A chatbot transcript is personal information under CCPA/CPRA

California's framework, and the similar laws that a growing number of states have since passed, treat a logged chatbot conversation the same as any other collected personal information - which means the business running the chatbot has disclosure obligations (what's collected, why, and who it's shared with) and has to honor consumer rights requests, including deletion, against that data.

This applies whether the chatbot is built in-house or bought from a vendor - the business deploying it, not just the AI vendor, carries the compliance obligation to its own customers.

If a customer submits a deletion request, your process needs to actually reach the chatbot's conversation logs and any third-party model provider's retained data - not just your primary customer database.

The vendor contract is where this gets missed

A common gap: a business signs up for a third-party chatbot tool without checking what that vendor's own data retention and deletion practices are, then discovers during a compliance review that it can't actually fulfill a consumer's deletion request because the vendor doesn't support it.

Before adopting any AI chatbot vendor, the contract needs explicit terms on data retention length, whether conversation data is used to train models, and a documented process for deletion requests to actually propagate through.

Check vendor deletion support

Your compliance obligation doesn't disappear because a third-party vendor handles the chatbot - verify they can actually execute a deletion request.

Disclose collection clearly

State what conversation data is collected and why, in plain language, before or during the chat interaction.

Building in-house gives you more control, not automatic compliance

A custom-built chatbot on top of Claude gives a business direct control over retention and deletion logic - but that control has to actually be built, not assumed. The compliance work is the same either way: know what's collected, disclose it, and make deletion actually work end to end.

Building or buying a chatbot and need the privacy compliance built in from the start? Talk to us about the right architecture.

Key takeaways

  • A logged chatbot conversation counts as personal information under CCPA/CPRA and the growing list of similar state privacy laws - the business deploying it carries the compliance obligation, not just the AI vendor.
  • Deletion request processes need to actually reach chatbot conversation logs and any third-party model provider's retained data, not just the primary customer database.
  • Check a chatbot vendor's contract for data retention length, training-data use, and deletion-request support before adopting it - this is the most commonly missed step.
  • Building a custom chatbot gives more control over retention and deletion logic, but that control has to be deliberately built - it isn't automatic.
This is general information, not legal advice. Which specific state privacy laws apply to your chatbot and what they require depends on your business and customer base - consult qualified privacy counsel.