If your business uses or plans to use an AI chatbot (on your website, WhatsApp or the phone), sooner or later you will have to show that it complies with EU Regulation 2016/679 (RGPD, the Spanish name for the GDPR), the LOPDGDD (Spain’s Organic Law on Data Protection and Digital Rights), the LSSI-CE (Spain’s law on information society services and e-commerce) and, from 2026, the AI Act. This guide is the minimum checklist every SME should review before putting the bot into production, and before a customer, a supplier or the AEPD (Spain’s data protection authority) asks questions.
This page is informational. It does not constitute legal advice. Final validation of a specific case is done by a legal adviser or the client’s DPO. For STAKKER’s technical approach, see IA y protección de datos.
TL;DR
- Make clear to users that they are talking to an AI before the first message (AI Act).
- Define an explicit legal basis (consent, contract, legitimate interest) for each flow.
- Sign a DPA with the provider that operates the chatbot and list sub-processors.
- Apply short retention of conversations (30-90 days by default).
- Always allow handoff to a human.
- For sensitive data (health, minors, judicial), reinforce with a DPIA + DPO.
Why your chatbot is data processing
A chatbot that receives a question and answers it is processing a message that almost always identifies the user: WhatsApp number, IP address, email, the name the user gives you, the content of the conversation. That is personal data under Art. 4.1 of the GDPR.
Being a short conversation does not exempt you from complying with the regulation. Neither does the bot being a third party’s SaaS: the third party is usually the processor, and your business remains responsible to the end user.
The minimum checklist (12 points)
1. Notice of AI interaction before the first message
From 2026 the AI Act requires you to state clearly that the user is interacting with an AI system. In practice:
- On WhatsApp: the bot’s first message includes “you are talking to a virtual assistant”.
- On the website: a badge or copy next to the chatbot identifying the system.
- On calls: a notice in the first few seconds (“you are being assisted by a virtual assistant”).
Hiding it “for the sake of the experience” is not acceptable. It is a regulatory requirement, not an aesthetic decision.
2. Linked privacy policy specific to the bot
The website’s general policy works as a starting point, but it should explicitly mention:
- That there is a chatbot that processes messages.
- What data it collects.
- What it uses it for.
- How long it keeps it.
- Who the processors (providers) are.
A clear paragraph is better than an endless PDF.
3. Legal basis documented per flow
Writing “consent” as a universal legal basis is not acceptable. Each bot flow may have a different legal basis:
- General enquiry from an anonymous visitor: the user’s consent when starting the chat (informed).
- Service for a customer with an active contract: performance of a contract.
- Commercial communications via WhatsApp after closing: prior express consent (LSSI Art. 21).
- Marketing outbound: prior consent or legitimate interest with a documented LIA.
If your bot sends messages to cold leads without opt-in and without an LIA, you risk sanctions.
4. Data minimisation
Ask the bot for only what you need for the answer or the booking. Asking for an ID number or income in a first enquiry is disproportionate and gets sanctioned. A clinic does not need to know your symptoms to book you an appointment; ask for them only at the in-person consultation.
5. Limited retention of conversations
Define it and publish it. By default STAKKER works with 30-90 days. Anything longer needs justification. Keeping conversations for three years “just in case” is not a legal basis.
6. DPA signed with the bot provider
If you outsource the chatbot to a SaaS or a technical provider (whether STAKKER or another), you must sign a data processing agreement (Art. 28 GDPR) that includes:
- Purpose of the processing.
- List of sub-processors (Hetzner, Anthropic, OpenAI, Twilio, ElevenLabs, etc.).
- Technical and organisational measures.
- Retention period.
- Breach notification within 24-72h.
- Return or deletion at the end of the contract.
Without a DPA, in an inspection, you are the one who answers alone.
7. Public list of sub-processors
Every chatbot provider processes data: the LLM, the WhatsApp gateway, the audio transcription system if there is one, the CRM the lead is pushed to. The list must be accessible to any user who asks for it (exercise of rights).
8. Encryption in transit and at rest
HTTPS is mandatory. Encrypted storage of the database where conversations are kept. Role-based access so that only people with a genuine need read the logs.
