Critical Compliance Issue
# support
t
Hey Vapi Team, I just wanted to reach out about something that’s become a critical issue for my business. I’ve built my entire voice assistant system on Vapi and honestly, I really enjoy the platform; it’s powerful, flexible, and exactly what I need. However, I work with EU-based clients, and because Vapi isn’t certified under the EU–U.S. Data Privacy Framework (DPF), I can’t legally continue using it to process personal data from those users. I know GDPR compliance can be achieved through other means like SCCs, but since I don’t have a direct legal relationship with Vapi (no DPA or SCCs signed), the lack of DPF certification is currently a blocker. Unfortunately, this is forcing me to start transitioning to another platform that does offer those compliance guarantees — which I really don’t want to do. I’m reaching out in the hope that DPF certification is either on your roadmap or being considered seriously. I’d love to stay on Vapi, but without a lawful transfer mechanism for EU data, it’s just not viable from a compliance standpoint. Thanks — and I really hope this is something that can be resolved soon.
v
Thank you for sharing your concerns. While Vapi is fully GDPR compliant and uses standard contractual clauses for EU data transfers, the documentation does not mention DPF certification or a direct mechanism for signing a DPA or SCC with customers. For the most accurate and up-to-date information on compliance roadmaps or to discuss your specific legal needs, please contact Vapi's Data Protection Officer or support team at [security@vapi.ai](security@vapi.ai) as recommended in the documentation. [See GDPR compliance details here.](https://docs.vapi.ai/security-and-privacy/GDPR) Source: - [GDPR compliance](https://docs.vapi.ai/security-and-privacy/GDPR)
c
Hey, sure I'll add that in our roadmap. Thanks for getting in touch with us.
t
Hi Aditya, Thanks for getting back to me and confirming that DPF certification is being added to the roadmap, I really appreciate that. Do you have any rough timelines for when this might be implemented? The reason I’m asking is that, if I understand the legal requirements correctly, any user of Vapi who processes EU personal data and is not on an enterprise plan currently has no access to a signed DPA. This is problematic because, under GDPR, when I collect personal data from callers via Vapi and then pass it to external systems (like a CRM via Make), I am acting as the Data Controller, and Vapi is acting as a Data Processor. In this scenario, Article 28 of the GDPR requires a DPA, and without it, that data flow is technically unlawful. I genuinely like Vapi and want to keep building with it, but if this interpretation is correct, it means a large number of developers and small businesses could be unintentionally operating in breach of EU data protection laws. Looking forward to your clarification and any updates you can share.
c
Hey, I currently don't have the timeline with me.
j
I join the question, the problem is quite urgent and we are pressed for time, and I know that many users have a problem with this and we lose a lot of leads due to this formality.
t
I contacted Vapi directly via email regarding this, and unfortunately at the moment the DPA is only offered to Vapi Enterprise users. I also had the opportunity to be on a feedback session with one of Vapi developers and I was advised that they are looking at servers in Europe but its not their priority. If I had to take a wild guess then this is not something that will become available anytime soon. If you want to have EU based clients then you might have to look at using other platforms. Unfortunately I had to make that move myself as well.
l
Hey, currently having the same legal issue. What platform did you end up moving to?
j
Does anyone know if it matters though? If the client doesnt mind the risk, how likely is it, that the client will be sued if he has smb?
c
Hi, we’d like to inform you, based on your previous conversation (just incase) that all customers can access DPA at the following link: http://security.vapi.ai/
j
But that requires work email. How does a regular customer on a pay as you go plan obtain work email?
c
By work mail, we mean a domain mail, like name@your-company.com. Gmail and others won't work. Trust center documents are gated documents, and this is a strict requirement.
3 Views