First, Know What ‘Sensitive Information’ Means
Before you can protect sensitive information, you need to know how to spot it. The definition is much broader than just passwords or credit card numbers. In a business context, sensitive data includes a wide range of information that should not be public.
Think about customer lists, employee records, and any personally identifiable information (PII). It also covers internal financial reports, sales data, and revenue forecasts. Furthermore, a company’s intellectual property—like trade secrets, strategic plans, marketing campaigns, proprietary source code, and unpublished research—is highly sensitive. Even seemingly routine documents like internal memos, draft contracts, or client feedback can contain details that could be damaging if exposed. The simple rule is: if this information leaked, could it harm your company, your clients, or your colleagues? If the answer is yes, treat it as sensitive.
Check Your Company’s AI Policy
This is the most critical first step. Before using any external AI tool for work, find out what your employer’s official policy is. Many organisations are now creating specific guidelines for using generative AI. These policies are designed to protect both you and the company from legal and security risks. If a policy exists, it will likely specify which AI tools, if any, are approved for use. It may also provide a framework for what kinds of information are strictly off-limits for AI uploads. If you can’t find a policy, don’t assume it’s a free-for-all. Ask your manager, IT department, or compliance officer for guidance. Using unapproved “Shadow AI” tools can expose the company to significant risks, from data breaches to regulatory fines, and could have serious consequences for your employment.
Distinguish Between Public and Enterprise AI
Not all AI tools are created equal, and the difference is crucial for data security. Public, consumer-facing AI tools (like the free versions of ChatGPT, Gemini, or Claude) are often the riskiest. By default, many of these platforms may use your inputs to train their models. This means your confidential data could inadvertently become part of the AI's knowledge base. In contrast, enterprise-grade AI tools, such as Microsoft Copilot within a corporate Microsoft 365 account or ChatGPT Enterprise, are built with business security in mind. These versions typically come with contractual guarantees that your company’s data will not be used for training public models and will remain within your secure environment. Always use the company-provided, licensed version of an AI tool if one is available.
Read the AI Tool’s Data and Privacy Policy
If you are considering a public tool for non-sensitive tasks, you must investigate its privacy policy. Don't just click “agree.” Look for specific language about data usage and retention. Key questions to answer are: Is my data used to train the AI model? Can I opt out of this? How long is my data stored? And can I delete my data permanently? For example, OpenAI allows users of its free service to turn off chat history to prevent conversations from being used for training. However, you shouldn’t assume this is a perfect failsafe. Think of public AI platforms like social media: if you wouldn't post the information publicly, don't enter it into the tool. Understanding these terms is essential to making an informed decision about risk.
Anonymise and Sanitise Before You Upload
If you absolutely must use an AI tool for a work-related task and have confirmed it is permitted, the safest approach is to manually strip out all sensitive details from your data before uploading. This process is called anonymisation or sanitisation. For example, if you want an AI to help you draft an email to a client, replace the client’s real name, company, and any specific project details with generic placeholders (e.g., “Client A,” “Project X”). Remove all names, addresses, phone numbers, financial figures, and any other proprietary information. This extra step ensures that even if the data were somehow exposed, it would contain no valuable or identifiable information, significantly reducing the risk of a breach.
Understand the Local Legal Landscape
Mishandling data isn’t just a policy violation; it can also be a legal one. In India, the Digital Personal Data Protection (DPDP) Act of 2023 establishes rules for how organisations—and by extension, their employees—must handle personal data. Uploading employee or customer data to a non-compliant AI tool could violate the principles of this act, which grants individuals rights over their data and holds companies (as “data fiduciaries”) accountable for its protection. An employee's actions can create liability for their employer, leading to significant penalties. Understanding your obligations under laws like the DPDP Act reinforces the importance of following company policy and handling all personal data with extreme care.














