Skip to main content
Back to blog

GDPR and Progressive Profiling: Is a Conversational Agent More Compliant Than a Form?

Published on September 2, 2026

Key takeaways

  • The core architecture shift: the B2B conversational agent moves part of the qualification process away from silent observation and toward information explicitly provided in the exchange, commonly referred to in marketing as "zero-party data." Done well, this can improve transparency and minimization, provided the agent's design and data policy meet GDPR requirements.

  • The compliance risk it does not remove: conversational profiling does not eliminate inference. What changes structurally is that inferences are grounded in information the person explicitly provided, rather than behavior observed without their knowledge.

  • The compliance condition: progressive conversational profiling can be more sound legally, provided it follows precise rules: clear information about the AI's nature, an explicit purpose at each stage of collection, a controlled retention policy, and respect for the limits placed on any automated decision with significant effects on the person.

The structural tension in classic marketing profiling

Prospect qualification online has historically relied on gathering as much preliminary information as possible. This approach, deeply embedded in commercial practice, can enter into tension with data protection requirements. Understanding why this classic model is under strain requires examining its legal and technical foundations.

The GDPR defines profiling in Article 4(4) as any form of automated processing of personal data used to evaluate certain personal aspects of a natural person[1]. In a B2B context, this translates into analyzing browsing behavior, measuring time spent on a specific page, or tracking whitepaper download history to infer a level of purchase intent.

This mechanism relies almost exclusively on silent tracking, a practice strictly governed by Article 5(3) of the ePrivacy Directive. This text requires prior consent for any operation that stores or accesses information on a user's terminal equipment, subject to two exemptions (transmission of a communication, or a service strictly necessary and explicitly requested by the user)[2]. The market long assumed this rule was limited to third-party cookies. That narrow reading had already been rejected by the Article 29 Working Party's 2014 opinion on fingerprinting, and was explicitly confirmed by the EDPB's Guidelines 2/2023 (version 2.0, finalized October 2024)[3]: the rule applies in a technology-neutral way, covering local storage, session storage, and invisible tracking pixels.

The attachment of tracking pixels to this consent regime became very concrete very recently, in email marketing, another common B2B qualification tool: France's data protection authority, the CNIL, published a dedicated recommendation on tracking pixels in emails (Deliberation No. 2026-042, adopted March 12, 2026 and published April 14, 2026), non-binding by nature but clarifying the prior-consent requirement already set out in Article 5(3) of the ePrivacy Directive for any pixel that identifies the recipient when a message is opened. It provides limited room for interpretation for certain uses tied to delivery security and to a strictly bounded measurement of deliverability for a message explicitly requested by the recipient. For addresses already collected before publication, it sets, in principle, a three-month deadline to inform recipients and let them opt out, extendable in case of documented objective difficulty. Italy's data protection authority (the Garante) published comparable guidelines on April 17, 2026, a sign of a European-wide movement rather than a French peculiarity[18][19].

To sustain lead-qualification volumes despite these constraints, many publishers have deployed opaque consent-collection interfaces. These practices led to the rise of "dark patterns," or deceptive interfaces. In its Guidelines 3/2022 on social media platform interfaces, the EDPB details these manipulative techniques, notably information overload and the deliberate concealment of refusal options within "privacy mazes"[5]. The purpose of these interfaces is to bias the visitor's choice toward a superficial agreement. Legally, consent extracted through a cognitive bias can invalidate the lawfulness of the processing.

Alongside behavioral tracking, the market has also relied heavily on exhaustive sign-up forms. The underlying logic is to demand as many fields as possible (job title, company size, direct phone number) at the very first point of contact. This practice can contravene the data minimization principle set out in Article 5(1)(c) of the GDPR, which requires data to be adequate, relevant, and limited to what is necessary for the purposes pursued, whenever the information requested exceeds what those purposes actually justify[1][4]. Preemptive collection of information, gathered on the off-chance the prospect later becomes relevant, weakens the company's entire compliance posture.

This framework applies regardless of the commercial context. The specific regime for B2B electronic prospecting, based on an opt-out right rather than prior consent (Article L34-5 of the French Postal and Electronic Communications Code)[6], does not exempt anything from the profiling and minimization obligations detailed here: it only sets the legal basis for sending the message, not for processing the data collected upstream.

