Omnichannels and AI: A Unified Solution demanding an Integrated Legal Approach

The adoption of AI-powered omnichannel solutions requires consideration of several intersecting regulatory frameworks, including data protection and privacy, labour law and AI-specific regulations. What key issues should stakeholders pinpoint to build legally compliant solutions?

I. What are omnichannel solutions and the role of AI?

Nowadays, organisations across all sectors widely adopt omnichannel strategies. As the prefix “omni” suggests, these are plans for engaging with multiple stakeholder groups – primarily customers, but also employees or suppliers – across all available touchpoints and channels.

To implement such strategies, organisations use omnichannel technological solutions, either built in-house or, more commonly, through commercial Software-as-a-Service (SaaS) platforms such as Salesforce, HubSpot, Zendesk or Adobe Experience Cloud. Unlike multichannel approaches, where each channel operates independently, an omnichannel solution centralises an organisation’s interactions across multiple communication channels — such as voice, e-mail, chat, video, social media and messaging applications — within a single, unified environment. This ensures a consistent and seamless user experience, regardless of how stakeholders choose to interact with the organisation (online, in-store, by telephone, through social media, etc.).

The progressive integration of artificial intelligence (“AI”) into omnichannel solutions aims at providing tools and features to improve operational efficiency, generate richer data insights, and enhance the customer experience. Examples include interaction recording and transcription, virtual agents and chatbots, speech and text analytics, sentiment and emotion analysis, automated quality monitoring, workflow automation and intelligent routing.

II. What are the legal challenges of AI-powered omnichannel solutions use?

Organisations using such AI-powered tools and features must navigate several intersecting regulatory frameworks. We highlight three in particular: data protection and privacy, labour law, and AI-specific regulations.

Each tool or feature is subject to its own specific regime and requires case-by-case analysis. In this Insight, we discuss interaction recording and transcription as an example, noting that even this single feature may raise different legal implications depending on its functionalities (for instance, whether it incorporates sentiment and emotion analysis).

1. Data protection and privacy regime: Your call may be recorded (but is it lawful?)

AI-powered omnichannel solutions raise immediate legal privacy and data protection implications. These tools and features may entail the processing of personal data of data subjects such as customers, employees, candidates, or supplier representatives.

In Portugal, the key legal instruments include the General Data Protection Regulation (“GDPR”), Law No. 58/2019, of 8 August (“GDPR Implementation Law”), the ePrivacy Directive and Law No. 41/2004, of 18 August (“ePrivacy Law”).

Regarding interaction recording and transcription, the ePrivacy Directive and ePrivacy Law establish the principle of confidentiality of communications, under which the recording of communications is generally prohibited, except (i) where the users concerned give prior consent; (ii) legally authorised recordings of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business/contractual communication; and (iii) public services recordings to respond to emergency situations.

The GDPR and any obligations arising therefrom also apply to the recording and transcription itself, as well as any further downstream processing.[1]

For organisations, the interaction recording and transcription feature would typically be permitted under the consent exception. Since the ePrivacy Directive and ePrivacy Law do not establish specific consent requirements, GDPR consent requirements apply to the recording and all downstream processing activities (e.g., storage, access, search, AI-assisted analysis). In particular, consent should be informed, meaning the organisation must provide minimum prescribed information to the data subject in accordance with the principle of transparency.[2]

2. Labour law: The legal considerations of AI use in the employee/employer power imbalance

Additionally, labour law should be considered. From an employment perspective, organisations typically use these tools and features either (i) internally to provide a more seamless work experience, or (ii) when interacting with external stakeholders, where employees, such as agents, HR professionals, and other staff, use the interaction recording and transcription feature.

We highlight three labour law aspects that can impact the use of AI-powered tools and features:

(i) Additional requirements to employee consent for the purposes of data processing

This feature also entails the processing of personal data of employees (e.g., their voice, image, and the content of their interventions may be captured). To comply with the ePrivacy Law, consent may be the legal basis for the processing of an employee’s personal data – however, in order to be valid, employers must ensure that this consent is freely given.  Due to the inherent power imbalance between employer and employee, in line with CNPD Deliberation No. 629/2010, consent cannot be considered freely given as a general rule. For employee consent to be valid, besides fulfilling the GDPR requirements, employers must ensure that (i) refusal to consent is not detrimental for the employee; and (ii) a genuinely equivalent alternative is provided (e.g., the option to participate in the interaction without being recorded, such as a non-recorded meeting to perform their duties or for interview purposes).

