An AI chatbot on an EU business website has two sets of rules to meet. Under the EU AI Act, visitors must be told they are talking to an AI, at the latest at their first interaction, and this applies from 2 August 2026. Under the GDPR, what visitors type often includes personal data, so you need a legal basis, a privacy notice that mentions the chat, a retention period, and an agreement with the AI provider that processes the messages.
This guide explains each duty in plain words and ends with a checklist. It is general information for small businesses, not legal advice: for your specific case, check with your data protection adviser or lawyer.
What the AI Act requires from a chatbot
The AI Act (Regulation (EU) 2024/1689) covers many kinds of AI. For a customer support chat on a website, the duty that matters is transparency, in Article 50.
- What: Article 50(1) says AI systems intended to interact directly with people must be designed so that the people concerned are informed that they are interacting with an AI system.
- When: Article 50(5) says this information must be given in a clear and distinguishable manner, at the latest at the time of the first interaction, and must meet applicable accessibility requirements.
- From when: Article 50 applies from 2 August 2026. The European Commission confirms the date in its FAQ on Article 50 transparency obligations. The grace period to 2 December 2026 mentioned there concerns marking AI-generated content, not the chatbot notice.
- Exception: the duty does not apply when it is obvious to a reasonably well-informed, observant person that they are talking to an AI. A chat bubble with a friendly name and a photo is not obvious. Do not rely on this exception for a support chat.
- Fines: the Commission's FAQ states that fines can reach 15 million euros or 3% of worldwide annual turnover. Enforcement is done by national market surveillance authorities.
Formally, Article 50(1) is addressed to the provider of the AI system. Your visitors, though, only see your website. Whoever built the chat, check yourself that the notice is shown on your site before the first message.
What a good AI notice looks like
Short, visible before the visitor types, and honest about limits. For example: "You are chatting with an automated assistant, not a person. It answers using this organisation's own documents, and it can be wrong." Add how long the conversation is kept and a link to your privacy notice. Translate it into every language your site uses.
GDPR and an AI chat: the four things to settle
People type names, order numbers, email addresses and sometimes much more into a chat box. That makes the conversation personal data, and your business the controller: the one that decides why and how it is processed.
1. A legal basis
The GDPR lists six legal grounds: consent, contract, legal obligation, public interest, vital interests and legitimate interests. Consent is not the only option. For answering questions that customers and prospects choose to ask, contract or legitimate interests may fit better, but legitimate interests requires you to check that people's rights are not seriously affected. Decide which ground you rely on and write it down.
2. A privacy notice that mentions the chat
The European Commission lists the information you must give people when you collect their data. For a chat, your privacy notice should say at least:
- that the site has an automated chat assistant and what it is for;
- what data it processes (the messages, and anything else you store with them);
- your legal basis;
- how long conversations are kept;
- who receives the messages (your AI provider and any other service involved);
- whether data goes outside the EU, and on what basis;
- people's rights, including access, deletion and complaint to a data protection authority.
Link the privacy notice from the chat itself, next to the AI notice.
3. A retention period
The Commission's guidance is that data must be stored for the shortest time possible, with set time limits for deleting or reviewing it. Reading old conversations is useful for improving your answers, but a few weeks or months is usually enough for that. Pick a number of days, say it in your privacy notice, and make sure deletion really happens automatically. Keeping chats "until someone remembers to clean up" is the easiest mistake to avoid.
4. Your AI provider: processor agreement and transfers
The company whose AI writes the answers receives each message. Under the GDPR it is your processor, and the Commission explains that working with a processor requires a contract. Most AI providers offer a data processing agreement (DPA) in their account settings or terms. Accept or sign it before the chat goes live.
If the provider processes data outside the EU, the DPA should say which transfer mechanism it uses. For the United States, this is often the EU-US Data Privacy Framework (for companies certified under it, based on the Commission's adequacy decision of 10 July 2023) or the Commission's standard contractual clauses. If you prefer to keep processing in the EU, some providers offer it; our guide to choosing an AI model for a website chatbot compares the options.
A practical checklist for your website chat
- The chat shows an AI notice above the first message, in every language of the site.
- The notice links to your privacy notice.
