GUIDE The Help Desk AI Maturity Journey Download now

Reading time 13 mins

GDPR help desk compliance: What support teams need to know

Learn what GDPR requires of your help desk, and what your support team can do to satisfy those requirements.

Madeline Jacobson
Madeline Jacobson / Content Marketing Manager
Help desk interface on a desktop computer is positioned in front of a security badge

Summary:

  • GDPR applies to your help desk if your organization is established in the EU or offers goods and services to people in the EU, with fines up to €20 million or 4% of global annual turnover.
  • You're the controller and your help desk vendor is the processor, so the core data handling obligations (lawful basis, transparency, data minimization, security, accountability) stay with your organization no matter who you hire.
  • Vendor choice is a compliance decision. Check for a signed Data Processing Agreement (DPA), EU or on-premise hosting, a published sub-processor list including any AI models, and the ability to find, export, and delete a person's data across tickets and integrations.

GDPR applies to your help desk in two situations. The first: your organization is established in the EU, in which case GDPR covers the personal data you process, regardless of where that processing physically takes place. The second: your organization is based outside the EU, but you offer goods or services to people in the EU, or process their data. Either way, any personal data, such as a customer’s name, contact information, attached files, and email or chat exchanges, falls under GDPR, and it becomes your organization’s responsibility to protect it.

But depending on your help desk setup, you may not have full control over that data. If you use a SaaS help desk, your customers’ data sits in that vendor’s infrastructure, in a public cloud provider’s data center, potentially within another country’s jurisdiction. That means your help desk data could fall under regional laws that conflict with your GDPR obligations–most notably the US CLOUD Act , which can compel a US-based vendor to hand data to US authorities regardless of where it's stored. Complying with an order like that can put you in breach of GDPR, and that legal responsibility stays with your organization, not the vendor.

Considering the fine for a GDPR violation is up to 20 million euros, or 4% of global annual turnover, whichever is higher, that’s not a risk your organization should take.

In the rest of this article, we’ll cover what every organization that handles EU customer data needs to know about GDPR help desk compliance: what counts as personal data, what you’re responsible for, and what to look for in a help desk to keep it compliant.

What GDPR means for your help desk

An EU-based customer's contact information attached to a ticket is an obvious example of data that’s protected under GDPR, but that’s far from the extent of it. Thread body text, attachments, voice transcripts, and the internal notes between your agents all qualify to the extent they contain information about an identified or identifiable person.

Within that scope, you are the controller: you decide why support data is collected and what happens to it. Your help desk vendor is the processor, acting on your documented instructions. You carry the overall responsibility for the support data in your help desk, while your vendor is responsible for their own GDPR compliance and may be liable to you if they break a controller-processor contract you’ve entered into with them. Understanding that distinction is important: as the controller, the legal obligations that follow are yours to meet, whoever you've hired to help.

The core GDPR responsibilities for support operations

Some GDPR obligations can't simply be handed to your legal or compliance team and forgotten–they're built into how support operates day to day, so the support team has to own them directly. These include:

  • The lawful basis for processing support data. You need to identify a legal basis for processing personal data before that processing occurs. In a help desk, the basis is usually consent (the customer has opted in) or contract (data processing is necessary to deliver a contractual or requested service).
  • Transparency. You tell people whose data you hold how it's being used, why you're collecting support data and what happens to it, usually through a privacy notice.
  • Data minimization. You collect only the information required to resolve the ticket.
  • Purpose limitation. Support data collected to resolve a ticket can't be repurposed for marketing without separate consent.
  • Accuracy. You keep the personal data in your help desk correct and up to date, and correct it when a customer tells you it's wrong.
  • Security of processing. You take security measures, such as encryption, access controls, and audit logging in your help desk to protect customer data.
  • Accountability. You must be able to show you’re compliant with evidence such as written retention schedules, a record of processing activities, and logs you can produce on request.

When a support ticket is a data subject request

The seven responsibilities above apply to all your help desk data, all the time. But there’s another kind of obligation that only kicks in when a customer acts: exercising the rights GDPR gives them over their own data. GDPR gives the people enforceable rights over how organizations handle their data, and a support ticket is one of the most common places those rights show up.

