Skip to content
Law, privacy & accessibility

Contact data from chat: getting consent right

When a chat needs consent and when pre-contractual steps carry it: legal bases under the GDPR, TDDDG and UWG, plus records and withdrawal at a glance.

13 min read EinwilligungUWGLeadqualifizierung

An AI chat assistant that takes a name, an email address and a request processes personal data. Many operators respond to this with a checkbox in front of the first sentence of the conversation. That is exactly where the most common mistake in practice begins. Most of what an assistant does in a sales or service conversation does not rest on consent at all, but on pre-contractual steps. Consent is needed elsewhere: where advertising begins, and where something is stored on the terminal equipment that is not required for the service the user asked for. This article separates the three layers cleanly and shows what has to remain of every consent when a supervisory authority asks.

Key takeaways

  • Collecting a name, an email address and a request in order to answer an enquiry rests on the performance of pre-contractual steps (Art. 6 para. 1 lit. b GDPR). Consent is not the right lever for that.
  • Consent is needed for advertising use. For email advertising, Sec. 7 para. 2 no. 2 UWG requires the recipient's prior express consent, regardless of whether the contact came from a form or from a chat.
  • Storing information on terminal equipment falls under Sec. 25 TDDDG. Whatever is strictly necessary for the expressly requested service falls under the exemption in paragraph 2 and needs no banner.
  • The burden of proof lies with the controller (Art. 7 para. 1 GDPR). The record must cover the timestamp, the wording, the version of the text and the confirmation of the channel being advertised in.
  • A consent banner at a point where no processing requiring consent takes place is not a harmless safety margin but misleading information.

Consent is a narrowly defined instrument. It is any freely given, specific, informed and unambiguous indication of the data subject's wishes (Art. 4 no. 11 GDPR). Anyone who applies it wherever data flows turns the instrument into a stopgap. Users have long responded with resistance: 76 percent (Bitkom) of internet users in Germany are annoyed by cookie banners and tracking settings, and 68 percent (Bitkom) do not want to deal with them at all. The figures come from a 2024 survey of 1,013 people aged 16 and over. A dialogue window that triggers the same resistance before the first question has been asked loses exactly the conversations it was built for.

Supervisory authorities take a similar view. In its 2025 annual report, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg devotes a section to why an unnecessary consent banner causes problems: suggesting that processing requiring consent is taking place, when a different legal basis applies, amounts to false and misleading information. In the same report the authority recorded a rise in complaints from 4,034 in 2024 to 7,673 (LfDI Baden-Württemberg) in 2025 and issued 101 fine notices (LfDI Baden-Württemberg) totalling 308,850 euros. The pressure therefore does not come from theory but from submissions by data subjects.

The costliest fallacy: consent as a safety margin

A checkbox that carries nothing offers no protection; it creates an additional point of attack. It suggests a right of withdrawal that does not exist in that form and therefore breaches the principles of fairness and transparency. The order of examination runs the other way round: first determine the processing, then look for the legal basis, and only obtain consent if no other basis applies.

Pre-contractual steps carry the contact details

Someone who writes in a chat window that they need a quote for two hundred metres of cable trunking, and leaves their address for that purpose, is making an enquiry. There is a dedicated legal basis for precisely this: processing is lawful if it is necessary in order to take steps at the request of the data subject prior to entering into a contract (Art. 6 para. 1 lit. b GDPR). The emphasis is on the request. The data subject triggered the step, and the controller only processes what is needed to answer. How an assistant gathers these details in conversation rather than forcing them into a form is set out in detail in qualifying leads via chat.

  • Name and form of address, as far as needed for the reply
  • Email address or phone number as a return channel for this specific enquiry
  • Company name and role, if a quote with terms is to be prepared
  • The content of the enquiry including quantity, specification and requested date
  • The conversation transcript, as far as it is needed to handle the case and keep it traceable

The boundary is sharp, and it runs along the purpose. Everything necessary to answer the enquiry rests on (b). As soon as the same data is to be used for something else, that basis ends. The newsletter, the webinar invitation, the mailshot about the new product line: those are separate purposes, and they need a basis of their own. The same applies to data that has nothing to do with the enquiry. Asking about annual turnover during a technical query leaves the realm of what is necessary. Technical enquiries make this especially visible, as the article on technical enquiries in mechanical engineering works through using concrete transcripts.

Step in the chatLegal basisConsent required
Answering a question about delivery timesArt. 6 para. 1 lit. b GDPRnot included
Collecting contact details to prepare a quoteArt. 6 para. 1 lit. b GDPRnot included
Storing a session identifier for the current conversationSec. 25 para. 2 no. 2 TDDDGnot included
Retaining the transcript to handle the caseArt. 6 para. 1 lit. b GDPRnot included
Audience measurement with an identifier on the deviceSec. 25 para. 1 TDDDGincluded
Newsletter to the address given in the chatArt. 6 para. 1 lit. a GDPR, Sec. 7 para. 2 no. 2 UWGincluded
Profiling across several visitsArt. 6 para. 1 lit. a GDPRincluded

Terminal equipment and storage: what Sec. 25 TDDDG covers

The second layer has nothing to do with the content of the data but with its location. Storing information in the end user's terminal equipment, or accessing information already stored there, is permitted only if the end user has consented on the basis of clear and comprehensive information (Sec. 25 para. 1 TDDDG). This applies regardless of whether personal data is involved. A chat widget regularly puts something down: a session identifier, the state of the window, sometimes an interim record of the conversation.

