Academy/Compliance/The privacy pack for your DPO
ReferenceFor DPOs & counsel

The privacy pack for your DPO

What AssistantLabs provides to your privacy officer, what stays with you, and the order to do it in — before an AI assistant answers your first customer.

AAssistantLabs Team
Academy
9 min read Updated Sep 2026

Who is responsible for what

Almost every question a privacy officer asks about an AI assistant resolves the same way once one distinction is clear. Israeli privacy law separates the database owner — the organisation the data is collected for and whose purposes it serves — from the holder, which keeps the database and may use it.

You are the database owner. AssistantLabs is a holder. Accountability to the individual and to the regulator stays with you; we run the system on your instructions and do not set the purposes of processing.

That is not a disclaimer, it is the operative fact. It means the obligations the law places on a database owner — registering the database, the notice duty, publishing a privacy policy, answering access and correction requests, reporting an incident to the regulator — do not move to us because you outsourced the software. It also means a short list of duties binds us directly, as a holder, and cannot be signed away to you:

  • Data security in practice. The Data Security Regulations apply to a holder directly.
  • The cross-border undertaking. Without it the transfer abroad is not lawful at all, so it is a condition of the service running.
  • Telling you about a security incident fast enough that you can make your own report.
  • Using the data only on your instructions — including not training models on it.

Those four are in our Israel Privacy Addendum. Everything else we do is capability we supply and configure to wording and settings you approve.

Not legal advice. This page describes how the service is built and what we will hand you. It does not tell you what your organisation is required to do — that is your officer's and your counsel's call, on your facts.

What we give you

Ask your account contact for the privacy pack and we will send these. There is no charge and you do not need to be an enterprise customer.

  • Data-flow description — what the assistant collects in a conversation, where it is stored, which sub-processors it reaches and in which country. This is the document your risk survey and your database registration are built on.
  • Sub-processor list — every third party that touches the data, its purpose and its location, from Annex B of our Data Processing Addendum. You need this to describe transfers in your own notice.
  • Security-measures description — Annex C of the DPA plus the detail needed to classify the database's security level.
  • Data Processing Addendum — controller/processor roles, breach notification, sub-processor flow-down, audit rights, deletion on termination.
  • Israel Privacy Addendum — the Israeli-law layer on top: the Regulation 2(4) undertaking for transfer abroad, the no-training commitment, a 24-hour incident notice, and the database-owner/holder allocation in terms of the Law.
  • Draft opening-disclosure text — a proposed first message in Hebrew, for you to review, amend and approve. A draft, never a final wording from us.
  • Configuration record — the retention period, response scope and blocked field types you chose, written down, so your file shows what was decided and by whom.
Why the record matters. The pack is also how each side's position stays defensible. It documents that we supplied the information and that the decisions were yours — which is exactly the allocation the law assumes.

What only you can do

None of these can be delegated to a vendor, and we will not offer to do them for you. Two of them are also the ones that most often turn out not to exist yet when someone finally asks.

  • Decide whether your organisation is a public body under the Law. This drives the registration duty, the officer-appointment duty and the security classification, so it is first.
  • Appoint your privacy officer, if one is required and there isn't one. The assistant does not create this duty — it surfaces it.
  • Register the database with the Registrar where that applies to you.
  • Publish and update your privacy policy. It is yours, on your site, and you are the controller named in it. A policy that does not mention the messaging channel or the use of AI does not cover this.
  • Approve the disclosure wording. We draft; you own the text and its accuracy.
  • Define what the assistant may answer on your behalf, and what must go to a person. If you are a public authority this is the exercise of your own powers and we cannot scope it for you.
  • Staff the route to a human. We build the path; somebody of yours has to be at the end of it.
  • Answer access, correction and deletion requests from individuals. We give you the data and the erase function; the reply is yours.
  • Report an incident to the regulator. We tell you; you report.
  • Set the retention period and tell us what it is.
  • Accessibility of the service you are offering the public.

If your organisation exercises public functions, there is one more that sits outside privacy law entirely: a written procedure for using AI, human review of what it produces, and staff training. Ask your counsel about it early — it is the item most likely to be missed, because it does not look like a privacy question.

The opening disclosure

The first message of every new conversation is where the notice duty is discharged. It has to be deterministic text — not something the model composes — which is why it is a setting rather than an instruction in the prompt.

A disclosure that carries its weight names all of these:

  • That the replies come from an automated AI system, not a person.
  • What the information is collected for, specifically.
  • Whether providing it is voluntary, and what happens if the person declines.
  • Who else receives the data — including a technology provider, and whether it goes abroad.
  • How to exercise the right of access and correction.
  • How to reach a human instead.

If you are a public authority, add one more: that the assistant's answers are general information and do not bind the organisation. That line protects you rather than us.

Send it once, at the start of a new conversation — not before every reply, and not partway through. Send it again when a conversation resumes after a long gap.
Two things to avoid. Do not give the assistant a human first name, and do not add artificial typing delays. Both undercut the disclosure, and both are prohibited by the WhatsApp Business messaging policy independently of anything in privacy law.

A link to the full policy is fine as a second layer, but the substance has to be readable in the message itself. Most people read it on a phone and never tap through.

Before you go live

The order matters more than the length. The first four are decisions, not work, and they gate everything else — but they run in parallel with the build, so starting them early costs you nothing.

Decisions first
  • Counsel determines whether you are a public body under the Law.
  • A privacy officer is appointed, or confirmed as already in place.
  • The database is registered, where registration applies to you.
  • You define what the assistant may answer and what must reach a person.
Paperwork
  • The DPA and the Israel Privacy Addendum are signed.
  • The privacy policy is updated to cover the channel and the use of AI.
  • Your officer has the privacy pack and has classified the security level.
  • The disclosure wording is approved by your officer and counsel.
Configuration
  • The approved disclosure is set to send on every new conversation.
  • The route to a human is live and staffed in defined hours.
  • The retention period is set and applied.
  • Sensitive field types you do not want collected are blocked.
  • A written AI-use procedure and staff training exist, if you exercise public functions.
One more time, plainly. This is a description of how our service works and what we will give you. It is not advice about your obligations, and it is not a substitute for your own legal review.
Was this helpful?