Can your customer service data be outside of Europe?

Why work with us:

– We improve your accessibility
– We enhance your customer experience
– We increase your efficiency

Want to know how we’ve been using AI to enhance the customer experience for years?

“With Pegamento, we found not just a supplier, but a true partner in change. Thanks to their expertise and our joint DevOps approach, we have made great strides in a short time. The technology supports our people so they can focus on where they make a difference: personal contact with entrepreneurs.”

Customer data from your customer service is basically not allowed to just be outside of Europe according to the AVG. The General Data Protection Regulation sets strict requirements for data transfer to countries outside the EU. For Dutch companies with customer service, this means that you must consciously choose suppliers that store data within Europe, or take extra precautions for international data transfer.

What does the AVG say about data location of customer data?

In principle, the AVG prohibits the transfer of personal data to countries outside the European Union unless adequate protection is guaranteed. This means that customer data from your customer service must stay within the EU by default, or you must take additional legal and technical measures.

For Dutch companies with customer service, this has direct implications. All call recordings, chat messages, emails, customer profiles and contact data you collect fall under these regulations. The AVG makes no distinction between different types of customer data: all personal data will receive the same protection.

The legislation does recognize that international cooperation is sometimes necessary. Therefore, exceptions are possible, but they always require additional safeguards. You cannot simply choose the cheapest international supplier without looking into the legal implications.

Importantly, the responsibility lies with you as a company. Even if you use an outside vendor for your customer service systems, you remain responsible for AVG compliance. This means you need to actively monitor where your data ends up and what protection is provided.

What risks does data storage outside Europe pose?

Data storage outside of Europe carries legal, operational and reputational risks that can severely impact your business. The AVG can impose fines of up to 4% of your annual turnover or 20 million euros, whichever is higher.

Legal risks are most immediate. The Personal Data Authority can launch investigations into your data processing if customers complain or in the case of data breaches. Without adequate safeguards for international data transfer, you run the risk of substantial fines. Customers can also claim damages if their data has been unlawfully processed.

Operational risks arise because different countries have different laws. For example, U.S. companies may be required to share data with government agencies, even if this violates European privacy laws. This can lead to legal conflicts where you as a Dutch entrepreneur are caught between two legal systems.

Reputational risk is perhaps the greatest danger. Customers expect their data to be handled securely. If it becomes known that you store customer data unprotected abroad, it can seriously damage trust in your company. In industries such as healthcare, financial services and government, this could even mean losing customers or not getting new contracts.

When is data transfer to countries outside the EU allowed?

Data transfers outside the EU are permitted if adequate protection is guaranteed by adequacy determinations, Standard Contractual Clauses or other recognized safeguards. These mechanisms ensure that your customer data receives the same level of protection as within Europe.

Adequacy determinations are the simplest solution. The European Commission has determined that countries such as the United Kingdom, Switzerland, Canada and a few others provide an adequate level of protection. You may transfer customer data to these countries without additional measures as if they were EU countries.

For other countries, such as the United States, you need Standard Contractual Clauses (SCCs). These are standardized contractual agreements that provide additional safeguards for your customer data. Your supplier must sign these clauses and demonstrate that they can actually provide the agreed-upon protection.

Other permissible safeguards include Binding Corporate Rules for large international companies, certifications and codes of conduct. In exceptional cases, you can also seek explicit consent from your customers, but this is practically difficult to implement for customer service operations.

Importantly, you can’t just rely on contractual agreements. You must also assess whether the host country has laws that could undermine the protection of your customer data, such as mandatory intelligence access.

How do you make sure your customer service remains AVG-compliant?

AVG compliance in your customer service starts with conscious choices when selecting vendors and systems. Preferably choose vendors that have their data centers within the EU and are transparent about their data processing and security measures.

Vendor selection is critical to compliance. Ask targeted questions about data location, security measures and certifications. Look specifically for ISO 27001 certification for information security, complemented by ISO 9001 and ISO 26000 for quality and corporate social responsibility. These certifications show that a vendor is serious about data protection.

Contractually, you must make clear agreements about data processing. Provide processor agreements that meet AVG requirements, with clear agreements on data location, security measures and incident reporting. Also include the right to audit and the right to terminate the cooperation if the supplier no longer complies with the agreements.

Technical measures are also essential. Implement encryption for data in transit and at rest, ensure access controls and logging of data processing activities. Regular security audits help identify vulnerabilities in a timely manner.

For companies looking to optimize their customer service without compromising on compliance, an integrated approach offers the best solution. By combining customer contact optimization with strict data protection, you get the best of both worlds. Our expertise in omnichannel customer service, AI-driven automation and compliance ensures that you get everything under one roof. From traditional telephony to modern agentic AI assistants that take initiative independently, all solutions are designed with privacy by design and European data residency in mind.

By choosing customized solutions with standard building blocks, you avoid costly implementations while still getting exactly what you need. With a single point of contact for your entire customer contact infrastructure, you maintain overview and control over your data processing, without the complexity of multiple vendors and different compliance requirements.

Frequently Asked Questions

How do I check if my current customer service vendor is AVG compliant?

