Agencies

Who is liable when a client’s data reaches a model?

If you build AI automations for clients, their personal data flows through infrastructure you chose. That makes you a processor, with obligations most agencies have not priced in.

The position agencies are in

An agency builds a workflow: a form submission arrives, a model classifies and drafts a response, a record is written to a CRM. The client's customers never hear of the agency. But the personal data passes through an orchestration layer the agency chose, calls model providers the agency selected, and is logged in places the agency configured.

Under the GDPR that makes the agency a processor acting on the client's instructions, and processors have direct obligations — security measures, sub-processor transparency, breach notification, deletion on termination. Those obligations do not depend on whether anyone wrote a contract. They arrive with the role.

Three exposures that show up late

Sub-processors nobody enumerated

A typical automation touches an orchestration platform, one or two model providers, a vector store, a transactional email service and a logging tool. Each is a sub-processor the client is entitled to know about and object to. Most agency contracts list none of them.

Logs as an unplanned data store

Workflow platforms retain execution data by default so you can debug. That means full prompt bodies — names, addresses, case details — sitting in a platform account, often indefinitely, usually outside any retention schedule the client agreed to. This is the single most common finding when an agency's client is audited.

Training and retention terms that change

Whether a provider trains on API traffic, and how long it retains it, is a contractual term that has moved more than once and will again. An agency that promised a client "your data is not used for training" on the basis of a page it read last year has made a commitment it does not control.

The structural fix

The reliable answer is not better contracts. It is arranging things so the personal data never enters the parts of the system you do not control.

If identifying values are replaced with typed placeholders before the payload leaves the client's environment, and restored on the way back, then the model provider, the orchestration logs and any intermediate store contain no personal data. Retention terms stop being load-bearing. Sub-processor lists get shorter and truthful. A breach at a provider is not a breach of your client's data, because their data was never there.

What this changes commercially

Agencies that can demonstrate this win procurement conversations they used to lose. The security questionnaire from a regulated client stops being a two-week negotiation, because the honest answer to "what personal data is shared with your AI sub-processors?" becomes "none". A per-run audit log turns your assurances into evidence you can attach.

Fairwall AI supports this directly: purpose-built n8n nodes put detection and restore inside the workflow, and white-label terms let agencies ship it as part of their own offering. See agency pricing or book a walkthrough.

See it on your own data.

A 30-minute walkthrough of detection, redaction and restore on the kind of documents your team actually handles.

Book a demo

Related reading

This article is general information, not legal advice. Fairwall AI is a brand and product of Data Dynamics AI FlexCo, Vienna, Austria.