9. Access logs and traceability
Who accesses the conversations, when and from where. This is required for audits and for responding to users’ rights requests (access, rectification, erasure).
10. Mechanism for user rights
Users must be able to exercise their rights without a fight. At a minimum:
- Email or form to request access, rectification, erasure, objection, portability and restriction.
- Response deadline of 1 month (GDPR).
- In the bot, an explicit option to speak to a human and request deletion.
11. Human handoff always available
Art. 22 GDPR limits automated decisions with significant effects on the individual. If the bot rejects a transaction or closes a sale, the user can ask for human review. Build it in from the start.
12. DPIA if the processing is high-risk
Health data, data on minors, judicial data, mass profiling, large-scale commercial communications: these require a Data Protection Impact Assessment (DPIA, Art. 35 GDPR) before going into production. The AEPD publishes a public template. Do not skip it.
Special categories: when NOT to use public AI
If your business handles sensitive data under Art. 9 GDPR (health, biometrics, sexual orientation, political opinions, judicial data, etc.), the rules get tougher:
- DPO mandatory or outsourced.
- Legal basis under Art. 9.2 (simple consent under 6.1.a is not enough).
- DPIA mandatory.
- Reinforced encryption and traceability.
- Human review of any decision.
- Sub-processors with verified safeguards.
In dental clinics, physiotherapy, aesthetics and veterinary practices: the bot can handle the administrative side (appointments, reminders, public FAQs) without touching clinical data. Sector-specific detail is in Sistemas IA para clínicas.
The most common SME mistakes
A. Bot that asks for an ID number in the first enquiry without need: failed minimisation.
B. Marketing WhatsApp message without express opt-in: LSSI Art. 21 + GDPR.
C. Privacy policy that does not mention the chatbot: incomplete.
D. Chatbot SaaS without a signed DPA: joint liability.
E. “Indefinite” retention of conversations: storage limitation principle breached.
F. No clear mechanism to speak to a human: Art. 22 failure.
G. Processing of sensitive data without a DPIA: high risk and open to sanction.
How we approach it at STAKKER
We build the system from the outset with these twelve points in mind and deliver:
- DPA with Art. 28 clauses ready to sign.
- Project-specific list of sub-processors.
- Default retention policy of 30-90 days, configurable.
- AI notice in the bot’s first message, call or WhatsApp.
- Human handoff in every flow.
- Logs and traceability active from day one.
- DPIA when the case requires it (clinics, regulated sectors).
We do not sign a project that breaches any of the twelve points. If the client has no DPO and the case requires one, we pause until they sort it out.
More detail in IA y protección de datos and on the service pages:
Frequently asked questions
Do I have to register my chatbot with the AEPD?
There is no public register of chatbots, but the processing must appear in the controller’s record of processing activities (Art. 30 GDPR) and in the DPA with the provider. An AEPD inspection will ask for those documents, not a “chatbot registration”.
What if my AI provider is outside the EU (OpenAI, Anthropic)?
You need international transfer safeguards: Standard Contractual Clauses (SCCs), adherence to the EU-US Data Privacy Framework or equivalent. Without safeguards, there is a risk. Most reputable providers already have them.
Does “accept the privacy policy” count as consent for everything?
No. Consent must be specific, freely given, informed and verifiable. A single checkbox does not cover multiple distinct purposes (chatbot + marketing + cookies + analytics).
What happens if the AEPD investigates?
They will ask for: privacy policy, record of processing activities, DPAs with providers, documented legal basis, rights mechanism, effective retention, breaches notified. If you have it all in order, the inspection is a formality. If not, GDPR fines go up to 20M EUR or 4% of global turnover.
Do I have to tell the user if I record the AI agent’s call?
Yes, before you start recording. Notice at the start + documented legal basis + limited retention. Without an explicit notice and a legal basis, you do not record.
Can I use the bot’s conversations to train the AI?
Only with explicit consent, separate from the main purpose. By default the big providers (Anthropic, OpenAI) offer modes that do not use data for training; configure it that way.
Next step
If you are going to set up an AI chatbot and want to know what applies to you before spending a euro, we can audit your case. The first review is free: we explain what applies to you under the GDPR and the AI Act, what risks you face and what is needed for the bot to operate lawfully.