How-To Guides

Live chat privacy checklist for small businesses

Live chat feels informal, but the conversation can contain names, contact details, order information, and personal context. Treat it like a real customer record from the first message.

A privacy checklist beside a protected website chat conversation.
Updated 7 Oct 2026•10 min read

What this checklist covers

This is an operational checklist for a small business using website chat. It is not a substitute for legal advice. Privacy requirements vary by location, audience, industry, and the information visitors choose to share. Use qualified advice for the rules that apply to your organisation.

The useful starting point is simple: know why you collect conversation data, collect only what you need, tell people what happens to it, control access, and delete it when the purpose ends. A long privacy notice cannot repair a workflow that nobody understands.

Review the complete journey before enabling a new widget or integration. The visible transcript is only one part of the record. Page context, identity fields, team notes, analytics events, email notifications, exports, and backups can all carry customer information.

Map the data before changing the notice

  • Information the visitor types, such as a name, email address, order number, or question.
  • Context added automatically, such as page URL, referrer, device information, or approximate location.
  • Team activity, including assignments, notes, replies, and conversation status.
  • Data sent to connected services, such as email, analytics, customer systems, or automation tools.
  • Exports, backups, logs, and copied conversation details outside the chat product.

For each field, record who supplies it, whether it is required, where it goes, who can see it, how long it remains, and how it can be corrected or deleted. Do not assume the visible transcript is the whole record.

Repeat the map when an integration changes. Sending a conversation summary to email, a customer system, or an automation platform creates another copy with its own permissions, retention, and request process.

Write down the purpose for each category

A support question, sales follow up, product analytics, fraud review, and marketing message are different activities. Do not bundle them into one vague purpose called customer experience. A precise purpose makes it easier to decide which fields are necessary and when they should be removed.

The UK Information Commissioner's Office explains the core data protection principles, including purpose limitation, data minimisation, accuracy, storage limitation, security, and accountability.

  • Name the business outcome for each item you collect.
  • Identify the lawful basis that applies where data protection law requires one.
  • Keep optional marketing activity separate from the service conversation.
  • Stop collecting fields that have no owner or defined use.
  • Document later uses before reusing old transcripts for a new purpose.

Put a clear notice where the conversation begins

A visitor should not need to search the footer after opening chat. Use concise text near the form or composer, then link to the full privacy notice. Explain who controls the data, why it is used, how long it is kept, who receives it, and how the person can ask questions or exercise applicable rights.

Keep the wording concrete. We use your email to send the reply is clearer than we process information to improve services. If conversation data also enters analytics, product training, or marketing workflows, describe that activity separately and accurately.

Check the notice on mobile, while the keyboard is open, and when the widget is embedded on a partner site. A technically present link is not useful if it is clipped, obscured, or shown only after the visitor has already submitted personal information.

Ask for less and discourage sensitive details

The ICO guidance for small organisations describes data minimisation as limiting personal information to what you need.

  • Do not request a phone number when an email reply is enough.
  • Ask for an order reference instead of a full payment record.
  • Tell visitors not to paste passwords, payment card details, medical records, or identity documents into ordinary chat.
  • Move identity checks and sensitive exchanges into an approved secure process.
  • Review saved replies so agents do not ask for excessive information out of habit.

Minimisation also applies to automatic context. Decide whether full URLs, query parameters, location, device data, and long histories are needed for the stated purpose. Remove values that create privacy risk without improving the reply.

Limit access inside and outside the inbox

  • Give access only to people who need conversations for their role.
  • Remove former team members promptly.
  • Use individual accounts and strong authentication.
  • Avoid copying transcripts into personal notes, private email, or unapproved documents.
  • Review integrations because each destination creates another access path.
  • Separate internal notes clearly from messages the visitor can see.

A shared inbox improves ownership only when sharing is controlled. Team convenience should not turn every conversation into an unrestricted company record. Review roles regularly and after organisational changes.

Train the team on what must never be pasted into chat and how to move a sensitive case into the approved process. Access controls cannot prevent a well meaning agent from copying information into the wrong place unless the operating guidance is clear.

Set a retention rule you can actually follow

Keeping every chat forever feels safe but creates a larger record to search, protect, and disclose. Choose periods based on the real purpose, contractual needs, dispute handling, and applicable law. Use different periods when support, sales, and regulated records genuinely need different treatment.

  • Document when the retention clock starts.
  • Define what is deleted from the primary system, exports, and connected tools.
  • Explain any backup delay honestly.
  • Test deletion with a sample conversation before promising the process.
  • Review legal holds or dispute needs through a controlled exception rather than keeping everything indefinitely.

Assign one owner for the schedule and review it at a fixed interval. A retention table that nobody runs is only documentation. Keep evidence that the process operated and investigate when copies remain beyond the intended period.

Review vendors and international transfers

List the chat provider, hosting services, analytics tools, email services, and integrations that handle conversation data. Record what each supplier receives, where processing occurs, which contract applies, and how a breach or request is handled.

A vendor badge or security page is useful evidence, but it does not replace your own decision about whether the service fits your data, visitors, and obligations. Recheck material claims and subprocessors rather than relying on a review completed years ago.

Know how to disable an integration and export necessary records if the supplier changes terms or the relationship ends. An exit plan is part of privacy operations because abandoned copies and forgotten credentials remain risks.

Create a route for access, correction, and deletion requests

A visitor may know only the email address or anonymous browser they used. Decide how the team will find relevant records, verify the requester proportionately, avoid exposing another person's conversation, and document the outcome.

Run a practice request. Search the inbox, notes, exports, email notifications, and connected systems. If staff cannot locate those copies, the public privacy notice is ahead of the operating process.

Give front line staff a clear escalation route instead of expecting them to interpret every request alone. Record the date received, identity checks, systems searched, decision, response, and any deletion still moving through backup cycles.

FAQ

Keep the conversation useful and controlled

Use Chatting for a focused shared inbox, then apply your own privacy policy, access rules, and retention process to the full customer data flow.

Start live chat free

FAQ

Should a live chat ask for consent before every conversation?

Not necessarily. The correct basis depends on the purpose and applicable law. Do not treat consent as a universal answer, and keep optional marketing separate from providing the requested reply.

Can visitors share order numbers in chat?

Often yes, if the number is needed to help them and access is controlled. Avoid requesting full payment details or more identity information than the task requires.

How long should chat transcripts be kept?

There is no single period for every business. Set a documented period tied to the purpose and relevant obligations, then make sure deletion also covers exports and connected systems.

Does using a privacy focused provider complete the review?

No. Your configuration, notices, staff access, integrations, exports, and retention choices remain part of the operating risk.

Small-team live chat

Start live chat free

Real-time conversations
without help desk bloat.

Start small-team live chat →

No credit card. No sales call.