
3 Steps To Make Sure Your Chatbot Is GDPR Compliant - Ebbot Blog
3 Steps To Make Sure Your Chatbot Is GDPR Compliant
In what way do chatbots fall under GDPR? What kind of data is protected? And what measures need to be taken to make sure your chatbot is GDPR compliant? Read on to get these questions answered and join us for a deep dive into the exciting world of data privacy.
What is GDPR?
Does May 25th 2018 ring a bell? It should (if you’re interested in data privacy 😎). For this is the birthdate of The General Data Protection Regulation, better known as GDPR. A regulation that came to mark a new age in data protection legislation. And the main purpose was to apply transparency in how and why data is collected, processed, used and stored online.
Simply said – a regulation for protecting privacy online.
The regulation states that all companies or service providers operating in the European Union are obliged to inform their visitors, users or customers about how and when data is collected. They also have to make sure that all users can have their personal information edited, retrieved, forgotten or removed at any time.
Data protected by GDPR
GDPR, compared to the former Data Protection Directive, introduced a new approach to what constitutes personal data. Before GDPR, personal data was basically your name, address and social security number. But as a result of the rise and spread of internet, companies suddenly had to apply the same level of protection for completely new kinds of data.
In short, GDPR protects data such as:
✅ Basic identity information (like name, address, email address, but also user-generated data, such as social media posts and personal images uploaded to websites etc.)
✅ Web data (such as location, IP address, cookie data, and RFID tags)
✅ Health, genetic and biometric data (such as your medical history)
✅ Racial or ethnic data, political opinions, religious beliefs, sexual orientation, and so on..
How does GDPR apply to chatbots?
Since chatbots are all about gathering data, GDPR is highly relevant. Especially for chatbots using Natural Language Processing (NLP) and machine learning. Because if you want to build a chatbot that actually works well – in other words – a chatbot that can understand context and provide meaningful conversations, you have to gather data. This includes data such as name, email address or even social security number if that is relevant.
In other words: Without data – no personalization. Without personalization – no chatbot. 🤷♀️
3 Steps to make sure your chatbot is GDPR compliant
As stated above, there’s no doubt that chatbots are an area of interest when it comes to data privacy. With this in mind, we have put together a checklist of what should be done before launching your chatbot project.
➡️ Step 1: Update your privacy policy
Make sure it’s clear and accessible
Having a clear and accessible Privacy Policy is one of the main requirements of GDPR. In this context, accessible refers both to the privacy policy being easy to find on the website, but also that it should be easy to understand. That is, it should be written in a conversational and natural language without any unnecessary legal jargon.
Be transparent & define your purposes
What comes next is to make sure that your privacy policy provides all information needed. Examples of information that the privacy policy must include are:
- What kind of personal data that is being collected
- How the data is collected
- Why the data is collected
- How the data will be used
- Who has access to the data. Are there any third parties involved in a data exchange?
- How long the data will be stored and what happens after.
- What your legal basis for collecting personal data is
Provide contact information
While making your privacy policy accessible and being transparent about your purposes is important; you should also make sure that your contact information is easily accessible and that it is clear for the user who is the company’s Personal Data Controller and how to get in touch with this person.
➡️ Step 2: Privacy by design
Provide information & get user consent
The easiest way to inform the user of how you manage personal data, or to get user consent, is to include this directly in the chatbot’s design. This can be done either by adding a question about user consent in the conversational flow, or by including a direct link to the privacy policy in the chatbot widget.
Allow users to retrieve their data
As earlier stated, a user must be able to retrieve their data at any time. When it comes to chatbots, this translates to users being able to download a copy of their conversation transcripts or have them deleted. One way to do it is to build a dialogue for this in the conversational flow, e.g ‘what data you are storing’ or ‘can you send me my data’. The response should include a presentation of the data or be sent by email. Another alternative is to add a link with the option (to download or delete the transcripts) in the chatbot’s persistent menu.
Make sure the chatbot is secure
Imagine that you run an e-commerce business. On the website you have implemented a chatbot for customer support purposes. One of the most common support inquiries the chatbot handles is regarding invoices. Invocide data is sensitive information that you shouldn’t distribute if you haven’t been able to verify the customers identification. To be able to provide users with sensitive information you should make sure to integrate a secure authentication method. The most used authentication method in Sweden is ‘BankID’. BankID is an e-ID provided by Swedish banks and can be integrated and used directly in a chatbot’s conversational flow.
➡️ Step 3: Make sure you store the data safely and securely
All data should be stored separated and encrypted, preferably on a cloud service. Using a cloud service makes it possible for your company to store information about user preferences and provide customized solutions, messages and products based on the behavior and preferences of users.
Choosing the right cloud provider can be challenging. There’s a lot of providers to choose from. But if you are a company operating in the EU and therefore have to obey GDPR, there is a benefit of choosing an EU-based cloud provider since these providers by default oblige all rules in GDPR.
One example of an european cloud provider is OVH. OVH has the highest standards of security and is also the largest hosting provider across all of Europe. They specialize in delivering industry-leading performance and cost-effective solutions to better manage, secure, and scale data.
PS. Don’t forget to set up a data retention policy, i.e. a set of guidelines defining how long information must be kept and how to dispose of the information when it’s no longer needed.
Some final words (finally..)
First of all – a big applause for making it through all the way. We are truly impressed! 👏
GDPR is not the ‘sexiest’ subject to say the least, but you can’t ignore the fact that it is as important as it is essential when working with chatbots. Therefore we hope that you, with this article, now feel more confident in how to ensure your chatbot project is GDPR compliant!
More stories

