GDPR
Last updated:
What the GDPR is
The General Data Protection Regulation is the European Union's main data protection law. It covers the processing of personal data: any information relating to an identified or identifiable person, such as a name, an email address, a phone number, an online identifier or a message that reveals who wrote it (Article 4(1)).
It applies to organizations established in the EU and, under Article 3(2), to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior there. This page is general information, not legal advice. How the rules apply depends on your sector, your country and what you do with the data.
How it works
The regulation is long, but a handful of rules shape most everyday decisions:
- Principles (Article 5): lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality.
- Lawful basis (Article 6): every purpose needs one of six bases: consent, a contract or steps before one, a legal obligation, vital interests, a public task or legitimate interests.
- Transparency (Article 13): tell people who you are, why you process their data, on which basis, who receives it and how long you keep it.
- Rights (Articles 15 to 21): people can ask for access, correction, erasure, restriction and portability, and can object to some processing. You normally have one month to respond (Article 12(3)).
- Controllers and processors (Article 28): whoever decides why and how data is processed is the controller. A provider that processes data on its behalf is a processor, and the two need a contract, often called a data processing agreement.
- Breaches (Article 33): a personal data breach must be reported to the supervisory authority within 72 hours where feasible, unless it is unlikely to result in a risk to people.
- Fines (Article 83): serious infringements can cost up to €20 million or 4% of worldwide annual turnover, whichever is higher.
Example
A furniture store adds an AI chatbot to its website. A visitor in Vienna asks about delivery and types her email address so the store can send a quote. That email address, the conversation and the session identifier that keeps the chat going are all personal data. As controller, the store needs a lawful basis for following up, should mention the chatbot in its privacy notice, needs a processor agreement with the chatbot provider and has to decide how long it keeps transcripts and leads.
Why it matters for business chatbots
A chatbot processes personal data from the first message. Visitors type questions that can include names, addresses or health details even when nobody asks for them. Lead forms collect email addresses and phone numbers. And the widget usually stores a session identifier in the browser, which also brings in the ePrivacy rules on cookies and similar technologies.
AI chatbots add another layer: the chatbot provider often sends messages to an AI model provider, which then acts as a further processor. Your records and privacy notice should name that chain. Switzerland has its own law, the revised Federal Act on Data Protection (FADP, in German nDSG), in force since September 1, 2023, which follows similar principles.
The GDPR and intoCHAT
No software makes a chatbot GDPR compliant on its own. That depends on your legal basis, privacy notice, consent setup and retention, and intoCHAT holds no data protection certification. What intoCHAT gives you is control over the parts that matter:
- You choose what the agent is trained on: the pages, files, text snippets and Q&A pairs you add, which you can edit, retrain or delete.
- The lead form collects only an email address and/or phone number, and only when the visitor chooses to share them. There is no name or custom field.
- You can export leads as a CSV file and delete individual conversations and leads, which helps when a visitor asks for access or erasure.
- intoCHAT uses an OpenAI model to answer, so visitor messages and relevant passages of your content are sent to OpenAI. Name it as a recipient in your privacy notice.