By Rafael Luque Ocaña

AI agents and data protection: what the AEPD says

An agent isn't a chatbot: it reasons in chains, remembers, acts on its own and connects to your systems. The AEPD has published guidance on what changes under the GDPR when AI stops responding and starts acting.

For a couple of years, "using AI" meant, for most companies, talking to a model: asking a question and getting an answer. That's changing fast. The new generation of tools doesn't just respond: it acts. It reads your email and replies, checks your calendar and books, browses, fills in forms, chains steps towards a goal. These are AI agents, and their arrival at the SME workplace is a matter of quarters, not years.

The Spanish Data Protection Agency (AEPD) hasn't waited for the phenomenon to mature: it has published specific guidance on agentic AI, analysing what changes — under the GDPR — when AI gains autonomy. It's worth reading, because it puts precise words to a correct intuition: an agent isn't a chatbot with more features, it's a different category of risk.

What makes an agent different

The guidance identifies the traits that set the agent apart from the classic conversational assistant, and each one has its own data protection reading:

Chain-of-thought reasoning. The agent breaks a goal down into steps and executes them sequentially. Consequence: personal data can pass through more processing stages than the user sees or imagines, and the "purpose" of each stage becomes harder to explain — precisely what GDPR transparency requires being able to explain.

Persistent memory. Unlike a conversation that gets forgotten, an agent can remember across sessions: preferences, data, context. That is processing with a vocation for permanence, which raises the classic questions of retention and minimisation with a new intensity: what does it remember, for how long, and how is it deleted?

Autonomy. The agent makes intermediate decisions without consulting on every step. When those decisions affect people, the shadow of Article 22 — automated decisions with significant effects — appears quickly, with its guarantees of human intervention and the right to contest.

Service integration. The agent connects to email, calendar, CRM, files. Each connection is a door through which personal data flows, and each connected service can be a processor — or a third party — that requires its own contract and safeguards (Article 28). The risk surface is no longer a single tool: it's a graph of connections.

The central idea: effective human oversight

If one concept runs through the guidance, it's this: human oversight of an agent has to be effective, not ceremonial. It isn't enough for someone to be theoretically "able to review" what the agent does; the design has to allow its actions to be understood, interrupted and corrected in time. An agent whose decisions nobody can follow isn't supervised just because a human sits at the end of the org chart.

For an SME, that principle translates into very concrete questions before granting an agent any permissions: what exactly can it do, and what is off-limits? Who reviews what it does, how often, and with what record? What happens — and who is accountable — when it chains together a wrong action?

How to govern agents without stopping them

The AEPD's guidance is exactly that, guidance: reference doctrine, not a new layer of obligations. The obligations are the usual GDPR ones — transparency, lawful basis, minimisation, processing contracts, security, the Article 22 safeguards — applied to a subject that stresses them more than any other. The sensible response isn't to ban agents or adopt them blindly, but to govern them with the same method as the rest of AI, raising the bar by one notch:

  1. Inventory the agents for what they are. Not as "just another tool": the inventory must capture which services each agent connects to, what permissions it holds, and what data it touches. An agent without a record is a blind spot with hands.
  2. Register the relationships, not just the pieces. An agent's risk lies in its connections — who orchestrates whom, which system feeds which. Documenting that map is what makes it possible to explain the data processing end to end.
  3. Assign oversight with a name and a method. A specific person, a specific scope, a record of reviews. It's the agentic version of a principle you already know if you follow this blog: diffuse responsibility is no responsibility at all.

At Alethexis we dedicate a specific module to agent governance precisely because this map of identities, relationships and oversight doesn't honestly fit into one more box in the general inventory. Agents are coming into your company either way; the only variable under your control is whether they arrive governed.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.