What can you put in?
The most important choice you make is before you press Enter: what do you put into the AI tool? A simple traffic light helps you make that choice in a few seconds.
- check_circle Which information is green, amber or red for AI tools
- check_circle Where personal data hides without you noticing
- check_circle Three habits for working safely with AI
Green: that is fine
- General information without personal data or confidential content, which you are allowed to share and use.
- Your own texts without data that makes someone directly or indirectly identifiable.
- General questions: “write a job advert for an accountant” or “explain how a pivot table works”.
You may use green information in a tool your organisation permits for that task. Public does not automatically mean green: a website can contain personal data too. Just leaving out names is not enough either.
Amber: only in the right tool
Two types of information are amber:
- Personal data Any information about a person you can identify: name, email address, phone number, address, customer number, photo, voice recording, but also a combination of details that together point to someone. : any data about an identifiable person, such as a name, email address, phone number, address, customer number, photo or voice.
- Confidential business information of your organisation or your customers: contracts, pricing agreements, financial figures, strategy, source code.
For both:
- You put them only in tools that the AI policy permits for this: an approved tool and account for this task and this type of data.
- You put in only what you really need for the task.
Having a contract reviewed, code checked or customer data processed can be done within an application that has been assessed and approved for it. A business account alone is not enough. It stays amber: check each time what is permitted and needed. If a customer contract forbids sharing with third parties, you follow that contract.
Red: not on your own initiative
You do not enter this information on your own initiative, not even in a business AI tool:
- Sensitive personal data Special categories include data about health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic data and biometric data for unique identification. Criminal data falls under a separate protection regime. : for example information about illness, religion or trade union membership.
- Criminal data, such as information about convictions or offences.
Using this is only possible within a specifically assessed and explicitly approved application that meets the legal conditions. For health data, among other things, a legal basis under Article 6 and an exception under Article 9 GDPR are both required. Criminal data has a separate regime under Article 10. Approval by your organisation does not replace those conditions.
Stop at such data and follow the specifically approved procedure. If there is none or you are in doubt, do not enter the data and ask the privacy coordinator. You never paste passwords, access codes or API keys into an AI prompt or attachment.
Where personal data hides
“I never put personal data in” is a good intention that quickly goes wrong. It is often where you do not see it:
- Forwarded emails: a whole email thread contains the names, signatures and phone numbers of everyone who took part.
- Screenshots: of a customer list, a calendar or a chat conversation.
- Attachments: an Excel file with a customer data tab, a PDF invoice, a CV.
- Meeting notes and transcripts: who said what, including about other people.
- Context in your question: “My colleague John has been off sick for three weeks, how do I plan…” is red straight away.
Three habits that help
- Remove unnecessary personal data. Also check job titles, customer numbers and details that keep someone identifiable. Replacing a name with “customer A” is usually pseudonymisation: it remains personal data if the person can still be identified. Only truly anonymous information falls outside the GDPR. Ask IT for help with a standard procedure; an automatic filter offers no guarantee on its own.
- Paste only what is needed. Not the whole email thread, but the paragraph that matters.
- Look first, then upload. Open a file and look at what is in it before you upload it.
An invoice question
“I want AI to write a polite payment reminder for a customer who is already a month and a half late.”
A pile of CVs
“I want to upload twenty CVs to get a short summary per candidate.”
An absence notification
What do you do?
Red. An operation is health information. There is no specifically assessed and approved application here that meets the legal conditions. That information is not needed for this reply either. If you like, ask for a general, friendly response to an absence notification, without data about an identifiable person or the reason.
What you take away from module 3
- bolt Green: information without personal data or confidential content, which you may use in the permitted tool.
- bolt Amber: personal data and confidential business information, only in tools the policy permits for it, and only what is needed.
- bolt Red: sensitive and criminal data, not on your own initiative. Only within a specifically approved, legally permitted application. Do not share passwords.
- bolt Personal data hides in email threads, screenshots, attachments and transcripts.
- bolt Remove unnecessary personal data, check identifiability through the context, and upload only what is needed.
Module 3 complete 🎉
You now know the traffic light. In module 4 you will learn how to handle what the AI gives back, and why genuine human review is needed.
On your way to the “Using AI safely” practice quiz
Complete all 8 modules and try the free practice quiz. The official exam with a certificate is in the GDPRWise app.