Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Zendesk Sunshine Conversations powers omnichannel messaging and the Zendesk Web Widget. A JavaScript widget sets cookies such as __zlcmid to persist conversations and recognise returning visitors. Conversation content, identifiers, and metadata are processed by Zendesk in the United States. Because persistent identifiers are involved, prior consent is required under the GDPR and the ePrivacy Directive.
Zendesk Sunshine Conversations is the messaging platform behind Zendesk omnichannel support and the Zendesk Web Widget. It lets businesses run continuous conversations across the website, mobile apps, and channels such as WhatsApp, Messenger, and SMS from a single thread. A JavaScript widget loads on the page, opens a live messaging session, and keeps the conversation history available when a visitor returns. The result is a persistent support experience rather than a one off chat.
The widget sets cookies including __zlcmid, a persistent live chat machine identifier that lasts about one year, and __zlcstore, a local storage helper. Session cookies such as _zendesk_authenticated, _zendesk_shared_session, and _help_center_session manage the authenticated state and the help centre. Alongside these identifiers, Zendesk processes the messages a visitor sends, contact details they provide, IP address, browser and device information, and metadata about the conversation.
A purely functional chat that only stores the open conversation state for the duration of a visit can sometimes rely on legitimate interest. However, __zlcmid is a persistent identifier that recognises a returning visitor across sessions, which goes beyond what is strictly necessary, so Article 5(3) of the ePrivacy Directive requires prior consent. The messages and contact details handled by the widget are personal data under the GDPR, so a lawful basis, transparency, and a record of processing activities are required.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because the widget relies on persistent identifiers, it should load only after the visitor accepts the functional or messaging category in your consent management platform. Consent must be freely given, specific, informed, and as easy to withdraw as to give, so pre ticked boxes and implied consent from continued browsing are not sufficient. Where you can offer a strictly necessary mode that drops persistent cookies and stores only the open session, you may present the widget by default and reserve consent for the full experience.
Zendesk processes data in the United States, with regional hosting available on some plans, so you must document the transfer under the Data Privacy Framework and the Standard Contractual Clauses and sign the Zendesk Data Processing Agreement. In practice, gate the widget behind your consent management platform, list the Zendesk cookies and their durations in your cookie policy, and name Zendesk, Inc. as a recipient. Review retention so that conversation transcripts and identifiers are not kept longer than necessary, and consider regional hosting to reduce transfer exposure.
Websites using Zendesk Sunshine Conversations must obtain user consent under GDPR regulations.
DPIA considerations
Zendesk Sunshine Conversations sets a persistent machine identifier (__zlcmid) lasting about one year that recognises returning visitors, stores conversation transcripts and contact details, and processes IP addresses on US infrastructure. A DPIA should assess the persistence of the identifier, the volume and sensitivity of free text messages that customers may share, the international transfer to the United States, and retention periods, together with mitigations such as consent gating, limited message retention, and regional hosting where available.
Sample consent text
We use Zendesk Sunshine Conversations to provide live messaging support and to keep your conversation history available when you return. Zendesk places cookies on your device to maintain the chat, recognise your browser, and manage your session. These cookies load only after you accept the functional or messaging category, and your messages and contact details may be processed in the United States. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
static.zdassets.comekr.zdassets.comyourbrand.zendesk.comwidget-mediator.zopim.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| __zlcmid | functional | 1 year | Persistent live chat machine identifier. Recognises a returning visitor across sessions so that the messaging widget can restore the conversation history. |
| __zlcstore | functional | Persistent (local storage) | Local storage helper used by the chat widget to store widget state and configuration on the visitor device. |
| _zendesk_authenticated | functional | Session | Indicates that the visitor is authenticated within the Zendesk session and maintains the signed in state for the current visit. |
| _zendesk_shared_session | functional | Session | Maintains a shared session across Zendesk components such as the widget and the help centre during the current visit. |
| _help_center_session | functional | Session | Manages the visitor session within the Zendesk help centre so that navigation and article views remain consistent during the visit. |
Zendesk Sunshine Conversations uses cookies for user preferences — inform visitors with a consent banner.
The messaging widget sets cookies such as __zlcmid, a persistent live chat machine identifier that lasts about one year, and __zlcstore, a local storage helper. Session cookies including _zendesk_authenticated, _zendesk_shared_session, and _help_center_session manage the authenticated state and the help centre for the current visit.
Yes. Because the widget relies on a persistent identifier (__zlcmid) that recognises returning visitors, it is not strictly necessary, so under Article 5(3) of the ePrivacy Directive and the GDPR you must obtain prior, opt in consent before it loads. A reduced mode that only keeps the open session may be presented by default.
The reading and writing of the persistent cookies relies on consent under the ePrivacy Directive, and the processing of messages and contact details relies on consent under Article 6(1)(a) of the GDPR. Strictly functional chat state that lasts only for the visit may rely on legitimate interest, but the persistent identifiers used here require consent.
Yes. Zendesk, Inc. processes conversation and identification data on infrastructure in the United States, although regional hosting is available on some plans. Transfers are covered by the EU US Data Privacy Framework and Standard Contractual Clauses, which you should reference in your privacy notice.
A full DPIA is not always mandatory, but it is recommended because the widget uses a persistent identifier, handles free text messages that may contain sensitive information, and transfers data internationally. Document the purposes, data categories, retention, and safeguards, and reassess if you enable identification or link chat data to other profiles.
Load the widget only after the visitor accepts the functional or messaging category in your consent management platform, and keep the persistent cookies blocked until then. Sign the Zendesk Data Processing Agreement, set sensible retention for transcripts, document the cookies in your cookie policy, and consider regional hosting where available.
Alternatives include EU based or self hosted messaging tools such as Crisp, Tidio, or open source options like Chatwoot, which can keep data in the EU and reduce transfer exposure. They may not match the omnichannel breadth of Sunshine Conversations, so the right choice depends on your channel mix and data residency needs.
List each Zendesk cookie, its purpose, and its duration, name Zendesk, Inc. as a recipient, and disclose the transfer to the United States. Keep the entries in sync with a regular cookie scan so that new or renamed Zendesk cookies are reflected accurately.