Data sovereignty used to sit with legal. This year it lands on the contact centre leader. Here is what has moved in the regulatory picture, where contact centres are most exposed, and five things worth checking against your own operation.
Every call, chat and bot conversation your contact centre handles is a piece of someone's life. Increasingly, it is also training data, QA input, or the basis for a decision an AI made on your behalf. That is why data sovereignty has stopped being a legal question and become an operational one.
Two things are happening at once. Regulators are tightening the rules on AI transparency and cross-border transfers, while customers grow more sceptical about how their conversations are used. 88% of contact centres now use AI-powered solutions, yet only 25% have properly integrated that AI into daily workflows, and 91% of leaders say they are under executive pressure to move faster anyway. Trust in AI has slipped at the same time. Only 59% of consumers say they trust it, 87% want to be told when they are talking to it, and 81% believe businesses adopt it mainly to cut costs rather than serve them better.
This post is written for leaders running operations across the Nordics, the Netherlands, and the UK. It is a primer, not legal advice.
The EU AI Act: relief, with a catch
The Digital Omnibus, approved by the Council in June 2026, pushed the toughest obligations for high-risk AI systems (Annex III, which likely covers many customer-facing AI solutions) back from August 2026 to December 2027. That gives most organisations breathing room. The catch is Article 50. The duty to tell people clearly when they are interacting with AI was not delayed and still applies from August 2026. If your virtual agents are not already disclosing themselves, that is the gap to close first.
GDPR and call recording: the bar is higher than most scripts assume
A passive "this call may be recorded" line does not, on its own, satisfy GDPR. Recordings of an identifiable voice are personal data, and the standard read among regulators and practitioners is that you need clear, informed, freely given consent. In practice that means an active opt-in rather than a buried disclosure. Fines for getting this wrong run up to 4% of global annual turnover.
UK adequacy: settled, for now
The European Commission renewed the UK's data adequacy decision in December 2025, extending it to 27 December 2031. For groups running Nordic, Dutch and UK operations together, personal data can keep moving between the EU and UK without extra transfer safeguards. Adequate does not mean identical, though. UK and EU GDPR are already drifting apart on some details, so a single group policy still needs a UK annex.
Transfers to the US: valid today, contested in court
The EU-US Data Privacy Framework, which many cloud and AI vendors rely on to move data to the US legally, remains in force. The EU General Court upheld it in September 2025. It is also under active challenge. Max Schrems and NOYB argue the US safeguards behind it do not hold up, and a CJEU ruling is expected late 2026 or into 2027. The Framework has been struck down twice before. If a vendor's only answer to "where does our data go" is "the DPF", that is a single point of failure. Ask about it now rather than after a ruling.
Where contact centres are exposed
Call recordings, chat transcripts and, increasingly, voice biometrics used for authentication or sentiment scoring are all personal data. Voice biometrics can tip into special-category data. That status does not change because the recording sits inside a CX platform rather than a filing cabinet.
AI adds a further question: what is this data being used for, really? Virtual agents, Conversational Intelligence and AI-assisted QA all touch raw customer conversations. If that data is repurposed, for example to train a vendor's general-purpose model rather than to serve the interaction it came from, that is a new processing activity and it needs its own lawful basis. Many contracts do not spell this out clearly enough to answer a customer, or a regulator, who asks directly.
There is a commercial angle too. 79% of people still say they would rather speak to a human than an AI agent. Combined with the finding that most consumers assume AI is there to cut your costs, every visible AI touchpoint is being judged on trust as much as efficiency. Getting the data story right is part of the product experience, not only a way to avoid fines.
Five things to check against your own operation
In short: real consent, no repurposing, explainable AI, known data locations, and transfer safeguards that outlast a court ruling.
-
Consent that would hold up. An active opt-in for recording and AI-assisted handling, not a passive announcement in an IVR script.
-
Purpose limits you can prove. Customer data analysed only for the interaction it was given for, and never repurposed to train a general-purpose AI model without a separate, explicit basis.
-
Explainability you can show a regulator. An audit trail behind AI-assisted decisions, and a human who can realistically override them.
-
Clarity on where data actually sits. Not where the contract is signed, but which data centres, sub-processors and cloud regions sit in the chain, and what happens if one of them is US-linked.
-
A transfer plan that survives a court ruling. Standard Contractual Clauses and data boundary commitments alongside frameworks like the DPF, not instead of them.
How Puzzel approaches this
We built the Puzzel platform around this checklist because we had to answer the same questions our customers now ask us. Two commitments sit at the centre.
Your data works for you, not for us. Customer data is analysed for your benefit only and is never used to train any AI model. Conversational Intelligence profiles conversations against a defined, research-based word list rather than subjective tone analysis, and there is no biometric categorisation.
Puzzel is a European partner, not a European add-on. We are headquartered and operated only in the EU/EEA/UK, ISO 27001 and ISO 27701 certified, SOC 2 compliant, GDPR-native as both controller and processor, and led by a dedicated CISO. Where parts of the platform rely on infrastructure with US ties, such as Microsoft Azure, we back this with contractual and technical safeguards including Customer Lockbox, an EU Data Boundary and mandatory Transfer Impact Assessments. The detail, including our position on Puzzel and US law, is published in the Trust Centre.
Where to go from here
None of this is static. The AI Act's timelines, the DPF's legal standing and UK-EU divergence will keep moving over the next 12 to 18 months. The organisations in the best position will not be the ones with the longest policy document. They will be the ones who can answer, clearly and quickly, where their customers' conversations go and why. To talk through how this applies to your operation, or to see our certifications, sub-processor list or Data Processing Agreement, contact your Puzzel account team or visit the Trust Centre.
This article is provided for general information and does not constitute legal advice. Seek your own legal counsel on specific compliance obligations.