Skip to content

GDPR

Last updated:

What the GDPR is

The General Data Protection Regulation is the European Union's main data protection law. It covers the processing of personal data: any information relating to an identified or identifiable person, such as a name, an email address, a phone number, an online identifier or a message that reveals who wrote it (Article 4(1)).

It applies to organizations established in the EU and, under Article 3(2), to organizations elsewhere that offer goods or services to people in the EU or monitor their behavior there. This page is general information, not legal advice. How the rules apply depends on your sector, your country and what you do with the data.

How it works

The regulation is long, but a handful of rules shape most everyday decisions:

  • Principles (Article 5): lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, and integrity and confidentiality.
  • Lawful basis (Article 6): every purpose needs one of six bases: consent, a contract or steps before one, a legal obligation, vital interests, a public task or legitimate interests.
  • Transparency (Article 13): tell people who you are, why you process their data, on which basis, who receives it and how long you keep it.
  • Rights (Articles 15 to 21): people can ask for access, correction, erasure, restriction and portability, and can object to some processing. You normally have one month to respond (Article 12(3)).
  • Controllers and processors (Article 28): whoever decides why and how data is processed is the controller. A provider that processes data on its behalf is a processor, and the two need a contract, often called a data processing agreement.
  • Breaches (Article 33): a personal data breach must be reported to the supervisory authority within 72 hours where feasible, unless it is unlikely to result in a risk to people.
  • Fines (Article 83): serious infringements can cost up to €20 million or 4% of worldwide annual turnover, whichever is higher.

Example

A furniture store adds an AI chatbot to its website. A visitor in Vienna asks about delivery and types her email address so the store can send a quote. That email address, the conversation and the session identifier that keeps the chat going are all personal data. As controller, the store needs a lawful basis for following up, should mention the chatbot in its privacy notice, needs a processor agreement with the chatbot provider and has to decide how long it keeps transcripts and leads.

Why it matters for business chatbots

A chatbot processes personal data from the first message. Visitors type questions that can include names, addresses or health details even when nobody asks for them. Lead forms collect email addresses and phone numbers. And the widget usually stores a session identifier in the browser, which also brings in the ePrivacy rules on cookies and similar technologies.

AI chatbots add another layer: the chatbot provider often sends messages to an AI model provider, which then acts as a further processor. Your records and privacy notice should name that chain. Switzerland has its own law, the revised Federal Act on Data Protection (FADP, in German nDSG), in force since September 1, 2023, which follows similar principles.

The GDPR and intoCHAT

No software makes a chatbot GDPR compliant on its own. That depends on your legal basis, privacy notice, consent setup and retention, and intoCHAT holds no data protection certification. What intoCHAT gives you is control over the parts that matter:

  • You choose what the agent is trained on: the pages, files, text snippets and Q&A pairs you add, which you can edit, retrain or delete.
  • The lead form collects only an email address and/or phone number, and only when the visitor chooses to share them. There is no name or custom field.
  • You can export leads as a CSV file and delete individual conversations and leads, which helps when a visitor asks for access or erasure.
  • intoCHAT uses an OpenAI model to answer, so visitor messages and relevant passages of your content are sent to OpenAI. Name it as a recipient in your privacy notice.

Frequently asked questions

What counts as personal data under the GDPR?

Any information relating to an identified or identifiable person. That includes names, email addresses, phone numbers, IP addresses and online identifiers, and also the content of a message if it reveals who wrote it. Data that has been truly anonymized is no longer personal data.

Does the GDPR apply to businesses outside the EU?

It can. Under Article 3(2), the GDPR also applies to businesses outside the EU that offer goods or services to people in the EU or monitor their behavior there. A website chatbot that serves visitors in the EU is part of such an offer.

Do I need consent to run a chatbot on my website?

Not always for the conversation itself, which can often rely on legitimate interests or steps before a contract. Storing an identifier in the visitor's browser is a separate question: the ePrivacy rules require consent unless the storage is strictly necessary for the service the visitor requested. This is general information, not legal advice.

Is intoCHAT GDPR compliant?

No software makes a chatbot compliant on its own, and intoCHAT holds no data protection certification. Compliance depends on how you set up and use the chatbot: your legal basis, privacy notice, consent setup and retention. intoCHAT lets you control what the agent is trained on, collects only the contact details visitors choose to share, and lets you export and delete leads and conversations.

See it answer from your own website

Paste your website address and chat with an agent built from your pages. It takes about a minute.

Create your agent free

Free plan, no credit card needed.