←
AI for Managers
Aware · M17 · lesson 17 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

Data Privacy Basics

10 min

Esteban Delgado leads an eight-person operations team at a healthcare staffing company. One evening, prepping for annual reviews, he did something that felt completely harmless. He pasted his full team roster into a free public AI chatbot, names, salaries, tenure, and his private performance notes on each person, and asked it to help him organize talking points. The output was great. The instinct was a problem. Three weeks later his company rolled out an AI usage policy, and the first line on the "never do this" list described almost exactly what he had done. Nothing leaked, as far as he ever knew. But it could have, and the realization changed how he worked. He did not stop using AI. He built a quick mental checklist he now runs before every prompt, and it takes about three seconds. This lesson is that checklist.

What This Lesson Covers

You can use AI to help with a great deal of your work. But not everything you do should go into an AI system. This lesson gives you the guardrails: what information is safe to share, what is risky, and how to protect the sensitive data you are responsible for. By the end, you will have a personal policy for what you will and will not put into an AI tool.

Data privacy here is not really about regulations and compliance checklists. It is about trust and responsibility. You are a steward of your team's data, your customers' data, and your company's confidential information. Protecting it is part of your job. Poor practices lead to confidential business information leaking, employee data being exposed (a legal issue), customer information made vulnerable, a breach of trust if your team finds out, and personal liability, because you made the decision to paste it in.

The rule that prevents almost every mistake is one question asked before you hit enter: would I be comfortable if this became public? If the honest answer is no, do not paste it.

The Five Information Categories

Not all information carries the same risk. Esteban learned to sort everything he might share into one of five buckets before deciding.

Category 1: Public information. Anything already public, or that would be fine if it were. Published articles and research, public company announcements, general industry knowledge, publicly available market data, well-known best practices. Risk is minimal. Safe to share with AI.

Category 2: Proprietary business information. Anything that gives your company a competitive edge. Unreleased product features, pricing strategy, customer lists and deal pipelines, financials and forecasts, roadmaps, proprietary code, research results. Risk is high; if this leaks, it damages your competitive position. Generally do not share, unless you are using an approved internal tool with strong protections. The danger: free public tools may store your input and use it to train future models, which means your data could in theory surface for someone else, and you may be breaching confidentiality owed to your board, investors, or partners.

Category 3: Personally identifiable information (PII). Anything about specific people. Names tied to performance data, email addresses, phone numbers, salaries, social security numbers, health information, location data, login credentials. Risk is very high, with real privacy and legal weight. Generally do not share unless it is anonymized. The danger: privacy violations against your own employees or customers, legal liability under data-protection laws, broken trust when people learn their data was shared, and identity-theft risk if credentials are exposed. This is the category Esteban walked into.

Category 4: Confidential communication. Sensitive conversations and decisions. Private discussions with executives, termination planning, sensitive feedback about employees, confidential HR matters, legal strategy, board discussions, anything marked "confidential." Risk is very high across legal, ethical, and relationship dimensions. Generally do not share. Exposing these can harm individuals and relationships and create legal liability.

Category 5: Anonymized or aggregated data. Information with the identifying details stripped out. "Three team members said they want more feedback" with no names. "Customers in the enterprise segment want faster support" with no company named. Aggregated metrics and general feedback themes without attribution. Risk is low to medium, and this is usually your safe path. Specific individuals cannot be identified, competitive sensitivity drops, and privacy risk is minimized. The skill this whole lesson builds is turning Category 2, 3, and 4 material into Category 5 before you share it.

The Four-Question Decision Framework

Before you share anything with AI, run it through four questions in order. This is the checklist Esteban built, and it takes seconds once it becomes habit.

  1. Is this information public, or would it be fine if it were public? If yes, it is probably safe to share. If no, go to question 2.
  2. Does this contain identifying information about a specific person? If yes, do not share unless you anonymize it first. If no, go to question 3.
  3. Does this contain proprietary or confidential business information? If yes, do not share unless you are on an approved internal tool. If no, go to question 4.
  4. Am I uncertain whether I should share this? If yes, do not share it; ask first. If no, you have evaluated it.

The logic is conservative on purpose. If every question lands on "no" or "probably OK," you are clear to share. If any question lands on "yes," you either do not share it or you anonymize it first. When in doubt, the answer is don't.

Four Worked Examples: The Wrong Way and the Right Way

The fastest way to internalize this is to see the same task done badly and then well. In every case, the fix is the same move: strip the identifiers, keep the pattern.