How the EU AI Act will shape the future of service automation
The clock is ticking. The EU AI Act is set to become law, reshaping how artificial intelligence is developed, deployed, and regulated in Europe. For organizations looking to integrate AI solutions, this legislation raises important questions about compliance, accountability, and the choice of AI providers.

Ebbot Achieves ISO 27001 Certification
In 2024, we took on a bold challenge: to earn the internationally recognized ISO 27001 certification. In December, we achieved that goal, marking an important milestone in Ebbot’s commitment to delivering AI-powered service automation with the highest standards of security.

Press release: Gofido first to launch EbbotGPT to customers - Ebbot Blog
Swedish insurance provider Gofido is taking a significant step in its commitment to delivering exceptional customer service by officially launching EbbotGPT. This marks a historic milestone as Gofido becomes the first insurance provider in Sweden to integrate generative AI into its customer support chatbot.

We’re opening our API for EbbotGPT
In celebration of the one-year anniversary of EbbotGPT, we are happy to announce that we are now opening our API for our EU-hosted LLMs, EbbotGPT. This marks a significant milestone in our journey to offer robust AI-driven customer service solutions that are fully compliant with EU data regulations.

From overwhelmed to empowered: GenAI’s role in succeeding with self-service in ITSM
In today’s fast-paced business world, having an efficient internal service management (ITSM) system is more important than ever. But let’s be honest—many ITSM systems are neither user-friendly nor scalable, which ends up making them inefficient. Enter Generative AI (GenAI), a technology that could solve this. But how can we take advantage of this technology in an effective use case without risking security? Let’s break it down.

Ebbot becomes the preferred GenAI partner to renowned chatbot expert Campfire AI
Stockholm, Sweden – July 8, 2024 Campfire AI, a Brussels-based conversational AI consultancy firm, has handpicked Ebbot as its new GenAI partner. From now on, Campfire AI will offer Ebbot’s services to all clients seeking to leverage GenAI in service automation. Ebbot,…

Enento Group chooses Ebbot as strategic AI partner for service automation
Stockholm, Sweden – June 19, 2024 **With a focus on providing a secure GenAI platform for automating service processes at scale, Ebbot has become an attractive partner for enterprises looking to deliver a world class AI service experience. Now signing the Nordic knowledge company [Enento…

Small vs. Large GenAI models – pros & cons
When it comes to generative AI (GenAI) models, size does matter—just maybe not how you'd expect. Both small and large GenAI models have their strengths and weaknesses. Understanding these can help you choose the best model for your needs. Let's break down the pros and cons.🌟 ## The buzz…

Coeo leverages Generative AI to enhance customer experience
coeo Inkassos is rapidly growing and aims to be one of Sweden's largest debt collection agencies in the next five years. Focusing on customer experience as a central strategy, coeo has now set itself apart by becoming the first in the industry to offer 24/7 support with generative AI.

How to make your data sources AI-ready: Step-by-step
Generative AI has revolutionized chatbot training. What once took hours is now completed in minutes. BUT, (there's always a but), the effectiveness of a Generative AI-trained chatbot heavily depends on the quality of its data sources. So, what constitutes a "good" data source for a GenAI chatbot, and what measures can be taken to prepare? Let's find out.

Cross-border service: coeo's live chat breaks down language barriers with a click
The debt collection company coeo Sweden takes its customer service to the next level by introducing an automatic translation feature in its live chat. With the new feature, users can now get real-time support in any language they prefer.

Ebbot Acknowledged by Deloitte as One of the Top 50 Fastest-Growing Technology Companies in Sweden
Stockholm, Sweden, November 2, 2023. Ebbot, providing a conversational AI platform for managing service processes at scale, has been acknowledged by Deloitte as one of the top 50 fastest-growing technology companies in Sweden. ### Background Ebbot,…