Expertise · Using AI responsibly

Protecting customer data when using AI

Using AI does not mean customer data must follow.

Quick summary

Do not input confidential data or personal information into public AI tools; this is a minimum safety practice, not an option. When it is necessary to use AI with sensitive data, choose tools with clear data processing agreements, only input what is truly needed, and ensure identification information is obscured. Any decision affecting personal data must be approved beforehand.

Quick comparison
You should choose this direction when
  • using a corporate agreement for data processing (DPA)
  • only include the minimum part that has blurred data
  • has established internal principles and clear legal basis
Not needed when.
  • directly input customer data into free AI tools
  • Industry under tight management lacks legal security experts
  • use personal AI accounts outside the organization's control
Quick glance
Commonly used industries
healthcareFinancelegalinsurance

From the brief stage, Sinh Vũ is already exposed to sensitive client data: names, contact numbers, contracts, unpublished strategies. When AI begins to participate in the workflow, the question is not "Is AI useful?" but rather "What data is fed into AI, and what data is absolutely off-limits?" The answer to that determines your credibility with clients, just as much as the quality of the product.

Data classification: the first step that cannot be overlooked.

Not every piece of data requires the same level of protection. It is necessary to clearly distinguish four layers:

  • Public data: information that has been published externally, with low risk when inputting into AI.
  • Internal data: processes, templates, internal documents that have not been shared externally. More caution is needed.
  • Confidential data: contracts, strategies, financial reports. Do not input into public AI.
  • Personal information (PII, meaning personally identifiable information): name, phone number, email, address, customer payment data. Highest level of protection, requiring clear legal basis each time it is processed.

The most common mistake is treating all data as a single block, then making decisions based on convenience rather than risk levels.

Choose the right tool for the type of work.

Free public AI: suitable for non-sensitive content, general ideas, sample text without specific names. Data policies typically allow providers to store and reuse the content you input. Enterprise AI with DPA (Data Processing Agreement): a tool that commits clearly to not using your data to train models, has mechanisms for data deletion, and assumes legal responsibility. This is the minimum option when sensitive data must be input into AI.

What needs to be checked before using any tool: does this tool have a DPA, will the data I input be used for training, and who has access to that data?

Minimization: core principle

Data minimization means only including the necessary parts for specific tasks in AI, not the entire record "just in case." This principle comes from international data protection standards and has clear practical reasons: data not included cannot be exposed.

  • Before inputting data into AI, ask: what data fields does this task really need?
  • Blur or replace names, phone numbers, and addresses before submission if the task does not require identifiable information.
  • Schedule deletion: delete data that is no longer needed, do not keep it "just in case."

Don't process personal data just because it might be useful later. Each processing needs a legal basis.

ICO, Data minimisation (AI and data protection toolkit)

Common mistakes and how to recognize them

  • Directly inputting client lists into free AI: a familiar action but carries the risk of data exposure. It’s not just because AI "repeats" immediately, but because there is no control over where that data goes afterward.
  • Using personal AI accounts for company work: when the account is beyond the organization's control, no one can check or revoke access when an employee leaves.
  • Thinking anonymity is enough: Many pieces of data combined can still identify individuals even if each piece has had names removed. Anonymization needs to be accompanied by minimization.
  • Unaware of the data policy of the tools being used: this is the most common gap. Using without reading the terms means accepting conditions without knowing what you are agreeing to.

The viewpoint of Sinh Vũ

Data discipline is a condition of credibility, not an additional burden. Customers trust you with sensitive information because they believe in how you operate, not because they are sure you won't be careless.

Sinh Vũ operates along three clear lines: confidential data and personal information of clients do not enter public AI tools. When AI support is needed, priority is given to environments committed to data protection, and only minimal, anonymized data is used. Any decision involving personal data requires approval. When issues exceed our scope, we refer them to security or legal experts instead of handling them ourselves.

You don’t need to be a technical expert to practice this. Just have a clear internal policy: which data is allowed into which AI, who is allowed to use it, and when in doubt, ask before proceeding.

The tool brings back.

Decision checklist

Topic: Protecting customer data when using AI. Sinh Vũ guide, sinhvu.com

0 more than 7 items

Select each item you find appropriate, then print or save as PDF to take with you.

Sign indicating that you should take action
Questions to answer before deciding

If you have marked most of the signs above, this is the time to discuss in more detail. Sinh Vũ can help you review and propose a direction.

References

NIST AI Risk Management Framework (AI RMF 1.0), privacy-enhanced section. ICO: Data minimization in AI and data protection toolkit. ICO: How do we ensure lawfulness in AI? Credal: Acceptable Use Policies for Generative AI. Practical experience from Sinh Vũ Studio.

Frequently asked questions

Is it okay to use the free version of ChatGPT to analyze the customer list?

There are real risks. The public free version often does not have a separate data processing agreement with organizational users, and data may be stored and used to improve the model. If personal information analysis is needed, use the enterprise version with a data protection commitment, and only include parts that have been anonymized.

Is data anonymization safe enough before feeding it into AI?

Anonymization reduces risk but is not foolproof. Many data points combined can still identify individuals, even if each point has been stripped of names. The correct practice is to combine anonymization with minimization: only include the data fields truly necessary for that specific task, not the entire profile.

When should you consult a security expert instead of handling it yourself?

When there is a large volume of personal data, when data moves across national borders, when belonging to tightly regulated industries like finance or healthcare, or when AI is used to make decisions that directly affect individuals. In these cases, Sinh Vũ does not make judgments but refers to legal or security experts.

← Back to Brand AI