An AI chatbot on your website is not prohibited in principle. What matters is which personal data it processes, for what purpose, who receives it and how you protect that processing. An EU server, a data processing agreement or a checkbox alone does not answer these questions. A manageable starting point is an assistant with a clearly limited role: explaining public company information and passing personal enquiries to your team.
This guide puts typical decisions for small businesses into context. It does not replace an assessment of your specific use, particularly where health data, job applications or other sensitive activities are involved. Sources checked: 10 September 2026.
First, map the journey of a message
Consider a trades business whose assistant explains its services and asks for a telephone number when someone requests a callback. Before switching it on, follow a test message from the browser through to deletion. The following table is a working template, not a statement about a particular platform.
| Stage | What may be processed | What to check in practice |
|---|---|---|
| Website and chat widget | IP address, session identifier, message | Which connection is established before the chat is even opened? |
| Platform and model provider | Message, conversation history, retrieved document excerpts | Which providers receive which parts? |
| Logs and support | Error data, chat history, staff access | Who can inspect the data, and for how long? |
| CRM or mailbox | Callback request, contact details, summary | What is actually needed? |
| Deletion and backups | Active records and backup copies | How is deletion handled across all affected systems? |
Request these details for your actual subscription and its settings. A general product brochure rarely provides enough information. Test abandoned conversations too: data may be left behind before a contact request is submitted.
Does every chat require consent?
No. Processing personal data requires an appropriate lawful basis; consent is one possibility, but not the only one. Processing based on a contract must be necessary for that contract or for requested steps before entering into it. Relying on legitimate interests requires an assessment of purpose, necessity and competing interests. The EDPB identifies supporting conversational assistants as a possible use case, but does not give blanket permission. EDPB: Opinion on AI models.
Distinguish at least three purposes: answering the current question, handling a contact request and using conversation content to improve the product. What is justified for the first purpose does not automatically cover the others. Document the decision before real customer data starts flowing. A mandatory “Privacy accepted” field does not replace this assessment.
Cookies and browser storage are a separate issue. Section 25 of Germany's TDDDG generally requires consent to store information on, or access information from, a user's device. Exceptions exist, particularly for operations that are strictly necessary for an explicitly requested service. This is not limited to cookies and can cover other storage technologies. Whether an exception applies to a particular chat session depends on its actual function. Section 25 TDDDG.
EU or US: Check the location and understand the data chain
Processing within the European Economic Area can avoid international transfers. It does not remove other data protection obligations. In addition to storage location, check model calls, subprocessors, backups and possible access from third countries. “EU hosting” and “all processing takes place exclusively within the EEA” are different commitments.
Transfers to the US are not prohibited across the board. The EU-US Data Privacy Framework provides a basis for covered transfers to participating US companies. Check the specific recipient, its current participation and the scope covered. Where that framework does not fit, other instruments such as Standard Contractual Clauses may be relevant; their conditions and any necessary supplementary safeguards must be assessed. A data processing agreement alone does not replace a transfer mechanism. European Commission: EU-US data transfers.
Four short questions are more useful when assessing a provider than a general seal of approval: Where does model processing take place? Which other companies receive content? Are inputs used for training? How is support access restricted and recorded?
What a processing agreement covers, and what it does not solve
Where a service provider processes personal data on your behalf, the relationship must be governed by a contract under Article 28 GDPR. This includes instructions, confidentiality, security, subprocessors, and assistance with individuals' rights and deletion. If a provider uses content for its own purposes, its role needs a separate assessment. Calling a document a “data processing agreement” does not turn every activity into processing on your behalf. EDPB: Controllers and processors.
Compare the contract with the technical configuration. A contractual exclusion of training should match the actual setting. Agreed deletion must also be possible in practice. Keep the version you checked and record when the settings were reviewed.
The checklist before the first real conversation
| Check | Useful evidence |
|---|---|
| Purpose and limits are defined | A short list of permitted questions and excluded activities |
| Lawful basis is assessed for each purpose | A documented decision with reasons |
| Data routes and providers are known | An up-to-date overview covering the model, logs and CRM |
| Contracts and transfers are addressed | Appropriate contracts and checks on recipients |
| Notices are accessible | An AI notice at the chat and understandable privacy information |
| Storage is limited | Justified retention periods instead of indefinite storage |
| Individuals' rights can be exercised | A tested process for access, correction and deletion requests |
| Access and handover work | Permissions, a responsible team and a tested contact route |
Privacy information must reflect the processing that actually happens. Include the controller, purposes, lawful bases, recipients, retention and rights, among other relevant details. A link is useful when it is visible in time and clearly leads to the information that matters. Handling access or deletion requests is also part of operating the service. EDPB: Respecting individuals' rights.
Less data makes operation easier
A bot explaining opening hours does not need a customer number. A callback often needs only limited contact details, rather than the entire conversation history. Define retention periods for each purpose; GDPR does not impose a universal “30 days for every chat”. Data minimisation and storage limitation require a reasoned choice. EDPB: Data protection basics.
Also use fictional data to test whether someone can retrieve another person's conversation or documents that have not been approved for access. A data protection impact assessment is required where the planned processing is likely to create a high risk for individuals, not automatically because it involves “AI”. EDPB: Security and risk assessment.
An AI notice is not privacy consent
Article 50 of the AI Act addresses transparency when interacting with AI. The corresponding provider obligation has applied since 2 August 2026. A clear introduction could be: “You are speaking with an AI assistant. For personal enquiries, please contact our team using the Contact link.” This information replaces neither a lawful basis nor privacy information. We explain the roles and current deadlines in our AI Act guide. Commission: Transparency guidelines.
For implementation, plan the assistant's limits, data routes and handover to people together. Our AI and automation services start with this process. A description of your task is enough for an initial assessment; there is no need to send confidential customer data.
