GDPR Compliant Chatbot: What Irish Businesses Should Check First
Table of Contents
A GDPR compliant chatbot is one that tells people what it collects before they start typing, runs on a lawful basis you have written down, keeps only the conversation data you genuinely need, and processes that data under a signed agreement with the provider. For businesses in Ireland and Northern Ireland, two questions settle most of the risk: where the data is hosted, and whether the provider uses your conversations to train its models. Ask for EU or UK data residency, a data processing agreement that names every sub-processor, and a written retention and deletion policy before you commit to anything.
Channels, tone of voice and integrations can all be changed later. Consent, storage and the contract are the parts that are expensive to fix after launch.
Most buyers arrive at this decision in the same order. They want the chatbot for the obvious reasons, namely after-hours enquiries and the same five questions asked forty times a week, and then someone in the business asks where the customer data actually goes. That question stops more projects than budget does, and it deserves a straight answer rather than a reassuring one.
This guide is written for owners and managers in Ireland, Northern Ireland and Great Britain who are assessing a chatbot and need the compliance side settled first. It covers what compliance means in practice, where data residency matters, what belongs in the contract, the questions to put to a vendor, and only then the build itself.
What Makes a Chatbot GDPR Compliant?
A chatbot is GDPR compliant when every piece of personal data it touches has a lawful basis, a stated purpose, a retention period and a route to deletion. Nothing about the technology changes the rules. A chat widget that captures a name and an email address is doing the same thing a contact form does, with two differences: it collects data conversationally, so people volunteer more than they mean to, and it often passes that data to a third-party model provider.
The Irish Data Protection Commission set out how this applies to generative tools in its guidance on AI, large language models and data protection, and the ICO covers the equivalent UK position in its guidance on AI and data protection. Both regulators land in the same place. Existing obligations apply in full, and the burden of showing compliance sits with the business deploying the tool, not the platform that sold it.
Lawful basis and consent
Decide your lawful basis before the widget goes live, and write it down. For a chatbot answering product questions and capturing enquiries, legitimate interests usually fits the operational side, with consent needed for anything beyond that, such as marketing follow-up or analytics cookies attached to the widget. If your site runs a consent management platform, the chatbot should sit behind the consent state rather than loading regardless of it. We cover the wider site-level position in our guide to GDPR compliance for websites.
What people see before they type
Show a short privacy notice at the top of the conversation, in plain language, linking to your full policy. It needs to say what is collected, why, how long it is kept, and that a human can take over. One or two sentences is enough. A wall of legal text in a chat window gets dismissed without being read, which defeats the point of showing it.
Minimisation, retention and erasure
Collect the least you need to answer the question. If the bot does not need a phone number to confirm opening hours, it should not ask for one. Set a retention period for chat transcripts, apply it automatically rather than by memory, and be able to find and delete an individual’s conversations when they ask. Anonymising older logs lets you keep the useful pattern data, such as which questions recur, without holding personal data indefinitely.
When you need a DPIA
A data protection impact assessment is expected where processing is likely to be high risk, which includes large-scale or systematic processing and anything touching special category data. A small service bot handling booking enquiries may not reach that threshold. A bot that handles health queries, financial details or job applications almost certainly does. Where you are unsure, doing a short assessment is cheaper than defending the decision not to.
At ProfileTree, our AI chatbot development service handles this groundwork alongside the build for businesses across Northern Ireland and the Republic, and much of what follows comes from that work. Our article on the common AI and GDPR pitfalls Irish businesses hit covers the mistakes we see repeated.
Where Does Your Chatbot Data Actually Live?
Data residency is the question to settle first, because it is the hardest thing to change once you have built on a platform. Many widely used chatbot platforms run on infrastructure hosted in the United States, and the underlying model provider may be somewhere different again. That does not make them unusable, but it does mean an international transfer is happening, and transfers need a valid mechanism and documentation behind them.
Ask for three things in writing: the region where conversation data is stored, the region where it is processed by the model, and the transfer mechanism covering anything that leaves the EEA or the UK. A provider that can answer those three quickly has thought about the problem. One that answers with a general assurance of compliance has not.
The Northern Ireland position
A business trading across the border is often handling both UK GDPR and EU GDPR at once, depending on where the customer sits. In practice this rarely means two systems. It means choosing a setup that satisfies the stricter of the two and documenting it once. Hosting inside the EEA usually gives you the simpler path, and UK hosting works where your customers are mainly in Great Britain and Northern Ireland.
Self-hosting and its trade-offs
Self-hosting a model or running one in your own cloud tenancy gives the tightest control over where data sits, and it costs more in setup and maintenance. For most small and medium firms the better answer is a managed platform with EU or UK residency and a clear contract, sitting on a site you already control. That side depends on stable infrastructure, which is what our hosting and site management service covers, and on a properly structured site, which is the job of web development.