A rigorous look at the market's stopgap solutions

Faced with tightening regulation and a rise in sanctions, digital players have looked for workarounds. These stopgap solutions try to treat the symptom, namely falling conversion rates, without addressing the root cause: opacity in processing. It is worth assessing these methods honestly against the applicable texts.

The most visible response was the widespread rollout of consent management platforms (CMPs). These banners are theoretically designed to guarantee a free and informed choice. Operational reality shows, however, that the conditionality of consent is rarely respected. The EDPB's Guidelines 05/2020 state that consent must be specific to each purpose, with a distinct opt-in per use[7]. The Court of Justice of the European Union (CJEU), in its Planet49 ruling (C-673/17), held that a pre-ticked box does not constitute a clear affirmative act under Article 5(3) of the ePrivacy Directive[8]. Furthermore, many banners long required more clicks to refuse than to accept: the CNIL sanctioned this practice with fines of €150 million for Google and €60 million for Facebook in late December 2021[9]. This design asymmetry is a factor that supervisory authorities regularly rely on to invalidate the free nature of consent, without this being an automatic rule.

Another common strategy is to drastically shorten visible forms to maximize immediate conversion, then use background data-enrichment services. When a visitor submits a simple email address, third-party databases are automatically queried to infer their job title, industry, and professional history. This approach creates a particularly opaque collection pipeline. It raises an issue under Article 14 of the GDPR, which requires the controller to inform the data subject when data was not collected directly from them, generally within one month[1]. Moreover, justifying this silent enrichment on the basis of legitimate interest has become riskier since the CJEU's ruling in Case C-252/21 (Meta), which restricted the use of that legal basis for aggregating behavioral data across services[10], a reasoning transposable by analogy to unexpected B2B enrichment, though the Court has not ruled on that exact scenario. Enrichment thus turns an active qualification act into profiling the person never consented to.

Finally, preference centers and static interactive questionnaires have emerged as more respectful alternatives. They aim to collect "zero-party data," meaning data the customer proactively and deliberately shares to improve their experience[11]. The voluntary nature of this approach improves transparency of collection and the control the person exercises over the information they provide, but this data remains personal data subject to the same purpose and minimization requirements as any other GDPR data. These solutions also suffer from clear structural rigidity. Visitors must navigate complex menus or answer fixed decision trees. The cognitive effort required stays high, limiting adoption and reducing overall qualification effectiveness.

Stopgap solution

Compliance risk (GDPR / ePrivacy)

UX impact

Key legal reference

Asymmetric cookie banners

High (defective free and informed consent)

Strong friction, navigation interruption

EDPB Guidelines 05/2020, Planet49 ruling (C-673/17), CNIL sanctions SAN-2021-023/024

Short forms with third-party enrichment

High (opaque source, missing information)

Low (reduced friction at input)

Article 14 GDPR, Meta ruling (C-252/21)

Static preference centers

Low (voluntary declarative data)

Heavy cognitive load, rigid flow

Article 5(1)(c) GDPR (minimization)

Three collection architectures, one shared analytical grid

Beyond the contrast between forms and conversation, three architectures coexist in the B2B market: explicitly requested data (form), observed or inferred data (behavioral tracking), and data requested progressively in context (conversation). Comparing them on the same dimensions moves past a binary opposition and pinpoints exactly where each architecture is structurally more or less exposed.

Dimension

Structured form

Behavioral tracking

Progressive conversation

Transparency of collection

High: visible field, stated purpose at the point of input

Low: collection is typically silent

High if the agent explains why it asks each question, low otherwise

Minimization of questions asked

Variable: depends on form design, often over-collected as a precaution

Not applicable: no question is asked, everything is observed

Good by construction if the agent only asks what moves the exchange forward

Minimization of data received

Good: the field constrains the form and content of the answer

Variable: depends on which collection points are active

A weakness specific to this model: natural language has no formal constraint

Typical legal basis

Depends on the purpose of each field: consent, legitimate interest, or pre-contractual necessity

Consent (Art. 5(3) ePrivacy) for the tracking act itself, subject to a narrowly defined exemption

Depends on the purpose of each piece of data requested: consent, legitimate interest, or pre-contractual necessity

User control

High: they choose what they type into each field

Low: they generally do not see what is being observed

High: they choose what they say, at their own pace

Data accuracy

Good if the field is well designed

Variable: directly observed data can be reliable, inferred data remains probabilistic

