← All chaptersChapter 7 of 8

Working Safely, Privacy-Consciously, and Responsibly

You will learn to classify data, distinguish true anonymization from pseudonymization, and handle rights and transparency responsibly.

After this chapterAfter this chapter, you will be able to determine for a task which information you do not use, use in a limited way, or use with appropriate safeguards.
Your progress0 of 48 lessons
7.1

The data traffic light

Classify information before you share it.

Use this traffic light as a simple rule for practice. Green: entirely fictional data, genuinely anonymous data, or public information containing no personal data or confidential content. Orange: internal information for which you first check necessity, company policy, and settings. Red: this includes passwords, API keys, identity documents, special categories of personal data, complete customer files, and trade secrets. Do not use red-category material in these beginner exercises.

The context also partly determines the risk. Individual pieces of data can together still make a person or confidential situation identifiable.

  • Green: fictional, genuinely anonymous, or public without personal data
  • Orange: internal; minimize the data and check policy
  • Red: do not enter without a formal, appropriate solution
  • Combinations can become sensitive
How you can use this

A public product feature is green. Internal revenue may be orange. A password or national register number is red.

Try this prompt
Classify these fictional examples or data categories as green, orange, or red: [categories, not actual sensitive data]. Explain why and give a safe practice alternative. Do not ask me to share the real data.
Knowledge check

You want to practise with names and personal contact details that are publicly available online. How do you assess this input?

Your practical exercise

Make a list of five pieces of data from an imaginary task and classify them before you write a prompt.

Source for this lesson

EDPB — Personal data and AI
Public availability does not automatically make personal data freely usable.
Checked: 2026-09-07

7.2

Data minimization and settings

Share only what is necessary and check product and workspace settings.

Privacy does not start with a subscription but with data minimization. Delete irrelevant names, attachments, metadata, and hidden tabs. Check data settings, memory, and company policy before entering material.

A business workspace may provide different contractual or administrative safeguards, but does not automatically make every input appropriate. The user or organization still needs to assess purpose, necessity, and access.

On the web, while signed in, open your profile and then Settings → Data Controls. The official explanation names the setting “Improve the model for everyone”. If you do not want conversations used for model improvement, turn that setting off; your conversations may still remain in chat history. Storage, model improvement and memory are different subjects. Record the setting, your choice and the date. Button language and placement can vary: if unsure, use the official explanation below and the help link in your account. Use fictional text throughout this exercise.

You have privacy rights in relation to the organisation deciding on the processing, such as information and access, and, subject to conditions, rectification, erasure, restriction, objection or portability. Start with its privacy contact; for Belgian questions you can also consult the Belgian Data Protection Authority. A request for erasure or transfer is not unlimited in every situation.

  • Minimal data
  • Check files for hidden content
  • View settings
  • Respect policy and contractual context
How you can use this

Work: share only the necessary columns from a table. Study: remove fellow students’ names. Personal use: use a fictional scenario.

Try this prompt
What minimal information do you need for this task: [task]? Create a version with placeholders and specify which data I need to fill in outside of ChatGPT.
Knowledge check

You only want a column of fictional product categories organised. The original work file also has real customer names in a hidden sheet. What do you share?

Your practical exercise

Take a fictitious text and remove everything that is not needed for the assignment.

Source for this lesson

OpenAI — Data Controls FAQ
Data settings and the distinction between use for model improvement and chat history. Check the display in your own account; this lesson does not require a paid feature.
Checked: 2026-09-08

Belgian DPA — What are my rights?
Privacy rights and contacting the responsible organisation. This source does not describe ChatGPT buttons or account settings.
Checked: 2026-09-08

7.3

Anonymizing is more than replacing a name

Pseudonymization reduces identifiability; true anonymization makes it reasonably impossible to link the data to a person.

Using “Customer X” is often pseudonymization. A date, role, location, unique incident, or amount may still make the person identifiable. True anonymization requires that identification cannot reasonably be achieved using available means.

For a beginner's exercise, the safest approach is usually a completely fictional case. In real business use, the organization must conduct an appropriate data and processor assessment.

If you want to learn from a real situation, first describe only the general problem yourself, without names, unique incidents, or other identifying details. Do not share the original data with an AI service and only then ask for it to be made safe.

  • Replacing the name may be insufficient
  • Indirect features count
  • Fictitious case is safe for practicing
  • Real files require policy and assessment
How you can use this

A unique complaint in a small organization can remain recognizable without a name.

Try this prompt
Create an entirely fictional practice case about [general situation]. Use only made-up people and events. Show which kinds of details might make someone identifiable. Do not ask for a real case file.
Knowledge check

You replace a real name with “Customer X” but keep a unique incident, exact date and small location. How do you assess this?

Your practical exercise

Turn an imagined sensitive situation into a fictional case without real people, data, or unique incidents.

Source for this lesson

EDPB — Anonymisation / pseudonymisation
The difference between data that is harder to link and truly anonymous data; a code does not replace an assessment of identifiability.
Checked: 2026-09-08

7.4

Copyright and human contribution

Usage rights and copyright protection are different questions; assess your own contribution and possible rights of others separately.

