GDPR and Chatbots: What You're Allowed to Collect From Conversations in Romania
A clear guide for Romanian businesses: what data a chatbot may gather, what you can do with it, and how to avoid data-protection fines.
A chatbot on your site sounds simple: it answers questions at night, catches leads, saves you phone calls. But the moment a visitor types anything into that window, you have started processing personal data. In Romania that means GDPR, with everything it involves: a legal basis, proper notice, consent where required, and a supervisory authority that can ask you to explain yourself.
The good news is you don't need to be a lawyer to use a chatbot correctly. You just need to understand a few concrete rules and follow them from the start, not after a complaint lands. In this article I'll show you exactly what data you may collect from a conversation, what to avoid, and what a clean setup looks like - no scare tactics, no empty promises.
Almost anything a customer types is personal data
Many owners think GDPR only covers names and ID numbers. In reality the definition is far broader: any information that lets a person be identified, directly or indirectly.
Inside a chatbot that includes, among other things:
- first and last name
- phone number and email address
- delivery address or location
- the content of the messages, if it reveals something about the person
- the IP address and technical identifiers collected automatically
Even a seemingly trivial conversation can contain sensitive data: someone writes about a medical issue before booking, about their orientation, about their finances. These special categories demand extra care. The simple rule: treat everything that enters the chat as information you must protect, not as just another log.
You need a legal basis - and it isn't always consent
GDPR doesn't forbid you from collecting data. It asks you to have a legitimate reason for everything you do with it. The most common bases for a business chatbot are:
- performing a contract or the steps before it: someone asks for a quote, a booking, a price
- legitimate interest: answering a support question the customer started
- consent: needed mainly when you want to use the data for later marketing
The difference matters. If someone messages you to learn a price, you have grounds to reply and keep the conversation for a reasonable time. But if you want to add them to a newsletter or send offers later, you need separate, clear consent that they actively give - not one you assume. Don't mix purposes: every use of the data needs its own basis.
What NOT to collect and NOT to store for no reason
The simplest compliance rule is minimisation: collect only what you need for the specific purpose, nothing extra.
In practice, for a chatbot that means:
- never ask for national ID numbers, ID card details, or card numbers in the chat window
- don't keep transcripts forever; set a retention period and delete afterwards
- don't send conversations to external services without knowing where the data ends up
The external-services point is the one most often ignored. Many AI chatbots send every message to a provider outside the EU. That is allowed, but it must be declared in your privacy policy and covered contractually. If you don't know where your customers' data travels, you can't answer correctly when someone asks - and someone will ask.
Notice, transparency and the customer's rights
Before anyone types in the chat, they should be able to find out easily who collects the data, for what purpose, and how long you keep it. You don't need a legal novel - a visible link to your privacy policy next to the chat window solves most of the problem.
Useful elements to have:
- a short note when the chat opens: who you are and why you collect data
- a link to the full privacy policy
- a way for the customer to request deletion or access to their data
GDPR gives people concrete rights: to see what data you hold, to correct it, to ask for deletion. If you store conversations, you must be able to honour these requests within a reasonable time. A setup where even you don't know where the transcripts are makes it impossible to respond - and that is exactly what invites trouble.
How we approach a compliant chatbot at MPO
We build premium websites delivered remotely across the country, and when we add a chatbot we start from a simple question: what is it allowed to collect, and where does the data go. We prefer setups where transcripts sit on infrastructure you control, with a clear retention period and a privacy policy that matches what the bot actually does.
Before you pay anything, we prepare a pre-built demo so you can see exactly how it looks and behaves, and pricing is transparent from the start. No magic promises, no data flung around carelessly.
If you want a chatbot that catches leads without creating legal exposure, message us on WhatsApp and we'll talk through your specific case in plain words. It's cheaper to build it right from the start than to fix it after a complaint.
Frequently asked questions
Do I need explicit consent for any chatbot?+
Not for every one. If the bot only answers a question the customer started or prepares a quote, you can rely on contract performance or legitimate interest. Separate consent becomes necessary when you want to use the data for later marketing, such as a newsletter or offers sent afterwards.
Can I use an AI chatbot that sends data outside the EU?+
Yes, it's allowed, but you must be transparent. State in your privacy policy which provider you use and that data may be processed outside the EU, and make sure there's a proper contractual framework with the provider. The problem only appears when you don't know where the data flows and can't explain it to the customer.
How long may I keep chat conversations?+
GDPR doesn't set a fixed number. The rule is to keep data only as long as you need it for the specific purpose, then delete it. For many businesses a reasonable retention period for transcripts, followed by automatic deletion, is enough. What matters is having a rule and following it, not keeping everything forever.
What happens if a customer asks me to delete their chat data?+
You must be able to honour the request within a reasonable time. That means you need a system where you know where transcripts are stored and can find and delete them. If you use an external service, check from the start that it lets you delete data on request.
Do I need to display anything next to the chat window?+
Yes, at least a short note and a link to your privacy policy. It doesn't need to be long: who collects the data, for what purpose, and where they can learn more. Transparency from the first message protects you the most and costs the least.
7 mistakes that drive clients away from your website
Leave your email and get the guide right here, instantly. No spam.
Want to see what your business's website could look like?
Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.