
The most common objection to AI chatbots isn't "does it work?" but "is it GDPR-compliant?". Rightly so - the assistant talks to customers, and conversations are data. The good news: it can all be put in order calmly. Here are the three questions every lawyer asks, and honest answers to each.
Three questions every lawyer asks
Before you get into the technical details, make sure you can answer three things: where conversation data physically ends up, who the data processor is and on what terms, and whether the AI model learns from your customers' data. Everything else is detail around those three axes.
Where conversation data goes
The key question is location and control. With us, ecChat runs on hosting in the European Union, and the data flow is designed to limit the information passed on to the necessary minimum.
It's also worth setting a retention policy: how long conversation transcripts are stored and when they are deleted. This should be a conscious decision, not a default setting.
Does the model learn from your customers
The biggest fear is: "will our conversations end up training someone else's model?". In a correctly configured implementation, the answer is no. The assistant uses your knowledge to answer, but conversation data is not used to train base models without explicit consent.
The assistant's knowledge comes from your materials (catalogue, FAQs, policies), and customer conversations do not feed the training of external models. The scope of processing is set out in the data processing agreement.
Data processing agreement and compliance checklist
The formal foundation is a data processing agreement (DPA). On top of that, a short checklist worth running through before launch:
- Hosting and processing location in the EU - confirmed in writing.
- A data processing agreement with a clearly defined scope and purpose of processing.
- A transcript retention policy - storage period and deletion rules.
- Informing the customer that they are talking to an AI assistant, and updating your privacy policy.
FAQ
Do I have to tell customers they're chatting with a bot?
It's good practice and part of transparency - we recommend clearly labelling the AI assistant and covering it in your privacy policy.
Where is conversation data stored?
In our ecChat implementation, data is processed on EU hosting, and the scope and storage period are governed by the data processing agreement.
Can a chatbot handle sensitive data?
We advise against collecting sensitive data in chat; the assistant is configured not to prompt for it, and we design the process in line with the data minimisation principle.