On October 2, 2025, the Dutch Data Protection Authority (AP) and the Authority for Consumers and Markets (ACM) issued a public call: "Keep people accessible." They made this appeal to companies, developers, and lawmakers to take action regarding the use of chatbots and to promote continuing human contact alongside chatbot technology. But why did they feel the need to do this, and what can organizations themselves do?

Risks of Using Chatbots

More and more organizations are choosing to support (or even replace) their frontline customer service functions with chatbots. This offers organizations many benefits, such as reduced costs and improved accessibility. Customers also see advantages, as they get responses more quickly and outside of office hours.

The downside is that chatbots often cannot handle more complex issues, and customers can become stuck in conversations with a chatbot without ever being able to speak to a human.

In addition, the use of chatbots brings privacy risks because they often process personal data to assist customers. People tend to share more personal information when a chatbot asks several questions, including sensitive and special categories of personal information. The AP specifically warns that chatbots often cannot answer complex questions, leaving customers stalled in conversations without the option to speak to a staff member.

Chatbots use data for training purposes, and this can include the data of people who use the chatbot. It is important for organizations to identify this so that requests for data deletion or access by customers can be adequately processed.

Another major risk is that organizations often do not clearly indicate when a chatbot is being used. In the past, this was less of an issue, as chatbots were easily recognizable by their way of responding. However, with the rise of advanced generative AI systems, it is becoming increasingly difficult for people to spot the difference. The chatbot adapts its language to the organization and the customers, may be programmed to wait before responding, or can even make jokes.

Sometimes a full conversation must be completed before an option is presented to speak to a staff member, or a customer may be given a phone number where they encounter yet another chatbot. Chatbots also often provide incorrect or incomplete answers, sometimes misleading customers.

These risks especially disadvantage people in already vulnerable positions. This is because they may be less skilled with computers and won’t immediately recognize a chatbot, may have less language proficiency which means the chatbot doesn't understand the question, and some chatbots are harder to use with just a keyboard.

What Can Organizations Do?

The risks associated with deploying chatbots can be managed. Organizations would be wise to begin preparing for (future) obligations regarding AI and data, such as the EU AI Act, Digital Fairness Act, and existing requirements under the Digital Services Act and the General Data Protection Regulation (GDPR). The actions an organization should take at a minimum regarding chatbots include:

  • Ensure that the chatbot always provides accurate and complete information. Incorrect or incomplete information can damage trust in your organization or its services.

  • Clearly indicate to customers when they are communicating with a chatbot, and tailor such notifications to your target audience. For example, adults will have different needs than minors. This can be done using pop-up messages or by sharing the privacy and/or AI statement, and making sure the language is clear for the target group.

  • Make sure human contact is always possible and that it is easy to find.

  • Implement robust AI policies and employ well-trained AI and privacy professionals in your organization.

  • When assessing the AI system, ensure that multiple disciplines (e.g., data engineers/scientists, IT, security, privacy, etc.) collaborate to properly understand its operation and associated risks.

Ellen de Kok Senior Legal Manager

Does your organization use a chatbot and want to ensure compliance with relevant obligations?

Feel free to contact us. Our privacy and AI consultants are happy to help assess, improve, and document your compliance with chatbot and other AI system regulations.

Our services orContact