Over the past few weeks we received a variant of the same question five times. A CEO who wants to send all his salespeople out with a recording device. Clients who notice that a supplier records every phone call and has it transcribed. A management team that wants to let ChatGPT or Claude read and answer its emails. A real estate agency wondering what it has to do for the AI Act. And with our own platform, where all of a company's communication comes together, the questions come naturally: is that actually secure, what about the privacy rules, who gets to see all of that, and won't my sensitive company data leak out?
Each time a law gets mentioned: the Data Act, the AI Act, the GDPR. Only they are constantly mixed up, and then you get either panic, or costs for something that is not mandatory. That is why we put them side by side here, and answer the five questions one by one.
Four laws, four subjects
GDPR
Everything that concerns people: names, emails, voices, recordings, transcripts.
Applicable since 25 May 2018
AI Act
Rules for AI systems, stricter as the risk increases.
In stages since 2 February 2025
Data Act
The data your devices and machines keep, and being able to switch cloud provider smoothly.
Applicable since 12 September 2025
Belgian Electronic Communications Act
Belgian law that governs the recording of phone calls.
Act of 13 June 2005, Articles 124 and 125
The most important thing to remember: almost all of the questions above are answered by the GDPR, not by the Data Act or the AI Act. As soon as a recording, an email or a transcript contains something that can be traced back to a person, the GDPR applies. And that is almost always the case.
The Data Act is often mentioned when people actually mean privacy. It is about something else. If you buy a device that is connected to the internet, such as a car or a heat pump, then you have a right to the data that device keeps, and not only the manufacturer. In addition, it makes it easier to leave a cloud provider with your data. Useful to know, but it says nothing about recordings or mailboxes. What it does do, you can read in what is the Data Act?
Are you allowed to record every sales conversation?
Short answer: yes, if the client knows and agrees. The real work starts after that: what do you do with all those recordings?
If you ask at the start of the conversation whether you may record and the client says yes, you have a valid basis. But that yes does not finish the job. You define what the recordings are for, how long you keep them and who can access them. The client may withdraw their consent or ask for a copy. And your own salespeople are recorded too: inform them in advance and agree on what the recordings will and will not be used for.
The fact that the recording device comes from an American company does not make it prohibited. You conclude a data processing agreement and you check whether your account is set to the European region. Plaud offers both.
And phone calls?
Short answer: here Belgium is stricter. Recording without the other side knowing is, in principle, not allowed. With regular contacts it is enough, however, to disclose it properly once.
For phone calls, a Belgian law applies on top of the GDPR, which only allows recording with the consent of all participants, apart from a few narrow exceptions. Recording all calls and having them transcribed "for internal use" is hard to fit into that. So the message at the start of the call is not a courtesy but a condition. A sentence in your general terms and conditions is not enough: the person who signs the order is usually not the person you call later.
Do you then have to repeat it on every call? Not with people you call or video call regularly. There it is enough to disclose it once, if you do it properly:
- Per person, not per company. Each contact hears it personally and agrees personally. A new colleague at the client starts from scratch.
- Clear and demonstrable. You say that you record and transcribe, what for, and how long you keep it. Keep track of who agreed and when.
- Anyone who objects says so once. You then no longer record that person.
- Everyone who does not know yet does get the notice. Unknown numbers, new contacts, and anyone joining a video call for the first time.
Unknown number
You do not know who is calling.
Disclose at the startRegular contact
Knows about it and agreed personally.
Once is enoughNew participant
A new colleague at the client, or someone joining the conversation for the first time.
Disclose againThat is a defensible reading of the rules, not a way of working that the regulator has explicitly approved. If you want no risk at all, leave the notice switched on for every call.
Two more things to know:
- Do you use a phone system yourself that records and transcribes? Then you are responsible, not the supplier of the phone system. You have to inform your callers and set a retention period.
- Are you being recorded yourself without having known it? Ask about it. You have a right of access and a right to a copy, and you can object.
All the rules and exceptions, for conversations at the table and on the phone, are in recording conversations: what is allowed in Belgium?
AI that reads and writes your emails
Short answer: that is possible, with a business plan and a few clear agreements. The promise "we do not train on your data" is necessary, but does not cover everything. And what you send remains yours, even if AI wrote it.
Two things are at stake here. You make the content of your emails available to an AI model such as ChatGPT or Claude, and you then send text that the model has written.
AI reads your emails
What happens to the content, and who can access it? That is a question for the GDPR and for your contracts.
AI writes your reply
Does the recipient need to know, and who is responsible? That is a question for the AI Act.
First the reading. The mailbox of a member of the management team contains just about everything: contracts, prices, HR matters, an acquisition in preparation. Four things to think about:
- Training. With the business plans of OpenAI and Anthropic, training on your data is contractually excluded by default. With free and personal accounts that is different. So never put company email in a personal account.
