Is tawk.to GDPR-compliant? What the vendor states — and what you have to handle yourself
By its own account, tawk.to processes all data in the US, is certified under the EU-U.S. Data Privacy Framework and provides a data processing agreement. That does not rule out GDPR-compliant use — but the duties are yours as the site owner: privacy policy, consent for storage in the browser, and a review of the sub-processors.
We make SilentChat, so we compete with tawk.to. That is why this article only states what tawk.to publishes itself, each with a source. It is not legal advice.
What tawk.to states
- Processing location: “We are located in the United States and we do all processing in the United States.” (privacy policy, last updated 9 April 2025)
- Data Privacy Framework: tawk.to is certified under the EU-U.S. Data Privacy Framework, including the UK and Swiss extensions.
- Data processing: There is a public Data Processing Addendum under Art. 28 GDPR between tawk.to Inc. (Las Vegas) with its UK affiliate tawk.to Ltd. and the customer. It applies by using the service and bases transfers on Standard Contractual Clauses.
- Sub-processors: 15 services, almost all located in the US — including DigitalOcean, Amazon Web Services, Google Cloud, Cloudflare, Twilio, Microsoft Clarity, PostHog and OpenAI for the AI assistant.
What that means legally
Transfers to the US
Since July 2023, the European Commission's adequacy decision on the Data Privacy Framework has applied. Transfers to certified US companies are therefore permitted without additional safeguards — tawk.to also names Standard Contractual Clauses. The Court of Justice of the EU did strike down both predecessors, though: Safe Harbor in 2015 and Privacy Shield in 2020. If you rely on transfers to the US, keep an eye on whether that holds.
Storage in the visitor's browser
tawk.to's privacy policy mentions cookies and web beacons but does not list what the chat widget itself stores on the visitor's device. Under the German TDDDG (§ 25) and the ePrivacy rules behind it, storing information on the device, or accessing it, requires consent unless it is strictly necessary for a service the visitor explicitly requested. Check in your browser (developer tools → storage) what is actually set after your page loads, and decide from there whether the widget belongs behind your consent tool.
AI answers
If you use tawk.to's AI assistant, you should assume chat content goes to OpenAI: the sub-processor list names OpenAI for “AI Assist”, located in the US. It belongs in your privacy policy. Visitors must also be able to tell that they are talking to an AI (Art. 50 AI Act).
Checklist for your website
- Read and file tawk.to's data processing agreement — it applies by use, but you still need to document it.
- State in your privacy policy: provider, purpose, legal basis, transfer to the US under the Data Privacy Framework, retention and, if you use AI, the AI provider.
- Check what the widget stores in the browser and load it only after consent if needed.
- Review the sub-processor list: do services such as analytics tools match what you promise your visitors?
- Set retention periods for chats.
What exactly belongs in the privacy policy is covered in our guide Chatbot on your website: what goes into the privacy policy?.
When an alternative from Germany makes sense
Some site owners cannot or do not want to send chat data to the US — for example because their own customers rule it out contractually. A valid adequacy decision does not help then.
SilentChat runs at Hetzner in Falkenstein, IONOS computes the AI in Germany, and the widget sets no cookies. Once a visitor uses the chat, it stores a random visitor ID in the browser's storage — check this as described above. You can switch on consent before the chat in the dashboard (off by default); if you prefer, the widget contacts our server only after a click. The fact-based comparison with prices and sources is at SilentChat vs. Tawk.to.
Sources
- tawk.to: Privacy Policy (retrieved 5 October 2026)
- tawk.to: Data Processing Addendum (retrieved 5 October 2026)
- tawk.to: Sub-processors (retrieved 5 October 2026)
- tawk.to: GDPR (retrieved 5 October 2026)