Jonáš Světlík

Where not to put sensitive data

AI is useful, but everything you type into it goes somewhere. A few simple rules will keep you from an expensive mistake.

What happens to your text

When you type into an AI, your text goes to the provider's servers. On the ordinary personal tiers it can also be used to train the model further. So do not treat the chat window like a private folder on your computer.

What never belongs in an AI

  • Passwords, card numbers, PINs.
  • National ID numbers and customers' personal data without their consent or without anonymising it.
  • Sensitive company secrets and contract content that must not get out.
  • Health data and other sensitive personal details.

How to use AI safely

  • Anonymise. Strip out names and details, replace them with "Company X" or "customer A". The quality of the answer does not suffer one bit.
  • Use the business tier. ChatGPT, Claude and Copilot all have paid business plans where your data is not used for training. For a company I would strongly recommend it.
  • Turn training off. Even the personal tiers have a setting to keep your conversations out of training. Turn it on.

GDPR in one sentence

When you put someone else's personal data into an AI, GDPR GDPR applies just as it does anywhere else - you need a lawful reason and you need to know where the data goes. I go into it in detail in the advanced course on AI in business.

Before you paste anything, ask: "Would I mind if this leaked?" If yes, do not put it in - or anonymise it first.

Want AI at work, and want it safe?

I can deploy AI and automation so sensitive data stays under your control - including setups that run on your own machines. Get in touch and we will talk it through, no strings attached.