Know where the information goes
Prompts, uploads, recordings, connector data and generated outputs can contain personal, confidential, commercially sensitive or licensed information. A user should not assume that a consumer AI account is an approved place for organisational data.
Do not enter sensitive information until the organisation has approved the specific product, account type and use. Verify retention, provider training use, access, subprocessors, data location, security, deletion and contractual terms.
Map the information flow
- Inputs. List prompts, files, audio, images, connector data, feedback and hidden context sent to the service.
- Processing. Identify the provider, models, subprocessors, locations and people or systems that can access the data.
- Retention and learning. Check how long information remains and whether it may improve or train products or models.
- Outputs. Decide where generated material is stored, copied, shared or used to make another decision.
- End of use. Confirm export, deletion, account closure and evidence that connected access has been removed.
Information that often needs restriction
- Personal, health, financial, employment or identity information.
- Client, customer, child or vulnerable-person information.
- Passwords, keys, tokens, security configurations or incident details.
- Trade secrets, negotiations, unpublished plans and confidential contracts.
- Copyrighted or licensed content without permission for the intended use.
- Material subject to professional confidentiality or sector rules.
Supplier and account checks
- Enterprise and consumer account terms are distinguished.
- Training-use controls and defaults are understood.
- Retention can be configured or justified.
- Identity, roles and account removal are controlled.
- Connectors receive only the access they need.
- Security and incident evidence covers the actual service.
- International transfers and applicable data rules are checked.
- Deletion includes prompts, uploads, outputs and connected copies where applicable.
Important jurisdiction context
Privacy and AI laws vary by country, sector, role and use. The UK ICO guidance is a useful risk-based data-protection resource. Organisations operating in or affecting the EU should check the current European Commission AI Act information. Obtain qualified advice for the applicable situation.
AI privacy and confidential-data FAQs
Can I put confidential information into an AI tool?
Only if the organisation has approved the specific service, account and use after checking the contract, retention, training use, access, security, location and deletion. Remove or minimise confidential information where possible.
Does deleting a chat delete all copies of the data?
Not necessarily. Interface deletion, provider retention, backups, safety logs, connected systems and exported copies may differ. Check the provider’s current terms and controls.
Is anonymised information always safe to use?
No. Information may be re-identifiable when combined with other details, and confidential or licensed material can remain protected even when names are removed. Assess the actual data and context.
Continue your AI decision
Use the next guide that matches the question or risk you still need to resolve.
