Guides

GDPR-Compliant Chatbot: EU Data Residency in 2026

Vera Sun

Last update

Summary

  • A GDPR-compliant chatbot needs a lawful basis, clear notices, limited data, security, processor terms, retention rules, a process for privacy requests, and safeguards for transfers outside the EEA.

  • EU hosting can reduce transfer risk, but it doesn’t prove where model requests, logs, backups, support access, or integrations are processed.

  • From 2 August 2026, Article 50 requires providers to ensure people are told when they are interacting with AI by the first interaction, unless that is already obvious.

  • We publish where our main databases are stored and who appears on our subprocessor list. We don't treat those records as proof that every processing step stays in one country.

Support teams often meet GDPR at the buying stage. Legal or security sends a list of questions, and the product team has to explain where each conversation goes after a customer presses Send.

A certificate can help, but it can't answer the whole question. You still need to trace the message through storage, model processing, logs, backups, support access, and connected tools. Together, these checks turn GDPR Articles 5, 12, 17, 28, and Chapter V into a practical evidence request.

Certifications Do Not Show the Data Path

A certificate covers a named set of controls and an audit scope. It doesn't show every system that receives a customer message.

Our published security information includes SOC 2 Type II and lists HIPAA BAA available. These records can support a vendor review, but they don't show where every message, log, backup, model request, or support action is processed.

EU data residency describes where selected data is stored or processed. It isn't another name for GDPR compliance.

Three questions make the review concrete.

Where Does Data Rest, and Where Is It Processed?

Data at rest is data saved in a database or backup. Processing covers every action performed on it, from model inference to a support employee opening a chat record.

Table of six processing steps — conversation database, logs and backups, model inference, retrieval and tool calls, analytics, remote support — each with the question to ask a vendor and the evidence that answers it

Caption: EU hosting answers where the active conversation database sits. The other five processing steps need their own evidence.

That is why a Frankfurt database doesn't settle the processing question. Model inference, analytics, connected tools, or staff access can create another route that needs its own evidence.

GDPR doesn't require all personal data to stay inside the EU or European Economic Area. The GDPR rules for transfers outside the EEA allow transfers under set legal conditions.

An adequacy decision or Standard Contractual Clauses may provide a safeguard, but you must still check the route, purpose, and risk.

Which Processors and Subprocessors Touch the Conversation?

A controller decides why personal data is used and how the main decisions are made. A processor handles that data for the controller. A subprocessor performs part of the processor's work.

Those roles depend on the setup and contract. A model provider may be a subprocessor when it receives personal data for the chatbot vendor, but the role isn't automatic.

The EDPB guidance on processors and subprocessors supports a clear record of the processing chain. Ask for each company's name, purpose, data fields, country, retention, transfer basis, and required or optional status. A head office address isn't proof of processing location.

The same distinction applies to knowledge controls. Grounding answers in approved company content can limit which sources an AI agent uses. It doesn't tell you where the customer's message travels while the answer is created.

What Happens When a Person Asks for Deletion?

Article 17 of the GDPR gives people a right to erasure in set cases, with legal exceptions. It doesn't promise that every copy disappears at once.

Under Article 12(3), the controller normally has one month to explain what action it has taken. It may extend that period by two more months when a request is complex, or there are many requests. The person must be told about the delay within the first month.

The controller handles the request. The processor must provide the help required by Article 28 and the contract. A usable deletion process should answer five separate questions:

  • How is the person matched to the right conversation?

  • Which databases, logs, backups, and connected tools are searched?

  • What is deleted or restricted first?

  • Which copies expire later, and on what schedule?

  • How is deletion by a downstream processor confirmed?

A no-training statement doesn't answer these questions. Model training and day-to-day storage are different uses of data, so a vendor should explain both.

What EU AI Act Article 50 Requires for Support Chatbots

Article 50 of the EU AI Act applies from 2 August 2026. For AI systems built to interact directly with people, the provider must design the system so the person knows they are speaking with AI. The rule has an exception when the AI use is already obvious to a reasonably informed and careful person in that situation.

The notice must be clear, easy to tell apart, accessible, and shown no later than the first interaction. The European Commission transparency guidance supports a direct first-message notice. “You are chatting with an AI assistant” gives the user more information than a vague assistant label or a note hidden in a privacy policy.

Our configurable greeting appears at the start of each chat and can carry that notice. We also document live support, email escalation, and help-desk handoff paths that can give users access to a person when configured.

Article 50 doesn't create a general human-handoff rule for every support chatbot. We still recommend a visible human path because support teams need a clear way to handle edge cases, restricted actions, and requests the AI can't finish.

Our 2026 resolution study reviewed 5,848,078 conversations across 14,318 businesses. It recommends first-message disclosure, a visible human path, transcript retention, clear routing rules, and retention checks as practical operating steps. Those recommendations support implementation, but they don't replace the wording of Article 50.

