# Live chat, privacy and the law in the United Kingdom

> What a UK small business must check before adding a chat widget: PECR regulation 6 consent since February 2026, the vendor contract, transcript retention, the UK Extension for US vendors and chatbot disclosure.

Published: 18 September 2026 · Updated: 18 September 2026 · Prices and limits verified: 18 September 2026 · By the live-chat.reviews team

This page was researched and drafted with AI assistance from the sources listed on it. We have not installed or tested these products ourselves. Method: [How we review](https://live-chat.reviews/en-gb/how-we-review)

A chat widget on a UK website meets two sets of rules. PECR decides what the widget may store on the visitor's device before anyone types a word. UK GDPR decides what you may do with the conversation afterwards. This guide sets out both as they stood on 18 September 2026, and ties each rule to a question you can put to a vendor.

> **General information, not legal advice** We are reviewers, not solicitors. Everything below comes from legislation, ICO guidance and government publications that we read on 18 September 2026, plus a small number of law-firm reports that we label as such. We have not installed or tested any product; vendor facts come from each vendor's own documentation, as described in [how we review](https://live-chat.reviews/en-gb/how-we-review). Take advice before you rely on any of it.

## PECR regulation 6: consent before the widget stores anything

The Data (Use and Access) Act 2025 replaced regulation 6 of the Privacy and Electronic Communications Regulations. [S.I. 2026/82](https://www.legislation.gov.uk/uksi/2026/82/made) brought the new text into force on 5 February 2026. [Regulation 6](https://www.legislation.gov.uk/uksi/2003/2426/regulation/6) now reads: "Subject to Schedule A1, a person must not store information, or gain access to information stored, in the terminal equipment of a subscriber or user." The rule covers information, not only personal data, so a visitor ID in a cookie or in local storage is caught. It also covers instigating storage or access, so the website operator who embeds a vendor's chat script is responsible, not only the vendor.

Schedule A1 holds the exceptions. The [ICO's guidance on storage and access technologies](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-exceptions/), final and last updated on 29 April 2026, lists five: communication, strictly necessary, statistical purposes, appearance or functionality preferences, and emergency assistance. The statistical and appearance exceptions come with conditions: clear information and a simple, free way to object. None of the five mentions live chat.

The exception a chat vendor is most likely to claim is "strictly necessary". The ICO says it applies where "the purpose of the storage or access is essential to provide the service the subscriber or user requests. This means that without it the service couldn't be provided on a technical level." The test is judged from the user's side. A visitor who has not opened the chat has not requested a chat. A visitor who clicks the launcher has.

> **This application to chat is ours, not the ICO's** The ICO does not address chat widgets by name. Reading its general test, storage needed to run a conversation the visitor has opened is strictly necessary, and identifiers the widget sets on page load are not. Treat that as a careful reading, not a ruling.

That reading leaves two safe patterns and one risky one.

- **Load after consent.** The vendor's script runs only once the visitor accepts the relevant category in your consent banner. Visitors who decline see no widget, or see a plain launcher that stores nothing.
- **Load on click.** Your page shows a lightweight launcher of your own. The vendor's script, and its storage, loads when the visitor clicks to open the chat. The same pattern helps page speed, as we explain in [does a chat widget slow your site](https://live-chat.reviews/en-gb/guides/does-a-chat-widget-slow-your-site).
- **Load on every page view.** This is the default snippet most vendors hand you. If the snippet writes a visitor ID, recognises returning visitors or tracks pages for proactive invitations before any click, that storage needs consent or a Schedule A1 exception you can defend.

Before you buy, ask the vendor for a list of every cookie and local storage key the widget sets, when each one is set, and whether the script can be held back until consent or a click. A vendor that cannot answer has given you the answer.

## What a PECR breach can now cost

[S.I. 2026/82](https://www.legislation.gov.uk/uksi/2026/82/made) also commenced section 115 and Schedule 13 of the Data (Use and Access) Act 2025, the Information Commissioner's new enforcement powers under PECR, on 5 February 2026. [Clifford Chance reports](https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2026/02/key-aspects-of-the-data--use-and-access--act-take-effect.html) that the maximum PECR fine rose from £500,000 to UK GDPR levels: £17.5 million or 4% of global annual turnover. We take that figure from a law firm, not from the regulator. On the day we checked, the ICO's own page on the consequences of non-compliance still said it would be updated once the new regime was in force. The safe working assumption is that cookie compliance now carries the same weight as UK GDPR compliance.

