Skip to content

Website chatbots and the GDPR: a practical guide for the EU, Germany and Switzerland

Last updated:

Read this first

This guide is general information for businesses adding an AI chatbot to their website, based on the official texts listed under Sources as checked in October 2026. It is not legal advice. The rules depend on your sector, your country and what your chatbot does, so check your setup with your data protection officer or a lawyer before you go live.

Which rules apply to a website chatbot

The GDPR (Regulation (EU) 2016/679) applies to businesses established in the EU and, under Article 3(2), to businesses elsewhere that offer goods or services to people in the EU. A chatbot on your website is part of that offer, so its conversations with visitors in the EU are covered.

Storing or reading information on a visitor's device is a separate question. Article 5(3) of the ePrivacy Directive requires consent unless the storage is strictly necessary for a service the visitor explicitly requested. Germany applies this rule through § 25 TDDDG, formerly the TTDSG.

Switzerland has its own law: the revised Federal Act on Data Protection (FADP, in German nDSG), in force since 1 September 2023, with cookies covered by Article 45c of the Telecommunications Act. Swiss businesses with visitors from the EU often need to consider the GDPR as well.

For AI specifically, the Swiss Federal Data Protection and Information Commissioner (FDPIC) states that the FADP applies directly to AI-supported processing and that people have the right to know whether they are talking to a machine. In the EU, Article 50 of the AI Act (Regulation (EU) 2024/1689) requires AI systems that interact with people to tell them so, unless it is obvious.

What personal data a chatbot handles

List what the chatbot actually processes. For most website chatbots that means:

  • Messages visitors type, which can contain names, addresses or health details even if you never ask for them.
  • Contact details. intoCHAT's lead form collects an email address and/or phone number, and the agent also records one that a visitor types into the chat.
  • A session identifier in the browser that keeps the conversation going across pages.
  • Technical data such as IP addresses, and anything exchanged with your systems when the chatbot calls your API.
  • Your training content, since public pages can also contain staff names and direct phone numbers.

Choose a lawful basis for each purpose

Under Article 6(1) GDPR, each purpose needs a legal basis: consent, a contract or steps before a contract at the person's request, a legal obligation, vital interests, a public task, or legitimate interests. Decide the basis for each purpose separately and write it down.

Legitimate interests are a common basis for answering questions visitors choose to ask. The EDPB's Guidelines 1/2024 set three cumulative conditions: a legitimate interest, processing that is necessary for it, and no overriding interests or rights of the visitor, taking their reasonable expectations into account. Someone who types a question expects an answer, not sales prospecting.

PurposeLegal basis often considered (GDPR)Practical note
Answering questions in the chatLegitimate interests, Art. 6(1)(f), or pre-contractual steps, Art. 6(1)(b)Say that it is an AI assistant
Following up by email or phonePre-contractual steps, Art. 6(1)(b), or consent, Art. 6(1)(a)Say next to the form what the details are for
Newsletters and marketingConsent, Art. 6(1)(a), plus national e-marketing rulesA chat enquiry is not a sign-up
Reviewing transcripts to improve answersLegitimate interests, Art. 6(1)(f)Mention it and limit who reads logs
Session identifier on the deviceConsent under Art. 5(3) ePrivacy and § 25 TDDDG, unless strictly necessaryDocument your reasoning

Sensitive data and the Swiss approach

Health data and the other special categories in Article 9 need an exception such as explicit consent. The simplest approach is not to collect them: ask visitors in the welcome message not to share sensitive details, and instruct the chatbot never to request them.

Swiss law starts elsewhere. The FADP does not require a legal basis for each processing activity by a private business, but processing must follow its principles, such as good faith, proportionality, purpose limitation and transparency. A justification such as consent is needed where processing would otherwise infringe a person's privacy.