Paragraph 2 exempts what is strictly necessary so that the provider of a digital service can make available a digital service expressly requested by the user (Sec. 25 para. 2 no. 2 TDDDG). Anyone who opens the chat window is expressly requesting the service. The session identifier, without which the conversation breaks off after the first page change, falls under it. What does not fall under it is everything running alongside: an identifier for recognition over weeks, a measurement of usage behaviour, a comparison with other offerings. Which storage locations an assistant actually needs and what retention periods apply is described in data protection and hosting and in the article on GDPR requirements for AI chatbots.

The assessment runs per storage operation, not per tool

An assistant is rarely a single thing. It has a window, a session, a knowledge base, often a link to a ticketing system. Each of these components stores or reads differently. The exemption in Sec. 25 para. 2 no. 2 TDDDG applies to one and not to the other. Setting a blanket banner because something somewhere is stored merely postpones the problem. Writing the operations down one by one usually ends with far fewer consent prompts than expected.

This is where consent is needed, and needed twice over. Under data protection law, advertising use rests on the data subject's consent for one or more specific purposes (Art. 6 para. 1 lit. a GDPR). Under competition law, an unreasonable nuisance is to be assumed in every case of advertising using electronic mail without the recipient's prior express consent (Sec. 7 para. 2 no. 2 UWG). Both layers have to be satisfied. Consent that is sound under data protection law but does not name the advertising channel is of little help in a competition dispute, and vice versa.

The existing-customer exemption in Sec. 7 para. 3 UWG is narrower than it is often read to be. It requires four things at once: the address must have been obtained in connection with the sale of goods or services, the advertising must concern the seller's own similar goods or services, the customer must not have objected, and they must be clearly informed of their right to object both when the address is collected and each time it is used. A chat enquiry without a purchase does not meet the first condition. Turning a quote request into a mailing list entry leaves the protected area, as the article on B2B quote requests in chat also shows at the handover to sales.

  • Separate request: the request for consent must be clearly distinguishable from other matters (Art. 7 para. 2 GDPR). A sentence that bundles enquiry and advertising into one checkbox carries neither.
  • No bundling: in assessing whether consent is freely given, account must be taken of whether performance of a contract is made conditional on consent that is not necessary for it (Art. 7 para. 4 GDPR). A quote must not hinge on the newsletter.
  • A specific channel: email, telephone and messaging are separate channels. Consent for one does not cover another.
  • Pre-ticked does not count: a box ticked in advance is not an unambiguous affirmative action within the meaning of Art. 4 no. 11 GDPR.
  • Plain language: the text has to be in clear and plain language, including inside a narrow chat window.

How people actually deal with such prompts is well documented and sobering. 24 percent (Bitkom) accept all settings as a matter of course because they cannot be bothered to engage with them. 33 percent (Bitkom) make a deliberate selection, and of those only 10 percent (Bitkom) expressly permit advertising cookies. 31 percent (Bitkom) say they do not understand the settings. Agreement born of exhaustion is legally vulnerable and commercially worthless: it fills a mailing list with addresses that neither open nor click. Consent given knowingly in conversation is rarer and worth considerably more, which the analysis of conversations also makes measurable over time.

Records: what has to be produced in a dispute

Where processing is based on consent, the controller must be able to demonstrate that the data subject has consented (Art. 7 para. 1 GDPR). That duty does not stand alone: the controller is responsible for compliance with the principles and must be able to demonstrate it (Art. 5 para. 2 GDPR). In practice this means that a database entry with the value true is not enough. What is needed is the complete operation: who, when, with what wording, in which version of the text, for which channel.

For consent declared electronically, the double opt-in procedure is required in order to verify the data subject's declaration of intent, and the evidentiary requirements set out by the Federal Court of Justice under the UWG must be taken into account when keeping records.

Datenschutzkonferenz, guidance on direct marketing, section 3.3

The guidance is very clear at this point: merely storing an IP address and asserting that consent was given from that address does not suffice under the case law of the Federal Court of Justice on the UWG (Datenschutzkonferenz). The decisive ruling dates from 2011 (Datenschutzkonferenz) under file number I ZR 164/09. Consent must be fully demonstrable, including as to its wording. For chat this means the confirmation email belongs to the procedure, not as a tiresome extra but as the actual evidence. What happens when records are missing and the operator has to answer for statements made by its assistant is shown in the article on liability after the OLG Hamm ruling.

