AI Receptionist compability to EU-GDPR

JiPa

Customer
Joined
Jun 2, 2026
Messages
11
Reaction score
0
Hello,

since AI is included in our license, I wanted to look into it and possibly let AI handle some basic calls.
But I see only "OpenAI" as provider. - I am not so familiar with the AI regulatory field yet, but I am with other DSGVO / GDPR topics. And everything I read about the way how it works seems to me that it will be very tough if not impossible to legally use an AI receptionist in 3CX as it is setup right now in EU/Germany. You wouldnt be even able to switch to OpenAI EU servers since you can only enter an API key if I am not mistaken?

Did anyone get it to work legally in germany? What are the steps?
 
Not legal advice, just adding to the discussion.

EEA entities opening an account with OpenAI would normally do so with OpenAI Ireland. The agreements provided cover their role as a Data Processor and are GDPR compatible via SCCs.
Even with the global endpoint URL, you should choose the relevant options when setting up your account with them to ensure that the maximum amount of processing stays within the EEA.
 
  • Like
Reactions: Evolute IT
Not legal advice, just adding to the discussion.

EEA entities opening an account with OpenAI would normally do so with OpenAI Ireland. The agreements provided cover their role as a Data Processor and are GDPR compatible via SCCs.
Even with the global endpoint URL, you should choose the relevant options when setting up your account with them to ensure that the maximum amount of processing stays within the EEA.

But 3CX will still hit the global endpoint URL right?
 
Yes, at this time the endpoint URL being used is the global one and not configurable from within the PBX.
It should be noted that OpenAI themselves do not support the full featureset, especially for audio, on their EU-only infrastructure, missing some of the latest models.
While I cannot know your specific requirements, if GDPR compliance is the metric, then that is achievable while using the global endpoints. If the aim is for no single data packet to cross outside the EEA, then it's a different mater.
 
In the US we need HIPAA compliance and OpenAI will provide us with the correct configuration and BAA.

However, its US only, so the endpoint becomes us.api.openapi.com/v1 - the global URL is prepended by "us." Everything works exactly the same.

Since we can't change the endpoint we can't use it. Ouch.
 

Forum statistics

Threads
112,000
Messages
590,220
Members
164,939
Latest member
soteris 2