Data Privacy Considerations for AI
AI at Work: Our Practical Toolkit - Part 3
AI tools can be powerful, but they're not magic boxes. What you put in matters - especially when it comes to sensitive information.
If you're using tools like ChatGPT, Claude, or NotebookLM, it's worth getting clear on what's private, what's not, and what's safe to share.
Here's a practical starting point.
1. Don't Put Private Or Personal Data Into Public AI Tools
That includes:
- Names, email addresses, phone numbers
- Anything that could identify a person (even indirectly)
- Confidential company documents or client info
- Health, legal, or financial details
Most public AI tools (like ChatGPT or Claude) don't store your data forever, but they may temporarily hold it for processing - and in some cases, to improve their models unless settings are changed.
If in doubt, leave it out.
2. Understand What Tool You're Using (And Who Sees The Data)
Not all tools are equal. Some are designed for enterprise use, with better privacy protections. Others are designed for consumers.
Check:
- Who runs the tool (OpenAI, Anthropic, Google, etc)
- Whether your org has a business or enterprise agreement
- Whether chat history is saved, and if so, where
If you're using a free version of an AI tool, assume that your input is not fully private.
3. Use Anonymised Or Public Examples When Testing
If you want to try out a prompt or process:
- Use placeholder names
- Swap client details for public equivalents
- Keep examples general, unless you're in a secure environment
This lets you test without risking exposure.
4. Check Internal Policy (Or Help Create One)
If your organisation doesn't yet have an AI usage or privacy policy, push for one.
Key questions it should cover:
- Which tools are approved for use?
- What types of data are allowed or banned?
- What review process is in place for AI-generated content?
You can use our AI Usage Policy Template as a starting point.
5. Treat Generated Content Like Any Other Draft
Even if no private data went in, the output still needs review. It might:
- Contain inaccuracies
- Pull in irrelevant or risky examples
- Sound more confident than it should
Don't share anything externally without a proper check.
Checklist: Safe Use Of AI And Personal Data
- Am I using a tool approved by my organisation?
- Is this input something I'd be comfortable emailing to a stranger?
- Did I remove any private, personal, or client-specific information?
- Do I know how this tool handles data?
- Have I reviewed the output for risks or mistakes?
AI tools can help us work faster and smarter - but only if we stay responsible with what we share.
Enjoyed this?
Subscribe to our Thoughts by Humans newsletter for more insights delivered straight to your inbox.