“For Irish SMEs the compliance question comes before the clever features. Sort out consent, storage and where the data lives first, and you can deploy a chatbot you’ll never have to apologise for,” says Ciaran Connolly, Director of ProfileTree.
What Should the Data Processing Agreement Cover?
The data processing agreement is where compliance becomes enforceable rather than aspirational. You are the controller, the chatbot provider is a processor, and the agreement has to set out what they may do with the data on your behalf. Read it before signing, and treat anything missing as a negotiating point rather than a formality.
Six clauses do most of the work. First, purpose limitation, stating the provider processes data only on your documented instructions. Second, an explicit position on model training, confirming your conversations are not used to train shared models, or naming the conditions where they are. Third, a list of sub-processors with notice before that list changes, since the model provider, the hosting provider and any analytics tool are all part of the chain. Fourth, retention and deletion, including what happens to your data when the contract ends.
Fifth, breach notification with a defined timeline that lets you meet your own reporting duty. Sixth, assistance with data subject requests, so that when someone asks for their conversation history or its deletion, you can act inside the statutory window rather than waiting on a support ticket.
What Should You Ask a Chatbot Vendor Before You Sign?
Ask short, specific questions and pay attention to how quickly they can be answered. The table below is the checklist we work through when scoping a build, and it translates directly into a procurement conversation.
| Question to ask | What a good answer sounds like | Warning sign |
|---|---|---|
| Where is conversation data stored and processed? | A named region for storage and for model inference, confirmed in writing | “On secure servers” with no region named |
| Do you train models on our conversations? | A clear no, written into the agreement, or a documented opt-out | An answer that covers only the default setting, not the contract |
| Who are your sub-processors? | A current published list with notice of changes | Reluctance to name the model provider |
| How long are transcripts retained, and can we set that? | A configurable period with automatic deletion | Indefinite retention described as a feature |
| How do we handle a deletion request? | Self-service lookup and deletion, or a defined response time | A manual process with no committed timeline |
| What transfer mechanism applies outside the EEA or UK? | Standard contractual clauses or the UK addendum, supplied on request | An assertion that transfers do not happen, without evidence |
| Can we export our data and leave? | Export in a usable format plus deletion on exit | No export path, or export for a fee |
How Do You Keep Personal Data Out of the Knowledge Base?
Clean the source documents before you upload anything. This is the step most often skipped, and it is the one that causes genuine embarrassment, because a bot grounded in messy internal files will eventually repeat something from them to a customer.
Work through the material you plan to use and strip out employee contact details, client names and figures, pricing that is negotiated rather than published, internal policy documents, and anything superseded. What should remain is the material you would happily publish on the site: services, hours, delivery terms, returns, FAQs, specifications. Once the bot is live, review a sample of transcripts weekly for the first month, both to catch wrong answers and to see what personal information customers are volunteering unprompted, which is usually more than you expect.
Staff habits matter as much as the file cleanse. Teams that understand what can and cannot go into an AI tool make far fewer mistakes than teams handed a login and left to it, which is why our AI training programmes and digital training tend to run alongside a build rather than after it.
Which Type of Chatbot Suits an Irish SME?
The right type depends on how varied your customer questions are and how much oversight you can give the tool. Simpler is often safer from a data protection point of view, because a bot that follows fixed flows touches less personal data than one that improvises.
| Type | Best for | Data protection notes | Indicative cost |
|---|---|---|---|
| Rule-based | Fixed FAQs, opening hours, simple booking flows | Smallest data footprint, no model provider in the chain | From around €30 a month |
| Generative | Varied phrasing, longer questions, product detail | Needs residency checks, training terms and log review | Roughly €100 to €300 a month |
| Custom or managed | CRM integration, regulated sectors, multi-site setups | Terms written around your own compliance position | Several hundred to several thousand euro to set up |
Those bands reflect what we see when scoping projects rather than any single published price list, so treat them as a starting point for your own quotes. To work out whether it pays, measure the hours your team currently spends on repetitive queries over a fortnight, price those hours at your own rate, and compare. The figure that usually tips the decision is not the saved admin time but the enquiries arriving outside working hours that nobody was answering at all. Our digital strategy service sets that calculation in the context of how the business actually wins customers.
Can You Run a GDPR Compliant Chatbot on WhatsApp?
Yes, with two conditions. The first is that the messaging platform becomes part of your processing chain, so its terms, retention and transfer position have to be assessed the same way you assessed the chatbot provider. The second is that you keep the channel appropriate to the data. Availability, order status and delivery updates are fine. Anything sensitive, including health details, payment information or complaints involving third parties, belongs in a channel you control.
