Skip to content
flag Introduction

When things go wrong, and new tools

Everyone makes a mistake now and then. What counts is what you do next. In this module you will learn how to respond quickly and correctly, and how to request a new AI tool in a safe way.

target What you will learn in this module
  • check_circle What you do straight away if you put something wrong into an AI tool
  • check_circle Why reporting quickly matters with a possible data breach
  • check_circle How to request a new AI tool
report Report straight away

Typed something wrong? Three steps

You paste a customer list into your personal account, upload the wrong file or notice that an AI tool is showing someone else’s data. This is what you do:

  1. Stop what you are doing. Do not enter any more data.
  2. Report it straight away to your organisation’s Privacy coordinator The person in your organisation who follows up privacy questions and incidents. If your organisation does not have a privacy coordinator, report it to your manager or the business owner. . Say what happened, which data it was, in which tool and when.
  3. Limit further damage following the incident procedure. Keep the necessary information about the incident and follow instructions on deleting or revoking access. Do not start an extensive investigation of your own first or wipe evidence. Deleting does not undo earlier processing.
timer The clock is ticking

Why every hour counts

Reporting a mistake feels uncomfortable. But the sooner you do it, the more time your organisation has to resolve it properly.

If personal data ends up with the wrong party, that can be a Data breach A security incident through which personal data is lost, ends up with the wrong party or can be viewed by unauthorised people. A mistake by an employee counts too. . Then the following applies:

  • Your organisation reports a data breach to the supervisory authority without undue delay and, where feasible, within 72 hours, unless a risk to people’s rights and freedoms is unlikely. So the duty to report does not only apply to “serious” breaches.
  • The deadline starts when your organisation knows with a reasonable degree of certainty that an incident has affected personal data. A first suspicion is not automatically that moment, but passing it on internally must not delay the report.
  • With a likely high risk, the people affected usually have to be informed too, without undue delay. That is a separate obligation.

You report a possible incident straight away, even if you are in doubt. Do not wait for certainty or for the next working day. The privacy coordinator coordinates the assessment and the report on behalf of the organisation.

volunteer_activism Reporting is always the right choice

Reporting a mistake quickly is always the right choice. Anyone who covers up a mistake makes the problem bigger, for the people whose data it is and for your organisation.

add_circle New tools

Want to use a new AI tool?

Have you seen a handy AI tool that is not yet on the list?

  • Request it first from the privacy coordinator and wait for approval for your use.
  • Do not try it out with real data from customers or colleagues.
verified_user Why request it first?

That way your organisation can assess the intended task, the data, the provider, the settings and the legal conditions. If the tool is approved, it goes on the list in the AI policy.

quiz What would you do?

The wrong account

upload_file
You notice that you have just uploaded an Excel list with 200 customer addresses into your personal ChatGPT account, instead of the business account. It is Friday, 4 pm.

What do you do?

quiz Practice · question 1 of 2
info Just practice, this does not count toward your progress
Who assesses whether an AI mistake is a data breach that has to be reported?
Correct: you report, the privacy coordinator assesses. That way you do not have to judge how serious it is yourself.
quiz Practice · question 2 of 2
You want to use a new AI tool that is not on the list. What is the right first step?
Correct: request it first and wait for approval. Your organisation assesses the tool, the task and the data before you use it.
summarize Summary

What you take away from module 7

  • bolt Put something wrong into an AI tool? Stop, report it straight away and follow the incident procedure.
  • bolt The organisation reports a data breach without undue delay, where feasible within 72 hours of becoming aware of it, unless a risk to people is unlikely.
  • bolt Report straight away yourself, even if you are in doubt. The organisation assesses the duty to report and whether the people affected have to be informed.
  • bolt You request a new AI tool first. Wait for approval for your use and do not test it with real data on your own initiative.
workspace_premium Module complete

Module 7 complete 🎉

You have completed all the modules. Now take the practice quiz to test your knowledge. If you follow the course through the GDPRWise app, you finish with the official exam and confirm your organisation’s AI policy.

lock_open 7 of 8 modules

Ready for the “Using AI safely” practice quiz

Try the free practice quiz. The official exam with a certificate is in the GDPRWise app.

check_circle Modules 1-7 completeradio_button_unchecked Final exam ≥ 70%
workspace_premium