- US legislation. An American provider falls under US law, even if your data is stored in Europe. The government cannot simply access it, but you cannot rule it out. For most companies that is an acceptable residual risk. For very sensitive information it weighs more heavily. How exactly that works, you can read in what is the CLOUD Act?
- What you have promised others. Your emails contain data about clients, suppliers and employees. State in your privacy notice that you use AI tools, and check whether a confidentiality clause prohibits sharing with third parties.
- An email can mislead the assistant. An assistant that reads your emails also reads what an outsider sends you. If an instruction is hidden in there, a poorly shielded assistant may try to carry it out. Give it read-only rights at first, and do not let it send anything without a human confirming it.
Then the writing. Do you have to disclose that an email was drafted by AI? For an ordinary business email that you proofread and send: no. The AI Act only imposes that disclosure obligation for texts that inform the public on matters of public interest, and even there not if a human has reviewed them and bears responsibility for them. It is different when an assistant writes and sends messages itself or holds a conversation in your name, without anyone reviewing them: then the recipient must know that they are dealing with AI. The same applies to WhatsApp and to an AI voice on the phone. An overview per situation is in our knowledge base article on the AI Act. And in both cases you are liable for what goes out in your name. A wrong price or a promise the model made up is your price and your promise. So read what you send.
If you want more control, you can use the models through a European cloud region, or with agreements under which the provider stores nothing. More on that in EU hosting and zero retention.
One company brain where everything comes together
Our own platform brings emails, phone calls, meetings and documents together in one place, so a team no longer has to search. That is exactly what makes it valuable. It also raises the same three concerns every time: does this comply with the privacy rules, who gets to see all of that, and does nothing leak out? For the first two, the same rules apply as above, and we build them in for every client:
- A purpose per source. Bringing client communication together to follow up on clients better is a defensible purpose. Using that same data to monitor employees is a different purpose, with different rules.
- Not everyone sees everything. The assistant must never show more than what the person asking is allowed to see. HR matters, salaries and management emails stay shielded.
- Employees know what is in it. They are informed in advance and clearly. In Belgium, moreover, the rules of Collective Labour Agreement No. 81 apply as soon as an employer monitors employees' online communication. Private messages do not belong in it.
- The risks on paper in advance. Anyone who brings communication together on this scale is well advised to carry out a data protection impact assessment (DPIA). In many cases it is also mandatory.
- Retention periods and a log. What is no longer needed goes. And you can check who requested what.
And does nothing leak out, then? We store the searchable data on European infrastructure. Only what is needed to answer one question goes to an external language model, under agreements whereby the provider stores nothing and does not train on it. Anyone who leaves loses their access the same day. But the technology only solves half of it. The other half is the agreements within your company. How to set up those permissions, we described in not everyone needs to see everything.
And what does the AI Act require?
Short answer: less than you think. For a company that uses AI as a tool, it comes down to two things: teach your people to work with it, and be honest about it.
Since February 2025 the AI Act has asked you to support the AI literacy of your employees, and that rule was watered down in July 2026: you do not have to guarantee a particular level. Since August 2026, anyone who chats or speaks on the phone with an AI assistant must also know that. The heavy obligations apply to high-risk AI, such as AI that selects job applicants. An assistant that prepares emails, answers questions or writes reports does not fall under that.
An AI inventory, a formal AI policy or evidence for an audit are not mandatory for that kind of use, even though it is sometimes presented that way. A list of your AI tools and a few clear agreements are sensible, though, and we recommend them ourselves too. The full explanation is in what is the AI Act, and what do you have to do for it?
Where do you start?
- Make a list of your AI tools. Which tools, who uses them, and which data goes into them. Not because the AI Act imposes it, but because otherwise you cannot shield anything.
- Business accounts only. With a data processing agreement and without training on your data.
- Disclose every recording. At the table you ask, on the phone you say it in advance, and in your privacy notice it is written out.
- Set retention periods. For audio, for transcripts and for reports, and let the deletion run automatically.
- Work with roles. The assistant never sees more than the person asking the question.
- Inform your employees. What is recorded and brought together, what for, and what not for.
- Give a short training. Practical, on your own tools, and keep track of who has followed it.
None of those seven points requires an expensive project. Above all they require someone in the company to set aside half a day for it, and that you keep it up to date afterwards.
This article is not legal advice. The rules were checked on 6 October 2026, and the AI Act was amended again this year. For a specific situation, certainly around recordings and staff, it is best to put it to a lawyer. If you are unsure what applies to your company, feel free to ask your question below.
You will find the legal texts and sources at the bottom of each knowledge base article.