Guides

GDPR and chatbots: what to sort out before you go live

Hosting, the DPA, no AI training on customer data, your privacy policy and telling visitors. What a GDPR-compliant chatbot actually needs to have.

Golden combination padlock on a computer keyboard

Almost every first conversation we have about chatbots turns to data protection within ten minutes. Fair enough. A chatbot takes in whatever visitors type, stores the conversation and sends requests to an AI model. Personal data ends up in there, planned or not. The moment someone writes "hi it's Tom Fletcher, order 40817 never turned up", you've got a name and an order number in your chat history.

The reassuring part is that running a chatbot in line with the GDPR doesn't need a legal department. Below are the points we get asked about most in our projects. They should help you judge any provider, not only us.

Quick note first: this isn't legal advice. It describes what we pay attention to in practice. For your specific situation, please talk to your data protection officer or a lawyer.

Where the data lives

The first question for any provider: where are conversations, uploaded documents and contact details stored? Servers in Germany or the EU make life simpler, because you don't have to deal with transfers to third countries for storage.

Then ask a bit further. An AI chatbot has more than one moving part: the platform that stores conversations, and the language model that writes the replies. Those models often come from big providers such as OpenAI, Google or Anthropic. Ask which sub-processors are involved and on what basis data goes to them. A decent provider will answer that without squirming.

With My-Chatify, data is hosted on servers in Germany and the EU, connections are TLS-encrypted, and each assistant has its own separate database. Your content is never shared with other customers.

The data processing agreement (DPA)

When a service provider processes personal data on your behalf, you need a data processing agreement with them under Art. 28 GDPR. In Germany this is called an AVV. With a chatbot provider it's practically always required, since they store your customers' conversations.

Things worth checking in the DPA:

  • Does one exist, and can you get it without chasing?
  • Are the sub-processors listed, for hosting and for the AI model?
  • Does it describe the technical and organisational measures in place?
  • Does it say what happens to your data when you cancel?

To be honest, if a provider gets vague about the DPA, we'd take that as a reason to walk away. My-Chatify provides one.

No AI training on your data

This one gets missed a lot. Some services use what people type to improve their models. For a customer service bot that's a real problem: your customers' questions, order numbers and complaints would feed into someone else's model.

Get it in writing that conversations and uploaded documents won't be used to train AI models, neither by the chatbot provider nor by the AI company behind it. At My-Chatify that's the rule: your data and your customers' conversations are not used for training, including by providers such as OpenAI.

What goes in your privacy policy

Once the bot is live on your site, visitors need to be able to find out what happens to their data. The information duties under Art. 13 GDPR apply here as they do anywhere else. The usual approach is a separate "Chatbot" section in your privacy policy.

It typically covers:

  • who runs the chatbot and where the data is processed
  • why the input is processed, such as answering enquiries and passing them on to your team
  • the legal basis for that
  • who receives the data, including the AI model provider
  • how long conversations are kept
  • what rights visitors have: access, erasure, objection

Also check whether the chat widget stores anything in the browser, for instance a session ID so a conversation doesn't drop when someone clicks to another page. Whether and how that belongs in your cookie banner is a question for your data protection officer. Template wording from the internet is a starting point, not a substitute for that check.

Tell visitors in the chat itself

Hardly anyone reads a privacy policy before typing a question. That's why, in our projects, a short note right inside the chat has worked well. The welcome message is a good place:

"Hi, I'm the automated assistant for this website. I answer based on the information on our site. Please don't share sensitive personal details here. More in our privacy policy."

Two things in there matter to us. Visitors know they're talking to an AI, not a person. That's simply fair, and nobody feels misled later. And the line about sensitive details stops people who would otherwise type their entire medical history into a chat box.

If you collect contact details through the chat, for example with a short form before the conversation starts, say why. "We only need your email to send you the quote" usually does the job.

What to avoid

The most common mistake has little to do with technology. It happens when people build the conversation flows: the bot asks for things it doesn't need.

A few typical examples:

  • A physiotherapy practice has the bot ask for the patient's diagnosis before booking. For an appointment you need a name, contact details and a preferred time. The diagnosis can wait for the treatment room.
  • A shop asks for date of birth and home address to check delivery status. The order number is enough.
  • A training provider asks for benefit paperwork in the very first chat message. That belongs in a proper consultation, not a website chat.

Health data, religious beliefs, financial details and ID documents have no place in a general website chat. If your line of work involves that kind of information, as a practice or a law firm might, use the bot for the organisational side (opening hours, document checklists, appointment requests) and handle anything sensitive through the channels you already use for it.

One more: don't upload internal documents containing personal data as knowledge sources. The staff list with direct dial numbers, a spreadsheet of customer records, old email threads. Anything in the sources can turn up in an answer.

A short checklist

ItemWhat to ask or do
HostingWhere are conversations and documents stored? Germany or the EU?
DPAIs there a data processing agreement, with a list of sub-processors?
AI trainingIs training on your data ruled out in writing?
Privacy policyIs there a chatbot section covering purpose, recipients and retention?
Notice in the chatCan visitors tell they're talking to an AI?
Data minimisationDoes the bot only ask for what it really needs?
SourcesHave you kept internal documents with personal data out?

Wrapping up

Data protection for a chatbot is less daunting than most people expect. Most of the work lies in sensible choices during setup rather than in legal text. If you'd like to look at My-Chatify without any pressure, you can try it for free. For the DPA or any data protection questions, drop our team in Dortmund a line via the contact page.

All articles
Ready in 3 minutes

Want to try it yourself?

Set up an assistant for free and test it with your own content before any customer gets to see it.

  • No credit card required
  • Cancel anytime
  • GDPR compliant