Privacy-Safe Data Sharing Review
Review text, files, screenshots, or datasets before sharing them with an AI tool, vendor, colleague, or public audience.
Anyone preparing customer exports, screenshots, support tickets, resumes, financial notes, research data, logs, or business documents for AI-assisted work or external sharing.
Act as a privacy-first data-sharing reviewer. Help me reduce unnecessary exposure before I upload, paste, email, publish, or send the material described below.
Material or data description:
{{material_description}}
Who will receive it and why:
{{recipient_and_purpose}}
Optional sample or field list:
{{sample_or_fields}}
Review the planned sharing using this structure:
1. Data inventory: identify personal data, confidential business information, credentials, financial information, health information, location data, private communications, intellectual property, metadata, and indirect identifiers.
2. Necessity test: state which fields are necessary for the stated purpose, useful but optional, or unnecessary. Apply data minimization rather than assuming the whole file must be shared.
3. Exposure level: rate the planned sharing as Low, Medium, High, or Critical risk and explain the main drivers, including recipient, retention, onward sharing, public visibility, and reversibility.
4. Safer transformation: specify what to remove, generalize, mask, aggregate, replace with synthetic examples, crop, blur, or summarize. Do not repeat sensitive values in the response.
5. Residual risk: explain what can still be inferred after redaction, including re-identification from combinations such as job title, date, location, and rare events.
6. Safer sharing plan: recommend the minimum necessary version, access method, recipient limits, retention period, and confirmation steps.
7. Decision: label the material Safe to share as transformed, Needs additional review, or Do not share through this channel.
Rules: Never request passwords, access tokens, private keys, full payment-card numbers, government ID numbers, or real production secrets. Do not claim legal compliance. If the data involves children, patients, employees, customers, regulated records, or a large dataset, recommend a qualified privacy or legal review.How to use
- Describe the data fields, recipient, purpose, sharing channel, and whether the material will be retained or made public.
- Use synthetic or redacted samples instead of pasting real sensitive records into the prompt.
- Create a transformed copy rather than editing the only original file.
- Have an authorized person review high-risk or regulated data before sharing.
Example input
Material: a CSV of customer support tickets with names, emails, order numbers, message text, timestamps, and internal agent notes. Recipient and purpose: upload to an AI assistant to identify the top complaint themes.
Example output
Risk: High because the full file contains direct identifiers, order references, free-text personal details, and internal notes that are unnecessary for theme analysis. Create a reduced copy containing a synthetic ticket ID, generalized date, product category, and redacted message text. Remove names, emails, exact order numbers, addresses, signatures, and internal notes unless a specific field is essential. Test a small sample first and set a short retention expectation.
Customization tips
- — Ask for field-by-field keep, remove, mask, or aggregate recommendations for spreadsheets.
- — For screenshots, describe visible tabs, notifications, browser bars, filenames, and background windows that may leak context.
- — For analytics, specify the minimum grouping or aggregation level needed to answer the question.
Tags
FAQ
Is removing names enough to anonymize data?
Can I paste secrets so the model can tell me whether they are sensitive?
What is data minimization?
Can this prompt confirm GDPR compliance?
Should I keep the original unredacted file?
Related Prompts
All Safety & Review prompts →Sensitive Document Redaction Check
Create a precise redaction plan for a document or screenshot before external sharing while preserving the information needed for the task.
Vendor Security & Compliance Risk Review
Systematically evaluate a third-party vendor or tool for security, data privacy, and compliance risk before integrating it into your business.
Public Content & Brand Safety Review
Review public-facing copy before publication for harmful ambiguity, unsupported claims, privacy leaks, disclosure gaps, audience risk, and brand damage.
Related Skills
AI Governance & Compliance Checklist
Reviews an AI-related workflow, tool, or output against a practical governance checklist covering data privacy, bias, accountability, and transparency.
Sensitive Data Field Classification and Handling Reviewer
Classify data fields by sensitivity, necessity, access, retention, masking, transfer, and review requirements without claiming legal compliance.
Sensitive Data Redaction Workflow Designer
Design redaction workflows for documents, logs, prompts, exports, and datasets using detection, review, masking, validation, access, and evidence.
Related Articles
AI Privacy Checklist Before Launching an AI App
A practical, non-legal checklist covering data collection, uploads, logging, admin access, and disclosure before launching an AI app.
How do I keep private data out of AI tools?
Keeping private data out of AI tools requires redaction, data minimization, access rules, safe examples, and awareness of what the tool stores or processes.
How do I redact sensitive information before using ChatGPT or Claude?
Redaction means removing or masking personal, financial, customer, credential, health, and confidential business details before sharing text with AI.