Good, subject to an inaccurate or incomplete statement

Retention period

Generally fixed, tied to the sales cycle

Often long in the absence of automatic purging

Entirely dependent on the transcript retention policy

Inference and automated decisions

Possible if answers feed a score or a decision, governed by Article 22 under the same conditions as the other architectures

High: behavioral inference is the very purpose of this model

Possible if the agent cross-references answers to qualify or disqualify, governed by Article 22 under the same conditions as the other architectures

This dimension-by-dimension reading shows that conversation does not win on every front: it shifts the compliance risk rather than removing it, from silent collection toward declarative overflow and inference. The next section details the concrete conditions for that shift to stay favorable.

Progressive conversational profiling as a structural response

The rise and maturation of generative AI make it possible to fully rethink the mechanics of B2B qualification. Progressive conversational profiling shifts the axis from opaque behavioral inference toward explicit, contextual declaration. This interface shift profoundly changes the legal nature of the data being processed.

In a conversational model, the user expresses their need directly, in natural language. Instead of inferring that a visitor is interested in wealth management because they viewed three specific articles in under ten minutes, the agent simply asks the question and adapts its response accordingly. The source data becomes purely declarative, which does not remove inference altogether: the agent can then derive a profile from it (purchase intent, urgency level, conversion probability), much like a classic scoring system would. The structural difference lies elsewhere: these inferences are grounded in information the person explicitly provided, rather than behavior observed without their knowledge. This approach respects the spirit of the GDPR by strengthening the person's control over the information they choose to disclose, not by eliminating profiling itself.

European legislation governs this new form of interaction. Article 50 of the EU AI Act, applicable from August 2, 2026, imposes transparency obligations on AI systems intended to interact with natural persons[12]. Unless this nature is already obvious to a reasonably informed person, the user must be informed that they are communicating with an algorithmic system, not a human operator. Honest collection starts with this clear disclosure about the nature of the counterpart.

Conversational profiling also makes it possible to request each piece of information exactly when it becomes necessary to the exchange, rather than forcing broad, abstract acceptance of a privacy policy before any value has been delivered. Consent is only one of several legal bases under the GDPR: this architecture mainly facilitates a clear statement of purpose at every step, a condition common to several legal bases, not just consent.

Well designed, this model also facilitates better-managed data minimization: the agent only asks for what moves the exchange forward, rather than collecting as a precaution. This property, however, depends on the configuration chosen and the retention policy applied to transcripts. It is not an automatic guarantee simply from using a conversational interface. Common good practice for conversational agents emphasizes purging data at the end of the session for simple requests, and limiting retention to the strict purpose of the processing for more complex support requests[13].

This architecture nonetheless has a rarely discussed downside: it minimizes the questions asked better than it minimizes the information actually disclosed. A form constrains the answer to a predictable field; a natural-language conversation has no such limit. A prospect might spontaneously explain why they are looking for a solution, for instance by mentioning a colleague's prolonged absence, an internal reorganization, or a dispute with a supplier, none of which was asked for or necessary for commercial qualification. A well-designed agent must therefore be able to discard that declarative overflow from the final profile, or risk collecting, by the back door, more data than a structured form would ever have captured.

The implementation of technology solutions such as Gamaro illustrates this architecture. By replacing the classic filter-tree search with a B2B conversational agent that refines its understanding turn by turn, profiling becomes grounded in the company's own proprietary data rather than in silent third-party collection. The visitor is no longer a passive target, but an active participant in their own qualification.

Strict limits on automated decisions and retention

While collecting information through conversation improves the collection phase, the subsequent use of this profile requires particular legal care. When a conversational agent evaluates a prospect on the fly and decides, entirely on its own, to deny access to a service, block account creation, or apply unfavorable pricing, a regulatory red line may be crossed.

Article 22 of the GDPR gives every person the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them, or similarly significantly affects them, subject to the exceptions in paragraph 2 (necessity for a contract, legal authorization, or explicit consent)[1]. In the SCHUFA ruling (C-634/21), the CJEU held that an automatically generated probability score can constitute a decision under this article where a third party relies on that score in a determinative way to make its final decision[14].