GDPR gives individuals eight rights over their personal data, which they can exercise through requests. The law doesn’t specify what channel the request has to come through, so any of them can land in a support ticket and support teams need to be ready when one does.

Four of those eight rights are the ones a support team is most likely to receive: the right of access, the right to data portability, the right to erasure, and the right to rectification.The others: to be informed, to restrict processing, to object, and rights around automated decision-making can surface too, but less often through a support queue. We’ll cover the four most common ones below.

Right of access

This is a customer requesting visibility: they want to know what personal data your organization holds. It covers their personal data wherever it sits in your system: tickets, attachments, chat transcripts, and the contact record, across every tool the data reached. Even internal notes an agent has written about their interactions with a customer qualify. This is the request GDPR calls a "subject access request.”

Right to data portability

Portability requests arise when a customer wants a machine-readable copy of their data so they can hand it to another provider, often because they’re switching.

Right to erasure

“Delete my data” is a request that can apply to ticket attachments, internal notes, linked records in integrated systems, past exports, and archived mailboxes.

GDPR does let you keep data in two situations that often come up in support. The first is when you might need the record to defend a legal claim, such as chargebacks or escalated complaints. The second is when another law requires you to hold onto it, which usually applies to tickets documenting a transaction covered by tax or accounting rules.

Right to rectification

This right means your organization must update inaccurate or incomplete personal data at an individual’s request. In a help desk, this could mean that you have to update a customer’s name or email while keeping the ticket history intact.

Once any of these requests arrives, the clock starts ticking. GDPR requires a response without undue delay and within one month of receipt, extendable by two further months where the request is complex or the customer has made several. If your organization fails to respond in that time, you risk a complaint to a supervisory authority and, potentially, a fine.

Data retention and deletion: How long to keep data in your help desk

We’ve covered what your organization is responsible for under GDPR and what you need to do if someone exercises one of their data subject rights, and next we’re going to look at how long you should keep customer data in your help desk.

GDPR doesn’t set any specific retention periods. Instead, it requires that personal data is kept in identifiable form no longer than is necessary for the purpose it was collected for. A “we’ve always kept every ticket forever” mentality is a compliance liability.

However, you don’t want to be overzealous about deleting data: depending on your business and industry, there may be tax and accounting statutes, sector regulations, and limitation periods for legal claims that require you to keep data for a certain amount of time. Your organization needs a defensible retention schedule, set by data type, with a stated purpose and legal justification behind each period.

That schedule also has to hold up against internal pressure to keep data around - quality assurance and analytics teams often want long ticket histories for context and trend analysis. "It's useful to keep" isn't a lawful basis for keeping it, though: the retention rule still applies, and if a purpose genuinely no longer needs identifiable data, the data shouldn't stay in identifiable form.

And a retention schedule is only as good as your ability to act on it. When deletion time comes, the data doesn't just sit with you, it's in your vendor's systems, and their sub-processors' systems too. As the controller, you're entitled to have it deleted on your instruction, but you can only rely on that if your vendor is contractually bound to act on it: that's what the Data Processing Agreement is for. Which is exactly where choosing the right help desk comes in.

Vendor due diligence: DPAs, sub-processors, and your help desk provider

If GDPR applies to your organization, choosing help desk software is as much of a GDPR-compliance decision as it is a feature-based one.

First, it’s important to understand a few roles. Your help desk vendor is your processor. Its own cloud host, any third-party tools it integrates with, and any AI models it uses to power its features are all sub-processors, engaged by the vendor and not contracted by you.

While your exact requirements will depend on your business, these are some of the GDPR-specific things worth checking before you sign with a vendor:

  • A Data Processing Agreement (DPA). GDPR requires one with every processor.. You and your help desk vendor need to enter into a written contract covering what each party is responsible for when it comes to protecting personal data.
  • EU hosting options. GDPR doesn't require you to keep customer data in the EU, but it does impose safeguards on transfers outside it. Keeping data on EU servers avoids that extra layer, so if that's your approach, check what EU hosting options a vendor actually offers.
  • The sub-processor list and change process. Your vendor relies on its own sub-processors, and their data-protection obligations should match the ones you've placed on the vendor. Ask any vendor you're evaluating for its sub-processor list, and check what each one is used for and where it handles your data. Pay particular attention to any third-party AI models–they're sub-processors too, and they may process data outside the EU even when the vendor offers EU hosting for everything else. EU hosting for the main service doesn't mean every sub-processor sits in the EU, and that's allowed, but data leaving the EU needs appropriate transfer safeguards in place, such as standard contractual clauses. So where a sub-processor is outside the EU, check those safeguards are covered rather than assuming EU hosting settles it.
  • Sovereign cloud and on-premise hosting capabilities. If you determine that your organization needs to maintain data sovereignty in addition to data residency, you’ll need to see if the help desk vendors you’re vetting offer sovereign cloud or on-premise hosting options. If you’ll be using their AI features, see if you can connect private models that you run in your own environment.

