Practical
AI and privacy: what data not to share and how to reduce risk
7 min read1,322 words
Share
In this article · 9 sections
A practical guide to classifying information, removing unnecessary data, and choosing the right channel before using an artificial intelligence tool.
You want to improve your résumé, so you paste the full document into an AI assistant. The task seems harmless, but the document includes your address, phone number, personal email, and perhaps references containing other people's information. None of those details was necessary to get writing help.
That is the everyday challenge of AI and privacy: a useful request can unintentionally become excessive disclosure. The answer is neither to distrust every tool nor to assume that any setting provides absolute protection. It is to make better decisions about which data are needed, which should be removed from the prompt, and which environment is appropriate for the task.
Key idea: The best protection begins before you press “send”: if a piece of data is not needed for a useful answer, remove it.
Start by classifying the information
Not all data cause the same harm if exposed. Before entering information into an AI tool, identify the group it belongs to:
- Public information: it has already been legitimately published, and reusing it does not create a material new risk. Even so, public does not mean free of context or responsibility.
- Personal information: it can directly or indirectly identify someone, such as a name, address, phone number, email address, location, or identification number.
- Especially sensitive information: it concerns health, biometrics, sex life, political views, beliefs, or other matters that can cause significant harm if disclosed. The precise legal categories vary by jurisdiction.
- Confidential or secret information: passwords, access keys, financial information, non-public contracts, trade secrets, or documents subject to professional duties.
- Third-party information: any data about another person, even if it seems ordinary to you.
This classification is not an academic exercise. It should change your decision. A public text may be used carefully; a document containing personal information calls for data minimization; a password or business secret should not go into an ordinary prompt.
The European Union’s General Data Protection Regulation defines personal data as information relating to an identified or identifiable person and recognizes special categories of data. It is a useful reference for understanding the concepts, not a universal legal rule: specific rights and obligations depend on the country and context.
The decision tree: omit, minimize, or use an approved environment
Once you have classified the information, ask these questions in order:
- Can the task be completed without this data? If yes, remove it. Editing the tone of an email does not require a client’s real name, phone number, or contract number.
- Can you replace it with fictional or more general information? Substitute names, dates, figures, and places with placeholders or ranges when those details do not affect the result.
- Does the remaining context still identify someone? An unusual profession, a small town, and a precise date can reveal an identity even after the name is removed.
- Is the information confidential or subject to organizational rules? Use only an environment approved for that kind of data, or do not make the request.
- Have you verified the service’s actual terms? Check the product, plan, account, and settings; do not rely on a general impression of the brand.
This approach reflects the principle of data minimization: use only information that is adequate, relevant, and necessary. Reducing identifiers lowers exposure, but it does not guarantee anonymity.
Removing a name does not always make data anonymous
Replacing “Maria Perez” with “Patient A” can help, but it is usually pseudonymization, not anonymization. If you retain a table that can restore the identity, or if the details are enough to recognize the person, the connection remains.
The European Commission explains that different pieces of information can be combined to identify a person. NIST also notes that the effectiveness of de-identification techniques varies and that re-identification remains a risk.
So removing the name is not enough. You may also need to generalize ages and dates, remove locations, summarize background details, or create a synthetic example that preserves the problem without reproducing the real story.
Key idea: Anonymization is not just hiding a visible identifier; it is reasonably preventing information from being linked back to a person.
What to check before using an AI tool
AI services do not all operate in the same way. Reading a promotional sentence is not enough, either. Guidance from the Australian Signals Directorate and its international partners recommends assessing the data entered and checking issues such as storage, retraining, terms, and controls.
Before working with information that is not public, check:
- whether inputs are retained and for how long;
- whether they may be used to improve or train systems;
- which option limits that use and whether it is enabled;
- who has access within a shared account or workspace;
- which integrations, extensions, or permissions are connected;
- where data are processed or stored, when that matters;
- how deletion can be requested and what the process covers;
- which internal policy, contract, or rule applies in your situation.
Retention, training, and deletion are different questions. Deleting a conversation from an interface does not by itself show that every copy has disappeared from every system. Consult the current documentation for the specific product, plan, and settings.
A favorable policy also does not fix a poorly configured account. Likewise, a useful account setting does not replace the technical, contractual, and organizational controls expected of a provider or institution.
Three practical situations
A résumé with contact details
Goal: improve achievements and clarity. You do not need to share an address, phone number, email address, identification document, or references’ names. Keep job titles, skills, and results; replace company names if disclosing them is not essential. Then apply the edits to the original document outside the tool.
A question about another person’s health
Goal: understand general questions for an upcoming appointment. Do not paste a clinical report or describe a combination of age, small location, rare diagnosis, and date that could identify the patient. Ask a general question or use a fictional case. An AI response also does not replace an assessment by a health professional.
A work document
Goal: summarize a contract or prepare a communication. If the file contains names, credentials, confidential clauses, or internal strategy, do not send it to a public tool. Use the organization’s approved channel if one exists and is authorized for that information. If not, work from an outline without real data.
In all three cases, the decisive question is the same: can I preserve the task’s usefulness while reducing the information exposed?
If you already sent information by mistake
Stay calm and avoid multiplying the problem:
- Do not reuse or paste the content into other prompts.
- Delete the conversation using the available controls, without assuming that this completes the process.
- Review the documentation on retention, data use, and deletion requests.
- Immediately change any exposed password, token, or credential.
- If third-party or organizational data were involved, report it through the appropriate internal channel and follow the incident procedure.
- Record what was sent, when, to which service, and from what type of account. That information helps assess the risk and respond proportionately.
Responsibility does not rest solely with the user: providers make design choices, and organizations should establish clear rules, access controls, and responses. But each person retains an important decision about what they disclose. That ability to choose is part of privacy and individual autonomy.
Key idea: No control makes a prompt prudent when it includes unnecessary secrets, credentials, or information about others.
The final rule is simple: share less and verify more. Define the task, remove data that do not change the answer, transform the example when possible, and reserve sensitive information for an expressly authorized environment. AI can be useful without requiring you to surrender control over your information or anyone else’s.
About the author
Daniel Sardá is an SEO Specialist, a university-level technician in Foreign Trade from Universidad Simón Bolívar, and editor of Libertatis Venezuela. He writes on liberalism, political economy, institutions, propaganda and individual liberty from an independent, non-partisan perspective.