The risky moment is often ordinary. Someone copies a long email into a chatbot because they want a shorter version. The email includes a client’s history, an attachment and six earlier replies. A five-minute writing task has become a decision about sharing someone else’s information.
Before pasting, ask two questions: does the tool need this information, and has this particular use been approved? Having access to a file at work does not automatically mean you can send it to another service.
The checklist below is a cautious starting point for general-purpose workplace chatbots. An approved specialist system handling personal information needs its own assessment, contract and procedures. A coloured label cannot replace that work.
Red: keep it out of a general-purpose chatbot
- Passwords and secrets. Never paste passwords, one-time verification codes, recovery codes, private keys, API keys or access tokens. Use your organization’s approved password and secret-management tools.
- Client, patient or service-user records. Case notes, assessments, counselling information and descriptions of someone’s circumstances belong in approved systems. Changing a name to “Client A” may still leave them identifiable.
- Information about children. Keep identifiable school, family, health and service records out. Small details can identify a child even when a document has no name on it.
- Personnel records. Performance reviews, accommodation requests, complaints, disciplinary matters, payroll and job applicants’ personal information need appropriate handling.
- Donor and customer lists. Names, addresses, donation history, purchases and contact preferences should not become convenient material for a prompt.
- Financial and identity documents. Bank details, payment card information, tax identifiers and identity documents should stay out.
- Material with a separate confidentiality obligation. Private board discussions, legal advice and information covered by a client agreement need review before any new use or disclosure.
When you need help with the shape of a document, make up the details. A fictional intake form can demonstrate a layout without including a real person’s story. For an email, ask for a generic structure and add the sensitive details yourself in your approved work system.
Yellow: pause and check
Some information needs a judgment call from the person responsible for it:
- An unpublished budget with no personal account information
- An internal process document or draft proposal
- A contract with identifying and confidential details removed
- Meeting notes believed to contain no personal information
- A summary of client activity or survey results
Check permission, the business purpose and the approved tool before proceeding. “Internal” is not a useful enough classification by itself. A lunch rota and an acquisition plan may both be internal, but the consequences of sharing them are very different.
Aggregated information can also reveal someone in a small group. “The only participant at the Tuesday session” can be identifying without a name. If you cannot confidently remove that risk, use synthetic data or leave the task outside the chatbot.
Green: a reasonable place to start
Lower-risk examples include your organization’s published service descriptions, an event announcement already approved for public use, fictional training scenarios and a generic question about how to structure an agenda.
Green still means checking that you are entitled to use the material and that the task is permitted. A person’s contact details appearing on a website do not make every new use appropriate. Canadian privacy regulators explicitly caution that information being accessible online does not remove privacy obligations. See their guidance on limiting collection and use.
Review the answer before using it. Low-risk input does not guarantee accurate output.
A paid plan does not answer all the privacy questions
A business subscription may have different terms and controls from a personal or free account. Read the terms for the exact product and plan you are using, then verify the settings in your workspace. Do not approve an upload because the account has a company email address or a paid badge.
Treat these as separate questions:
- Training: Are prompts, files and outputs used to train or improve models? Can feedback submissions change that treatment?
- Storage: What is retained, for how long and for what purpose? What happens to uploaded files, backups and logs when a chat is deleted?
- Access: Who in your organization or at the provider can access the information? What access do support staff and subprocessors have?
- Connections: Do extensions or connected services receive information under different terms? Which folders, mailboxes or other records can they reach?
- Control: Can an administrator enforce settings, remove departing staff, review activity and end access promptly?
A promise about training does not, by itself, answer storage or access questions. Record the answers and their source, rather than relying on a settings screenshot alone. OIPC’s cloud guidance stresses reviewing the provider’s contract and retaining accountability when personal information is outsourced. Read the cloud guidance.
A short note on BC privacy duties
In BC, PIPA generally governs private-sector organizations, including businesses, charities and nonprofits. For organizations subject to it, collecting, using or disclosing personal information needs authority under the Act, generally consent unless an exception applies, and a purpose a reasonable person would consider appropriate. Organizations must make reasonable security arrangements and remain responsible for information under their control when a vendor processes it. Retention and access obligations also matter. OIPC’s private-sector resources, its AI scribe guidance and its explanation of security and retention duties provide context. The scribe guidance is healthcare-specific; it is not a general approval for chatbot use. This paragraph is general information, not legal advice. Your sector, activities and information flows may bring other laws, contracts or professional duties into play.
Three habits that make this easier
1. Work from a clean excerpt. Read the exact text you intend to share. Remove email signatures, reply chains, comments, screenshots and unnecessary details before moving anything. Prefer a fictional example when it answers the same question. Do not send the original document to the chatbot and ask it to anonymize the document after upload.
2. Check the account before each new task. Confirm that you are in the approved work account and that the tool and feature are allowed for the information involved. A personal browser profile, a new extension or a newly connected app can change the situation.
3. Have an easy route for uncertainty and mistakes. Staff need a named person to ask before an upload, and a clear way to report one that should not have happened. If information is shared accidentally, stop using that workflow, record the tool and time, and report the kind of information involved without copying it into another channel. Let the responsible person coordinate containment and assess next steps.
A useful rule for a busy day is simple: if you cannot explain why this tool needs this information and who approved the use, stop before pasting. Getting the answer first is easier than trying to recover information after it has been shared.