Summary:
GDPR applies to your help desk in two situations. The first: your organization is established in the EU, in which case GDPR covers the personal data you process, regardless of where that processing physically takes place. The second: your organization is based outside the EU, but you offer goods or services to people in the EU, or process their data. Either way, any personal data, such as a customer’s name, contact information, attached files, and email or chat exchanges, falls under GDPR, and it becomes your organization’s responsibility to protect it.
But depending on your help desk setup, you may not have full control over that data. If you use a SaaS help desk, your customers’ data sits in that vendor’s infrastructure, in a public cloud provider’s data center, potentially within another country’s jurisdiction. That means your help desk data could fall under regional laws that conflict with your GDPR obligations–most notably the US CLOUD Act , which can compel a US-based vendor to hand data to US authorities regardless of where it's stored. Complying with an order like that can put you in breach of GDPR, and that legal responsibility stays with your organization, not the vendor.
Considering the fine for a GDPR violation is up to 20 million euros, or 4% of global annual turnover, whichever is higher, that’s not a risk your organization should take.
In the rest of this article, we’ll cover what every organization that handles EU customer data needs to know about GDPR help desk compliance: what counts as personal data, what you’re responsible for, and what to look for in a help desk to keep it compliant.
An EU-based customer's contact information attached to a ticket is an obvious example of data that’s protected under GDPR, but that’s far from the extent of it. Thread body text, attachments, voice transcripts, and the internal notes between your agents all qualify to the extent they contain information about an identified or identifiable person.
Within that scope, you are the controller: you decide why support data is collected and what happens to it. Your help desk vendor is the processor, acting on your documented instructions. You carry the overall responsibility for the support data in your help desk, while your vendor is responsible for their own GDPR compliance and may be liable to you if they break a controller-processor contract you’ve entered into with them. Understanding that distinction is important: as the controller, the legal obligations that follow are yours to meet, whoever you've hired to help.
Some GDPR obligations can't simply be handed to your legal or compliance team and forgotten–they're built into how support operates day to day, so the support team has to own them directly. These include:
The seven responsibilities above apply to all your help desk data, all the time. But there’s another kind of obligation that only kicks in when a customer acts: exercising the rights GDPR gives them over their own data. GDPR gives the people enforceable rights over how organizations handle their data, and a support ticket is one of the most common places those rights show up.
GDPR gives individuals eight rights over their personal data, which they can exercise through requests. The law doesn’t specify what channel the request has to come through, so any of them can land in a support ticket and support teams need to be ready when one does.
Four of those eight rights are the ones a support team is most likely to receive: the right of access, the right to data portability, the right to erasure, and the right to rectification.The others: to be informed, to restrict processing, to object, and rights around automated decision-making can surface too, but less often through a support queue. We’ll cover the four most common ones below.
This is a customer requesting visibility: they want to know what personal data your organization holds. It covers their personal data wherever it sits in your system: tickets, attachments, chat transcripts, and the contact record, across every tool the data reached. Even internal notes an agent has written about their interactions with a customer qualify. This is the request GDPR calls a "subject access request.”
Portability requests arise when a customer wants a machine-readable copy of their data so they can hand it to another provider, often because they’re switching.
“Delete my data” is a request that can apply to ticket attachments, internal notes, linked records in integrated systems, past exports, and archived mailboxes.
GDPR does let you keep data in two situations that often come up in support. The first is when you might need the record to defend a legal claim, such as chargebacks or escalated complaints. The second is when another law requires you to hold onto it, which usually applies to tickets documenting a transaction covered by tax or accounting rules.
This right means your organization must update inaccurate or incomplete personal data at an individual’s request. In a help desk, this could mean that you have to update a customer’s name or email while keeping the ticket history intact.
Once any of these requests arrives, the clock starts ticking. GDPR requires a response without undue delay and within one month of receipt, extendable by two further months where the request is complex or the customer has made several. If your organization fails to respond in that time, you risk a complaint to a supervisory authority and, potentially, a fine.
We’ve covered what your organization is responsible for under GDPR and what you need to do if someone exercises one of their data subject rights, and next we’re going to look at how long you should keep customer data in your help desk.
