Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
LivePerson is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. LivePerson supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, LivePerson ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.
LivePerson is a conversational AI and messaging platform that enables websites and mobile apps to offer live chat, asynchronous messaging, chatbots and voice assistants. It combines human agents with AI driven automation to handle customer support, sales and engagement at scale. The service is widely used by enterprises in retail, telecom, finance and travel to deliver real time conversations across web, SMS, WhatsApp, Apple Messages for Business and social channels.
LivePerson is integrated through a small JavaScript snippet (lptag) that loads from lptag.liveperson.net. The tag injects the chat window, sets persistent and session cookies such as LPVID and LPSID, and also uses indexedDB, localStorage and sessionStorage on LivePerson domains to keep state. Chat content, page context, visitor identifiers and behavioural signals are transmitted to LivePerson servers, primarily in the United States, where agents and bots can interact with the visitor in real time.
LivePerson processes visitor identifiers, IP address, user agent, page URL, referrer, time on page and the full content of chat messages. Depending on the use case, visitors may share names, email addresses, phone numbers, order numbers, account information or even special categories of data such as health questions. Because LivePerson links sessions over time through LPVID, it enables long term profiling of returning visitors, which raises GDPR considerations around purpose limitation, transparency and data minimisation.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
In the EU and UK, the LivePerson chat widget sets cookies that are not strictly necessary for a service explicitly requested by the user, including identifiers used for analytics and personalisation. Under ePrivacy rules these cookies require prior, informed and freely given consent before they are set. The processing of chat content itself relies on Art 6(1)(a) GDPR consent for marketing oriented use cases, or on Art 6(1)(b) GDPR for pre contractual and contractual support requests. Sites should not load the LivePerson tag before consent is obtained.
LivePerson is a US company and stores conversation data primarily on infrastructure located in the United States. Transfers from the EU rely on Standard Contractual Clauses and, where applicable, the EU US Data Privacy Framework. Enterprise customers can request EU based hosting and a Data Processing Addendum. Operators must document these transfers in their record of processing activities, perform a Transfer Impact Assessment where required and inform users in the privacy notice.
To deploy LivePerson in line with GDPR and ePrivacy, load the lptag script only after explicit consent, document LivePerson in your cookie banner and privacy policy, configure data retention to the shortest period needed and mask sensitive fields in chat. Train agents on data minimisation, restrict access by role, sign a DPA with LivePerson, monitor sub processors and ensure visitors can easily exercise their rights of access, rectification, erasure and objection.
Websites using LivePerson must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is recommended when LivePerson is deployed at scale, integrated with CRM systems, or used for automated decision making through conversational AI. Key risks include large scale processing of chat transcripts that may contain sensitive personal data, profiling of visitors via LPVID, transfers to the United States, and potential use of AI bots that classify or score conversations. Mitigations include data minimisation in chat forms, masking of sensitive fields, short retention periods, robust access controls for agents and clear information to data subjects.
Sample consent text
We use LivePerson to provide live chat and conversational support on this website. LivePerson sets cookies (LPVID, LPSID, HumanClickID) and stores data in your browser to identify your session, maintain conversation continuity and analyse interactions. Some data is transferred to LivePerson servers in the United States under appropriate safeguards. By accepting, you consent to the use of LivePerson cookies and the processing of your chat messages.
Third-party domains contacted
lptag.liveperson.netliveperson.netva.liveperson.netlpsnmedia.netCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| LPVID | analytics | 1 year | LivePerson visitor ID, cross session tracking |
| LPSID | technical | session | LivePerson session ID, chat continuity |
| HumanClickID | marketing | 90 days | Tracks chat invitation interactions |
LivePerson uses cookies for user preferences — inform visitors with a consent banner.
LivePerson sets LPVID (a persistent visitor identifier valid roughly one year), LPSID (a session cookie that maintains chat continuity for about 30 minutes) and HumanClickID (used to track chat invitation interactions). It also writes localStorage and indexedDB entries on the liveperson domain to hold chat state and queue information.
Consent is required for the non essential cookies (LPVID, HumanClickID) and for any behavioural tracking or proactive chat invitations. Reactive chat triggered by an explicit user click can arguably rely on legitimate interest, but most regulators expect prior consent for the full lptag.js script, so CMP gating is the safer default.
The recommended legal basis is consent under Article 6(1)(a) for chat content, cookies and analytics. Reactive, user initiated chat may rely on legitimate interest under Article 6(1)(f) provided strong safeguards exist (clear notice, easy opt out, minimal data, no profiling). Sensitive data shared in chat may require Article 9 conditions.
LivePerson Inc. is certified under the EU US Data Privacy Framework, which provides a valid transfer mechanism for chat transcripts, cookie data and operator interactions sent to its US infrastructure. For flows not covered by the DPF the company offers Standard Contractual Clauses as a fallback, supported by a transfer impact assessment.
A DPIA is recommended when chat is deployed at scale, when sensitive categories of data (health, financial, legal) are likely to be exchanged, or when conversational AI performs profiling. Document the processing purposes, data flows, retention, transfers and risks, and define mitigations such as masking, retention limits and operator training.
Configure the CMP to block lptag.js before consent, sign the DPA with LivePerson, set retention rules for chat transcripts and recordings, restrict access on the operator console, train agents on personal data handling and document the processing in the record of activities. Use the supplied sample consent text in the cookie banner.
EU based or self hostable options include Crisp Chat (EU hosted), Intercom (with EU data residency), Zendesk Chat (with EU pod), Tidio (EU plan) and self hosted open source solutions. Each option still requires consent and a DPA, but reduces or removes the cross border transfer footprint compared with the default US hosted LivePerson configuration.
List LPVID, LPSID and HumanClickID with their purpose and retention, clarify that chat transcripts are processed by LivePerson Inc. in the United States, mention the legal basis (consent) and the DPF certification, link to the LivePerson privacy notice, and explain how users can withdraw consent and request access, deletion or portability of their chat data.