I’m currently building an AI voice agent / AI receptionist business and I want to make sure everything is fully compliant from day one (EU + US market). I’ve been looking into GDPR and general regulations around AI + telephony, but I want to double-check that I’m not missing anything. Here’s what I have so far: 📄 Legal & compliance: - Terms & Conditions - Privacy Policy (website) - DPA’s (with clients + with tools) - Service Agreement / Client contract - Subprocessor list (e.g. Twilio, Retell AI, Make.com) 📢 Call / AI compliance: - Privacy notice before recording (“this call may be recorded…”) - AI disclosure (making it clear the caller is speaking with AI) - Recording only starts after the notice 🔐 Data & security: - Basic security measures (access control, API key safety, data protection) - Data breach procedure (72-hour rule) - Data retention policies 🌍 International: - EU → US data transfers (SCCs, etc.) - Awareness of US state laws (e.g. call recording consent rules) --- 👉 My question: Am I missing anything important? Thinking about: - legal documents - compliance risks - things people often overlook - best practices for AI voice agents / SaaS / telecom I want to set this up properly from the start and avoid issues later. Any input is appreciated 🙌