The short version
- Get the privacy contract right. California requires specific written terms before you hand customer data to a vendor, and most other state privacy laws require something similar.
- Healthcare support needs a BAA first. Vendors often offer one only on certain plans, which makes it a pricing question.
- Announce call recording on every call. Federal law needs one party's consent; California needs everyone's.
- Chat widgets are a lawsuit target in California. Disclose the vendor and get consent before the widget captures what visitors type.
- Say when a bot is a bot. California, Maine and Utah already have disclosure rules, and Colorado's take effect in 2027.
- There is no federal click-to-cancel rule. Read the auto-renewal terms of your own help desk contract yourself.
What must the contract with a help desk vendor say?
There is no single federal privacy law for customer support data. California sets the pattern. Under the California Consumer Privacy Act, section 1798.100(d), a business that discloses personal information to a service provider must have an agreement that limits use to specified purposes, requires the provider to give the same level of protection, lets the business check on and stop unauthorized use, and requires the provider to say if it can no longer comply.
The vendor only counts as a service provider, the law's term for a company that handles data on your behalf, if the contract also bars it from selling or sharing the information, from using it outside your business relationship, and from combining it with data from other sources. That is the definition in section 1798.140(ag). If a help desk vendor uses ticket content for its own purposes beyond those limits, such as unrestricted AI model training, handing it the data may count as a sale or sharing. This is why our reviews record what each vendor says about training AI on customer data.
California is not alone. MultiState's tracker counts twenty states with comprehensive privacy laws as of 2026, or nineteen if you leave out Florida's narrower law. Indiana, Kentucky and Rhode Island took effect on January 1, 2026. Most of these laws require a vendor contract along the same lines. In practice, this contract is the vendor's data processing agreement, usually shortened to DPA, and it should mention the CCPA by name.
When do you need a HIPAA business associate agreement?
Patients write health details into tickets and chats whether you ask them to or not. Under 45 CFR 164.502(e), a healthcare provider, plan or clearinghouse may let a vendor receive or store protected health information only after getting assurances in a written contract, called a business associate agreement or BAA. 45 CFR 164.504(e) sets out what it must contain: permitted uses, safeguards, reporting of unauthorized uses, the same restrictions on subcontractors, and return or destruction of the data when the contract ends.
Sign the BAA before go-live, not after the first patient email. Help desk vendors often sign one only on higher plans, so check the plan before you compare prices. Each review on this site lists whether a BAA is documented.
Do you have to announce call recording?
Federal wiretap law, 18 U.S.C. 2511(2)(d), allows recording when one party to the call consents. Some states require everyone's consent. California Penal Code section 632 penalizes recording a confidential communication without the consent of all parties. A support line takes calls from every state, so the safe default for a help desk with a phone channel is a recording announcement at the start of every call.
Can a chat widget get you sued?
In California, yes. Penal Code section 631, part of the California Invasion of Privacy Act, penalizes anyone who reads a communication in transit without the consent of all parties, and anyone who helps them. Plaintiffs argue that a third-party chat or session-replay vendor eavesdrops on the visitor's conversation with your website, and that you helped.
The litigation is ongoing as of September 2026. In Thomas v. Papa John's, the Ninth Circuit held that a party to a conversation cannot be liable for eavesdropping on its own conversation, according to Crowell & Moring's summary. That helps website operators, but claims that the operator aided the vendor, and claims against vendors themselves, continue in district courts. A reform bill, SB 690, reached the Governor on September 4, 2026, and is not yet law. Nixon Peabody's analysis confirms it would not touch the section 631 theories aimed at chat widgets in any case.
The practical steps are the same whichever way the cases go: name the chat vendor in your privacy notice, get consent before the widget captures what a visitor types, and use a contract that bars the vendor from using chat content for its own purposes.
Do AI features in a help desk need a disclosure?
If the help desk's AI agent talks to customers, several state laws apply. California's bot disclosure law makes it unlawful to use a bot to mislead a person about its artificial identity in order to drive a sale; a clear disclosure avoids liability. Maine prohibits using an AI chatbot in commerce in a way that may lead a reasonable consumer to believe they are dealing with a human, unless the consumer is clearly told otherwise. Utah requires disclosure when a person clearly asks, and gives a safe harbor to AI that discloses itself at the outset and throughout.
