Knowledgebase

Using AI Systems With Personal Data Print

  • 0

Newer technology, existing obligations.

WHAT DOES NOT CHANGE

Every data protection obligation applies.

WHAT CHANGES

Scale, opacity, and the difficulty of explanation.

WHAT TO ESTABLISH BEFORE USING ANY AI SERVICE

What data is sent Where it is processed What the provider does with it Whether it is used to train their models How long it is retained

WHY TRAINING MATTERS MOST

Data used for training may be irretrievable and may surface elsewhere.

WHAT TO CHECK

The provider's terms, specifically on data use.

WHAT TO NEVER SEND

Personal data you have no basis to share Sensitive data, without careful assessment Customer content, without permission

WHAT TO MINIMISE

What is included in any prompt.

WHAT TO CONSIDER

Removing identifiers before sending.

WHAT TO ASSESS

Whether an impact assessment is required.

WHEN IT USUALLY IS

Automated decisions, large-scale processing, or novel applications.

WHAT TO TELL PEOPLE

That AI processing occurs, where it affects them.

WHY

Transparency obligations apply regardless of the technology.

WHAT TO BE CAREFUL WITH

Staff pasting customer data into public tools.

WHAT TO DO ABOUT IT

A policy, and training.

WHAT TO PROVIDE

An approved tool, so the need is met safely.

WHY

Prohibition without an alternative produces unmonitored use.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot