Privacy and Compliance: What Can You Share with AI?
You understand privacy implications and know which data to share.
Why this lesson matters
Everything you type into an AI tool can be stored, used for training or (worst case) leaked. So with every prompt you need to ask yourself: is this okay to share? With GDPR, data breaches and stricter regulation, this is daily reality.
This lesson gives you a clear framework for what you can and can't do.
What you'll learn
- How AI tools handle your data
- What GDPR means for using AI
- The difference between enterprise and consumer AI
- A practical policy for your organisation
How AI tools handle your data
AI tools differ a lot when it comes to privacy.
| Aspect | Consumer (free) | Enterprise / API |
|---|---|---|
| Data used for training | Often yes | Usually not |
| Data storage | Unknown duration | Fixed by contract |
| Servers | US / unknown | Choice of region (EU) possible |
| Encryption | Basic | Enterprise-grade |
| Audit trail | None | Available |
| Data processing agreement | No | Yes |
The free versions of ChatGPT, Gemini and other tools can use your input to train their models. What you type in then no longer belongs to you alone.
What should you NOT share with AI?
A clear classification:
Never share (red)
- Personal data of customers or employees
(names, addresses, citizen service number/BSN, salaries)
- Login details and passwords
- Financial data of individuals
- Medical data
- Trade secrets and intellectual property
- Non-public financial results
- Legally privileged informationKeep reading
Leave your name and email address and you can read the rest
You get the whole lesson right away, and every other lesson stays open after that. No password, no confirmation email.
Share with care (orange)
- Internal strategic plans (anonymise)
- Customer feedback (anonymise names and companies)
- Contract terms (remove party names)
- Internal processes (no specific names)Free to share (green)
- Publicly available information
- Generic questions without company context
- Fictional sample data
- Requests for templates and structures
- Language help (grammar, wording)In doubt? Ask yourself: "Would I post this on a public forum?" If not, it doesn't go into a consumer AI tool.
GDPR and AI: the basics
The GDPR (the AVG in Dutch law) applies as soon as you process personal data through AI.
Core principles
- 1Purpose limitation: you may only use data for the stated purpose
- 2Data minimisation: share no more than necessary
- 3Storage limitation: data may not be kept longer than necessary
- 4Transparency: data subjects must know that AI is being used
- 5Data processing agreement: required with enterprise AI tools
In practice: what does this mean?
| Situation | GDPR action needed |
|---|---|
| Typing customer names into a prompt | Don't, without a data processing agreement |
| Using AI for HR decisions | Privacy Impact Assessment (PIA) required |
| Analysing anonymous data | Allowed, provided it's truly anonymous |
| Introducing an AI tool in your team | Data processing agreement + entry in the record of processing activities |
Anonymising and pseudonymising are two different things. "Customer A in Amsterdam with 50 employees in IT" can often still be traced. True anonymisation means no one can identify the person or the company.
Enterprise vs. consumer AI
For organisations, the choice of an enterprise solution matters.
An AI policy for your organisation
Every organisation that uses AI needs a policy. At minimum:
AI USAGE POLICY - TEMPLATE
1. APPROVED TOOLS
- Which AI tools may be used?
- Which versions (enterprise vs. free)?
2. DATA CLASSIFICATION
- Red: never share with AI
- Orange: only with enterprise AI + anonymisation
- Green: free to use
3. RESPONSIBILITIES
- Who is responsible for AI output?
- Who approves new AI tools?
4. VERIFICATION
- Which output has to be checked?
- By whom?
5. INCIDENTS
- What do you do if you've accidentally shared
sensitive data?
- Who do you report it to?
6. TRAINING
- Who has to take this training?
- How often is the policy reviewed?"We don't need an AI policy because we don't use AI" is rarely true. Employees are already using it. The question is whether they're doing it safely.
The anonymisation technique
If you still want to analyse company-specific scenarios:
Original (do NOT share):
"Customer Bakker BV in Rotterdam pays 45,000 per month
and is considering cancelling because of service problems."
Anonymised (OK to share):
"A mid-sized customer in the Randstad pays ~50K/month
and is considering cancelling because of service problems.
What are retention strategies?"You get the same usable advice without the privacy risk.
What is the biggest difference between consumer and enterprise AI tools when it comes to privacy?
You want to ask AI for advice on a tricky customer situation. What is the safest approach?
Want to keep your progress, get the practice files and sign up for the free evening? Create a free account. All you do is click a link in your email.
Create a free account