Handled that way, messaging apps work well here because customers are already in them daily and reply rates are high. Answers should come from the same knowledge base as the website widget so that a customer gets one version of the truth wherever they ask, and marketing use of the same list needs its own consent, separate from the service conversation.
How Do You Build and Launch One Without Compliance Surprises?
The build is more straightforward than most owners expect. Preparation decides whether it works.
Prepare the knowledge base
Gather FAQs, opening hours, delivery and returns terms, service descriptions and brand guidelines into one cleaned source of truth. Currency matters more than volume. A short, accurate knowledge base beats a large one containing last year’s prices.
Connect it to the site and the CRM
Embed the widget, then decide deliberately what flows into your CRM and what does not. Passing every transcript into a sales system multiplies the number of places personal data sits, which multiplies the work when someone asks for deletion. Capturing the enquiry and discarding the chatter is usually the better design.
Test, soft launch and keep the handoff visible
Have staff run realistic awkward questions, including the ones customers ask when they’re annoyed, and note where the bot stumbles. Soft launch to a portion of traffic, review transcripts, then widen. Keep a visible route to a human at every stage, because refunds, complaints and complicated bookings still need a person, and a bot without a clean handoff creates more work than it removes.
“The businesses that get the most from a chatbot treat it as a member of staff that needs training and review, not a switch you flip once. Keep the knowledge base current and the handoff sharp, and it earns its keep,” says Ciaran Connolly.
Once it is running, tell people it exists. A short explainer on the page and in social posts lifts take-up, and our guide to practical AI uses for small business and our work on AI in marketing are useful next reads.
What to Settle First
A GDPR compliant chatbot is a procurement decision before it is a technology decision. Settle where the data lives, get the processing agreement right, clean the knowledge base, and set retention and deletion so they run without anyone remembering to run them. Do that first and the rest of the project, the channels, the integrations and the tone, becomes ordinary work. Skip it, and you inherit a system that captures customer data you cannot account for.
Frequently Asked Questions
What makes a chatbot GDPR compliant in Ireland?
It needs a documented lawful basis, a privacy notice shown before the conversation starts, data minimisation, a set retention period and a working route to deletion. It also needs a data processing agreement with the provider covering where data is stored, who the sub-processors are and whether conversations are used for model training.
Where should our chatbot data be hosted?
Inside the EEA or the UK is the simpler path for businesses serving customers in Ireland, Northern Ireland and Great Britain, because it avoids relying on transfer mechanisms for everyday processing. If the platform or its model provider processes data elsewhere, ask for the transfer mechanism and the documentation in writing before you sign.
Can the vendor use our chat logs to train their AI model?
Only if your agreement permits it, which is why the training clause should be checked rather than assumed. Many providers offer a no-training position by default on business plans, but a default setting can be changed and a contract term cannot, so get it written into the agreement.
Is there a GDPR compliant chatbot that keeps all our data in the EU?
Yes, several platforms offer EU data residency for both storage and inference, and self-hosted or private cloud setups keep everything inside infrastructure you control. The trade-off is usually cost and configuration effort, so it is worth deciding how sensitive your conversations really are before paying for the strictest option.
I keep getting vague answers from chatbot vendors about where our data goes. What should I actually ask?
Replace the general question with three specific ones: name the region where transcripts are stored, name the region where the model processes them, and send the current sub-processor list. Ask for the answers in an email rather than a call, because a vendor who cannot put it in writing has told you something useful.
How long should we keep chatbot conversation logs?
Keep them only as long as they serve a stated purpose, which for most service bots means weeks rather than years, with automatic deletion after that. If you want the long-term insight into what customers ask, anonymise older transcripts so the pattern survives without the personal data.
Do we need a DPIA before launching a chatbot?
You need one where the processing is likely to be high risk, including large-scale monitoring or any handling of special category data such as health information. For a small bot answering published questions it may not be required, though a short documented assessment is a cheap way to show you considered it.
What happens if the chatbot gives a customer the wrong answer?
Your business is accountable for it, so the mitigation is a current knowledge base, regular transcript reviews and a visible option to reach a person. Limit the bot to areas where the answer is stable and published, and route pricing exceptions, complaints and anything contractual to staff.
How much does a GDPR compliant chatbot cost for a small business?
Subscription platforms typically start around €30 a month for rule-based tools and run to €300 or more for generative setups, with custom integration and compliance work carrying a separate upfront cost. EU or UK residency is often tied to a higher plan tier, so check which plan actually includes it before comparing prices.
Does the chatbot need cookie consent as well as a privacy notice?
If the widget sets cookies or similar identifiers that are not strictly necessary, it falls under your consent banner and should not load until consent is given. A privacy notice inside the chat window explains the processing, but it does not replace consent for tracking technologies.