Example 1: Performance feedback. Esteban's original mistake looked like this: "Here is feedback on Sarah Chen, John Martinez, and Angela Patel. Sarah misses deadlines and needs better time management. John has great technical skills but could improve communication. Angela exceeded expectations and is ready for promotion." That names specific people, attaches sensitive performance judgments to them, and creates real employment-law risk if it ever surfaces. The rewrite keeps everything useful and removes the danger: "I have feedback on three team members. One struggles with deadline management. One has strong technical skills but could improve communication. One has exceeded expectations and is ready for more responsibility. Help me structure how I will discuss these themes in feedback conversations." The themes survive. The people disappear. The AI can still help.

Example 2: Customer and market information. The wrong version: "Here are our key customers and their feedback. Acme Corp, $2M revenue, wants faster onboarding. Global Industries, $5M, worried about reliability. FastStart Inc, $500K, wants feature X." That leaks your customer list and their revenue, both proprietary, and could hand strategy to a competitor. The right version: "Our customers most frequently ask for three things: faster onboarding (about 40%), better reliability (about 30%), and a specific feature (about 25%). Help me think about how to prioritize these." Same insight, no exposure.

Example 3: Code or technical information. The wrong version pastes a real codebase snippet and asks the AI to critique it, sending proprietary intellectual property to an external tool. The right version describes the situation instead: "Our team does code review. We want it faster. Current challenges: 2-to-3-day turnaround, junior developers waiting on senior reviews, and reviews that sometimes miss edge cases. What are best practices that address these?" You get general guidance; your code stays yours.

Example 4: Organizational data. The wrong version: "Here is my team. Sarah, engineer, 4 years, $150K, excellent. John, engineer, 2 years, $120K, good. Angela, manager, 6 years, $180K, excellent." That bundles names, salaries, and performance into a single PII-and-compensation disclosure that can even touch pay-equity compliance. The right version: "My team has 3 engineers with 2 to 4 years tenure, 2 with 6+ years, and 1 manager with 6+ years. Average tenure is 4 years. Performance distribution is 5 excellent, 2 good. Looking at tenure versus performance, help me think about development opportunities." The analysis is identical. The privacy violation is gone.

Classification Is an Ongoing Habit, Not a One-Time Check

This habit matters more over time, not less. Right now you might use AI once or twice a day, so a single classification slip stays contained. But as you fold AI into daily work, into team planning, data analysis, stakeholder communication, the volume of data flowing through these tools climbs sharply, and one careless paste can compound. Think of classification as a muscle. At first you build it consciously, pausing before every prompt. Over time it becomes instinct, and that instinct is what separates managers who use AI responsibly from those who quietly create risk.

Three habits build that muscle now:

  • Pause before pasting. Take three seconds and ask whether you would be comfortable if this became public. That single pause prevents most privacy mistakes.
  • Anonymize by default. Make stripping names, identifiers, and specific financial figures your standard move, not your exception. You can always add specificity back later. You cannot take it back once shared.
  • Know your organization's data governance policy. If one exists, read it. If one does not, raise that with leadership. Governance is a management responsibility, not just an IT concern.

Four Ways Good Managers Still Get This Wrong

"It is just a little information." The thinking: "I will share one name and a bit of feedback, that is probably fine." Why it fails: even a little identifying information removes privacy, and a single name is enough to identify someone. The fix: if you are tempted to write "Sarah" or "the customer," anonymize instead.

"Our internal tool is safe, so anything goes." Why it is risky: even internal tools should follow data governance, and "internal" does not automatically mean "anything is fine." The fix: ask what the policy is for sensitive data in that specific tool before you share.

"I will just use the free tool, no one will know." Why it fails: free tools often use your input for training, so you are handing confidential information to the tool provider, breaching confidentiality and creating legal risk. The fix: use only approved tools for anything sensitive, never a public free tool.

"I shared it, so now I am done." Why it is risky: data does not vanish after you send it. It may be stored, logged, or used for training, with downstream effects you cannot see. The fix: treat sharing as a permanent action and be deliberate about what you send.

Your Judgment Checkpoints and Accountability

Before sharing anything with AI, run the same five questions Esteban now asks automatically:

  • Would I be comfortable if this became public? If no, do not share.
  • Does this identify a specific person or customer? If yes, anonymize first.
  • Is this proprietary to my company? If yes, use only an approved tool.
  • Is this confidential? If yes, do not share it with an external tool.
  • Have I checked my organization's policy? If uncertain, ask before sharing.

Two responsibilities sit underneath all of this. The first is transparency with your team: if you are using AI on anything team-related, your people should be able to trust that you are protecting their privacy. The second is personal accountability: you are the steward of the data you handle, and when you are in doubt, the safe default is to protect first and ask later. Your judgment call is often the last line of defense before a breach.

