The short answer
A chatbot cannot be “GDPR compliant” on its own — compliance belongs to the business deploying it, which is the controller for every conversation. The vendor is your processor. What you need from them is a data processing agreement, a subprocessor list, a lawful transfer mechanism and honest answers about where data goes. What you need from yourself is a lawful basis, a privacy notice that mentions the assistant, and a way to answer deletion requests.
Most articles on this subject are written by vendors and answer the question “is our product compliant?”, which is not a question that has an answer. Compliance is a property of a deployment, not of a piece of software. Here is the checklist that actually applies to you.
1. Work out who is who
Get this wrong and every later step is aimed at the wrong party.
- You are the controller for everything visitors say to your assistant. You chose to deploy it, you decided what it collects, and you decide why.
- The vendor is your processor. They act on your instructions.
- The model provider is a subprocessor. This is the leg people miss, and it is not optional — see step 4.
Practical consequence: when a visitor asks to be deleted, they ask you. If your vendor answers that request directly instead of routing it to you, that is a problem with your vendor.
2. Have a lawful basis, and know which one
For a support assistant, legitimate interests usually works and consent usually does not — a consent banner in front of a help widget is both annoying and legally fragile, because consent has to be freely given and a person who needs help is not in a strong position to refuse.
Do a short legitimate interests assessment and keep it: the interest, why the processing is necessary for it, and the balance against the visitor’s rights. Half a page. It is the document a regulator asks for and almost nobody has.
If your assistant does marketing outreach rather than support, that is different, and consent rules do apply.
3. Update your privacy notice
It has to mention the assistant specifically. Say what it collects, that conversations are processed by a third-party provider and by AI models, how long transcripts are kept, and how to ask for deletion. A notice written before you added a chatbot does not cover the chatbot.
4. Find out where the conversation actually goes
This is the step that separates diligence from box-ticking. Ask your vendor, in writing:
- Which model providers receive message content, and on what proportion of messages? For any retrieval-based assistant the honest answer is “all of them” — generating an answer requires sending the question and the retrieved passages to a model. A vendor who is vague here is either confused or hoping you are.
- Do they train on it? Get the answer for the vendor and for the model providers underneath, because the vendor can only promise what their own contracts let them promise.
- Which countries? Then check step 5.
- Can you choose a region? Many cannot offer this. The useful answer is a straight no rather than a maybe.
Ours are in the subprocessor list and the AI transparency statement, and the answer to the last one is no.
5. Get the transfer mechanism right
If data leaves the EEA — and it almost certainly does, because the major model providers are American — you need a transfer mechanism. In practice:
- Standard Contractual Clauses (Decision 2021/914), Module Two where you are a controller and the vendor is a processor. These should already be inside the vendor’s DPA. If you have to ask for them separately, that tells you something.
- A transfer impact assessment. Post-Schrems II this is on you as exporter, though a decent vendor will hand you most of the inputs. What matters is destination-country access law and the supplementary measures against it — encryption, isolation, and a published policy on how the vendor handles government requests.
- UK transfers need the UK Addendum, which rides on the same SCCs. Switzerland needs its own reading of them.
6. Decide retention, and make it real
“As long as necessary” is what people write when they have not decided. Pick a number for transcripts, pick a number for captured leads, write them in your notice, and confirm your vendor can actually enforce them. Then check that deletion is deletion rather than a hidden flag.
7. Handle the data you did not ask for
You cannot stop a visitor typing a card number, a diagnosis or a national ID into a chat box. What you can do is not design the assistant to ask, and have a route to delete it when it happens. If you are in healthcare or financial services, this is the step that decides whether a chatbot is appropriate at all.
8. Do not deploy it on a service aimed at children
Thresholds differ and the strictest one governs you if you operate there. India’s DPDP Act treats anyone under 18 as a child and requires verifiable parental consent — higher than the GDPR’s 13 to 16 and COPPA’s 13. Very few chatbot vendors have built for verifiable parental consent, so the practical answer is not to.
9. The AI Act disclosure, which is not yours
Since 2 August 2026, Article 50(1) requires people to be told they are interacting with an AI system, at the first interaction. That duty falls on the provider — the vendor — not on you as deployer. Your job is to not undermine it: do not remove the disclosure, and do not configure the assistant to claim to be a person.
You do owe Article 4 AI literacy for the staff who operate it. We wrote the full argument up separately in Article 50 applies to your chatbot, and probably not to you.
10. If you sell to Indian customers, DPDP is coming
The Digital Personal Data Protection Act 2023 is in force in phases, and the substantive obligations commence on 13 May 2027. Two features differ enough from the GDPR to catch people out: the consent notice must be available in English and each of the 22 Eighth Schedule languages, and cross-border transfer works as a blacklist — permitted everywhere except countries the government restricts — which is considerably friendlier than the GDPR’s model.
The checklist, compressed
- You are the controller. The vendor is your processor.
- Lawful basis chosen, and a written LIA if it is legitimate interests.
- Privacy notice mentions the assistant specifically.
- You know which model providers see message content, and that it is all of them.
- SCCs in place, TIA done, UK Addendum if relevant.
- Retention periods decided, published, and actually enforced.
- A route to delete something a visitor should not have typed.
- Not deployed on anything aimed at under-18s.
- Disclosure is the vendor’s duty; do not switch it off.
- AI literacy recorded for whoever operates it.
This is a practitioner’s checklist, not legal advice, and we are not lawyers. Our own research, with the primary sources and the parts we could not verify marked as such, is published in the repository behind this site. If something here is wrong, tell us and we will fix it — this guide is maintained rather than dated.