Here’s why you need privacy controls for cobrowsing sessions
Retain customers’ trust
Your customer needs to have control over the cobrowsing session to feel secure while working with your agent. Privacy controls allow them to retain control over their mouse and keyboard throughout the session, and they can exit the session at any time.
Minimize data exposure
Your customer needs to know that your agent can’t view or access their PII when they join a Cobrowse session. Privacy controls allow the organization to hide customer data or sensitive fields from the agent’s view, minimizing the risk of accidental data exposure.
Maintain compliance
Businesses are responsible for handling customer data with care and protecting it from leaks, breaches, or theft by malicious entities. They must be compliant with global regulations like GDPR, HIPAA, ISO 27001 and SOC 2 Type 2. Privacy controls in a Cobrowse session make it easier for a business to prevent privacy risks while providing the best services for their customer.

What privacy controls are there in a Cobrowse session?
Here's a list of privacy controls in Cobrowse by Zoho Assist:
Redaction of sensitive data
Blacklist any elements or fields where your customers will enter sensitive information like passwords or any national identification numbers. These elements will be masked from your agent’s view when they are in a Cobrowse session.
Read-only mode
Once a customer joins a Cobrowse session, the agent can only view and annotate on the shared website. If they need to scroll, navigate, or type in any fields, they must request control from the customer.
User control
During a Cobrowse session, the customer has full control over their mouse and keyboard. Even if the customer accepts an agent’s request to control the website, they retain their controls in the session.
Customer consent and termination
When an agent requests control of the website during a Cobrowse session, the customer can accept or reject the request. The agent can control the website only with the customer’s consent. Likewise, the customer can end the Cobrowse session at any time.
Data minimization
Excluding timestamps and audit logs, customer information or sensitive data is not stored outside of the session, and the agent cannot record the session itself.
Agent authentication
Only agents who are part of the organization can initiate a Cobrowse session. Once a session key is generated, only one agent can initiate a session with it. If another agent tries to use the same session key, it will be invalid, and they must generate a new one.
How Cobrowse by Zoho Assist is built for data protection and privacy
In addition to the session-level privacy controls, Cobrowse by Zoho Assist has a robust security architecture with data protection and privacy at its core. It offers industry-grade encryption for your cobrowsing sessions, where all transmissions are encrypted with the TLS and AES-256 bit protocols. It is GDPR and HIPAA compliant, ensuring that your customers’ data remains safe and confidential until they request its erasure.
