{"reference":"DPIA-2025-03","assessment_date":"2025-02-10","version":"1.0","project":{"name":"Customer support chatbot with transcript analysis","owner":"Head of Customer Success","summary":"Deploy an AI assistant on our support page that answers questions by reading recent conversation transcripts. Transcripts are processed by a third-party LLM provider."},"controller":{"name":"Acme Supplies SRL","contact_email":"privacy@acme-supplies.eu","dpo_name":"Marie Laurent","dpo_email":"dpo@acme-supplies.eu"},"processing_description":{"nature":"Automated analysis of support conversation transcripts by a large language model to generate reply suggestions and, after agent approval, send replies.","scope":"Approximately 5,000 conversations per month across 12,000 active customers; no special-category data collected in scope, but transcripts may contain health or financial mentions volunteered by customers.","context":"Customer-initiated support interactions via chat widget on the website and via email-to-ticket. Interactions fall under the customer contract.","purposes":["Faster, more consistent support responses","Reduced agent load on repetitive questions","Improved support quality metrics"],"data_flows":"Chat widget → our ticketing system (EU) → LLM provider API (EU region) → response back to agent → customer. Transcripts retained 24 months."},"high_risk_triggers":["Innovative use of technology (LLM on free-text customer data)","Systematic monitoring of customer interactions","Processing of data that may include volunteered special-category mentions"],"necessity":{"lawful_basis":"Art. 6(1)(b) contract performance for responding to support requests; Art. 6(1)(f) legitimate interests for the quality-improvement aspect, balanced by the data-minimisation measures below.","proportionality":"The chatbot augments human agents rather than replacing them; customers can opt out of AI-assisted replies and speak to a human at any time.","data_minimisation":"Personally identifying information is redacted from transcripts before they leave our infrastructure; only pseudonymised IDs reach the LLM provider.","retention":"24 months rolling window, aligned with the underlying support ticket retention policy."},"consultations":[{"party":"Customer support team","date":"2025-01-22","outcome":"Supportive; concerns raised about over-reliance on suggestions mitigated by mandatory agent approval before send."},{"party":"Sample of 8 customers (in-app survey)","date":"2025-01-29","outcome":"Mixed; 6/8 supportive when told human agents remain involved, 2/8 uncomfortable — visible opt-out added."}],"risks":[{"id":"R-1","description":"Re-identification from pseudonymised transcripts by LLM provider.","likelihood":"low","severity":"medium","impact":"A provider employee could plausibly re-identify a customer from free-text content combined with timestamp patterns, though the contract forbids attempts.","mitigations":["Contractual prohibition on re-identification attempts in the DPA","Provider certified under EU-US DPF + ISO 27001","Quarterly sampling audit of provider logs"],"residual_likelihood":"low","residual_severity":"low"},{"id":"R-2","description":"Incorrect suggestion sent to customer leading to financial or reputational harm.","likelihood":"medium","severity":"medium","impact":"Customer receives an inaccurate answer about fees, returns, or product information; monetary or trust damage.","mitigations":["Mandatory human agent approval before any reply is sent","Agent UI highlights AI-generated text distinctly","Weekly quality review of 50 sampled conversations","Prominent 'That wasn't helpful' button for customers"],"residual_likelihood":"low","residual_severity":"low"},{"id":"R-3","description":"Customer volunteers special-category data (health condition, religion) in a message, and it is processed by the LLM without a valid Art. 9 condition.","likelihood":"medium","severity":"high","impact":"Unlawful processing of Art. 9 data.","mitigations":["PII redaction pass includes special-category keyword detection","Transcripts flagged as potentially containing special-category data are excluded from LLM processing","Agents trained to delete such content before LLM suggestion is generated"],"residual_likelihood":"low","residual_severity":"medium"}],"dpo_opinion":"The DPIA adequately identifies the risks; the residual risk level is acceptable on condition that the PII redaction accuracy is independently measured at 30 and 90 days post-launch with a target of ≥98% recall on the special-category keyword set.","conclusion":{"decision":"proceed_with_conditions","rationale":"Launch is authorised subject to (i) publication of the redaction accuracy report at 30 days, (ii) a customer-facing opt-out in the chat widget from day one, (iii) quarterly review of this DPIA.","review_date":"2025-08-10"},"signoff":{"controller_signatory":"Isabelle Durand","controller_title":"Managing Director","dpo_signatory":"Marie Laurent"}}