The sensitive data rule
Why employee information never goes into consumer AI tools, and how to work safely anyway.
Here is the rule that protects your team and your job: never put sensitive employee information into a consumer AI tool. Not performance notes, not compensation, not health or personal circumstances, not a named complaint, not anything from a private one-on-one.
Why it matters. What you paste into a personal AI account can leave your control, may be retained, and could be used in ways you never agreed to. A leaked performance note or a compensation figure is a privacy breach with real consequences for a real person, and often a legal one for your employer under rules like GDPR and various state privacy laws.
How to work safely without giving up the help:
- Strip identity. Replace names with placeholders such as Engineer A, and remove anything that could identify the person or the situation.
- Work on structure, not the person. Ask AI to improve feedback phrasing in general, then apply the wording yourself to the real, private text.
- Use approved tools for real data. If your organization provides an enterprise AI tool with a contract that covers your data, use that for anything sensitive — never a personal account.
- Know your data classes. Match the tool to the class of information, and when in doubt, keep it out.
The habit to build: before you paste, ask one question — if this leaked publicly, would it harm someone. If yes, it does not go into the tool.
Take a real piece of manager writing that references a person. Produce a fully de-identified version with no names and no identifying details, and notice how much help you can still get once the person is removed.
Enjoying the free lessons? Get an email when we publish new courses and updates — no spam, unsubscribe anytime.
Discussion (0)
Ask a question or share what worked for you. Comments are reviewed before they appear.
No comments yet. Be the first to start the discussion!