Privacy, security and tool selection
Choose digital tools without exposing confidential or personal information.
Covered in this guide
- Classify information before entering it into a tool.
- Apply data minimisation and access controls.
- Match the tool to the task and risk.
A tool can be capable yet unsuitable. Check the sensitivity of the input, contractual permissions, retention policy, model-training terms, access controls and the consequences of error before use.
Capability is not permission
A tool can be capable yet unsuitable. Check the sensitivity of the input, contractual permissions, retention policy, model-training terms, access controls and the consequences of error before use.
A tool that kept the wrong data
A team wants an external AI service to summarise interview notes containing names, health disclosures and salary expectations.
Try this
Recommend a safe course of action.
Review answer guidance
Do not upload the notes without an authorised data-processing arrangement and a documented purpose. Prefer an approved protected tool, remove unnecessary identifiers, restrict access and retain only the minimum output needed.
How tool-choice items are framed
Check the sensitivity of the input, who can see the output, and whether the contract allows that use. A capable tool can still be the wrong tool.