Update your privacy notice

Article 13 lists what visitors must be told, and Article 12 asks for clear and plain language. For a chatbot, cover at least:

  • who is responsible and how to reach you or your data protection officer
  • the purposes and the legal basis for each, including any legitimate interests
  • the recipients, such as your chatbot provider and the AI model provider it uses
  • transfers outside the EU or Switzerland and the safeguards used
  • how long you keep transcripts and leads
  • the visitor's rights, including withdrawing consent and complaining to a supervisory authority

Information in Switzerland and in the chat

The FADP's duty to inform (Article 19) is similar but stricter on transfers: according to the FDPIC, you must name the destination countries, whether or not they offer adequate protection, and the safeguards used.

In the chat itself, a short welcome message can say that the visitor is talking to an AI assistant, that answers can be wrong, and that sensitive details should not be shared.

Collect less: data minimization in practice

Article 5(1)(c) limits data to what is necessary, and Article 25 GDPR and Article 7 FADP require privacy by design and by default. For a chatbot, that is mostly configuration:

  • Ask only for the contact details you will use. intoCHAT's lead form offers just email and phone, and you choose one or both.
  • Show the form when it is relevant: manually, when the AI decides, by rules, or a mix. It appears at most three times per conversation.
  • Instruct the chatbot not to ask for dates of birth, ID numbers, payment details or health information.
  • Train it only on public content: pick pages from the crawl, exclude paths with patterns, and leave out documents with personal data.
  • When the chatbot calls your API, choose which response fields the model sees.

Processor agreements and transfers

Your chatbot provider processes visitor data on your behalf, so it is usually your processor. Article 28 requires a contract that covers the subject matter, duration, nature and purpose of the processing and the types of data and people concerned, and binds the processor to your documented instructions. Further processors need your written authorization. Swiss law allows the same by contract (Article 9 FADP), provided the processor handles data only as you may and keeps it secure.

AI chatbots rely on further providers. intoCHAT, for example, uses an OpenAI model to create embeddings of your content and to generate answers, so visitor messages and relevant passages of your content are sent to OpenAI. Name each provider in the chain in your records and privacy notice.

Transfers outside the EU need an adequacy decision or safeguards such as the European Commission's standard contractual clauses (Articles 44 and 46). Switzerland uses a Federal Council list of countries with adequate protection, and the FDPIC recognizes the EU clauses for other countries. Ask your provider:

  • Do you offer a data processing agreement?
  • Which sub-processors do you use, and where do they process data?
  • Which safeguards cover transfers abroad?
  • What happens to the data when we close the account?

Cookies, local storage and consent banners

Article 5(3) of the ePrivacy Directive is not limited to cookies. The EDPB's Guidelines 2/2023 confirm that it also covers local storage and similar technologies, whether or not the information is personal data.

Like most chat widgets, intoCHAT's widget keeps a random session identifier in a cookie and in local storage so a conversation continues across pages. Whether that is strictly necessary for a service the visitor requested depends on how and when it is set, so discuss it with your adviser. If you need consent, most consent tools can hold back a script until the visitor agrees.

Valid consent must be freely given, specific, informed and unambiguous. Scrolling is not consent, and withdrawing must be as easy as giving it (EDPB Guidelines 05/2020).

In Switzerland, Article 45c of the Telecommunications Act requires you to inform users about processing on their devices and tell them they can refuse it. The FDPIC's cookie fact sheet (March 2026) adds that explicit prior consent is needed where processing is unexpected, high-risk or involves sensitive data.

Retention: how long to keep chats and leads

Article 5(1)(e) lets you keep personal data only as long as the purpose requires, and the FADP likewise requires deleting or anonymising data that is no longer needed. Set a period for transcripts and one for leads, publish them in your privacy notice, and apply them on a schedule.

In intoCHAT you can delete individual conversations in the chat logs and individual leads in the leads table, so a regular review is enough.

Handling visitor requests

Visitors can request access, correction, erasure, restriction and portability, and can object to processing based on legitimate interests (Articles 15 to 21). You must respond within one month, extendable by two months for complex or numerous requests (Article 12(3)). In Switzerland, the FDPIC states that access must in principle be given free of charge within 30 days. Prepare the steps now:

  • Find: search the chat logs by text and date, and use the filters in the leads table. Each lead links to its conversation.
  • Provide: export leads as CSV and copy the relevant transcripts.
  • Erase: delete the conversation and the lead, and any copies in other systems.
  • Stop: end follow-up calls or emails when a visitor objects.

