← All chaptersChapter 7 of 8

Working Safely, Privacy-Consciously, and Responsibly

You will learn to classify data, distinguish true anonymization from pseudonymization, and handle rights and transparency responsibly.

After this chapterAfter this chapter, you will be able to determine for a task which information you do not use, use in a limited way, or use with appropriate safeguards.
Your progress0 of 48 lessons
7.1

The data traffic light

Classify information before you share it.

Green is public, fictional, or truly anonymous material. Orange is internal or limited sensitive information for which policy, settings, and necessity must be checked. Red includes passwords, API keys, identity documents, special personal data, complete customer files, and trade secrets.

The context also partly determines the risk. Individual pieces of data can together still make a person or confidential situation identifiable.

  • Green: public or fictitious
  • Orange: internal, minimize and control policy
  • Red: do not implement without a formal, appropriate solution
  • Combinations can become sensitive
This is how you can use this

A public product feature is green. Internal revenue can be orange. A password or national register number is red.

Try this prompt
Classify this information as green, orange, or red and provide reasoning: [list]. Suggest a safe alternative for each orange or red category.
Quick knowledge check

Which information is always red?

Your practical assignment

Make a list of five pieces of data from an imaginary task and classify them before you write a prompt.

7.2

Minimize and settings

Share only what is necessary and check product and workspace settings.

Privacy does not start with a subscription but with data minimization. Delete irrelevant names, attachments, metadata, and hidden tabs. Check data settings, memory, and company policy before entering material.

A business workspace may provide different contractual or administrative safeguards, but does not automatically make every input appropriate. The user or organization still needs to assess purpose, necessity, and access.

  • Minimal data
  • Check files for hidden content
  • View settings
  • Respect policy and contractual context
This is how you can use this

Work: only share the necessary columns from a table. Study: remove names of fellow students. Private: use a fictitious scenario.

Try this prompt
What minimal information do you need for this task: [task]? Create a version with placeholders and specify which data I need to fill in outside of ChatGPT.
Quick knowledge check

What is the first privacy measure?

Your practical assignment

Take a fictitious text and remove everything that is not needed for the assignment.

7.3

Anonymizing is more than replacing a name

Pseudonymization reduces recognizability; true anonymization makes linking to a person reasonably impossible.

Using 'Client X' is often pseudonymization. Date, function, location, unique incident, or amount can still make the person identifiable. True anonymization requires that identification through available means is reasonably not possible.

For a beginner's exercise, the safest approach is usually a completely fictional case. In real business use, the organization must conduct an appropriate data and processor assessment.

  • Replacing the name may be insufficient
  • Indirect features count
  • Fictitious case is safe for practicing
  • Real files require policy and assessment
This is how you can use this

A unique complaint in a small organization can remain recognizable without a name.

Try this prompt
Rewrite this scenario as a completely fictional exercise case. Remove or generalize direct and indirect identifiers: [scenario].
Quick knowledge check

What is 'Customer X' usually?

Your practical assignment

Turn a self-conceived sensitive situation into a fictional case without real people, data, or unique incidents.

7.4

Copyright and human contribution

AI output is not automatically legally yours; rights and protection require source and contribution verification.

In the EU, copyright in principle requires an original intellectual creation. Purely generated output without human creative choices may be unprotected. With meaningful human contribution, assessment is needed on a case-by-case basis.

Input also counts. Do not upload or rewrite protected work as if permission is not needed. Check terms of use and third-party rights when using text, images, brands, or persons commercially.

  • Human creative choices
  • Assessment on a case-by-case basis
  • Rights to input remain valid
  • Check platform terms and third-party rights
This is how you can use this

Use an AI concept as material, document your own choices, and do not take recognizable text or style from a living creator as a shortcut.

Try this prompt
Evaluate this use case for source rights, human contribution, third-party rights, and required permissions: [scenario]. Provide general points of attention, not a legal final judgment.
Quick knowledge check

Which is correct?

Your practical assignment

In a creative exercise, note which content came from you, which from AI, and which sources or rights you verified.

7.5

Transparency about AI use

Inform people when AI interaction or synthetic content is reasonably or legally required.

Since August 2, 2026, certain transparency obligations apply in the EU for, among other things, direct AI interaction, deepfakes, and certain texts about matters of public interest without human editorial control. The exact application depends on role and situation.

Apart from the law, transparency is wise when AI use significantly affects expectations, trust, or interpretation. Human editing and responsibility remain important.

  • Direct AI interaction may request notification
  • Deepfakes require special transparency
  • Public interest text can activate rules
  • Document human review
This is how you can use this

An internal language correction is something different from a customer who talks directly with a chatbot or sees a synthetic video of a person.

Try this prompt
Analyze whether this scenario may require AI transparency: [scenario]. Specify role, audience, type of content, human review, and which current rule or expert I should check.
Quick knowledge check

Which situation has the clearest transparency risk?

Your practical assignment

Write a short, clear message for a fictional chatbot that informs the user they are communicating with AI and how human assistance can be obtained.

7.6

A safe fixed routine

Classify, minimize, check, edit, and store consciously.

A reliable routine starts before the prompt. Classify data, choose minimal input, and check settings. After the response, verify claims, edit the text, and decide what is stored or shared.

In case of doubt, stop and ask for internal or professional advice. Working safely does not mean never using AI; it means that risk and consequence determine the strength of your controls.

  • Classify
  • Minimize
  • Check sources
  • Edit and decide
  • Keep or delete consciously
This is how you can use this

Create a short house rule for a team or family with what is never shared, what is first anonymized, and who decides in case of doubt.

Try this prompt
Create a checklist of no more than seven steps for safe use in [task]. Add a stop rule for doubt or high impact.
Quick knowledge check

What is the best stop rule?

Your practical assignment

Apply the full routine to a fictional task and note your decision at each step.

Chapter assignment

Bring everything together

Classify a fictional dataset with the traffic light, minimize the input, and write a safe prompt with an explicit stop rule.