Is Intercom GDPR Compliant?
Verdict: Yes — strong GDPR programme with EU hosting available
Intercom is GDPR compliant with a comprehensive Data Processing Agreement, EU data hosting options, and strong privacy controls. As a customer data platform that handles personal data at scale, Intercom has invested significantly in compliance infrastructure.
Key Compliance Features
Data Processing Agreement: Available for all paid Intercom plans. Automatically incorporated into Intercom's terms for commercial customers.
EU Data Hosting: Available — Intercom operates in EU data centres (Dublin). Select EU hosting when setting up your workspace.
Fin AI Agent: Intercom's AI customer service agent processes conversation data within Intercom's existing infrastructure under the DPA. Fin does not train on your customer data without consent.
Data Deletion: Intercom provides tools for deleting individual user records — essential for handling GDPR erasure requests from customers.
The High-Risk Nature of Customer Support Data
Customer support platforms process some of the most sensitive personal data in your organisation:
- Customer names, email addresses, and contact details
- Purchase history and account information
- Complaints and disputes
- Potentially health, financial, or legal information shared in support conversations
This makes getting the GDPR configuration right in Intercom particularly important.
Key Configuration Steps
1. EU data hosting: Confirm your Intercom workspace is in the EU region. Contact support if you're unsure — migrating regions requires a support ticket.
2. Data retention: Configure Intercom's data retention settings to delete conversation data after your specified retention period. The default retention is indefinite — change this.
3. Cookie consent: Intercom's messenger uses cookies. Ensure your cookie consent banner blocks the Intercom messenger until consent is given.
4. Custom bot disclosures: Under GDPR and the EU AI Act, customers must know they are talking to an AI. Ensure Fin AI agent identifies itself clearly.
5. Sensitive data handling: If customers share sensitive personal data (health, financial) in support chats, ensure your agents are trained not to store this information unnecessarily.
The EU AI Act and Customer Support AI
From August 2026, AI systems that interact with customers must disclose they are AI — this is Article 50 of the EU AI Act. Intercom's Fin AI agent must clearly identify itself as an AI at the start of every conversation. Intercom has confirmed compliance with this requirement.
[Browse GDPR-compliant customer support tools on stckfndr →](/?category=productivity&compliance=gdpr)