Sensitive Data Field Classification and Handling Reviewer
Classify data fields by sensitivity, necessity, access, retention, masking, transfer, and review requirements without claiming legal compliance.
Sensitive Data Field Classification and Handling Reviewer is a free AI skill for safety, privacy & compliance. Classify data fields by sensitivity, necessity, access, retention, masking, transfer, and review requirements without claiming legal compliance. It works with Claude, ChatGPT and is ready to use out of the box.
About this skill
Turn a field list, schema, form, export, or integration payload into a practical data-handling matrix. The skill identifies direct and indirect identifiers, secrets, regulated or confidential information, purpose, minimization, access, masking, logging, transfer, retention, and deletion needs.
What it does
It creates a field-level sensitivity and handling map, flags excessive collection and exposure, and produces implementation and review actions.
What is included
- Field inventory
- Sensitivity classification
- Purpose and necessity review
- Access and role matrix
- Masking and redaction rules
- Logging and analytics controls
- Transfer and third-party review
- Retention and deletion needs
- Risk-ranked findings
- Implementation checklist
How to use it
1. Download the sensitive-data-field-classification-and-handling-reviewer-SKILL.md file 2. Upload it to Claude, ChatGPT, or your privacy-review workspace 3. Provide field names, descriptions, sources, purposes, users, storage, transfers, and retention context 4. Use schemas or synthetic examples rather than real sensitive values 5. Have qualified privacy, legal, security, and data owners approve the final handling rules
Examples
Review the fields in our signup form, CRM, support system, analytics events, and AI prompt logs. Classify sensitivity and recommend collection, masking, access, retention, and deletion controls.
A field inventory, sensitivity level, purpose, necessity, access roles, masking, logging, transfer, retention, deletion, risks, and implementation actions.
FAQ
Can the skill confirm whether a field is legally regulated?
What are indirect identifiers?
Does masking make data anonymous?
Can it review analytics events?
Should sensitive values appear in logs?
How is this different from a general privacy policy?
Related Skills
Data Access and Least Privilege Reviewer
Review data access for least privilege, role design, sensitive fields, segregation, approvals, logging, reviews, and revocation.
Data Retention and Deletion Policy Mapper
Map data categories to retention, deletion, legal-hold, backup, archive, ownership, and evidence requirements without claiming legal compliance.
Sensitive Data Redaction Workflow Designer
Design redaction workflows for documents, logs, prompts, exports, and datasets using detection, review, masking, validation, access, and evidence.
Related Prompts
Privacy-Safe Data Sharing Review
Review text, files, screenshots, or datasets before sharing them with an AI tool, vendor, colleague, or public audience.
Vendor Security & Compliance Risk Review
Systematically evaluate a third-party vendor or tool for security, data privacy, and compliance risk before integrating it into your business.
Sensitive Document Redaction Check
Create a precise redaction plan for a document or screenshot before external sharing while preserving the information needed for the task.
Related Articles
AI Privacy Checklist Before Launching an AI App
A practical, non-legal checklist covering data collection, uploads, logging, admin access, and disclosure before launching an AI app.
How to Use an AI Security Review Skill Before Launching a Vibe-Coded App
Use an AI security review skill to prepare a vibe-coded app for safer launch without sharing secrets or claiming compliance.