A medical secretary files cardboard folders in a shuttered cabinet, with an open binder on the reception counter

· 6 min read

Agentic AI and personal data: who is responsible under GDPR?

In July, the CNIL published a note on agentic AI and personal data. It describes agents passing information from service to service and responsibility becoming difficult to assign. What it says, and what to retain before starting a project.

On July 20, 2026, the CNIL and the Conseil de l'IA et du numérique published a note on agentic AI and personal data protection. It contains no figures. It describes a difficulty: when agents carry out tasks in sequence, identifying who is responsible for processing under the GDPR becomes complicated.

What the note describes

According to the note, an agentic system brings together an orchestrating agent that the user addresses in natural language, specialist agents coordinated by that orchestrator, and external services used by those agents. Each agent has its own context, erased at the end of a task, and persistent memory storage that is independent of individual tasks and fills up as exchanges continue. The note observes that these systems process substantial volumes of personal data, sometimes sensitive, within a legal framework designed for processing decisions made by humans with purposes established in advance. The gap between those two worlds is the subject of the document.

Memory: the point affecting your project

The first mechanism the CNIL highlights is persistent memory. It allows an agent to know you better from week to week while building a detailed profile of you at the same time. The note cites an incident reported in the press: an employee at a large technology company saw her agent delete numerous work emails and had difficulty interrupting the process remotely. The note draws a requirement from this that is useful to anyone commissioning software: you must be able to quickly identify where an action originated, correct it, and limit its effects. An agent team building a product raises the same question on a smaller scale. The answer lies in keeping a trace of what each agent received and wrote.

Unclear responsibilities

On the legal side, the note maintains that deploying agents does not remove the requirement to identify a data controller. It finds that multiplying agents and third-party services makes it harder to allocate controller and processor roles and to demonstrate accountability. It goes further: developers, model providers, integrators, deployers, and users form a chain in which civil, and even criminal, responsibilities remain unclear. There is no dedicated European regime following the abandonment of the proposed AI Liability Directive in 2025. In France, ordinary law still applies, and the precise allocation depends on your contract. Have your adviser examine this point before signing with a provider that uses agents to work for you.

Safeguards the note proposes

The note concludes by proposing legal and technical ways to reconcile these concerns. On the legal side, it proposes stronger transparency rules around agents' actions and mandatory human approval for the most critical decisions. On the technical side, it proposes separating agents' memories to prevent data accumulation, deploying them in isolated environments, and providing an emergency stop controlled by the user. Regarding approval, the note recalls the interpretation adopted by the Court of Justice in the SCHUFA case on December 7, 2023: human intervention must be real and effective, and must influence the final decision. Formal approval that merely rubber-stamps the result is not enough.

Where data goes when agents build your software

We need to distinguish two flows, and we apply that distinction to ourselves. The first is storage: with Maestro, your project, documents, and code live on your Mac, access keys stay in macOS Keychain, and no Maestro server sees your projects. The second is processing: what agents send in order to work goes to the assistant you selected, Claude Code, Codex, Cursor, or Mistral Vibe, and its provider receives it. It would be false to write that your data never leaves your machine. Choosing an assistant therefore also means choosing a recipient. On August 11, 2026, Mistral announced regional endpoints that let you specify the processing region, which matters for a GDPR-covered project or when dealing with a public-sector client.

In practice, before starting work

Write a list of the real data you intend to let agents read during construction, and remove anything unnecessary. Fictional test datasets are enough to build screens, and nobody needs your actual patients to design a follow-up record. Then check who receives the work by looking at the selected assistant, and record that choice explicitly in your compliance documentation. Finally, note who in your organisation can stop work in progress and return to an earlier version: that is the practical counterpart of the emergency stop the note calls for. Our data flows are detailed on /vos-donnees, and what confidentiality changes for healthcare professions provides a concrete example. We learned our most expensive lesson through a key left visible in our own code.

Read the complete guide: build an application without coding

Back to the journal

Take the baton.

Leave your email to try Maestro in the first waves.

The beta is open by invitation on macOS 13 and later. Leave your email for an upcoming wave of access. Windows is in development.

The beta is currently available on macOS 13 or later. Your answer helps us plan other versions.

Your email is only used to let you know when access opens. Nothing else, we promise.