Using AI does not mean customer data must follow.
Do not input confidential data or personal information into public AI tools; this is a minimum safety practice, not an option. When it is necessary to use AI with sensitive data, choose tools with clear data processing agreements, only input what is truly needed, and ensure identification information is obscured. Any decision affecting personal data must be approved beforehand.
From the brief stage, Sinh Vũ is already exposed to sensitive client data: names, contact numbers, contracts, unpublished strategies. When AI begins to participate in the workflow, the question is not "Is AI useful?" but rather "What data is fed into AI, and what data is absolutely off-limits?" The answer to that determines your credibility with clients, just as much as the quality of the product.
Not every piece of data requires the same level of protection. It is necessary to clearly distinguish four layers:
The most common mistake is treating all data as a single block, then making decisions based on convenience rather than risk levels.
What needs to be checked before using any tool: does this tool have a DPA, will the data I input be used for training, and who has access to that data?
Data minimization means only including the necessary parts for specific tasks in AI, not the entire record "just in case." This principle comes from international data protection standards and has clear practical reasons: data not included cannot be exposed.
Don't process personal data just because it might be useful later. Each processing needs a legal basis.
ICO, Data minimisation (AI and data protection toolkit)
Data discipline is a condition of credibility, not an additional burden. Customers trust you with sensitive information because they believe in how you operate, not because they are sure you won't be careless.
Sinh Vũ operates along three clear lines: confidential data and personal information of clients do not enter public AI tools. When AI support is needed, priority is given to environments committed to data protection, and only minimal, anonymized data is used. Any decision involving personal data requires approval. When issues exceed our scope, we refer them to security or legal experts instead of handling them ourselves.
You don’t need to be a technical expert to practice this. Just have a clear internal policy: which data is allowed into which AI, who is allowed to use it, and when in doubt, ask before proceeding.
Topic: Protecting customer data when using AI. Sinh Vũ guide, sinhvu.com
Select each item you find appropriate, then print or save as PDF to take with you.
If you have marked most of the signs above, this is the time to discuss in more detail. Sinh Vũ can help you review and propose a direction.
NIST AI Risk Management Framework (AI RMF 1.0), privacy-enhanced section. ICO: Data minimization in AI and data protection toolkit. ICO: How do we ensure lawfulness in AI? Credal: Acceptable Use Policies for Generative AI. Practical experience from Sinh Vũ Studio.
There are real risks. The public free version often does not have a separate data processing agreement with organizational users, and data may be stored and used to improve the model. If personal information analysis is needed, use the enterprise version with a data protection commitment, and only include parts that have been anonymized.
Anonymization reduces risk but is not foolproof. Many data points combined can still identify individuals, even if each point has been stripped of names. The correct practice is to combine anonymization with minimization: only include the data fields truly necessary for that specific task, not the entire profile.
When there is a large volume of personal data, when data moves across national borders, when belonging to tightly regulated industries like finance or healthcare, or when AI is used to make decisions that directly affect individuals. In these cases, Sinh Vũ does not make judgments but refers to legal or security experts.