A GDPR-Compliant Chatbot Vendor Checklist

Don't ask only whether a vendor is GDPR-compliant. Ask it to show how the exact plan, model, region, and integrations you want will handle personal data.

  1. Map every stored copy. Request the regions used for active chats, form responses, logs, backups, analytics, and connected tools.

  2. Trace each processing step. Include model inference, retries, failover, retrieval, tool calls, monitoring, and remote support access.

  3. Check who can open a conversation. Ask which employees or contractors have access, why they need it, and which countries they work from.

  4. List every processor in the route. Record the company, purpose, data received, country, retention period, and whether its service is required or optional.

  5. Confirm the selected model provider. Ask which provider serves your setup and what happens to prompts and outputs. Check retention, training use, abuse checks, and failover separately.

  6. Read the Data Processing Agreement. Confirm which DPA applies, how it is accepted, and how the vendor gives notice when its subprocessor list changes.

  7. Match each transfer to a safeguard. Ask which adequacy decision, SCCs, Binding Corporate Rules, or other transfer tool covers each recipient outside the EEA.

  8. Define your own legal setup. Record the lawful basis, privacy notice, and data-minimization rules for your use case. A Data Protection Impact Assessment depends on the risk, so it isn't automatic for every chatbot.

  9. Separate each retention period. Active records, logs, backups, model-provider copies, analytics, and integrations may follow different schedules.

  10. Walk through a privacy request. Check how access, correction, export, restriction, objection, and erasure requests are found, verified, sent to other processors, and recorded.

  11. Review the AI notice. Test the wording, timing, language, placement, and accessibility on every channel you plan to use.

  12. Test the stopping point. Check human handoff, ticket creation, transcript transfer, routing rules, restricted actions, and failed connections.

Ask for the evidence behind each answer. Useful records include a data-flow map, subprocessor list, DPA, transfer terms, retention schedule, deletion test, sample AI notice, and escalation test.

Where Our Public Evidence Is Clear and Where Questions Remain

We store our servers and databases, including chat and user data, in Frankfurt, Germany. We also publish our current subprocessor list, including each company's service, country, and required or optional status.

Those records support our EU-hosting statement for that storage scope. They don't prove that every model request, log, backup, support action, or optional integration stays inside the EU. Our privacy policy says third parties may process data outside the EU.

Our public pages don't yet provide one confirmed processing map for every model and connected service. They also don't give one deletion timeline for every conversation record, log, backup, and integration. Treat those points as questions for our team, not published guarantees.

Some buyers need contract terms for EU-only inference, a processor chain inside one region, customer-managed encryption keys, or self-hosting. If one of these controls is required, ask us to document whether the selected setup supports it. If it doesn't, another deployment may suit that requirement better.

Review Your Data Path With Our Team

Use the checklist before your legal, privacy, or security review. Start by testing an AI support agent grounded in your own content against the help-center material you plan to use, then check what it answers, cites, refuses, and sends to a person.

You can also review current Wonderchat plan details without treating a plan name as proof of how your data will be handled.

Primary button: See what it answers from your own help center

For contract, subprocessor, regional-routing, retention, or deletion questions, talk to our team about your data path.

Frequently Asked Questions

Does GDPR require chatbot data to stay in the EU?

No. GDPR doesn't set a blanket EU-only storage rule. Transfers outside the EEA need an accepted Chapter V safeguard, while the wider rules on lawful processing, notices, security, retention, processor oversight, and privacy rights still apply.

Is EU hosting the same as EU processing?

No. Hosting often describes where a database stores data. Model inference, logs, backups, staff access, analytics, and integrations may involve other countries. Ask for a data-flow map that names the region, recipient, purpose, transfer safeguard, and retention rule for each step.

Is the AI model provider a subprocessor?

Often, but not always. A model provider may be a subprocessor when it handles personal data for the chatbot vendor. Its role depends on the purpose, contract, and real data route, so ask who receives the message and why.

What should happen after a chatbot deletion request?

The controller should find the relevant data, assess the Article 17 request, and respond within the Article 12 timeline. Processor support should cover relevant active copies and downstream systems. The vendor should also explain backup schedules and any legal reason for keeping data longer.

Does the EU AI Act require a chatbot to say it is AI?

Article 50 requires providers to design directly interactive AI so that people are informed, unless the AI use is obvious in context. The notice must be clear, accessible, and shown by the first interaction. Human access is recommended, but it isn't a general Article 50 duty.

See what it answers from your own help center

Vera Sun

Vera Sun is the co-founder of Wonderchat, an all-in-one AI Support and Conversion agent platform built for companies with large knowledge bases. Her background is in product design and product management, which shapes how she thinks about the messy space between what a customer asks and what a product can answer. She writes about AI agents in production, customer support, and go-to-market for technical buyers, and can usually be found tinkering with new AI tools.