What to look for in a GDPR-ready help desk

Before you get too far into choosing a new help desk, there are a few GDPR essentials worth checking. If a vendor can't offer these and you need GDPR compliance, it's unlikely to get through your compliance team's full review. Confirming them early saves you carrying a vendor through a process it was never going to pass.

When choosing a help desk, check that it offers:

  • Deployment and hosting options - EU, sovereign cloud, or on-premise - to match your data residency needs.
  • Strong security measures over your data, including encryption and role-based access controls so agents only see what they need.
  • A signed DPA, and a published list of its sub-processors, including any that process data outside the EU.
  • The ability to locate, export, and delete a person's data across tickets, attachments, and integrated systems, so you can meet access, portability, and erasure requests.
  • Clear answers on how any AI features handle your data, where it's processed, whether it trains on your data, and whether you can connect your own private models.
  • Workflow and SLA tools to manage data subject requests so you can route each request and track the one-month response deadline against the ticket.

How Deskpro enables GDPR-compliant customer support

Deskpro is built for teams that need to deliver great support experiences while still meeting compliance requirements, including GDPR. We approach this in a few different ways:

Deployment flexibility. While GDPR doesn’t impose data residency requirements, it does lay out strict conditions for international data transfers. Keeping your help desk in the EU simplifies your compliance workload, and Deskpro makes that possible with our flexible deployment options, including hosting on the AWS European Sovereign Cloud, regional private clouds, and on-premise.

Access controls and audit trails. Role-based permissions limit which agents see which data, and audit logging helps you keep a record of activity and access history to support your accountability and investigation needs.

Documentation you can hand to a Data Protection Officer (DPO). A DPA, a published sub-processor list, and security documentation, without a compliance add-on tier.

A bring-your-own-AI approach. Rather than locking you into specific AI models, Deskpro lets you connect your own, including private models that keep data processing within your defined security perimeter. This enables your team to take advantage of AI productivity tools for your agents, such as ticket summarization and suggested replies, without risking a GDPR violation.

If you’re evaluating help desks and know you need to comply with GDPR, it’s worth taking a closer look at Deskpro. You can book a demo with our team, or get started with a self-guided tour at any time.

FAQs

Does GDPR apply to customer support tickets?

Yes, if your organization is established in the EU, or you offer goods or services to people located in the EU or monitor their behavior there, GDPR applies to the personal data in your customer support tickets. It also applies to internal notes your agents add to it, to the extent they relate to an identifiable person.

How long can you keep support tickets under GDPR?

GDPR doesn’t set a fixed time, but it does require that personal data be kept in identifiable form no longer than is necessary for the purpose it was collected for. That means you set the schedule and justify it, factoring in minimum retention obligations based on your organization and industry.

What is a Data Processing Agreement (DPA), and does my help desk vendor need one?

A Data Processing Agreement (DPA) is the contract GDPR requires between a controller and a processor. It sets out what the processor may do with the data, the security measures it applies, how it handles data subject requests and breaches, and what happens to the data when the contract ends. Your help desk vendor is your processor, so a DPA is required. It should also list the vendor's sub-processors and give you a right to object to changes.

Is Deskpro’s help desk GDPR compliant?

GDPR compliance is a property of how an organization processes data, so no help desk can be GDPR-compliant outright. What a help desk vendor supplies is the deployment options, controls, and documentation that let you meet your GDPR obligations. Deskpro offers a DPA and a published sub-processor list, EU and sovereign cloud or on-premise deployment for teams that need to keep data in-region, role-based access controls with audit logging, and the ability to connect your own AI, including private models. Our security documentation sets out the specifics.