Timestamp and origin

Date, time, the language of the conversation and the point in the transcript at which the prompt appeared. Without that link it is impossible to show later what the agreement referred to.

Wording and version

The full text of the prompt with a version number. If the wording changes, the old version stays retrievable; otherwise the record hangs on a text that no longer exists.

Channel and purpose

Which channel and purpose the agreement covers. Email advertising and telephone contact are recorded separately because Sec. 7 UWG treats them differently.

Confirmation and withdrawal

The response from the second step and any later withdrawal with a timestamp. Both belong in the same record so the current position stays readable at any point.

Information duties inside the chat window

Where personal data is collected from the data subject, the controller shall provide a set of details at the time the data is obtained (Art. 13 para. 1 GDPR). These include the identity and contact details of the controller, the purposes of the processing and the legal basis. This information has to be provided in a concise, transparent, intelligible and easily accessible form, using clear and plain language (Art. 12 para. 1 GDPR). A chat window is a poor place for running text but a very good place for a short notice with a link that opens the full version without breaking off the conversation.

  1. One sentence when the window opens: who is responsible and what the details are used for
  2. A visible link to the full privacy notice, reachable in one click
  3. The note on the retention period or the criteria used to determine it
  4. The note on the right of withdrawal as soon as consent is obtained (Art. 13 para. 2 GDPR)
  5. The note on the right to lodge a complaint with a supervisory authority
  6. A statement of whether providing the data is necessary in order to enter into a contract

That these points are no formality is shown by the workload of the supervisory authorities. The Bavarian Data Protection Authority received a total of 9,746 complaints and requests for investigation (BayLDA) in 2025, an increase of 61 percent (BayLDA) over the previous year and the highest level since the regulation took effect. The largest share of complaints, at 21 percent (BayLDA), concerns internet and digital services. On the other hand, 62 percent (BayLDA) of concluded formal complaints were handled within three months. Anyone who has documented the connection of their assistant to existing systems cleanly, as described under integration, answers such an enquiry in hours rather than weeks.

Withdrawal, deletion and the confirmation afterwards

The data subject has the right to withdraw consent at any time, and it must be as easy to withdraw as to give consent (Art. 7 para. 3 GDPR). This symmetry is often overlooked. If the agreement comes about with one sentence in the chat, the withdrawal must not be a form behind a login. The clean implementation is a withdrawal link in every advertising email plus a command inside the assistant itself that shows the current position and takes the agreement back. It also matters that the lawfulness of processing carried out up to the withdrawal remains unaffected: a withdrawal does not delete retroactively, it ends.

Technically this means the withdrawal is written to the same place as the agreement, with a timestamp and a trigger. Deleting the record instead loses exactly the evidence needed later to show that advertising between agreement and withdrawal was lawful. A short confirmation to the data subject is also sensible. When a person takes over the conversation, the same rules continue to apply, as the article on handover to staff describes. The separation also holds for booking appointments in chat: the appointment itself runs on pre-contractual steps, the reminder email about the next offer runs on consent.

Keep the current position readable at all times

A consent record should answer three questions without a follow-up: does the agreement apply now, what exactly did it refer to, and when did it last change. Having that in a single view makes it possible to answer a request in minutes. The same holds during a disruption, when the assistant switches to simpler operation: the article on outage and fallback explains why the consent path must not be simplified in the process.

Building a sound consent path

The order of work decides the effort. Anyone who builds the banner first and then asks what it is for ends up with a path that neither holds legally nor wins conversations. Anyone who writes the processing operations down before the first interface exists gets by with one small, clear prompt in exactly one place. The following order has proven itself in projects and can be worked through in a few days.

  1. List every processing operation of the assistant, from the session identifier to the handover to the ticketing system
  2. Determine the legal basis for each operation and record in writing why it applies
  3. Mark every operation that stores on or reads from the terminal equipment and test it against Sec. 25 para. 2 TDDDG
  4. Sort the remaining operations that require consent by channel and purpose
  5. Draft a short prompt text with a version number for each purpose and file it
  6. Define the record format: timestamp, wording, version, channel, confirmation, withdrawal
  7. Build the withdrawal path and check whether it is as easy as giving consent
  8. Place the notices under Art. 13 GDPR in the window and connect them to the privacy notice
  9. Run the complete flow once as a test case and document the outcome

What remains is a path that asks less and carries more. The enquiry runs on pre-contractual steps and needs no consent prompt. Storage on the terminal equipment is limited to what makes the requested service possible. Advertising has its own separate and demonstrable consent that the prospect gave knowingly. This separation costs thinking time once and then saves lasting arguments with the authorities, with sales and with the prospect. Which building blocks are available for it is set out in the services overview.

Sources and studies

This article draws on data from Bitkom, the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, the Bavarian Data Protection Authority and the Datenschutzkonferenz. The figures cited refer to the state of the respective publication.

Related Articles