English
consentglass · GDPR scanner for websites

HomeGuides › Service

Embedding Tawk.to in a GDPR-compliant way

Tawk.to (tawk.to, tawk.to inc., USA) is one of the most widely used free live chats. The widget loads scripts from *.tawk.to on page load, sets cookies and transmits the IP address to US servers.

Tawk.to is popular because it is permanently free — the service is financed through paid add-ons and optionally removable branding. For the GDPR the constellation is unfavourable: the provider is based in the USA, the widget loads on page load, sets several cookies and transmits visitor data (IP, pages visited, time spent) to US servers. This advance processing takes place before the visitor even clicks the chat.

Two levels are affected legally: Section 25(1) TDDDG for the access to the device (cookies, scripts) and Article 44 et seq. GDPR for the transfer to the USA. The transfer may be covered by the EU-US Data Privacy Framework if tawk.to is certified — but that does not change the fact that the device access requires consent before use.

The simplest approach is to load the widget only on click: the page shows a custom button; the Tawk.to embed script is only inserted on the click. Anyone who wants to keep the chat but display it globally has to include it in the consent tool and may only initialise it after consent. For many small websites, the most data-frugal solution is anyway to offer a simple contact form instead of a live chat.

Is this a risk?

Tawk.to loads several scripts and resources on page load, sets cookies (among other things to recognise visitors) and transmits data to servers in the USA. Without consent, the standard integration violates Section 25(1) TDDDG; on top of that comes the third-country transfer, which needs its own basis.

What you can do

Häufige Fragen

Is the free version of Tawk.to GDPR-compliant?
The cost question is independent of data protection. The integration is decisive: if the widget loads globally on page load, it needs consent. If it only loads after a click, the use can be based on Section 25(2) TDDDG.
Which cookies does Tawk.to set?
Typically several cookies for visitor recognition and session management (e.g. TawkConnectionTime, ss, __tawkuuid). The exact list should be checked in the network tab and documented in the cookie statement.
Is data transferred to the USA?
Yes. tawk.to inc. is based in the USA and operates servers there. The transfer needs a basis (usually the EU-US Data Privacy Framework) and must be stated in the privacy policy.
Is there a more data-frugal alternative?
A provider with EU hosting (e.g. Crisp with an EU region) reduces the third-country question. Only a server-side rendered contact form works entirely without device access.

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.