Checklist before you go live

  • Document what data the chatbot processes, why, and on which legal basis.
  • Update your privacy notice, including recipients and transfers.
  • Say in the welcome message that visitors are chatting with an AI assistant.
  • Sign a data processing agreement and review the sub-processors.
  • Decide how the session identifier fits into your consent setup.
  • Limit the lead form to the contact details you need.
  • Instruct the chatbot not to ask for sensitive data.
  • Set retention periods and a review routine.
  • Check whether you need a data protection impact assessment (Article 35 GDPR, Article 22 FADP).

What intoCHAT lets you control

No software makes a chatbot compliant on its own, and intoCHAT holds no data protection certification. What it gives you is control over the parts that matter:

  • What the agent learns from: the pages, files, text snippets and Q&A pairs you choose, which you can edit, retrain or delete.
  • What it says: your instructions and welcome message, plus built-in rules that keep answers grounded in your sources.
  • What it collects: only the email and/or phone number visitors choose to share, with lead form triggers you set.
  • What it sees from your API: the response fields you select for each custom action.
  • What you keep: chat logs and leads you can export and delete.

Sources

Official texts and guidance, checked in October 2026:

  • GDPR, Regulation (EU) 2016/679 (EUR-Lex)
  • ePrivacy Directive 2002/58/EC, consolidated version (EUR-Lex)
  • AI Act, Regulation (EU) 2024/1689, Article 50 (EUR-Lex)
  • EDPB Guidelines 05/2020 on consent
  • EDPB Guidelines 1/2024 on processing based on Article 6(1)(f) GDPR
  • EDPB Guidelines 2/2023 on the technical scope of Article 5(3) ePrivacy Directive, version 2.0
  • FDPIC, The new Data Protection Act from the FDPIC's perspective
  • FDPIC, Right to information
  • FDPIC, fact sheet on cookies and similar technologies, March 2026
  • FDPIC, Current data protection legislation is directly applicable to AI, May 2025
  • § 25 TDDDG (gesetze-im-internet.de)

Frequently asked questions

Do I need consent before visitors can use a website chatbot?

Not necessarily for the conversation itself, which can often rely on legitimate interests or pre-contractual steps. Storing an identifier in the browser is a separate question: the ePrivacy rules, and in Germany § 25 TDDDG, require consent unless the storage is strictly necessary for the service the visitor requested.

Is my chatbot provider a processor under the GDPR?

Usually yes, because it processes visitor data on your behalf and on your instructions. Article 28 GDPR then requires a contract, often called a data processing agreement, and the provider may only use sub-processors with your authorization. Ask for both before you go live.

Do I have to tell visitors they are chatting with an AI?

It is good practice everywhere and increasingly a legal requirement. The Swiss FDPIC says people have the right to know whether they are talking to a machine, and Article 50 of the EU AI Act requires AI systems that interact with people to make this clear unless it is obvious. One line in the welcome message covers it.

How long can I keep chatbot transcripts?

Only as long as you need them for the purpose you stated. Neither the GDPR nor the Swiss FADP sets a fixed number of days, so choose a period that fits your use and publish it in your privacy notice. Then delete older conversations and leads on a regular schedule.

Does a Swiss website need a cookie banner for a chatbot?

Swiss law generally requires information and an option to refuse rather than prior consent, under Article 45c of the Telecommunications Act. According to the FDPIC, explicit prior consent is needed where processing is unexpected, high-risk or involves sensitive data. If you also serve visitors in the EU, the stricter EU rules can apply as well.

Is intoCHAT GDPR compliant?

No software makes a chatbot compliant on its own, and intoCHAT holds no data protection certification. Compliance depends on your legal basis, privacy notice, consent setup and retention. intoCHAT lets you control what the agent is trained on, collects only the contact details visitors choose to share, and lets you export and delete conversations and leads.

See it answer from your own website

Paste your website address and chat with an agent built from your pages. It takes about a minute.

Create your agent free

Free plan, no credit card needed.