# Handling Personal Data — AI Safety, Evaluation and Cost Control

Source: https://www.geekswithgeeks.com/en/ai-safety/io-pii

> Detect and mask personal information before it reaches the model, logs or third parties.

## Data you never send cannot leak

**PII** (personally identifiable information) includes names, emails, phone numbers, addresses and government or financial IDs. Where the task does not need it, **mask it before** it goes into a prompt, a log or an analytics tool. Pattern-based masking (regular expressions) is a fast first layer, and dedicated PII-detection tools or models add coverage for names and free text. Neither is perfect, so also limit retention and access.

## A regex scrubber, run

I ran this. Both phone formats and the email are masked; the 7-digit order number is left alone. Real systems need more patterns and testing for your region's ID formats.

```python
import re
EMAIL = re.compile(r"[\w.+-]+@[\w-]+\.[\w.]+")
PHONE = re.compile(r"(?<!\d)(?:\+91[- ]?)?[6-9]\d{9}(?!\d)")

def scrub(t):
    t = EMAIL.sub("[EMAIL]", t)
    return PHONE.sub("[PHONE]", t)

print(scrub("Mail asha@example.com or call +91 9876543210 / 9123456789. Order 1234567."))
```

Output:

```
Mail [EMAIL] or call [PHONE] / [PHONE]. Order 1234567.
```

## Check the law and your policy

Data-protection laws such as the GDPR and India's Digital Personal Data Protection Act, 2023 affect what you may collect, how long you keep it and what users can ask for. This is not legal advice; involve your legal or compliance team for real products.

**Quiz:** When is the best time to mask personal data?

- [ ] Never
- [x] Before it enters prompts, logs or analytics
- [ ] After a breach
- [ ] Only in the UI

*Answer:* Before it enters prompts, logs or analytics. Data that never leaves your boundary in raw form cannot be leaked from downstream systems.
