# How should a business evaluate AI agents for GDPR-governed work?

A business should evaluate an AI-agent workflow by its purpose, data location, processor terms, retention, access controls, source permissions, and human decision boundary before production. Queli agrees these controls with the customer for the specific process and environment.

## Start with the data and the purpose

Before discussing a model, list the sources the workflow needs: an invoice, customer message, employee record, ERP entry, CRM history, or field document. Decide why each source is needed, who may access it, what the workflow prepares, and which person remains responsible for the consequential decision. An agent should receive the minimum authorized context for that process, not an open view of the company.

The same question applies to outputs. A prepared invoice draft, customer follow-up, or decision packet can contain personal or commercial information. The workflow needs an agreed owner, review state, retention period, and evidence trail. If the source is incomplete or the model is uncertain, the result should become an exception rather than an unreviewed action.

## Queli’s documented deployment boundary

For GDPR-governed deployments, Queli agrees data location, processor terms, retention, access controls, and responsible human decisions with the customer before production use. Model provider, region, retention configuration, and customer-hosted options are selected per workload and confirmed before production.

The result is a concrete deployment checklist rather than a generic security label. Model provider, region, retention, connection method, and access depend on the customer’s systems, permissions, data boundaries, and the purpose of the workflow.

## Keep the agent inside the approval boundary

A sound business-agent design keeps preparation separate from consequential action. Makra can organize authorized records, prepare a draft or classification, and route an exception. An authorized person approves, changes, or rejects the result, and the workflow records that decision before the next system action.

Legal and security review still belongs to the customer’s responsible teams. Ask for the processing agreement, data-location decision, retention setting, access model, audit or decision record, deletion process, and model-specific handling before production. Use the Queli wording as a boundary for that review, not as a substitute for the review itself.

## Sources

- https://www.queli.ai/
- https://www.queli.ai/llms.txt

## Other languages

- [English](https://www.queli.ai/ai-agents/answers/gdpr-business-ai-agents)
- [Hrvatski](https://www.queli.ai/hr/ai-agenti/answers/gdpr-i-ai-agenti-za-poslovanje)
- [Deutsch](https://www.queli.ai/de/ki-agenten/answers/dsgvo-und-ki-agenten)
