About this story: This is a fictional composite based on common chatbot deployments. It is not a named client case.
A weekend launch
An Irish online retailer installed a chatbot to answer common questions: delivery times, returns and product availability. It connected to the website in a weekend and reduced repetitive emails almost immediately.
Customers soon asked harder questions. They entered names, email addresses, order numbers, delivery addresses and detailed complaints. One person included health information while explaining why a product had to be returned. The bot stored every conversation in the retailer’s CRM.
The owner thought the bot only answered FAQs. In reality, it had become another place where the business collected personal information.
The questions nobody had asked
The business had no clear answer to five basic questions:
- Did visitors know they were talking to AI?
- What information should the bot ask for—and what should it refuse?
- How quickly could a person take over?
- How long were conversations kept?
- Could the business find and delete one customer’s chat if requested?
The EU AI Act contains transparency rules for systems designed to interact directly with people. GDPR applies when the conversation contains personal data. The Irish Data Protection Commission also advises businesses to know where information sent to AI goes, whether it is retained or reused, and how data rights can be supported.
Why “it’s only customer service” was not enough
The bot occasionally invented a returns promise that was not in the company policy. It also asked for an order number before it was necessary. Left alone, those small problems could become refunds, complaints, privacy requests the team could not fulfil and loss of customer trust.
The risk came from the full process—not simply from the AI model. The website wording, CRM storage, staff handover and retention settings all mattered.
A safer version
The retailer kept the chatbot but narrowed its job. The opening message clearly said it was an AI assistant. It warned customers not to enter payment or sensitive information. The bot could answer approved questions, collect minimal contact details and hand uncertain cases to a person.
The team added a monthly review of sample conversations, fixed a retention period and tested how to find, export and delete a conversation. Important answers linked to the retailer’s actual policy rather than relying on the model’s memory. A staff member became the named owner.
The cost of doing nothing
Without those controls, the retailer risked misleading customers, collecting more personal data than it needed and being unable to honour a deletion or access request. A public chatbot error could also spread quickly through screenshots and reviews. The practical controls were cheaper than rebuilding trust after an incident.
Plain-English takeaway
Your chatbot is part of a business process, not a floating website feature.
Give it a limited purpose, a human owner, clear customer wording and a tested path for escalation and deletion.
Your first three actions
- Read the chatbot’s opening message as if you were a customer. Is it obvious that it is AI?
- Submit a deletion request using a test identity and see whether you can complete it.
- Check what happens when the bot does not know the answer or receives sensitive information.
Official sources: EU AI Act, Article 50 ↗ · Irish DPC guidance on AI and data protection ↗