GDPR doesn’t set any specific retention periods. Instead, it requires that personal data is kept in identifiable form no longer than is necessary for the purpose it was collected for. A “we’ve always kept every ticket forever” mentality is a compliance liability.
However, you don’t want to be overzealous about deleting data: depending on your business and industry, there may be tax and accounting statutes, sector regulations, and limitation periods for legal claims that require you to keep data for a certain amount of time. Your organization needs a defensible retention schedule, set by data type, with a stated purpose and legal justification behind each period.
That schedule also has to hold up against internal pressure to keep data around - quality assurance and analytics teams often want long ticket histories for context and trend analysis. "It's useful to keep" isn't a lawful basis for keeping it, though: the retention rule still applies, and if a purpose genuinely no longer needs identifiable data, the data shouldn't stay in identifiable form.
And a retention schedule is only as good as your ability to act on it. When deletion time comes, the data doesn't just sit with you, it's in your vendor's systems, and their sub-processors' systems too. As the controller, you're entitled to have it deleted on your instruction, but you can only rely on that if your vendor is contractually bound to act on it: that's what the Data Processing Agreement is for. Which is exactly where choosing the right help desk comes in.
If GDPR applies to your organization, choosing help desk software is as much of a GDPR-compliance decision as it is a feature-based one.
First, it’s important to understand a few roles. Your help desk vendor is your processor. Its own cloud host, any third-party tools it integrates with, and any AI models it uses to power its features are all sub-processors, engaged by the vendor and not contracted by you.
While your exact requirements will depend on your business, these are some of the GDPR-specific things worth checking before you sign with a vendor:
Before you get too far into choosing a new help desk, there are a few GDPR essentials worth checking. If a vendor can't offer these and you need GDPR compliance, it's unlikely to get through your compliance team's full review. Confirming them early saves you carrying a vendor through a process it was never going to pass.
When choosing a help desk, check that it offers:
Deskpro is built for teams that need to deliver great support experiences while still meeting compliance requirements, including GDPR. We approach this in a few different ways:
Deployment flexibility. While GDPR doesn’t impose data residency requirements, it does lay out strict conditions for international data transfers. Keeping your help desk in the EU simplifies your compliance workload, and Deskpro makes that possible with our flexible deployment options, including hosting on the AWS European Sovereign Cloud, regional private clouds, and on-premise.
Access controls and audit trails. Role-based permissions limit which agents see which data, and audit logging helps you keep a record of activity and access history to support your accountability and investigation needs.
Documentation you can hand to a Data Protection Officer (DPO). A DPA, a published sub-processor list, and security documentation, without a compliance add-on tier.
A bring-your-own-AI approach. Rather than locking you into specific AI models, Deskpro lets you connect your own, including private models that keep data processing within your defined security perimeter. This enables your team to take advantage of AI productivity tools for your agents, such as ticket summarization and suggested replies, without risking a GDPR violation.
If you’re evaluating help desks and know you need to comply with GDPR, it’s worth taking a closer look at Deskpro. You can book a demo with our team, or get started with a self-guided tour at any time.
Yes, if your organization is established in the EU, or you offer goods or services to people located in the EU or monitor their behavior there, GDPR applies to the personal data in your customer support tickets. It also applies to internal notes your agents add to it, to the extent they relate to an identifiable person.
GDPR doesn’t set a fixed time, but it does require that personal data be kept in identifiable form no longer than is necessary for the purpose it was collected for. That means you set the schedule and justify it, factoring in minimum retention obligations based on your organization and industry.
A Data Processing Agreement (DPA) is the contract GDPR requires between a controller and a processor. It sets out what the processor may do with the data, the security measures it applies, how it handles data subject requests and breaches, and what happens to the data when the contract ends. Your help desk vendor is your processor, so a DPA is required. It should also list the vendor's sub-processors and give you a right to object to changes.
GDPR compliance is a property of how an organization processes data, so no help desk can be GDPR-compliant outright. What a help desk vendor supplies is the deployment options, controls, and documentation that let you meet your GDPR obligations. Deskpro offers a DPA and a published sub-processor list, EU and sovereign cloud or on-premise deployment for teams that need to keep data in-region, role-based access controls with audit logging, and the ability to connect your own AI, including private models. Our security documentation sets out the specifics.