## UK GDPR basics for the conversation itself

| Duty | What it means for a chat widget | What to ask the vendor |
| --- | --- | --- |
| Transparency | Give privacy information when you collect the data: at the pre-chat form or the first message, not only in a footer link. Name the chat vendor as a recipient and state how long you keep transcripts. | Can the pre-chat form show our own privacy text and link? |
| Processor contract | The ICO's [contracts guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/contracts/) says: "Whenever a controller uses a processor to process personal data on their behalf, a written contract needs to be in place between the parties." A hosted chat vendor that stores transcripts for you is a processor. | Is a data processing agreement available on our plan, and how do we sign it? |
| Retention | Decide how long transcripts are kept and make the tool enforce it. Chat history limits on a free plan are a product limit, not a retention policy. | Can we set automatic deletion, and does deletion cover backups and any AI training data? |

The regulator's own notice is a useful model. The [ICO's privacy notice for people who contact it](https://ico.org.uk/global/privacy-notice/how-you-can-contact-us/) names the third-party provider of its live chat service, names its chatbot separately, and gives separate retention periods: 100 days for live chat and 12 months for chatbot conversations, which the ICO says it keeps "for training and analysis". A small business can copy that structure in four sentences.

## US vendors: the data bridge needs the UK Extension

Most chat vendors are American or use American sub-processors. The [government's data bridge factsheet](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-factsheet-for-uk-organisations) says: "From 12 October 2023, businesses in the UK can start to transfer personal data to US organisations certified to the 'UK Extension'" to the EU-US Data Privacy Framework. Two checks follow. The vendor must be an active participant on the Data Privacy Framework list, and its entry must show the UK Extension. A vendor certified for the EU only is not covered for UK data. Without the UK Extension, use the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU standard contractual clauses. The factsheet adds that special category data must be identified as sensitive when it is sent.

The bridge rests on the EU-US framework. The EU General Court [dismissed a challenge](https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf) to that framework on 3 September 2025. An appeal to the Court of Justice is reported by law firms; we found no hearing date or judgment as of 18 September 2026. Keeping the IDTA or the Addendum in the vendor contract as a fallback costs nothing.

Our catalogue records what each vendor documents, and no entry records a UK Extension. The entries for [Freshchat](https://live-chat.reviews/en-gb/reviews/freshchat) and [Tidio](https://live-chat.reviews/en-gb/reviews/tidio) list the EU-US Data Privacy Framework. The entry for [tawk.to](https://live-chat.reviews/en-gb/reviews/tawk-to) lists a self-certified Data Privacy Framework participation, a data processing addendum with standard contractual clauses and a UK Addendum, and a UK ICO registration. In every case, check the vendor's entry on the Data Privacy Framework list yourself before you rely on the bridge.

## "EU data residency" is not UK residency

Vendors sell EU hosting as the answer to European privacy questions. An EU region keeps transcripts out of the United States. It does not keep them in the United Kingdom, and data hosted in the EU is still hosted outside the UK, so ask which UK transfer mechanism the vendor's contract names. If a customer contract or a sector rule requires UK hosting, an EU region does not meet it.

Of the products in our catalogue, only [Zendesk](https://live-chat.reviews/en-gb/reviews/zendesk) documents a UK region: its pricing page lists the United Kingdom among its data centre locations, the option is available on Suite Professional and above, and it has to be switched on through support. The other entries document EU or EEA hosting (Crisp, Tidio, LiveChat, HubSpot Live Chat, Freshchat), hosting in Germany (Lime Connect), EU hosting on Advanced and Expert only (Intercom), or storage in the United States (tawk.to). Smartsupp's own statements on hosting conflict. We compare these in [EU-hosted live chat software](https://live-chat.reviews/en-gb/best/eu-hosted-live-chat).

