Data Protection Impact Assessment (summary)
Last updated: 2026-07-16
Last updated: 16 July 2026
Why a DPIA
Large-scale processing of voice recordings by an AI system can be high-risk under GDPR Art. 35, so we maintain a DPIA for the AI Fortis Voice AI Platform.
Processing described
AI voice agents make and receive phone and web calls on behalf of clients, record and transcribe them where enabled, and extract structured outcomes and analysis.
Necessity and proportionality
Processing is limited to the client's documented instructions and the campaign purpose; data minimisation applies, and data is deleted on account closure, on verified erasure requests and via the automatic purge of website demo data.
Risks and mitigations
- Unauthorised access to recordings / transcripts → TLS, AES-256-GCM encryption of secrets, row-level-security tenant isolation, role-based access with optional MFA.
- Lack of caller awareness → AI and recording disclosure configured in each agent's greeting and script (see the AI & Recording Disclosure page).
- International transfer → EU Standard Contractual Clauses + transfer impact assessment.
- Over-retention → deletion on account closure + erasure on verified request + automatic purge of website demo data.
Residual risk
Assessed as acceptable with the controls above. This summary is a template — a full DPIA should be completed with counsel for each high-risk use case.