Using AI does not remove an organisation’s existing responsibilities for personal data.
Map the information involved
Identify whether a proposed AI workflow processes personal, confidential or commercially sensitive data and document its purpose.
Check the provider and contract
Review the relevant terms, data processing arrangements, retention settings, transfer arrangements and available administrative controls.
Limit access and inputs
Apply data minimisation, least privilege and approved accounts. Test whether an AI integration could reveal information through existing overly broad permissions.
Assess higher-risk uses
Consider whether a data protection impact assessment is required and obtain appropriate professional advice for consequential or sensitive use cases.
Train employees
Make it easy to recognise inappropriate prompts and report accidental disclosures promptly.
Book cybersecurity and AI training
Learn these skills with Matthew Southgate in our combined full-day course. View and book upcoming training events, or register interest in the online training course.