πŸ’¬ Everyday AI Β· The Lab Β· NBN IA

AI Course Β· Module 19 Β· Level ++

Professional privacy: GDPR & AI Act

At work, pasting the wrong data into an AI can be illegal (GDPR) or dangerous. Sort this professional data: OK to put in an AI, or forbidden / anonymise first? πŸ‘‡

01-18 βœ“19 Β· Pro privacy20 Β· Project 🏁
The game Β· sort the professional data

OK, or forbidden / anonymise?

Sort the 5 cases0 / 5
βš–οΈ GDPR: personal data (names, emails, phone numbers, health…) is protected β€” no processing without a legal basis or via an unapproved tool. AI Act (2026): transparency about AI-generated content. (General info, not legal advice.)
What this teaches you

The rule at work

🚫 Personal data = caution

Customers, employees, patients: their data doesn't go into a consumer AI. Use an "enterprise" tool with the right guarantees, or anonymise.

🏒 Check the internal policy

Many companies have rules about AI. Follow them. When in doubt, ask β€” and never expose a company secret.

Check that you got it

2 quick questions

1. Your customers' personal data, in a consumer AI tool?

Right: the GDPR protects that data. No processing without a legal basis, and not through a tool that wasn't meant for it.

2. What does the AI Act require for AI-generated content?

Right: clearly indicate that content was generated by AI. (General information, not legal advice.)

What to remember

  • Personal data (GDPR): never in a consumer AI β€” anonymise or use a dedicated tool.
  • Company secrets: out of the question to paste without a framework.
  • AI Act: flag AI-generated content (transparency).