Colorado replaced its 2024 AI Act with a narrower law, SB 26-189, effective January 1, 2027, and passed a separate chatbot disclosure law with the same effective date. We could not verify whether that law exempts plain customer-service bots. Several other states passed chatbot laws in 2026, mostly aimed at companion apps, according to Orrick's survey. The simplest policy is a notice in the first message that the customer is talking to an AI.
The Federal Trade Commission has said there is no AI exemption from the ban on deceptive practices. For a buyer, that cuts two ways: treat a vendor's "resolves most of your tickets" claim with care, and do not overstate what your own bot can do. Our guide to what an AI help desk is explains the features involved.
Is there a click-to-cancel rule for auto-renewing seats?
Not at the federal level. A court vacated the FTC's amended Negative Option Rule in July 2025, days before it was due to apply. In March 2026 the FTC asked for public comment to restart the process, and we found no proposed or final rule as of September 2026. Gibson Dunn notes that the FTC still enforces existing law against hard-to-cancel subscriptions, and state auto-renewal laws apply.
This matters twice. Your help desk subscription probably renews automatically, so read the notice period and the rules on reducing seats before you sign. And if your support team handles cancellations for your own customers, the flow you build in the help desk has to satisfy the same laws.
What about card numbers in tickets?
PCI DSS is an industry standard enforced through your card-processing contract, not a statute. The PCI Security Standards Council says the standard prohibits sending unprotected card numbers through end-user messaging, and that email, chat and SMS all count. Customers paste card numbers into tickets anyway, which can pull the help desk into the scope of your PCI assessment. Automatic card-number redaction is the feature that addresses this.
What rules apply to SMS support?
Text messages are calls under the Telephone Consumer Protection Act. Under 47 CFR 64.1200, informational support texts need the customer's prior express consent, and marketing texts sent with an autodialer need it in writing. Since April 11, 2025, a customer may revoke consent by any reasonable method, including replying "stop", and you must honor that within ten business days. A broader rule that would apply one opt-out to all future messages from the same sender has been delayed to January 31, 2027. The FCC has also confirmed that AI-generated voices count as artificial voices, so outbound calls that use one need prior consent.
What to check in a help desk before you buy
- The data processing agreement. It should contain the CCPA service-provider terms and be signed before you import real tickets, including during a trial.
- What the vendor does with your data. Look for a written statement on whether customer content trains AI models, and a list of sub-processors, the other companies the vendor passes data to.
- A BAA, and the plan it comes with. If any protected health information could reach a ticket, confirm the plan and get the signature first.
- Hosting region. If you serve European customers, see our list of help desks with EU data hosting.
- Retention and deletion. Check that you can set how long tickets are kept and delete one person's tickets, attachments and recordings on request.
- Redaction. Automatic card-number redaction, and a way for agents to redact other sensitive text by hand.
- Call recording controls. An announcement at the start of each call, and a way to pause recording.
- SMS opt-out handling. Keyword opt-outs and a suppression list, if you plan to text customers.
- An AI notice you can keep switched on from the first message, if the AI agent talks to customers.
- Renewal and exit terms. The notice period, the rules on reducing seats, and the export format. Our migration checklist covers the export side, and SLA basics covers response-time targets.
Frequently asked questions
Does the CCPA apply to data in a help desk?
Yes, if your business is covered by the CCPA. Ticket history, chat transcripts and call recordings are personal information, and the law requires a written contract that limits what the help desk vendor may do with them. Around twenty states had comparable laws on the books as of 2026.
Do I need a BAA for my help desk?
You need one if you are a HIPAA covered entity or business associate and protected health information could reach the help desk, which it usually can, because patients write it into tickets. The agreement must be in place before the vendor receives the data. Many vendors offer it only on certain plans.
Is it legal to record support calls in the United States?
Federal law allows recording with one party's consent, but California and some other states require the consent of everyone on the call. Because a support line receives calls from every state, the safe approach is to announce recording at the start of every call.
Does a customer service chatbot have to say it is a bot?
In some states, yes. California, Maine and Utah have disclosure rules in force as of September 2026, and Colorado's take effect on January 1, 2027. A clear notice in the first message satisfies all of them and is what regulators expect.
Keep reading
- Help desk vs shared inboxguide
- What is an AI help desk?guide
- Per-seat vs per-resolution pricingguide
- Do you need the AI add-on?guide
- Best help desk softwarebest list
- Help desk true-cost calculator
This page was researched and drafted with AI assistance from the sources listed on it. We have not run hands-on tests of these products. Method: How we review