When things go wrong, and new tools
Everyone makes a mistake now and then. What counts is what you do next. In this module you will learn how to respond quickly and correctly, and how to request a new AI tool in a safe way.
- check_circle What you do straight away if you put something wrong into an AI tool
- check_circle Why reporting quickly matters with a possible data breach
- check_circle How to request a new AI tool
Typed something wrong? Three steps
You paste a customer list into your personal account, upload the wrong file or notice that an AI tool is showing someone else’s data. This is what you do:
- Stop what you are doing. Do not enter any more data.
- Report it straight away to your organisation’s Privacy coordinator The person in your organisation who follows up privacy questions and incidents. If your organisation does not have a privacy coordinator, report it to your manager or the business owner. . Say what happened, which data it was, in which tool and when.
- Limit further damage following the incident procedure. Keep the necessary information about the incident and follow instructions on deleting or revoking access. Do not start an extensive investigation of your own first or wipe evidence. Deleting does not undo earlier processing.
Why every hour counts
Reporting a mistake feels uncomfortable. But the sooner you do it, the more time your organisation has to resolve it properly.
If personal data ends up with the wrong party, that can be a Data breach A security incident through which personal data is lost, ends up with the wrong party or can be viewed by unauthorised people. A mistake by an employee counts too. . Then the following applies:
- Your organisation reports a data breach to the supervisory authority without undue delay and, where feasible, within 72 hours, unless a risk to people’s rights and freedoms is unlikely. So the duty to report does not only apply to “serious” breaches.
- The deadline starts when your organisation knows with a reasonable degree of certainty that an incident has affected personal data. A first suspicion is not automatically that moment, but passing it on internally must not delay the report.
- With a likely high risk, the people affected usually have to be informed too, without undue delay. That is a separate obligation.
You report a possible incident straight away, even if you are in doubt. Do not wait for certainty or for the next working day. The privacy coordinator coordinates the assessment and the report on behalf of the organisation.
Reporting a mistake quickly is always the right choice. Anyone who covers up a mistake makes the problem bigger, for the people whose data it is and for your organisation.
Want to use a new AI tool?
Have you seen a handy AI tool that is not yet on the list?
- Request it first from the privacy coordinator and wait for approval for your use.
- Do not try it out with real data from customers or colleagues.
That way your organisation can assess the intended task, the data, the provider, the settings and the legal conditions. If the tool is approved, it goes on the list in the AI policy.
The wrong account
What do you do?
Stop and report it straight away. Pass on which data ended up in which tool and when. Follow the procedure to limit further damage and keep the necessary incident information. Deleting alone does not solve it. The organisation assesses the duty to report; waiting until Monday can use up a large part of the available reporting deadline. The weekend does not pause that deadline.
What you take away from module 7
- bolt Put something wrong into an AI tool? Stop, report it straight away and follow the incident procedure.
- bolt The organisation reports a data breach without undue delay, where feasible within 72 hours of becoming aware of it, unless a risk to people is unlikely.
- bolt Report straight away yourself, even if you are in doubt. The organisation assesses the duty to report and whether the people affected have to be informed.
- bolt You request a new AI tool first. Wait for approval for your use and do not test it with real data on your own initiative.
Module 7 complete 🎉
You have completed all the modules. Now take the practice quiz to test your knowledge. If you follow the course through the GDPRWise app, you finish with the official exam and confirm your organisation’s AI policy.
Ready for the “Using AI safely” practice quiz
Try the free practice quiz. The official exam with a certificate is in the GDPRWise app.