Lesson 24 / 27
Privacy, Data Handling and Compliance
Know what leaves your system and what the provider does with it.
A prompt is data you send to someone else
Everything in a request leaves your infrastructure. Before sending customer data, check the provider's data-usage and retention terms (whether API data is used for training, how long it is stored, options for zero or limited retention, regional processing), your contracts and laws (for example privacy and sector regulations), and whether you need a data-processing agreement. Reduce exposure: send the minimum, redact or pseudonymise personal data (replace names and IDs with placeholders, map them back after), avoid sending secrets, and keep audit trails of what was sent. Tell users when they are talking to an AI and what is stored, and keep a human responsible for high-stakes decisions (medical, legal, financial, hiring).
Pseudonymise, call, restore (illustrative)
The provider sees placeholders instead of the customer's name and email. Not run here.
mapping = {"[NAME_1]": "Asha Verma", "[EMAIL_1]": "asha@example.com"}
prompt = "Draft a polite reply to [NAME_1] ([EMAIL_1]) about her delayed order."
reply = call_model(prompt) # provider never sees the real name or email
for placeholder, real in mapping.items(): # restore locally, after the call
reply = reply.replace(placeholder, real)Map placeholders back locally
Keep the placeholder-to-real mapping in your system and restore after the reply, so the provider never sees the real values.
Quick check: What is a good first step before sending customer data to a provider?
- Ignore the terms
- Send everything for context
- Check data-retention terms, send the minimum and redact personal data
- Disable logging only
Answer
Check data-retention terms, send the minimum and redact personal data — Data minimisation and clear terms reduce legal and privacy risk.