AI Chatbot Data Privacy Checklist: GDPR, CCPA, HIPAA Compliance
A 25-point data privacy checklist for AI chatbots in 2026 covering GDPR (EU/UK), CCPA (California), HIPAA (US healthcare), PIPEDA (Canada), and DPDP (India). Concrete controls, vendor questions, audit-ready answers.
The fastest way to fail a privacy audit is to assume your AI chatbot vendor has handled compliance for you. They have handled some of it; you are responsible for the rest. This checklist tells you which is which.
1. Lawful basis & consent
- Lawful basis documented (consent, contract, legitimate interest)
- Visible privacy notice before first chat
- Cookie banner integration
- Granular consent for marketing follow-up vs support only
- Easy withdrawal of consent in chat
2. Data minimization
- Only collect data necessary for the use case
- PII redaction enabled before sending to LLM
- Conversation retention period set (90 days default)
- Auto-delete on customer request
- No sensitive categories (race, health, etc.) without explicit basis
3. Vendor & sub-processor controls
- Data Processing Agreement signed with chatbot vendor
- LLM provider listed as sub-processor with DPA
- Data residency option for EU/UK/Canada/India
- BAA for HIPAA workloads
- Sub-processor change notifications subscribed
4. Subject rights
- Erasure (right to be forgotten) within 30 days
- Access requests fulfilled within 30 days
- Portability: export of conversation data on request
- Objection & restriction handled in dashboard
- Automated decision-making opt-out where applicable
5. Security & audit
- Encryption at rest (AES-256)
- Encryption in transit (TLS 1.3)
- Role-based access control
- SOC 2 Type II report from vendor
- Audit logs retained 12+ months
Which Law Applies to Your Chatbot
Most teams process data under two or three of these frameworks at once. Here is the quick version of what triggers each one and the single control that matters most for a support chatbot.
| Framework | Triggers when | Control that matters most |
|---|---|---|
| GDPR (EU/UK) | Any EU or UK visitor uses your chat | Signed DPA plus a lawful basis on record |
| CCPA/CPRA (California) | $25M revenue, or 100K+ consumers, or data sales | Do-not-sell and deletion within 45 days |
| HIPAA (US health) | You handle protected health information | BAA with vendor and LLM provider, PHI redaction |
| PIPEDA (Canada) | You collect data from Canadian users commercially | Meaningful consent and breach reporting |
| DPDP (India) | You process personal data of people in India | Free, specific, unambiguous consent |
How to Run This Checklist Without a Legal Team
You don't need outside counsel to get 90% of the way there. Here is the order we recommend when a team is standing up a website AI chatbot for the first time:
- Turn on PII redaction before you go live. This strips names, emails, card numbers, and phone numbers before anything reaches the LLM. It is the single control that shrinks your risk surface the most.
- Publish a one-paragraph privacy notice inside the chat launcher. State what you collect, why, how long you keep it, and how to request deletion. Link it from the widget, not just your footer.
- Get the DPA and sub-processor list from your vendor in writing. If a vendor can't name its LLM sub-processors, that's a red flag. You need those names for your own records.
- Set a retention window and a delete path. 90 days is a sane default for support transcripts. Make sure a customer request actually erases the record, not just hides it.
- Log access. Who on your team can read transcripts, and is that logged? Role-based access plus 12 months of audit logs answers most auditor questions in one screenshot.
A quick example. A 15-person DTC brand ran this checklist in an afternoon. The only gap was retention: transcripts were being kept forever with no delete path. They set a 90-day window, wired up the erasure endpoint, and were audit-ready by end of week. Total cost: about three hours.
If you want to pressure-test your own setup at zero cost, EzyConn's free plan ships with redaction, a configurable retention window, and a DPA available on request. It includes 2 seats and 100 AI conversations a month with no vendor branding, which is enough to validate your controls before you commit. Compliance features scale up from there; see current pricing for the tiers that add EU data residency and HIPAA BAAs.
Frequently Asked Questions
Is chatbot data covered by GDPR?
Yes. Any user-identifiable data sent to an LLM provider is subject to GDPR. DPA, lawful basis, and erasure rights all apply.
Can chatbots be HIPAA compliant?
Yes, with signed BAAs (chatbot vendor plus LLM provider), encryption, audit logging, and PHI redaction.
Does a small business really need all 25 controls?
No. Start with lawful basis, a visible privacy notice, PII redaction, and a signed DPA. Those four cover most of your exposure. Add the rest as you grow. Our small business chatbot guide walks through the minimum viable setup.
Which laws apply if I only sell in the US?
CCPA if you hit California thresholds, plus the newer state laws (Colorado, Virginia, Texas). HIPAA only if you handle protected health information. GDPR still applies the moment an EU visitor uses your chat, so most teams just build to the stricter standard once.
Compliance built in
EzyConn ships SOC 2, GDPR, CCPA, and HIPAA-ready defaults. EU data residency on Pro+. Read our compliance overview.
Start FreeLast updated . Not legal advice. View more guides.