GDPR and LGPD in Customer Service: A Practical Checklist
A practical GDPR/LGPD checklist for the whole customer service operation: CRM, tickets, data export, deletion and audit trails — not just the chat banner.
Ask most teams about GDPR or LGPD in customer service and the first thing that comes up is the consent banner on the live chat widget. It matters, but it only covers a fraction of the problem: a contact’s data flows through the CRM, tickets, multiple teams and, increasingly, AI decisions. If compliance stops at the widget, the rest of the operation is still exposed. Here’s a checklist for the parts that usually get left out.
Consent is the starting point, not the destination
A consent banner built into the chat widget, with timestamp and context logged, is the baseline. But once a visitor accepts the terms, where does that data go? Who can see the conversation history, and for how long does it stay accessible? A mature operation treats consent as the start of a data flow that needs to stay traceable from first contact through ticket closure. It’s worth reviewing how that flow is structured today — the security page breaks down the controls a customer service platform should offer along the way.
CRM and conversation history: what to check
A conversations CRM centralizes contact, company and commercial context for the whole team — great for sales, but it raises the stakes on access control:
- Permissions by role and company: not every agent needs to see every contact’s full history.
- Segregation between teams: a support team and a sales team may need different views of the same contact.
- Data retention: is there a clear rule for how long conversation history is kept?
- Audit logs: every access to sensitive data should leave a trace — who saw what, and when.
Without that, the CRM becomes an uncontrolled repository of personal data, which is exactly the kind of risk GDPR and LGPD exist to prevent.
Tickets and SLAs: sensitive data moving between teams
Commercial tickets move between support, sales and sometimes finance. Each handoff is a point where personal data can end up exposed beyond what’s needed. A minimal checklist here:
- Is the SLA tracked in real time while ticket content access still respects the viewer’s role?
- Do volume, conversion and quality reports use aggregated data, or do they expose identifiable information unnecessarily?
- Is there an internal chat between agents to discuss a case without exposing the contact’s full history to people who don’t need it?
These questions sound operational, but this is exactly where GDPR and LGPD audits find gaps in practice — not in the consent banner, but in how data moves internally.
Export and deletion on request
Both GDPR and LGPD give data subjects the right to request a copy of their data or ask for deletion. In practice, that needs to be an operational process, not a manual exception someone remembers to handle:
- Export by contact: can the company generate, in minutes, every piece of data tied to a specific contact?
- Automated deletion: does the process actually remove the data (chat, CRM, tickets) and confirm it to the requester, or does it stay scattered across systems?
- Response time: is there a defined flow, so the request doesn’t depend on someone remembering to act on it manually?
Compliance that depends on an agent remembering a manual process isn’t compliance — it’s luck with an expiration date.
Audit trails: proving what the team and the AI did
With AI increasingly involved in triage, response suggestions and lead qualification, auditing has gained a new layer: it’s no longer enough to prove what an agent did — you also need to explain what the AI decided. An AI audit panel with contact search and an explanation of decisions — why a lead was qualified a certain way, why a conversation got escalated to a human — is what turns a compliance policy into something verifiable. For companies that want full control over which AI model processes their contacts’ data, BYOK (bringing your own AI key) also belongs on this checklist.
An audit panel for DPOs, with date filters and per-contact data export, closes the loop: consent, use, access and deletion, all traceable in one place.
Conclusion
GDPR and LGPD in customer service aren’t solved with a well-configured banner — they require every point the data passes through (CRM, tickets, reports, AI) to have access control, an audit trail and a working deletion process end to end. If this checklist turned up gaps in your own operation, it’s worth reviewing the pricing plans or scheduling a demo to see how it works in practice.