Safety, Privacy & Compliance

Sensitive Data Field Classification and Handling Reviewer

Classify data fields by sensitivity, necessity, access, retention, masking, transfer, and review requirements without claiming legal compliance.

Last updated Jul 18, 2026
FreeClaudeChatGPT
TL;DR

Sensitive Data Field Classification and Handling Reviewer is a free AI skill for safety, privacy & compliance. Classify data fields by sensitivity, necessity, access, retention, masking, transfer, and review requirements without claiming legal compliance. It works with Claude, ChatGPT and is ready to use out of the box.

Download Skill.md Package

About this skill

Turn a field list, schema, form, export, or integration payload into a practical data-handling matrix. The skill identifies direct and indirect identifiers, secrets, regulated or confidential information, purpose, minimization, access, masking, logging, transfer, retention, and deletion needs.

What it does

It creates a field-level sensitivity and handling map, flags excessive collection and exposure, and produces implementation and review actions.

What is included

  • Field inventory
  • Sensitivity classification
  • Purpose and necessity review
  • Access and role matrix
  • Masking and redaction rules
  • Logging and analytics controls
  • Transfer and third-party review
  • Retention and deletion needs
  • Risk-ranked findings
  • Implementation checklist

How to use it

1. Download the sensitive-data-field-classification-and-handling-reviewer-SKILL.md file
2. Upload it to Claude, ChatGPT, or your privacy-review workspace
3. Provide field names, descriptions, sources, purposes, users, storage, transfers, and retention context
4. Use schemas or synthetic examples rather than real sensitive values
5. Have qualified privacy, legal, security, and data owners approve the final handling rules

Examples

Example input
Review the fields in our signup form, CRM, support system, analytics events, and AI prompt logs. Classify sensitivity and recommend collection, masking, access, retention, and deletion controls.
Example output
A field inventory, sensitivity level, purpose, necessity, access roles, masking, logging, transfer, retention, deletion, risks, and implementation actions.

FAQ

Can the skill confirm whether a field is legally regulated?
No. It can identify common sensitivity patterns and flag areas requiring qualified legal or privacy review.
What are indirect identifiers?
They are fields that may identify a person when combined, such as job title, date, location, and rare event details.
Does masking make data anonymous?
Not necessarily. Masking reduces exposure, but re-identification and linkage risk may remain.
Can it review analytics events?
Yes. It checks whether event properties include unnecessary identifiers, content, or sensitive metadata.
Should sensitive values appear in logs?
Usually they should be minimized, masked, or excluded, but the correct rule depends on the operational need and approved policy.
How is this different from a general privacy policy?
It creates field-level technical handling requirements for collection, access, masking, logging, transfer, retention, and deletion.

Related Skills

Safety, Privacy & ComplianceFree

Data Access and Least Privilege Reviewer

Review data access for least privilege, role design, sensitive fields, segregation, approvals, logging, reviews, and revocation.

ClaudeChatGPT
#least privilege#data access review#privacy controls
Safety, Privacy & ComplianceFree

Data Retention and Deletion Policy Mapper

Map data categories to retention, deletion, legal-hold, backup, archive, ownership, and evidence requirements without claiming legal compliance.

ClaudeChatGPT
#data retention#data deletion#privacy policy
Safety, Privacy & ComplianceFree

Sensitive Data Redaction Workflow Designer

Design redaction workflows for documents, logs, prompts, exports, and datasets using detection, review, masking, validation, access, and evidence.

ClaudeChatGPT
#data redaction#privacy workflow#sensitive information

Related Prompts

Free

Privacy-Safe Data Sharing Review

Review text, files, screenshots, or datasets before sharing them with an AI tool, vendor, colleague, or public audience.

ClaudeChatGPT
#data privacy#redaction#data minimization
Free

Vendor Security & Compliance Risk Review

Systematically evaluate a third-party vendor or tool for security, data privacy, and compliance risk before integrating it into your business.

ClaudeChatGPT
#vendor risk#security review#compliance
Free

Sensitive Document Redaction Check

Create a precise redaction plan for a document or screenshot before external sharing while preserving the information needed for the task.

ClaudeChatGPT
#document redaction#sensitive data#metadata

Related Articles

Article · Safety & Review

AI Privacy Checklist Before Launching an AI App

A practical, non-legal checklist covering data collection, uploads, logging, admin access, and disclosure before launching an AI app.

Jul 6, 20268 min read
Read AI Privacy Checklist Before Launching an AI App
Article · Safety Privacy and Compliance AI Skills

How to Use an AI Security Review Skill Before Launching a Vibe-Coded App

Use an AI security review skill to prepare a vibe-coded app for safer launch without sharing secrets or claiming compliance.

Jul 8, 20268 min read
Read How to Use an AI Security Review Skill Before Launching a Vibe-Coded App