A commercial disqualification is not automatically "significant" within the meaning of Article 22: this must be assessed case by case. If it is, and none of the paragraph 2 exceptions apply, the fully automated decision is simply prohibited. If an exception applies, Article 22(3) then imposes minimum safeguards: the right to obtain human intervention, to express one's point of view, and to contest the decision. In both cases, involving a human before the decision becomes final is what, in practice, keeps the decision outside the strict scope of Article 22, or satisfies its safeguards. This intervention must, however, be real and meaningful: a purely formal human rubber-stamp of the algorithmic recommendation is not enough, as the Article 29 Working Party makes clear in its guidelines on automated individual decision-making, endorsed by the EDPB[20]. If the agent additionally qualifies as a high-risk system under the AI Act, Article 14 of that regulation imposes an additional human-oversight requirement, one specific to high-risk systems, not a general rule for every conversational agent[15].

Finally, the legal soundness of a conversational agent depends on how conversation transcripts are handled. Many organizations want to retain conversation history to retrain or fine-tune their language models. The EDPB's Opinion 28/2024 makes clear that AI models trained or fed with personal data are not presumed anonymous by default and must be assessed case by case, with the risks of memorization and regurgitation of user data well documented[16].

The process of anonymizing conversation histories must be rigorously documented and tested before any analytical reuse. The EDPB's Guidelines 02/2026, adopted July 7, 2026 and still under public consultation as of this article's writing (September 2026), propose a combined three-criteria evaluation grid to qualify data as anonymous: the impossibility of isolating an individual (no record isolation), the impossibility of linking datasets together (no linkage), and the impossibility of inferring new sensitive information (no inference)[17]. Simply replacing the prospect's name with asterisks in a conversation log does not, in any case, amount to genuine anonymization.

The shift from behavior-driven profiling toward transparent conversational qualification is not just an ergonomic evolution for B2B platforms. It is a shift in collection architecture: the inferred profile is grounded in declared source data rather than in behavior observed without the person's knowledge, and compliance becomes a property of design rather than a layer bolted on afterward. The applicable rules, however, do not change: this architectural shift does not remove any of the obligations covered here, nor the human oversight they impose where relevant.

Sources

  1. GDPR (Regulation (EU) 2016/679), consolidated text, Articles 4(4), 5(1)(c), 14 and 22: EUR-Lex

  2. Directive 2002/58/EC (ePrivacy), consolidated text, Article 5(3): EUR-Lex

  3. EDPB, Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive, version 2.0 (October 2024): official PDF

  4. CNIL, "Minimising collected data": cnil.fr

  5. EDPB, Guidelines 3/2022 on dark patterns in social media platform interfaces: official PDF

  6. Article L34-5 of the French Postal and Electronic Communications Code (B2B prospecting): Légifrance

  7. EDPB, Guidelines 05/2020 on consent under the GDPR: edpb.europa.eu

  8. CJEU, Planet49 ruling, C-673/17 (October 1, 2019): official press release

  9. CNIL, sanctions against Google (€150M) and Facebook (€60M), December 2021: cnil.fr

  10. CJEU, Meta Platforms and Others ruling, C-252/21 (July 4, 2023): official press release

  11. Zero-party data and the GDPR: overview

  12. AI Act (Regulation (EU) 2024/1689), Article 50, transparency obligations: artificialintelligenceact.eu

  13. "Chatbots and GDPR: compliance obligations" (French): donneespersonnelles.fr

  14. CJEU, SCHUFA Holding ruling, C-634/21 (December 7, 2023): InfoCuria

  15. AI Act, Article 14 (human oversight, high-risk systems): overview, French

  16. EDPB, Opinion 28/2024 on AI and personal data: official PDF

  17. EDPB, Guidelines 02/2026 on anonymisation, version 1.0 (July 7, 2026, under public consultation): official PDF

  18. CNIL, Recommendation on tracking pixels in emails (Deliberation No. 2026-042, March 12/April 14, 2026): cnil.fr

  19. Garante per la protezione dei dati personali (Italy), guidelines on tracking pixels (April 17, 2026): garanteprivacy.it

  20. Article 29 Working Party, Guidelines on Automated individual decision-making and Profiling (WP251rev.01, adopted October 3, 2017, revised February 6, 2018, endorsed by the EDPB): ec.europa.eu

Cet article est aussi disponible en français