Work AI Data Hygiene Checklist
Use this before sending work content to an AI tool, including through uploads, repository indexing or connected apps. Follow your organization’s policy. This checklist records a decision; it does not grant permission or establish legal compliance.
1. Identify The Tool
- Exact product, account or tenant, and configuration:
- Task and data class:
- Approval covers this exact data and task? Yes / No / Unknown
- Approval reference and responsible owner (no confidential details):
- Recipients, connectors, retention and access rules checked? Yes / No / Unknown
- Training terms and any feedback exceptions checked? Yes / No / Unknown
If approval is No or Unknown, stop before sending work content and ask the responsible team. If relevant data-handling controls are unknown, stop and confirm them too. A paid plan, enterprise label, disabled training or temporary mode does not establish approval for the data. Do not use a personal account for customer data, employer source code or confidential documents.
2. Classify The Data
Public
Examples: Public website text, public docs, published job ads.
Rule: Use an authorized tool; check rights, terms and task policy.
Internal
Examples: Process notes, de-identified examples, generic templates.
Rule: Use the approved workflow for the data and task; minimize inputs.
Confidential
Examples: Customer data, source code, contracts, financials, strategy.
Rule: Only a workflow approved for this exact data and need; otherwise do not send.
Restricted
Examples: HR investigations, legal privilege, health, regulated data.
Rule: Stop until the designated legal, privacy or security team confirms whether processing is permitted.
These are starting categories, not universal legal classifications. Your organization’s policy may be stricter. Do not lower a classification merely because names were replaced.
3. Remove What The Model Does Not Need
- Prefer fictional practice data. Replace real names with placeholders only where the approved task permits it.
- Remove emails, phone numbers, addresses, IDs, and account numbers.
- Use ranges only if they preserve the task’s meaning; do not silently change numbers needed for the analysis.
- Remove credentials, tokens, URLs with secrets, and internal hostnames.
- Strip comments or metadata from uploaded files if not needed.
Removing direct identifiers does not necessarily make data anonymous. Combinations of details can identify someone; see the European Commission’s personal-data explanation. Check the prepared copy for residual data before sending it; keep originals under the applicable retention and incident-handling policy.
4. Decide The Review Level
- Draft only: human edits before use.
- Internal use: human checks factual claims.
- Customer-facing: human reviews every word unless the workflow is approved for automation.
- Legal, HR, finance, medical, or regulated: specialist review required.
5. Log The Decision For Repeat Work
- Use case:
- Approved data bucket:
- Approved tool:
- Human owner:
- Review rule:
- Recheck date:
Record only the minimum decision metadata. Do not copy sensitive prompts, customer details, credentials or source documents into this record.