- Your privacy notice has a section on the chat: purpose, data, legal basis, retention, recipients, transfers, rights.
- You have accepted or signed the DPA of your AI provider (and of any second service, for example the one that builds the search index).
- Conversations are deleted automatically after a set number of days.
- You store no more than you need: no IP addresses or extra tracking unless you have a reason.
- The chat answers only from your own documents, so it cannot promise things your company never said.
- When it cannot answer, it gives a way to reach a person.
- You can find and delete a person's conversations if they ask.
- Someone reads the conversations now and then, and knows what to do if a visitor shares sensitive data.
How to do it: by hand, with a general tool, or with Answer Desk
By hand or with a general chatbot
Most items on the checklist are writing and paperwork: the privacy notice section, the DPA, the legal basis. Those are yours whatever tool you use. The technical items (notice before the first message, automatic deletion, finding a person's chats) depend on the chatbot. Before choosing one, ask its vendor: can the AI notice be hidden by mistake? Where are conversations stored, and can I set a deletion period? Who receives the messages, and where?
With Answer Desk on WordPress
Answer Desk is our WordPress plugin for a support chat that answers from your own documents. It handles the chat's technical part in the free version too, on Answer Desk > Rules and privacy:
- AI notice: shown above the first message and cannot be switched off, only reworded in Your wording. The retention sentence and the privacy link are added automatically; Shown to visitors right now: displays the final text.
- Retention: Delete them after sets the number of days (default 90). Deletion runs once a day and really removes the data. The free version applies at most 30 days; with a licence the number you chose applies.
- No IP address stored: to limit messages per visitor, it keeps a one-way fingerprint that recognises a visitor for an hour.
- Processors: a table lists your AI provider, the index provider and your own site, with what each receives and where it processes.
- WordPress privacy tools: it suggests an "Automated chat assistant" paragraph in Settings > Privacy and works with Tools > Export Personal Data and Tools > Erase Personal Data (these find conversations of visitors who were logged in, by email address).
The Where you stand card shows a tick or an exclamation mark for five items. It is a checklist, not a certificate: signing the DPA with your AI provider and mentioning the chat in your privacy notice remain your job. The full walkthrough is in AI notice, privacy and limits, and Read and export conversations covers reading and deleting single chats.

Common mistakes
- A notice in the footer or the privacy page only. The AI Act asks for it at the first interaction, so it belongs in the chat.
- A human-sounding name and photo with no notice. This is exactly what the transparency rule is about.
- Keeping every conversation forever "for training" or "just in case".
- Letting the AI answer from general knowledge. Not a GDPR issue, but an invented price or delivery date is your company speaking.
- Forgetting the second provider. If one service writes answers and another builds the search index, both are processors.
Summary: who needs what
Every EU business with an AI chat on its website needs the AI notice before the first message (since 2 August 2026) and a GDPR setup: legal basis, a privacy notice that covers the chat, a retention period and a DPA with the AI provider. If you already have a chatbot, check the notice and the deletion period first, since those are the two items most often missing. If you are choosing one, pick a tool that makes the notice impossible to hide and deletes old chats on its own, then spend your time on the paperwork only you can do. For how the chat finds its answers, see AI chatbots trained on your own documents.
Frequently asked questions
Does the AI Act apply to a chatbot on a small business website?
Yes. The transparency duty in Article 50 covers AI systems that interact directly with people, whatever the size of the business, and it applies from 2 August 2026. Visitors must be told they are talking to an AI at the latest at the first interaction.
Do I need consent to use an AI chatbot under GDPR?
Not necessarily. Consent is one of six legal grounds; for answering questions visitors choose to ask, contract or legitimate interests may fit. Whichever you choose, state it in your privacy notice.
How long can I keep chatbot conversations?
The GDPR sets no fixed number of days: data must be kept for the shortest time needed for its purpose. Choose a period, say it in your privacy notice and delete older conversations automatically.
Is it a problem if my AI provider is in the United States?
Not in itself, but the transfer needs a legal basis, such as the EU-US Data Privacy Framework for certified companies or standard contractual clauses. Check the provider's data processing agreement, and mention the transfer in your privacy notice.

