AI and GDPR in real estate: the questions to ask before automating
Automating part of the client relationship saves real time — provided you do not create a compliance problem while solving an organisational one. The data a real-estate agency handles is among the most sensitive in everyday commerce: budget, family situation, financing, sometimes identity documents. The GDPR fully applies, and in Luxembourg the supervisory authority is the CNPD.
This guide is not legal advice: it is the list of questions an agency should put to any provider of conversational AI — and to itself — before getting started.
Where is the data?
The first question, and the easiest to check. Where are conversations hosted, where are they processed, and by whom? Hosting in the European Union simplifies the file considerably: no transfers outside the EU to frame, a single legal framework.
Ask for the list of sub-processors (the AI provider has providers of its own) and check that the contract includes a data-processing agreement — the DPA — specifying who processes what, where, and under which safeguards.
Does the prospect know they are talking to an AI?
Transparency is a core GDPR requirement, and it is also a matter of commercial trust. The prospect must be informed that they are talking to an automated assistant, know which company is the data controller, and be able to reach the privacy policy easily.
In practice: a clear notice at the start of the conversation, and an up-to-date privacy policy describing this processing. Nothing more complicated — but nothing less.
Is the data used to train models?
A question to put to the provider explicitly, in writing. Your clients’ conversations should not be used to train AI models, nor reused for the tool’s other customers. The answer belongs in the contract, not just in a sales pitch.
How long are conversations kept?
The GDPR requires that data not be kept beyond what is necessary. For prospecting conversations, that means defining a duration — and sticking to it, ideally through automatic purging. The information useful for commercial follow-up (the qualification, the contact details) lives in the CRM under its own rules; the verbatim of conversations does not need to be kept indefinitely.
Document this choice in your record of processing activities: it is precisely the kind of simple measure a supervisory authority expects to find.
What happens when someone exercises their rights?
Access, rectification, erasure, objection: a prospect can exercise their GDPR rights over the data exchanged with your assistant just like any other. Check that the tool lets you find and delete a person’s data without acrobatics, and that your privacy policy says who to write to.
Can a human take over?
Beyond compliance, this is a common-sense requirement: a conversation that goes off-script — negotiation, complaint, a delicate personal situation — must be able to pass to a human agent, with the history. A system without a human exit is a commercial problem before it is a legal one, but it often ends up being both.
The checklist in short
Before signing with an AI assistant provider:
- Hosting and processing in the EU, sub-processors listed, DPA signed.
- Clear information for the prospect (automated assistant, data controller, privacy policy).
- Written commitment: no model training on your data.
- Defined retention period, automatic purging, record of processing up to date.
- A simple procedure for data-subject rights.
- Built-in human handover, with history.
These requirements echo good WhatsApp practice: in both cases, the framework is manageable as long as you choose European tools and document your practices.
The takeaway
The GDPR does not prohibit automating the client relationship — it requires doing it properly. For an agency, compliance plays out less in grand principles than in a series of concrete checks when choosing the tool. An hour of questions to the provider avoids months of regularisation.