How it works
Website chatbots and GDPR: what you need in place
What data a website chatbot collects, what your privacy policy must say, and how to handle transcripts and consent under GDPR.
In short
A website chatbot processes personal data as soon as a visitor types their name or email, so your privacy policy must name it, explain what is stored, and say for how long.
Keep the bot from asking for sensitive data, store only what you need, and give visitors a route to request deletion.
Key facts
Key facts
- Chat transcripts containing names or emails are personal data under GDPR.
- Your privacy policy should mention chat processing and retention.
- Do not configure the bot to collect health, financial or identity data in chat.
- Visitors must have a way to request deletion of their conversation.
What to put in your privacy policy
- · That a chat assistant operates on the site and conversations may be stored.
- · What is collected: messages, and contact details if the visitor provides them.
- · Why: to answer questions and respond to enquiries.
- · How long transcripts are kept.
- · How to request access or deletion.
Design the bot to collect less
The easiest compliance win is not collecting data you do not need. A bot that asks for an email to follow up is fine; a bot that asks for a date of birth or a card number is a problem you created yourself.
Consent and cookies
If the widget sets cookies or local storage beyond what is strictly necessary, it belongs in your cookie banner. Keep the chat session identifier minimal and functional, and describe it honestly.
The product behind this guide
A chatbot trained on your own website, live today
Defaltam builds AI chatbots that read your public pages and answer with your real prices, services and policies. Support is €79/month, Sales is €149/month, both start with a 5-day free trial, and installation is one script tag.
FAQ
Questions people ask about this
Is a website chatbot GDPR compliant?
It can be. Because transcripts can contain personal data, your privacy policy must mention chat processing, what is stored and for how long, and visitors need a route to request deletion. Avoid collecting sensitive data in chat entirely.
Do I need consent before someone chats?
Not for the visitor's own message, but you should disclose the processing clearly and handle any non-essential storage through your cookie banner.
How long should I keep transcripts?
Only as long as you need them to answer and improve. State the period in your privacy policy and stick to it.
Can the chatbot handle health or financial details?
It should be configured not to ask for them. Route those conversations to a secure channel instead.
Related
Keep reading.
How AI chatbots actually work →
From the visitor's question to the answer on screen: retrieval, context, the language model and why grounding in your content matters.
How to stop a chatbot from making things up →
Hallucinated prices and invented policies destroy trust. The four controls that keep a website chatbot honest, and how to test for them.
Running a multilingual AI chatbot →
How a modern chatbot answers in the visitor's language from a single-language website, where it goes wrong, and what to translate anyway.
Designing a chatbot handoff to a human →
When a bot should stop answering, what it should collect before passing over, and how to make the handoff feel like service rather than failure.
Website chatbot security basics →
Prompt injection, data leakage, abuse and rate limits — the security questions to ask before putting an AI chatbot on a public website.
Why most website chatbots fail →
Chatbots fail for four predictable reasons: no clear job, thin content, no handoff and nobody reading the logs. Each has a straightforward fix.
AI chatbot plans and pricing →
Support €79/mo, Sales €149/mo, 5-day free trial.
How to add an AI chatbot to your website →
The ten-minute install guide, platform by platform.