU removes an entire category of question. Outside it, you need to be able to explain the transfer mechanism.
- Deletion. You need to be able to delete a person's data on request, and to set a period after which old tickets go. "We keep everything forever" is not a policy.
- Export. The right to data portability is not optional, and neither is your own ability to leave.
The AI question
This is the part that changed recently. An AI assistant that drafts replies has to read the ticket – and if the model runs at a third-party provider, the ticket content leaves your processor chain.
That is not automatically unlawful, but it is a separate processing operation with its own agreement, its own transfer question and its own entry in your records. A model that runs on the same server as the data avoids all three. It is worth asking a vendor exactly where their AI runs, and not accepting "securely" as an answer.
A practical checklist
- Is there a data processing agreement, and does it name the sub-processors?
- Where are the servers, and where are the backups?
- Can you delete one person's data without deleting the ticket history of everyone else?
- Is there an automatic deletion period, and can you set it?
- Can you export everything, in a format somebody else can read?
- Where does the AI run, and can it be switched off?
- Are tenants separated, if the vendor serves several customers on one system?
This guide is general information and not legal advice. For a binding assessment, ask a lawyer or your data protection officer.
Try rapidFOX free for 7 days
Help desk software with a local AI – GDPR compliant, hosted in Germany. No card, ready in 2 minutes.
Start free nowCommon questions
Do we need a data processing agreement with our help desk vendor?
If they process personal data on your behalf – and any hosted help desk does – then yes.
Is a US-hosted help desk automatically a problem?
Not automatically, but it requires a transfer mechanism you can explain and document. EU hosting removes the question rather than answering it.
How long may we keep tickets?
As long as you have a reason to. Once the reason ends, so should the data – which is why an automatic deletion period is worth having.
What about the AI reading our tickets?
It is a processing operation like any other. A model running on the same server as your data keeps it inside the boundary you already documented.
Read on
Help desk explained: what it is, how it works, which features matter, what it costs and wh...
Introducing a help desk without a project: what to decide first, what to leave until later...
Help desk, ticketing system, service desk, shared inbox: what the terms actually mean, whe...