Ask your vendor for documentation on data location, certifications (such as ISO 27001), and their processing agreement. Check specifically where data centers are located, what security measures are in place, and whether Standard Contractual Clauses apply when transferring data outside the EU. Also perform an audit or have a specialist do this.

What should I do if I discover that my customer data is stored outside Europe?

Don't stop the service immediately, but first evaluate what safeguards are in place. Check for adequacy determinations or Standard Contractual Clauses. If not, act quickly: negotiate additional safeguards, consider migration to an EU vendor, or engage legal expertise for risk analysis.

Are cloud services such as Microsoft Teams or Slack allowed for customer service?

This depends on configuration and contractual agreements. Microsoft and Slack offer EU data centers, but you must explicitly configure and contractualize this. Check the Data Processing Addenda of these vendors and make sure you have Business Associate Agreements that guarantee EU data residency.

What costs should I charge for AVG compliance in my customer service?

Costs vary greatly by business size and complexity. Expect 10-30% higher vendor costs for EU hosting, €2,000-10,000 for legal compliance audits, and possibly migration costs of €5,000-50,000 depending on your systems. Also invest in training your team (€500-2,000 per employee).

Can I send customer data to the UK after the Brexit?

Yes, the UK has been granted an adequacy decision by the EU, which means you can store customer data there without additional safeguards. This decision is valid for now until June 2025, but is likely to be extended. Do keep an eye on developments and make sure you have contractual backups.

How do I deal with customers who explicitly consent to data transfers outside the EU?

Explicit consent is legally possible but practically difficult. You have to prove that the consent was given voluntarily, specifically and informed. Customers need to know exactly which country data is going to, why, and the risks involved. For customer service, this is usually too complex - rather opt for structural safeguards.

What happens if a data breach occurs at my international customer service vendor?

You are required to notify the Personal Data Authority within 72 hours, regardless of where the leak occurs. With international suppliers, information provision can be slower due to time zones and procedures. Therefore, make sure you have clear escalation procedures in your contract and 24/7 contact options for incident response.

More blogs

Download the white paper here

Deepen your knowledge with Pegamento’s white papers.

Ernst Vegter-Business consultant Pegamento

Ernst Vegter

Business Consultant

Hospitality is one of my deepest motivations.
Not surprisingly, of course, customer service is a common thread in my career. Aspects of hospitality is being able to connect, to facilitate but mainly to make someone feel genuinely welcome. My intuition is my greatest asset to be able to put myself in the shoes of a guest. A customer is my guest.

Fed by various senses, an image forms around the client. I listen to what is being said, watch facial expressions, taste the underlying tone and get a feel for the challenge to be addressed. An image literally forms on my retina. I have to be able to see it. If I can see it, I can create it.

In this, the trick is to pursue simplicity, give the client a warm feeling that the problem is understood, receive good advice, facilitated and carefully guided to the solution. Trust, connect and unburden.

The feeling when a guest arrives at your hotel after a long tiring journey, can sit in front of the fireplace, be handed a good glass of wine and stare carefree at the fire. My guest knows it will be okay.

This piece was written by Ernst Vegter, working as a Business Consultant at Pegamento.

Ger Koedam-Communication & Marketing Pegamento

Ger Koedam

Marketing & Communications

How can I help you? That’s pretty much the first question I ask when talking to people who are curious about our services. In such a conversation, the use of senses is very important. Because not everyone is the same. One person thinks in images, while for another words are important or how something feels. For me, sight and hearing are the most beautiful senses, because both eyes and ears absorb information and can convey or process emotions.

Why hearing? Because listening is essential in contact. And it’s the key to unlocking valuable insights.

I developed this skill early on. As a child, I enjoyed radio plays on the radio, bringing the stories to life in my head.

Rob Roode-Research Development

Rob Roode

Research & Development

Recognizing and automating patterns. Tasks we are constantly working on when implementing our robots at Pegamento. My 2 Drentsche Patrijshonden are hunting dogs and certainly not robots. The hunting instinct and intuition is basically in their genes. Continuing to offer new forms of training has taught them to recognize and act independently in hunting situations. Even “unsupervised,” even if I’m not around.

But when you try to teach a brain something, it also starts to see things you don’t expect. Dogs pick up on the slightest deviation in your voice or directions. To start recognizing that and correcting it again is perhaps the most complex challenge. But in our work, for the wonderful clients for whom we get to work, it often yields the most beautiful new insights!

This piece was written by Rob, founder of Pegamento and in charge of Marketing and R&D.

Serge Poppes-CEO Pegamento

Serge Poppes

CEO

Feeling. That’s the best thing Pegamento stands for. Feeling for technology in the broadest sense of the word. Not only feeling for the exciting stuff like AI, but also for the basics of communication.

The very best part of my job is selling, listening, translating and thinking about what really matters. We bring the digital transformation with a great team!
The diversity of our team, how sharp we are, but especially the wonderful things we get to make makes me feel extremely good. Hence, I intuitively chose the sense of “feeling.

Feeling gives life and differentiation!