Customer service
Privacy and GDPR in live chat: what to watch out for
2 December 2025 · 5 min read
Chat means processing personal data
In almost every chat conversation, a customer shares personal data: name, contact details, order numbers. Your chat platform — and, if outsourcing, your service partner — are therefore data processors. That requires a data processing agreement and clear arrangements on security and retention.
Five boxes to tick
Check the following five points with every supplier or partner:
- An up-to-date data processing agreement with clear terms on purpose and security.
- Data storage within the EU, or appropriate safeguards for storage elsewhere.
- An agreed retention period with automatic deletion of old conversations.
- Access rights: who can view conversations, and is that logged?
- A data breach procedure with clear notification timelines.
Consent and duty to inform
State in your privacy policy that you store chat conversations and why. For proactive chat or tracking-based triggers, ask for proper cookie consent. If you're unsure about the setup, have it reviewed — this article is not legal advice.
When outsourcing: extra points of attention
An outsourced partner processes data on your behalf. Define which systems they can access, how accounts are managed, and what happens to the data once the partnership ends. Choose partners who proactively communicate about this themselves — that says more than any certificate.
Conclusion
GDPR-proof chatting isn't an obstacle, it's a checklist. Get the processing agreement, retention periods and access rights right, and you meet both the law and your customers' expectation that their data is safe.