GDPR
GDPR and website chatbots: what businesses should consider
A website chatbot can help customers quickly while processing messages or contact details. Data protection therefore belongs in the design of the service – not only in the privacy notice.
01
Start with purpose and legal basis
Before a chatbot processes data, the purpose should be clear. Answering a general question, preparing a callback, and requesting an appointment are different purposes and may require different information.
The appropriate legal basis depends on the specific use. Businesses should not copy it from a generic template but assess it alongside the actual functions, data flows, and their own legal requirements.
02
Only request necessary data
The GDPR identifies data minimisation as a core principle. Opening hours do not require a phone number. For a callback, a name, contact method, and a short description of the enquiry are often sufficient.
Fewer required fields do more than improve privacy. They reduce drop-off and make the conversation faster. Sensitive information should not be requested as a precaution.
- Justify required fields for each conversation purpose
- Do not keep free-text messages longer than needed
- Do not request or encourage sensitive information in examples
03
Make transparency understandable
Visitors should recognise that they are writing with a digital assistant, understand which data is processed, and know where to find further information. The notice must be clear and match the real technical setup.
The handover matters too: When can a team member read the conversation? Which information is sent to email, a CRM, or a calendar? Transparency comes from specific explanations, not lengthy legal text inside the chat window.
04
Review providers and processing agreements
Businesses need to understand their own role and the provider’s role in processing. Where a service provider acts as a processor, Article 28 GDPR sets requirements for the contractual basis.
The review should also cover subprocessors, processing locations, technical safeguards, and possible international transfers. An EU server location alone does not describe the entire data flow.
05
Organise deletion, access, and data subject rights
Define how long conversation data is needed for support, handover, or quality review. Retention periods should be technically enforceable and match the information in the privacy notice.
Internal rules matter as well: Who may view conversations? How are access, correction, or deletion requests handled? And how are changes to functions or providers documented?
Privacy-conscious customer communication comes from clear purposes, minimal data collection, and transparent technical and organisational processes.
This article provides practical orientation and does not constitute legal advice. The appropriate implementation depends on your organisation’s specific use case and data flows.
Sources and further reading
See how AuraServe can support your team.
Open live demo