Lesson 26 / 29
Privacy, Compliance and Data Handling
Know what leaves your system and what you must be able to show.
Data flows are the compliance story
Compliance questions start with data flows: what personal or confidential data enters prompts, where it is sent (which provider, which region), how long it is stored (provider retention, your logs, caches, fine-tuning sets, vector indexes), who can access it, and how a person's data can be deleted everywhere it landed. Practical steps: map the flows; minimise and redact; choose providers with suitable data-use, retention and residency terms, and sign the agreements your organisation requires; give users notice and choice where the law or ethics require it; apply access control and encryption to logs and indexes; support deletion requests across caches, indexes and logs; and keep records (which model and prompt produced which decision) so you can explain outcomes. Sector rules (health, finance, education) and regional laws add requirements, so involve your privacy and legal teams early rather than at launch.
Involve privacy and legal early
Retrofitting compliance after launch is much harder.
Quick check: What makes deleting a person's data hard in LLM systems?
- Copies can exist in logs, caches, vector indexes and fine-tuning data
- Models forbid deletion
- Data is never stored
- It is easy everywhere
Answer
Copies can exist in logs, caches, vector indexes and fine-tuning data — Map data flows so every copy can be found and removed.