There are two different questions: may you use the AI output, and is that output itself protected by copyright? The service’s terms set out, among other things, the rights of the provider and user in relation to each other. Such an agreement does not by itself establish that copyright arises. Any rights held by others remain a separate consideration.

In the EU, the author’s own intellectual creation is central: the work must reflect free, creative choices. Using AI therefore does not automatically rule out protection, but a generated result is not automatically your protected work either. Whether the human contribution is sufficient requires assessment of the specific result. Keep versions that show your own creative choices and edits.

  • Human creative choices
  • Assessment on a case-by-case basis
  • Rights to input remain valid
  • Check platform terms and third-party rights
How you can use this

Use an AI draft as material, document your own creative choices, and check the rights to any recognizable content you have reused.

Try this prompt
Review this entirely fictional use scenario for rights to source material, human contribution, third-party rights, and possible permission: [made-up scenario, without a real document]. Give general points to consider and what I should check with a reliable source; do not give a final legal opinion.
Knowledge check

You want to use an AI illustration commercially. You made your own composition choices, but do not yet know which terms and third-party rights matter. What do you check?

Your practical exercise

In a creative exercise, note which content came from you, which from AI, and which sources or rights you verified.

Source for this lesson

WIPO – Creating and inventing with AI
The distinction between creative contribution, terms of use, and third-party rights; legal protection varies by jurisdiction.
Checked: 2026-09-07

7.5

Transparency about AI use

Tell people about AI interaction or synthetic content when disclosure is reasonably expected or legally required.

Since August 2, 2026, certain transparency obligations apply in the EU for, among other things, direct AI interaction, deepfakes, and certain texts about matters of public interest without human editorial control. The exact application depends on role and situation.

Apart from the law, transparency is wise when AI use significantly affects expectations, trust, or interpretation. Human editing and responsibility remain important.

  • Direct AI interaction may require disclosure
  • Deepfakes require special transparency
  • Text on matters of public interest may trigger rules
  • Document human review
How you can use this

An internal language correction is something different from a customer who talks directly with a chatbot or sees a synthetic video of a person.

Try this prompt
Analyse whether this scenario may require disclosure of AI use: [scenario]. Specify the role, audience, content type, human review, and which current rule I should check or expert I should consult.
Knowledge check

An association wants to use a chatbot. Visitors may think a volunteer is replying live. What is a suitable design step?

Your practical exercise

Write a short, clear message for a fictional chatbot that informs the user they are communicating with AI and how human assistance can be obtained.

Source for this lesson

European Commission — AI transparency
Article 50: certain transparency obligations apply from 2 August 2026; roles and exceptions matter.
Checked: 2026-09-07

7.6

A safe fixed routine

Classify, minimize, check, edit, and store consciously.

A reliable routine starts before the prompt. Classify data, choose minimal input, and check settings. After the response, verify claims, edit the text, and decide what is stored or shared.

In case of doubt, stop and ask for internal or professional advice. Working safely does not mean never using AI; it means that risk and consequence determine the strength of your controls.

  • Classify
  • Minimize
  • Check sources
  • Edit and decide
  • Keep or delete consciously
How you can use this

Create a short house rule for a team or family with what is never shared, what is first anonymized, and who decides in case of doubt.

Try this prompt
Create a checklist of no more than seven steps for safe use in [task]. Add a stop rule for doubt or high impact.
Knowledge check

Just before uploading, you find a confidential attachment that is unnecessary for your task. You do not know whether it may be shared. What do you do?

Your practical exercise

Apply the full routine to a fictional task and note your decision at each step.

Worked example

Creating safe practice data before sharing

Fictional practice material; incorrect answers have been created deliberately for this exercise.

A fictional work exercise. You want to learn how to draft a reply to a complaint. You do not need a real customer file for practice.

Input

Unsafe approach for discussion, not to be carried out: “Here is the complete real complaint. First anonymize it, then write a reply.”

First practice answer

An AI answer might replace names with “Customer X”. However, the original file has already been shared, and unique details may remain identifiable.

Check

Stop before uploading. Describe only the general practice problem yourself and use made-up data. Safe prompt: “Entirely fictional exercise: a chair that was ordered arrived two days late. Write an understanding draft reply. Do not invent a refund or delivery promise.”

Improved version

I am sorry the chair arrived later than expected. I understand that this was inconvenient. [Add only a confirmed next step here.] Check: fictional input, no name or case file, and no unconfirmed promise. The draft is ready for real use only after the next step has been filled in and checked.

Try it yourself

Create a safe prompt for a fictional complaint about a damaged book. Do not enter a real message.

View the model answer

Entirely fictional exercise: a book arrived damaged. Write an understanding draft reply without names, customer numbers, or commitments. Leave the possible solution open until it has been confirmed. Check before entering the input and before real use.

Chapter assignment

Bring everything together

Classify a fictional dataset with the traffic light, minimize the input, and write a safe prompt with an explicit stop rule.

Maximum 10,000 characters per note.

Progress and notes are stored only in this browser on this device. Do not enter sensitive data. Download your notes regularly. This course sets no automatic expiry date. You can delete the data through your browser’s site-data settings; export anything you wish to keep first. Browser settings or cleanup may erase it earlier. These local notes are not sent to Finaudax.