Privacy and data minimization
Collecting and sending only what you need—**data minimization**—and protecting what remains: access control, retention limits, and careful vendor choices.
What it is
Collecting and sending only what you need—data minimization—and protecting what remains: access control, retention limits, and careful vendor choices.
Why it matters
Prompts and logs become privacy incidents. AI features amplify how much sensitive text moves around.
How it works (plain)
Ask: Must this field leave the device? Must it hit a third-party model? How long do we keep prompts? Who can replay logs? Default to less.
Everyday example
A support bot that only receives redacted ticket text—not full SSNs—in the model prompt.
Try it
For one AI feature, list data in → where it goes → retention → who can see it.
Myths
- ⚠️ Myth: “Enterprise API” means no privacy work for you.
- ✓ Reality: Contracts help; your app design still decides what you send.
- ⚠️ Myth: Encryption alone equals minimization.
- ✓ Reality: Encrypted hoarding is still hoarding.
Sources
- Course 19 security-basics; Course 20 policy
- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework ↗
- Your local privacy regulator guidance (primary)