## When a bot answers first

The UK has no statute that requires you to tell visitors they are talking to a bot, and we found no ICO guidance specific to customer-service chatbots. The ICO's [guidance on transparency in AI](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-transparency-in-ai/) still requires you to explain how personal data is processed in an AI system; the page carries a notice that it is under review because of the Data (Use and Access) Act. UK consumer-protection law on misleading practices may also bite on a bot that passes itself off as a person. We did not research that area, so we say no more than that.

A UK business that serves visitors in the EU meets a harder rule. [Article 50(1) of the EU AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689) has applied since 2 August 2026 and requires chatbots to be designed so that people are told they are interacting with an AI system, unless that is obvious. The [Commission's FAQ](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act) frames this as the provider's duty, which for a bought-in bot is the vendor. Label the bot anyway: in the first message or the widget header. The differences between a scripted bot and an AI agent are set out in [live chat vs chatbot vs AI agent](https://live-chat.reviews/en-gb/guides/live-chat-vs-chatbot-vs-ai-agent).

One further point matters only if the bot decides things, for example refusing a refund without a human involved. New Articles 22A to 22D of UK GDPR on automated decision-making date from 5 February 2026. The ICO is reported to have consulted on draft guidance from 31 March to 29 May 2026; that report is not confirmed by us, and we could not confirm a final version.

## Complaints that arrive through chat

Several law firms, including [DLA Piper](https://privacymatters.dlapiper.com/2026/06/uk-new-complaints-handling-rules-under-duaa-take-effect-on-19-june-2026-are-you-ready/), report that a new section 164A of the Data Protection Act 2018 took effect on 19 June 2026. As reported, it requires controllers to offer a way to make data-protection complaints, including an electronic form, to acknowledge a complaint within 30 days and to respond without undue delay. This is reported, not confirmed by us: we saw it in search results only and did not read the legislation or an ICO page. If it applies to you, a chat agent who receives such a complaint needs a route to pass it into that process.

## Checklist before you switch the widget on

1. Get the vendor's list of cookies and local storage keys, with the moment each one is set.
2. Hold the vendor script until consent, or until the visitor clicks to open the chat.
3. Sign the processor contract and name the vendor in your privacy notice.
4. Show privacy information at the pre-chat form and set a transcript retention period.
5. For a US vendor, confirm an active Data Privacy Framework entry that shows the UK Extension; otherwise use the IDTA or the UK Addendum.
6. Do not read "EU data residency" as UK residency.
7. Label the bot in its first message, and give visitors a way to reach a person.

## Sources

- [PECR regulation 6, as substituted](https://www.legislation.gov.uk/uksi/2003/2426/regulation/6), legislation.gov.uk
- [S.I. 2026/82, Data (Use and Access) Act 2025 (Commencement No. 6) Regulations](https://www.legislation.gov.uk/uksi/2026/82/made), legislation.gov.uk
- [ICO guidance on storage and access technologies: what are the exceptions?](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-exceptions/), last updated 29 April 2026
- [ICO guide to accountability and governance: contracts](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/contracts/)
- [ICO privacy notice: how you can contact us](https://ico.org.uk/global/privacy-notice/how-you-can-contact-us/)
- [ICO guidance on AI and data protection: transparency](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-transparency-in-ai/), marked as under review
- [UK-US data bridge: factsheet for UK organisations](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-factsheet-for-uk-organisations), GOV.UK
- [General Court press release on Latombe v Commission, T-553/23](https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf), 3 September 2025
- [Regulation (EU) 2024/1689, the AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689) and the [Commission's Article 50 FAQ](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act)
- Law-firm analysis, not a primary source: [Clifford Chance on the Data (Use and Access) Act](https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2026/02/key-aspects-of-the-data--use-and-access--act-take-effect.html) for the PECR fine level; [DLA Piper on the complaints duty](https://privacymatters.dlapiper.com/2026/06/uk-new-complaints-handling-rules-under-duaa-take-effect-on-19-june-2026-are-you-ready/), seen in search results only

## Frequently asked questions

### Does a live chat widget need cookie consent in the UK?

Usually, for anything the widget stores before the visitor opens it. [PECR regulation 6](https://www.legislation.gov.uk/uksi/2003/2426/regulation/6) bans storing or reading information on a visitor's device unless a Schedule A1 exception applies, and the ICO's guidance names no exception for chat. On our reading of the ICO's "strictly necessary" test, storage needed to run a chat the visitor has opened is exempt, and identifiers set on page load are not. The ICO has not said this about chat by name.

