Insights
Updated September 2026

Privacy by Design for Emotional AI Robots

Robots that infer emotion raise questions about measurement, lawful processing and usable privacy choices. Consent is not the only possible legal basis.

9 min read

General information, not legal advice. Legal position as of . Limitations in the Legal Notice

Review status: legal and language review by a named human reviewer is pending.

In this article

Imagine a care robot that uses a camera and microphone to adapt its responses. Before asking how to explain its privacy policy, ask what it actually measures, whether that processing is necessary and whether the intended use is permitted. This is a design scenario, not a claim about a particular hospital or product.

Emotion inference is an uncertain measurement

An expression is not a direct reading of a person's inner state. Barrett and colleagues' 2019 review describes substantial variation across people and contexts and cautions against inferring a specific emotion from facial movements alone. Its corrigendum corrects figure attribution and presentation. A supplier's label such as “confused” or “happy” therefore needs validation for the intended setting, not treatment as an established fact about a patient.

Privacy questions also extend beyond identification. McStay's 2020 research, combining stakeholder interviews, a UK survey and a workshop, examined concerns about emotional AI that does not identify individuals. It does not establish that every friendly robot causes greater disclosure or that a particular notice design solves the problem.

A warm voice or familiar shape may influence an interaction. Test that possibility with the intended users. Do not assume that all older people, children or isolated users respond alike, or infer their capacity to consent from an emotion score.

Privacy-by-Design Layers for Emotional AI

Under the GDPR, assess whether the information is personal data and which processing is proposed. Images and recordings are not automatically biometric data within Article 4(14). Article 9's biometric-data limb concerns processing for the purpose of uniquely identifying a person. Health information may fall within Article 9 independently of that purpose.

An Article 6 legal basis is needed where the GDPR applies. Processing within Article 9 also needs an applicable Article 9(2) condition. Consent is one possible route, not the universal basis for every robot interaction. Where consent is relied on, examine whether it is freely given, specific, informed and unambiguous (Article 4(11)); for Article 9 data, Article 9(2)(a) requires explicit consent, and Union or Member State law may provide that consent cannot lift the prohibition. A care relationship may make a refusal difficult in practice. Do not treat a nominal choice as sufficient.

Map purpose, recipients, retention and access before selecting safeguards. Article 25 requires data protection by design and by default: appropriate measures from the moment the means of processing are determined, and default settings that process only the data necessary for each purpose. Evaluate the need for a data protection impact assessment under Article 35. Local processing can reduce some disclosures, but does not remove the need to justify collection or secure the device.

Check the AI Act prohibition before high-risk duties

The consolidated EU AI Act prohibits specified workplace and education emotion-inference uses in Article 5(1)(f), with an exception for medical or safety reasons. That exception is not blanket permission under other law.

Emotion-recognition systems appear in Annex III point 1(c), insofar as their use is permitted. High-risk classification must be read with Article 6, including its conditions and limited exceptions. A permitted use is not necessarily low-risk because a human remains involved.

Article 50(1) addresses informing people of direct AI interaction, with an obvious-context exception and other specified limits. Article 50(3) separately requires deployers to inform people exposed to emotion-recognition systems, subject to its exception. The required information must meet Article 50(5), including timing and accessibility. A notice cannot legalise a prohibited practice.

The relevant Article 5 prohibition has applied since 2 February 2025 and Article 50 generally since 2 August 2026. Under the amending Regulation (EU) 2026/1744, relevant Annex III high-risk duties apply from 2 December 2027, subject to applicable transitions. These are separate dates and obligations.

The same regulation added two prohibitions to Article 5(1), points (ba) and (bb), which apply from 2 December 2026 under Article 113, third paragraph, point (a). They cover AI systems that generate or manipulate realistic images, videos, audio or similar material of an identifiable person's intimate parts or of an identifiable person in sexually explicit activity without that person's freely given, specific, informed, unambiguous and explicit consent, and systems that generate or manipulate child sexual abuse material or performances within the meaning of Article 2(c) and (e) of Directive 2011/93/EU, except where a “without right” defence applies under national law. Under Article 5(1a), placing such a system on the market or putting it into service is prohibited only where that output is its intended purpose, or a reasonably foreseeable and reproducible outcome without significant technical modification and without adequate safeguards; a deployer is covered when it uses a system for that purpose. For point (ba), Article 5(1b) excludes manipulation that neither increases the exposure of depicted intimate parts nor alters the nature of a depicted sexually explicit activity. These prohibitions concern generated content rather than emotion inference, but a robot with cameras and generative features needs the same check. No label or notice makes a prohibited use lawful.

Design explanations and controls people can use

The following are design proposals to test, not five empirically validated solutions:

  1. Explain the actual processing. Describe the sensors, purpose, recipients and retention in concrete language. Distinguish an inferred label from a confirmed observation.
  2. Offer appropriate channels. Provide accessible text, audio or visual explanations suited to the users and setting, and choose them for that setting: using every channel at once is not a general legal requirement.
  3. Make choices practical. Where applicable, allow people to refuse or withdraw consent, pause a sensor or request human assistance. Explain the consequences honestly.
  4. Keep explanations consistent. A spoken summary and written detail should not contradict each other. Do not invent a rule that every communication channel has identical legal status.
  5. Use explicit preferences first. Let people select language, text size or an alternative explanation. Inferring confusion to tailor privacy information may itself introduce additional uncertain and intrusive processing.

Article 12 GDPR requires clear, accessible information; it does not prescribe one universal robot interface. Test comprehension and the ability to exercise choices with representative users. A friendly tone is not proof of understanding, and a click is not proof of valid consent.

Assess Swiss obligations separately

The Swiss FADP has its own rules, including data protection by design and default in Article 7 and high-risk impact assessments in Article 22. Under Article 5 letter c, health data and biometric data that uniquely identify a person are sensitive personal data, and Article 22 names their large-scale processing as a case of high risk. Unlike the GDPR, the FADP does not require a legal basis for every private-sector processing operation. A justification such as consent, an overriding interest or the law is needed where processing breaches personality rights (Articles 30 and 31), and where consent is required, it must be explicit for sensitive personal data (Article 6 paragraph 7). Healthcare confidentiality, sectoral rules and, where relevant, cantonal law also need examination.

Swiss regulatory status (checked 26 September 2026). Switzerland has no AI-specific legislation yet; the FDPIC states that the current FADP applies directly to AI-supported data processing. On 12 February 2025 the Federal Council decided to ratify the Council of Europe AI Convention, which applies primarily to state actors. The Federal Department of Justice and Police is to prepare a consultation draft by the end of 2026, in particular on transparency, data protection, non-discrimination and supervision. Switzerland signed the Convention on 27 March 2025. When this was checked, the Federal Office of Justice (German text) did not yet list a published draft.

For a Swiss organisation, EU AI Act applicability requires analysis of Article 2's actual connecting factors, including certain outputs used in the Union. Simply saying that a robot “affects EU individuals” is not an adequate scope assessment.

Privacy questions for emotional AI

0/7

Key Takeaway

Start with permitted purposes and defensible measurements. Privacy communication must explain the real system and support usable rights and choices; it cannot compensate for unlawful or unnecessary processing.

Clarify how AI decisions are made

Connect business, HR, IT and risk through clear ownership and review routines.

You might also like

Need clearer footing for an AI decision?

Start with a focused conversation about a live AI use case, workflow bottleneck, training need, or governance gap.