Key takeaways
- A chatbot processes personal data (names, emails, chat messages, IP addresses), so the GDPR applies from the first conversation.
- You need a signed processing agreement (DPA, GDPR art. 28) with your chatbot provider, because they process data on your behalf.
- Where the data is hosted matters: EU hosting (for example Germany) avoids the extra hurdles of transfers to the US.
- The safest setup answers only from your own content and does not use your conversations to train the AI model.
- Visitors keep their GDPR rights (access, deletion), so you must be able to find and remove their data on request.
What personal data does a chatbot actually process?
More than most people assume. The obvious data is what a visitor types: a name, an email address, an order number, a phone number, sometimes a full description of a complaint or a health question. But a chatbot also collects data in the background: the IP address of the visitor, a session or device identifier, timestamps, the page someone was on, and the full transcript of the conversation. Under the GDPR, almost all of this counts as personal data, because it can be traced back to an identifiable person.
This matters because the GDPR does not care whether you meant to collect personal data. The moment a chatbot can receive and store it, you are processing it, and you are responsible. A good habit is to assume every conversation may contain personal data and to design around that: keep only what you need, do not ask for more than the conversation requires, and make sure sensitive input (like health details) is handled with extra care.
On what legal basis? Consent versus legitimate interest
The GDPR says you may only process personal data if you have a valid legal basis. For a customer-service chatbot, two bases are common. The first is legitimate interest: helping a visitor who deliberately started a conversation with you is a normal, expected part of running a business, and handling their question falls within that. The second is consent, which becomes relevant when you go beyond answering the question, for example by placing tracking cookies, adding someone to a mailing list, or using the chat for marketing profiling.
In practice the honest rule is: be transparent up front. Tell visitors in a short line and a link to your privacy statement that they are chatting with an AI assistant, what happens with their data, and how long it is kept. Do not hide it. Transparency is not just polite, it is a GDPR requirement, and it is also what keeps trust intact when a real person later reads the transcript.
The processing agreement (DPA): the piece people forget
When you use a chatbot tool, that provider processes personal data on your behalf. Under GDPR article 28 that makes them your processor and you the controller, and it means the two of you must have a written data processing agreement (DPA). This document is not optional paperwork. It records what data is processed, for what purpose, how it is secured, whether sub-processors are used, and what happens when the contract ends. Without it, you are technically not compliant, even if everything else is perfect.
The practical test for any chatbot vendor is simple: can they hand you a DPA, and can they do it without a sales call? ovellan, for example, publishes a downloadable DPA so you can read it, sign it, and keep it on file before you ever go live. If a provider cannot produce one, or hides it behind an enterprise tier, treat that as a red flag rather than a detail.
Where does the data live? Why EU hosting matters
Data location is one of the most underrated parts of chatbot compliance. The GDPR allows personal data to move freely inside the EU, but transferring it to countries outside the EU, the United States being the big one, comes with extra conditions and legal uncertainty that has kept European regulators busy for years. Many chatbot tools quietly route your visitors data through US servers, which means you inherit that complexity whether you wanted to or not.
The cleaner answer is to keep the data in the EU from the start. ovellan hosts on infrastructure in Germany (Hetzner), so your conversations and customer data stay inside the European Union. That does not magically solve every GDPR question, but it removes the single messiest one: you are no longer relying on a cross-border transfer mechanism to justify where your customers data ends up. For a business talking to customers, that is exactly the setup regulators expect to see.
Does the AI train on your conversations?
This is the question that separates a genuinely private chatbot from a leaky one. Modern chatbots run on large language models, and some setups feed the conversations back into training data. If that happens, a customer complaint or an email address someone typed could, in theory, resurface somewhere you never intended. From a GDPR perspective that is a serious problem, because you lose control over where personal data goes and you cannot cleanly delete it on request.
The honest, defensible design is the opposite: the chatbot answers only from your own content (your website, your documents, your FAQ), and your conversations are not used to train the underlying model. ovellan works this way on purpose, and it even says I don't know when your content does not contain the answer, rather than inventing something. That keeps two things true at once: the bot stays accurate, and your visitors data stays yours. Combined with the DPA and EU hosting, that is what a GDPR-proof chatbot actually looks like in practice.
Frequently asked questions
Is a chatbot allowed under the GDPR at all?
Do I really need a DPA for a chatbot?
Why does it matter where the chatbot data is hosted?
Will the AI use my customer conversations to train itself?
What if a visitor asks me to delete their chat data?
See it answer for your own business
Point ovellan at your website and watch it answer your customers' real questions, in your language, around the clock.
Try ovellan free7-day free trial. Starter needs no card.Sources