Switching customer service system is a data project as much as a tooling project. Several years of tickets, customer records, attachments and internal notes have to go somewhere, and most of it is personal data. This article covers what GDPR requires of you when you move customer data between two vendors, what should move, what should be deleted and what to demand from the vendor you are leaving.
Who is responsible for the customer data during the switch?
You are the controller for the customer data throughout, and both the old and the new vendor are processors. Moving the data changes nothing about that. According to the Swedish Authority for Privacy Protection, IMY, a processor must, when the agreement ends, either delete or return the personal data and delete existing copies, unless legislation requires that they be kept. You decide which.
In practice that means three things. You need a data processing agreement with the new vendor before the first record moves there. You need to read the agreement with the old vendor to see what it says about export, deletion and deadlines. And you need one person who owns the switch and makes the decisions about what moves, because the vendors cannot make them for you.
What should move, and what should not?
What is still needed for a clear purpose moves. What is not needed is deleted in the old environment, not moved to the new one. The storage limitation principle means, according to IMY, that personal data may only be kept as long as it is needed for the purpose, and that you must have routines for deletion. A switch is the moment most companies discover that the routine was missing.
| Data | Moves? | Why |
|---|---|---|
| Open and recently closed tickets | Yes | The customer may come back, the answer must be there |
| Tickets older than your retention period | No, deleted | The purpose has been fulfilled |
| Customer records with contact details | Yes, for active customers | Needed to reply |
| Knowledge base and help articles | Yes | Rarely contain personal data, and are the company's knowledge |
| Attachments in tickets (receipts, photos, ID documents) | Only those belonging to tickets that move | Attachments often contain more than you think |
| Internal notes about customers | Reviewed first | Anything written about a person is personal data |
| Call recordings and chat logs | Per the rule you set for them | Their own retention period, usually shorter |
| Deletion requests already carried out | Must not reappear | A migrated backup can resurrect deleted data |
The last row is the one that most often goes wrong. If a customer asked for deletion in March and you migrate an export from February, the customer is back. How such requests work is described in the article on GDPR requests in the inbox; at a switch, the list of completed deletions should be checked against what is being moved.
How long may you keep old tickets?
As long as the purpose requires, and you decide that yourself with a written rule. GDPR sets no time in months. A common split is that a ticket is needed as long as it can come back, which for most online stores and service companies means the complaint period, three years, for tickets about a purchase, and considerably shorter for questions like "where is my order".
Bookkeeping is the exception. Accounting records, such as invoices and credit notes, must according to the Swedish Tax Agency be kept for seven years after the end of the calendar year in which the financial year ended. That requirement applies to the bookkeeping, not to the chat log where the customer asked about the invoice. A common mistake is to let the whole ticket history inherit the seven years of bookkeeping; it is the other way round: the invoice is kept in the accounting system, the ticket is deleted according to customer service's rule.
Write the rule before you export. It decides how big the export is, how much is deleted at the old vendor and what you can tell a customer who asks.
How do you move the data safely?
The data moves as an export in a machine-readable format, over an encrypted channel, into an environment where only the people working on the switch have access, and it is verified before the old environment is closed. Four things decide whether it goes well.
- The format. Ask for the export in a format the new vendor can import without manual work: structured data per ticket with customer, timestamps, messages and attachments, not one PDF per ticket. Before signing with a new vendor, ask how you get the data out again. It is the same question as in the buyer's guide to ticketing systems, and the answer says a lot about the vendor.
- The route. Export files must not be emailed, put in a shared folder or sit on a laptop. They contain everything you know about your customers. A lost export is a personal data breach that may have to be reported to IMY within 72 hours.
- The check. Count tickets, customers and attachments in the source and in the target. Open a sample and compare. Check in particular that deleted customers have not been resurrected and that access permissions have not come across wrongly.
- The transition. For a period the data exists in two places. Decide how long that period is, who has access to the old environment during it and when it is closed. The longer it is, the more tickets end up in the wrong system.
What do you demand from the old vendor when the contract ends?
That it deletes or returns everything, including copies and backups, within a written time, and confirms it in writing. Article 28 of the GDPR gives you the choice between deletion and return, and according to the European Data Protection Board's guidelines on controllers and processors the contract should let you change that choice before the end of the service. Choosing "delete" when the contract was signed does not prevent you from requesting an export first.
Ask about three things that rarely appear in the contract: how long backups remain after deletion, whether sub-processors (such as a cloud provider) delete at the same pace, and whether the vendor keeps anything with reference to law, and if so what. Request a written certificate that deletion has been carried out, with a date. That is the document you show if IMY asks.
Where does the data end up with the new vendor?
In the country and with the sub-processors the data processing agreement names, and you should know that before you move. Storing personal data in a cloud service counts as a transfer to the country where the service is located, according to IMY's page on transfers to third countries. Storage within the EU and EEA needs nothing extra. For the United States, the European Commission's adequacy decision has applied since 10 July 2023, according to IMY's page on transfers to the USA, provided the recipient is certified under the EU-US Data Privacy Framework. Other countries require standard contractual clauses and your own assessment.
Also ask what the vendor does with the data beyond storing it. Are the tickets used to train AI models, and if so whose? What applies when an AI reads tickets is covered in the article on GDPR and AI in customer service. What Supportifier answers to those questions, including where data is stored and what the processing agreement covers, is on the security page.
What to do
- Appoint an owner for the switch who makes the decisions about the data. The vendors will not.
- Write the retention rule before you export: how long each ticket type is kept and why.
- Read the old processing agreement and request export, deletion and a written certificate under it. Change the choice between deletion and return if you need to.
- Sign a processing agreement with the new vendor and check storage country, sub-processors and what the data is used for.
- Prune at the source before export: tickets older than the rule, customers who requested deletion, attachments that do not belong to what moves.
- Move, count and compare. Check totals and a sample, especially that deleted people have not come back.
- Close the old environment on a set date, receive the deletion certificate and file it with the processing agreement. If you switch to Supportifier, you get a list of what is needed from the old vendor in the first call.
Common questions
Do we have to move the whole ticket history to the new system?
No, and you should not. Move what is still needed for a clear purpose: open tickets, tickets within your retention period and records for active customers. Everything else is deleted at the old vendor. A migration is the only moment when pruning is free, because you are going through the data anyway.
May the old vendor keep a copy after the switch?
Only if the law requires it, and then the vendor must be able to say which law and what is kept. Otherwise everything is deleted, including backups, within the time the contract states. Request a written certificate with a date. Also ask how long backups remain before they are overwritten.
What happens if we lose an export file?
It is a personal data breach. Assess the risk to the individuals: a file with names, email addresses and ticket texts for thousands of customers is rarely low risk. Then the breach must be reported to IMY within 72 hours of discovery, and at high risk the customers must be informed. Avoid the situation by never moving the export via email or shared folders.
Do we have to tell customers that we are switching system?
Not about the switch itself, as long as the purpose and the processing stay the same. If the new vendor is in another country or you start using the data in a new way, for example for an AI chat, the privacy policy must be updated so that it is accurate. Check that it names the right categories of recipients and the right storage country.
Sources
- Personuppgiftsbiträdesavtal — Swedish Authority for Privacy Protection, read 2026
- Grundläggande principer — Swedish Authority for Privacy Protection, read 2026
- Överföring av personuppgifter till tredjeland — Swedish Authority for Privacy Protection, read 2026
- Överföringar av personuppgifter till USA — Swedish Authority for Privacy Protection, read 2026
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR — European Data Protection Board, 2021
- Bokföring: vad kräver lagen? — Swedish Tax Agency, read 2026