You will be able to recognise the kinds of information that should not go into an assistant without approval.
Before you paste anything into an AI assistant, check whether it contains personal data or confidential business data. If it does, it stays out until your company has approved that use, and when you can't tell, you ask your manager or the data protection officer instead of deciding on your own.
Hafiz, whom you met in Lesson 2.1, handles a lot of HR-type material. On a normal Tuesday, before lunch, a medical certificate arrives by email. A manager sends him notes for a staff appraisal. Finance asks him to confirm next month's payroll changes. A recruitment agency forwards three CVs with the candidates' phone numbers, home addresses and expected salaries. In between, he is rewriting a job advert. Hafiz and his Tuesday are an invented example, but the mix will look familiar.
None of this feels dramatic. It is ordinary work, and because handling it feels routine, sensitive information is easy to paste into an assistant without thinking. An assistant could help Hafiz with every one of these tasks, so he needs a quick way to tell which items can go in.
Personal data is information about a person who can be identified from it, either on its own or combined with other information you hold. A name alone may or may not identify someone. A name with a phone number, email address or employee ID does.
In an office, the common examples are names with contact details, NRIC numbers, dates of birth, home addresses, salaries and bank account numbers. Some categories need extra care because a leak does more harm: health information such as medical certificates and diagnoses, performance and disciplinary records, and anything about a person's finances or family circumstances. Hafiz's medical certificate, appraisal notes and payroll changes each fall into one of these categories.
Personal data also turns up where people don't look for it. A screenshot of a group chat shows names and phone numbers. A meeting transcript records who said what. A customer order spreadsheet holds names, addresses and buying history. A useful rule of thumb: if you would be uncomfortable seeing it forwarded to a stranger, treat it as personal data.
In Singapore, the PDPA (Personal Data Protection Act) governs how organisations collect, use and disclose personal data. Broadly, organisations should collect and use personal data only for purposes people were told about and agreed to, protect it with reasonable security, and not keep it longer than needed. The Personal Data Protection Commission oversees the Act and publishes guidance at pdpc.gov.sg.
If Hafiz pastes a staff member's details into an outside assistant, his company is sending personal data to a third party. Whether that is allowed depends on factors such as the purpose, the company's agreement with the provider and the security in place. A company-approved tool under a proper contract is a very different situation from a personal account on your phone. The company is responsible for how personal data is handled, and that responsibility reaches you through the company policy and the data protection officer, so this is a call you should not make alone. Lesson 2.3 covers how to find and apply your company's policy on handling personal data.
Confidential business data is information the company or its clients would not want outside the organisation. Typical examples are client lists and contact databases, contracts and their terms, pricing and margins, unreleased financial results, product or restructuring plans, and anything covered by a non-disclosure agreement.
To test a document, ask two questions. Would the company or a client object if it appeared outside the firm? Would it hurt if a competitor got it? If the answer to either is yes, it is confidential. Material is confidential whether or not it is labelled, and many of the most important documents carry no label at all.
Client data is often personal and confidential at once. A list of a client's employees with their salaries is both. When both apply, follow the most restrictive rule.
Some cases are genuinely unclear, such as whether an internal org chart is confidential, or whether a summary of anonymous survey comments counts as personal data when the team has only four people. When you are unsure, treat the material as confidential and ask your manager or the company's data protection officer. Asking takes a few minutes, while undoing a disclosure is much harder and sometimes impossible.
Hafiz uses a quick three-colour sort to decide what can go into an assistant:
Green: already public, or contains nothing about people or clients, such as a published job description. Fine to use. Amber: internal material with no personal details, such as a draft policy. It can go into an approved company tool. Red: anything with personal data, health or pay details, or client confidential terms. It stays out of any assistant unless it has been redacted or the policy clearly allows it.
When he sorts his Tuesday, the medical certificate, the appraisal notes, the payroll changes and the CVs are all red. The only green item is the job advert he was rewriting. If something doesn't fit cleanly into one colour, he treats it as confidential and asks his manager or the data protection officer before using it.
Sorting your own files this way tends to change how people see their week. Work through a week of your own files with the same three colours in mind, and pick out five examples of the personal or confidential data you handle.
Go through one week of your work files and list five examples of personal or confidential data you handle, sorted by how sensitive each one is.
Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).