browsewith.me
← All articles

Is co-browsing GDPR compliant? A checklist for EU teams

By the BrowseWithMe team · Updated 25 September 2026

Short answer

Co-browsing can be used in a GDPR-compliant way. No tool is compliant on its own. It depends on how you use it and on the provider: where the data is hosted, who owns the provider, what the agent can see, and whether the customer agrees. Use the six checks below.

1. Where is the data hosted?

During a session, the agent sees personal data: names, addresses, account numbers. Ask where the session data is processed and stored. Hosting inside the EU keeps things simpler, because you avoid transfers outside the EU.

2. Who owns the provider?

Location is not the whole story. Providers owned by non-EU companies can be subject to their home country’s laws, even when their servers are in Europe. This is why many EU banks, insurers and public bodies prefer providers that are both EU-hosted and EU-owned.

3. Is there a data processing agreement (DPA)?

Under GDPR, the co-browsing provider processes data for you. You need a written DPA with them. Ask for it before you start.

4. Does the customer agree first?

The customer should start the session and clearly accept anything more, like giving the agent control or sharing their screen. Good tools make this a clear yes-or-no step for the customer.

5. Does the agent see only what they need?

GDPR asks you to use as little personal data as possible. Co-browsing helps here: the agent sees only your website, not the customer’s other tabs, apps or files. Screen sharing shows more, so use it only when needed.

6. Are sessions recorded, and for how long?

Recording is useful for training and disputes, but it is stored personal data. Only turn it on if you need it. Tell customers, and set how long you keep recordings.

How BrowseWithMe fits

This article is general information, not legal advice. Check with your data protection officer for your own case.

EU co-browsing, hosted in Brussels$5 per agent per month.
Start free trial