(ii) Specific regime of remote surveillance of employees

The Portuguese Labour Code, complemented by CNPD Deliberation No. 1638/2013, clarifies that employers generally may not use systems enabling the continuous monitoring or tracking of employees’ activities without their knowledge, nor may they store or extract information produced or stored by employees. Additionally, employers must not collect data concerning employees’ private lives under any circumstances (e.g., a call where the employee refers to their private life circumstantially).

(iii) Information requirements for a few selected uses

If the AI-powered tool or feature is used in employment-related decision-making — including access to and retention of employment, working conditions, profiling and monitoring of professional activity (e.g., quality assessments/performance evaluation) — the Labour Code also requires employers to inform employees.

We note that the line between legitimate quality evaluation and prohibited permanent monitoring is fact-specific and must be drawn carefully.

3. AI-specific regulations: Where does your AI-powered omnichannel solution fall on the risk spectrum?

The AI Act introduces a risk-based regulatory framework that is directly relevant to AI-powered omnichannel solutions. Its obligations are being phased in progressively, with the majority of obligations applying from 2 August 2026.

The AI Act’s practical impact will depend fundamentally on how the specific AI tools and features in question are classified under its risk taxonomy: prohibited, high-risk, limited and minimal risk.

Where AI is used solely for recording and transcription — without influencing decisions about individuals — the system is unlikely to be classified as high-risk, and the compliance burden will be correspondingly lighter. However, if it incorporates workplace sentiment and emotion analysis, for instance, it may constitute a prohibited AI practice; if used for candidate profiling and automated employee quality scoring, it may instead fall under high-risk AI systems, triggering comprehensive obligations for providers and deployers (typically including the organisations using the tools and features), including risk management, human oversight, transparency, data governance, record-keeping, and conformity assessment.

Additionally, the AI Act imposes a general obligation on all deployers to ensure adequate levels of AI literacy among their staff, proportionate to the context and risks involved.

III. Building and using an AI-powered omnichannel solution: The need to make a regulatory compliance checklist

Whether an AI-powered omnichannel solution complies with the law depends on which tools and features it uses. Each solution needs a case-by-case analysis because legal requirements differ. Beyond the regimes discussed here, others may apply – such as cybersecurity rules (including the NIS2 Directive), data governance laws like the Data Act, or sector-specific rules (e.g., in healthcare or finance).

As such, to navigate the increasingly complex and ever-changing regulatory landscape, businesses should:

– Conduct comprehensive compliance and risk assessments to identify applicable legal obligations;

– Develop and maintain an implementation roadmap and governance framework;

– Review supplier contracts to ensure they meet regulatory requirements and manage risks;

– Review the relevant customer-facing and internal processes and documents;

– Provide targeted training to relevant staff.

The path to compliant deployment of these solutions must have at its core a genuine commitment to the principle that technology, however powerful, must operate within the boundaries set by law. The omnichannel promise is one of seamless integration. The legal reality, for now, is rather more fragmented – but compliance is feasible for those who set it as a priority.


[1] The Portuguese National Data Protection Commission (Comissão Nacional de Proteção de Dados,“CNPD”) has issued guidance on the processing of call recordings (Deliberations No. 629/2010 and 1039/2017) addressing the legitimate processing of recorded calls, primarily for three purposes: (i) in the context of a transaction within a contractual relationship; (ii) for service quality monitoring; and (iii) emergency situations.

[2] Under GDPR Article 4(11), valid consent means “freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her”. See also the European Data Protection Board Guidelines 05/2020 on Consent and Article 29 Working Party – Guidelines on Transparency.

Os Insights aqui publicados reproduzem o trabalho desenvolvido para este efeito pelo respetivo autor, pelo que mantêm a língua original em que foram redigidos. A responsabilidade pelas opiniões expressas no artigo são exclusiva do seu autor pelo que a sua publicação não constitui uma aprovação por parte do WhatNext.Law ou das entidades afiliadas. Consulte os nossos Termos de Utilização para mais informação.

Gostaríamos muito de ouvir a tua opinião!

Estamos abertos a novas ideias e sugestões. Se tens uma ideia que gostarias de partilhar connosco, usa o botão abaixo.