LexVibe
European Union
In force since 25 May 2018

GDPR compliance for an AI chatbot

General Data Protection Regulation (Regulation (EU) 2016/679). This page applies it to one kind of product (AI chatbot), so you get the obligations that are actually yours instead of a summary of the whole statute.

Does it apply to you?

Any organisation processing personal data of people in the EU, regardless of where it is established.

What an AI chatbot typically processes

  • conversation content sent to a model provider
  • prompts and outputs retained for quality or safety review
  • account data linked to conversation history

Each of these is processing you have to disclose. Adding an SDK later adds to this list — which is why a policy written once goes stale.

Documents you need

The intersection of what GDPR requires and what an AI chatbot actually does:

  • Privacy policy

Rights you must honour

GDPR gives people in the European Union the right to:

  • Access a copy of their data
  • Correct inaccurate data
  • Have their data deleted
  • Receive their data in a portable format
  • Object to certain processing
  • Restrict processing
  • Withdraw consent at any time
  • Ask for human review of an automated decision

Cookies and trackers

Nothing non-essential may load before the visitor agrees. Analytics and marketing scripts must be blocked until then — a banner that only informs is not enough.

The EU AI Act angle

A product like this that puts a model in front of users falls under the transparency duties of Article 50: you have to tell people they are interacting with an AI system, and machine-readable marking of generated content is required. Those duties apply from 2 August 2026; the high-risk obligations of Annex III were pushed to 2 December 2027.

See the EU AI Act timeline →

See what your site is actually missing

Paste your URL. We fetch the live page, detect the trackers, payments and AI calls that really ship to visitors, and tell you which documents and consent you need. No signup.

No signup · result in seconds

Primary sources

  • GDPRGeneral Data Protection Regulation (Regulation (EU) 2016/679) · official text
  • Art. 6Lawful bases for processing
  • Art. 13Information to provide when collecting data
  • Art. 15–22Data subject rights
  • Art. 28Processor contracts (DPA)
  • Art. 44–49International transfers

Everything we track about GDPR

GDPR for other kinds of product

Other frameworks for an AI chatbot

This page is an engineering summary of publicly available regulatory requirements, generated from LexVibe's framework registry — not legal advice. Every framework links to its official text so you can check it yourself. For decisions about your own compliance posture, consult the primary sources and a lawyer qualified in the relevant jurisdiction.