Your Prompts Are Data: Handling Employee Inputs Correctly

Organisations spend considerable care on which documents may be uploaded to an AI system, and almost none on what employees type into it. The typing is where the unpredictable data goes.

What actually gets typed

Consider an ordinary day. Someone pastes a customer's angry email to get help drafting a measured reply. Someone pastes a CV to summarise it. Someone describes a dispute with a supplier to think through options. Someone pastes an internal report to produce a summary. Someone asks how to handle a colleague's performance problem, describing the situation in detail.

Each is a sensible use. Each puts personal data — some of it sensitive — into the system. And none of it was in the plan.

Why this is a data protection matter

Personal data does not become less regulated because it arrived by paste rather than upload. The customer's email is their personal data. The described performance problem is the colleague's.

Your processing agreement, your record of processing activities and your retention policy all need to account for this. If they describe only the documents you formally process, they describe a fraction of what actually happens.

Where it goes wrong

Consumer accounts. If staff use free public tools, company data is going into services with no agreement, no defined location and, depending on the terms, possible use for model improvement. This happens in most companies that have not provided a sanctioned alternative.

Conversation history. Retained conversations are a store of whatever was pasted, often for a long time, frequently outside your normal retention rules.

Shared workspaces. Where conversations can be shared with colleagues, a summary containing personal data can reach people with no need to see it.

Access requests. If someone exercises their right of access, does your answer cover what employees typed into an assistant about them? For most companies the honest answer is that they could not find out.

What to do about it

Provide a sanctioned option. This is the substantive fix. Staff use these tools because they help. Give them one inside your environment, under your contracts, reached through your identity system — and the informal usage largely stops on its own.

Write one page of rules. Not a policy document nobody reads. A short, concrete list: what may go in, what must never, and what to do when unsure. Include examples, because abstract categories do not help someone at their desk.

Set retention deliberately. Decide how long conversations are kept and make it match your other retention rules. Indefinite by default is a decision, just not a considered one.

Cover it in your records. Your Art. 30 record should reflect that employee inputs are processed, with the categories of data that realistically appear.

Tell people the reasoning. Staff comply with rules they understand. "Do not paste customer data into external tools" invites workarounds; explaining that the company must be able to say where customer data went does not.

The underlying point

The risk here is not that employees are careless. It is that a text box accepts anything and nobody treats typing as a data transfer. Naming that clearly, once, changes behaviour more than any technical control.

This article is general information, not legal advice. For your specific situation, consult a qualified lawyer.

All Articles
Let’s Talk

about the process
AI should run.