Answers to the questions that arise most often, with the article cited alongside wherever the answer follows from a rule.
Questions and answers
Does our virtual assistant have to identify itself as a machine?
Yes. Article 50 of Regulation (EU) 2024/1689 requires that a person interacting with an AI system be informed of that fact, unless it is obvious to a reasonably well-informed person. The duty has applied since 2 August 2026, with a grace period to 2 December 2026 for systems already in operation.
Article 50 of Regulation (EU) 2024/1689
Can we analyse our agents’ emotions?
No. Article 5 of Regulation (EU) 2024/1689 prohibits the placing on the market, putting into service and use of AI systems that infer emotions of a natural person in the workplace, save for medical or safety reasons. The prohibition has applied since 2 February 2025, with no transition period. Sentiment analysis applied to agent performance evaluation falls within it.
Article 5 of Regulation (EU) 2024/1689
We hold a quality certification. Are we covered?
No. Certification against a voluntary standard demonstrates conformity with that standard, not with the law. Certification schemes address service quality; the legal regimes address obligations, deadlines and evidence. An operation can be certified and non-compliant at the same time, and frequently is.
How many regimes apply to a contact centre?
Six, and they do not cross-refer. The national customer service regime, where one exists; the rules on the cost of consumer contact lines; consumer law as it applies to service and to distance contracting; data protection, as regards recording, logging and unsolicited communications; accessibility of support services; and transparency of automated interaction systems. Each layer has its own instrument, its own timetable and its own authority, and none of them refers to the others.
Our customer service is outsourced. Who is responsible?
The undertaking that offers the service to the consumer. Outsourcing distributes execution, not liability to the consumer, without prejudice to any allocation of liability agreed between the parties. Where personal data is processed, the outsourcing provider is generally a processor and a contract under article 28 of the General Data Protection Regulation is required.
Article 28 of Regulation (EU) 2016/679
Your question is not here
Put it directly. Recurring questions are added to this page.