Knowing When to Stop and Run the Checkpoint

Knowing the five checks is only half of it. The other half is noticing the moment that should trigger them, because privacy mistakes almost never happen when you are thinking carefully about privacy. They happen when you are busy and the paste feels routine. Esteban's slip came at the end of a long day, on a task he had done manually a dozen times before.

A handful of moments reliably deserve the pause. Stop when your prompt contains anyone's name, whether it is an employee, a customer, or a contact at a partner company, because a name alone is enough to identify someone. Stop when you are copying material out of a document you did not write, since you may not know how it was classified or who it belongs to. Stop when the content includes a figure that came from an internal system: salaries, revenue, deal values, headcount by team. Stop when you are working in a tool you have not used before, and check what its policy actually says rather than assuming it matches the last one. And stop when you are moving fast on something urgent, because speed is when the pause is both most valuable and least likely.

Once you have stopped, the five questions above take a few seconds to run. What matters more is what you do with an uncomfortable answer. There are only three legitimate outcomes: anonymize the material and proceed, move the work to an approved tool, or do not use AI for it at all. If none of those feels obviously right, that is the uncertainty flag from question four, and uncertainty is itself an answer. Decide now, while you are calm, who you would ask in that situation. For most managers it is a data protection or security contact, a legal or compliance partner, or their own manager. Knowing the name in advance is what makes asking realistic when you are in a hurry.

The Responsibilities Behind the Checklist

The checklist protects you. These four responsibilities are why it matters to everyone else.

Know your organization's data governance. Policies differ enormously between companies, and the rules that applied at your last employer may not apply here. Find out what yours says about AI tools and sensitive data, and find out before you need it rather than after. If your organization has no policy at all, that gap is worth raising with leadership rather than quietly working around. Data governance is a management responsibility, not something that belongs solely to IT.

You are a steward of data that is not yours. Your team's personal information, your customers' details, and your company's confidential material were entrusted to you because of your role. None of it is yours to hand to a third party for convenience. Framing it as stewardship rather than compliance changes the instinct: the question stops being "am I allowed to?" and becomes "would the person this belongs to be comfortable with what I am about to do?"

Be transparent with your team. If you are using AI on anything team-related, your people should know it and should be able to trust that you are protecting their privacy. This is a short conversation, not a policy document. Tell them what you use AI for, such as structuring feedback themes or organizing your own notes, and tell them plainly what you never put into it, such as their names, their compensation, or the specifics of anything they told you in confidence. Trust here is easy to keep and very hard to rebuild once someone discovers their performance notes went into a chatbot.

Own the decision personally. Every paste is a judgment call that you make and that nobody reviews. There is no approval queue and usually no audit trail before the fact. That means your caution is often the last line of defense, and the conservative default is the right one. When you are in doubt, do not share. Protect first, ask afterward. The information you decided not to send is the only information that can never leak.

Practice and Reflection

Work through these deliberately. The goal is to leave with a written personal policy rather than a general sense of caution.

  • Find your policy. What does your organization actually say about AI and sensitive data, and do you know where the document lives? If you cannot find it in ten minutes, that is a finding worth raising.
  • Audit your own data. List the sensitive information you handle in a normal week: personnel notes, customer records, financial figures, confidential plans. For each one, decide now how you will handle it if you want AI's help with it later.
  • Rewrite the four examples. Take each of the wrong-way prompts above and produce your own anonymized version before reading the fix. Compare. The gap between your version and the one here is where your instincts still need work.
  • Write your never list. What is the short, specific list of things you will never put into an AI tool, regardless of deadline pressure? Keep it to five items so you can actually remember it.
  • Draft the team conversation. In three or four sentences, how would you explain to your team that you use AI on team-related work without ever exposing their personal information? Practice it until it sounds like you.
  • Name your escalation contact. If you are genuinely unsure whether something can be shared, who do you ask, and how do you reach them quickly? Write the name down now, while you are not under pressure.

Key Takeaways

  • Sort every piece of information into a category first. Public, proprietary, PII, confidential, or anonymized. The category tells you the risk before you decide.
  • Run the four-question framework before sharing. Is it public, does it identify a person, is it proprietary or confidential, and am I uncertain? Any "yes" means stop or anonymize.
  • Anonymize by default. Strip names, identifiers, and specific figures, and keep only the pattern. Almost every legitimate use survives anonymization intact.
  • Protect proprietary and confidential information. Keep it out of external tools unless you have explicit approval and strong protections.
  • Know your organization's policy. Rules vary by company, and internal tools are not automatically safe. When unsure, ask.
  • When in doubt, do not share. A three-second pause and a conservative default prevent the vast majority of privacy mistakes, and the data you do not share can never leak.