Lesson 5 / 25

Handling Personal Data

Detect and mask personal information before it reaches the model, logs or third parties.

Data you never send cannot leak

PII (personally identifiable information) includes names, emails, phone numbers, addresses and government or financial IDs. Where the task does not need it, mask it before it goes into a prompt, a log or an analytics tool. Pattern-based masking (regular expressions) is a fast first layer, and dedicated PII-detection tools or models add coverage for names and free text. Neither is perfect, so also limit retention and access.

A regex scrubber, run

I ran this. Both phone formats and the email are masked; the 7-digit order number is left alone. Real systems need more patterns and testing for your region's ID formats.

import re
EMAIL = re.compile(r"[\w.+-]+@[\w-]+\.[\w.]+")
PHONE = re.compile(r"(?<!\d)(?:\+91[- ]?)?[6-9]\d{9}(?!\d)")

def scrub(t):
    t = EMAIL.sub("[EMAIL]", t)
    return PHONE.sub("[PHONE]", t)

print(scrub("Mail asha@example.com or call +91 9876543210 / 9123456789. Order 1234567."))

Output:

Mail [EMAIL] or call [PHONE] / [PHONE]. Order 1234567.

Check the law and your policy

Data-protection laws such as the GDPR and India's Digital Personal Data Protection Act, 2023 affect what you may collect, how long you keep it and what users can ask for. This is not legal advice; involve your legal or compliance team for real products.

Quick check: When is the best time to mask personal data?

  • Never
  • Before it enters prompts, logs or analytics
  • After a breach
  • Only in the UI
Answer

Before it enters prompts, logs or analytics — Data that never leaves your boundary in raw form cannot be leaked from downstream systems.