Lesson 11 / 25
Privacy and Data Governance
Apply data minimisation, retention limits, access control and provider terms.
Collect less, keep less, share less
Good data governance follows a few rules. Minimise: send the model only what the task needs. Limit retention: delete prompts and outputs after a fixed period unless there is a reason to keep them. Control access: only people who need logs can read them. Know your provider: read the terms on data use, training and retention, and choose settings or agreements that match your obligations. Be transparent: tell users what data you use and how, and give them ways to delete it where the law requires.
A data-handling note
Write it down in plain language. Teams, auditors and users can all read it.
What we send to the model user question + retrieved help-centre text (PII masked)
What we store question, answer, feedback: 30 days, then deleted
Who can read logs support leads and on-call engineers only
Provider terms no training on our data; enterprise settings enabled
User rights users can request deletion through the settings pageQuick check: What is data minimisation?
- Collecting everything just in case
- Compressing files
- Deleting the model
- Sending the model only the data the task needs
Answer
Sending the model only the data the task needs — Less data collected and shared means less that can leak or be misused.