### Is loading the chat widget on click enough to comply with PECR?

It is one of the two patterns we consider safe, alongside loading after consent. A click on the launcher is a request for the chat service, so storage that is technically essential to run that chat fits the "strictly necessary" exception as the ICO describes it. Storage for analytics, advertising or visitor tracking still needs consent after the click. This is our application of the ICO's general test, not an ICO statement about chat.

### What is the maximum fine for breaking PECR cookie rules?

New ICO enforcement powers under PECR commenced on 5 February 2026 under [S.I. 2026/82](https://www.legislation.gov.uk/uksi/2026/82/made). [Clifford Chance reports](https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2026/02/key-aspects-of-the-data--use-and-access--act-take-effect.html) a maximum of £17.5 million or 4% of global annual turnover, up from £500,000. That figure comes from a law firm; the ICO's own enforcement page had not been updated when we checked on 18 September 2026.

### Can a UK business use a US chat vendor?

Yes, with a transfer mechanism. The [UK-US data bridge](https://www.gov.uk/government/publications/uk-us-data-bridge-supporting-documents/uk-us-data-bridge-factsheet-for-uk-organisations) covers vendors whose Data Privacy Framework certification is active and includes the UK Extension. If the vendor's entry does not show the UK Extension, use the IDTA or the UK Addendum to the EU standard contractual clauses. Our catalogue does not record a UK Extension for any vendor, so check the list yourself.

### Does EU data hosting satisfy a UK data residency requirement?

No. An EU region stores transcripts in the EU, not in the UK. Of the products in our catalogue, only [Zendesk](https://live-chat.reviews/en-gb/reviews/zendesk) documents a UK region, on Suite Professional and above. If you need EU hosting rather than UK hosting, see [EU-hosted live chat software](https://live-chat.reviews/en-gb/best/eu-hosted-live-chat).

### Do I have to tell UK visitors they are talking to a chatbot?

No UK statute says so, and we found no ICO guidance specific to customer-service chatbots. General transparency duties under UK GDPR still apply, and [Article 50(1) of the EU AI Act](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689) has required disclosure for bots serving people in the EU since 2 August 2026. Labelling the bot in its first message covers both. See [live chat vs chatbot vs AI agent](https://live-chat.reviews/en-gb/guides/live-chat-vs-chatbot-vs-ai-agent).

> **Scored on a public rubric, from pages you can open.** Every score on this site comes from five published criteria: free-plan usability, cost as you add agents, AI billing clarity, channels and integrations, and data location and compliance. Each price and limit is stored once, links to its source, and shows the same value on every page. Rubric v1.0 · We have not installed or speed-tested these widgets yet, and no page here claims we did. [Read the full method](https://live-chat.reviews/en-gb/how-we-review)

## Keep reading

- [Is a free live chat plan enough for your team?](https://live-chat.reviews/en-gb/guides/is-a-free-live-chat-plan-enough)
- [Per-seat vs per-workspace pricing: what your team size does to the bill](https://live-chat.reviews/en-gb/guides/per-seat-vs-per-workspace-pricing)
- [How live chat vendors bill for AI](https://live-chat.reviews/en-gb/guides/how-live-chat-vendors-bill-for-ai)
- [Live chat vs chatbot vs AI agent](https://live-chat.reviews/en-gb/guides/live-chat-vs-chatbot-vs-ai-agent)
- [Best live chat software in 2026](https://live-chat.reviews/en-gb/best/live-chat-software)
- [Free-plan audit: does your team fit a free live chat plan?](https://live-chat.reviews/en-gb/tools/free-plan-audit)

---

Canonical: https://live-chat.reviews/en-gb/guides/live-chat-privacy-and-the-law
