Hi Aditya,
Thanks for getting back to me and confirming that DPF certification is being added to the roadmap, I really appreciate that.
Do you have any rough timelines for when this might be implemented?
The reason I’m asking is that, if I understand the legal requirements correctly, any user of Vapi who processes EU personal data and is not on an enterprise plan currently has no access to a signed DPA. This is problematic because, under GDPR, when I collect personal data from callers via Vapi and then pass it to external systems (like a CRM via Make), I am acting as the Data Controller, and Vapi is acting as a Data Processor.
In this scenario, Article 28 of the GDPR requires a DPA, and without it, that data flow is technically unlawful.
I genuinely like Vapi and want to keep building with it, but if this interpretation is correct, it means a large number of developers and small businesses could be unintentionally operating in breach of EU data protection laws.
Looking forward to your clarification and any updates you can share.