Unit 10 / 11

Privacy, Data Security and Verification Habit

Gains:

  • Ability to classify data according to its sensitivity (public/internal/confidential/critical) and anonymise confidential and critical data without revealing them to public tools
  • Turning verification into a reflex and marking the facts, going to the source and scaling the steps of opening the source given by artificial intelligence according to the risk
  • Ability to apply the ethics of transparency, attribution and confidentiality by understanding that deletion is not protection and that responsibility cannot be attributed to the medium.

Two principles recurred in each unit of this module: maintain confidentiality and verify each output. This unit turns those two principles into one systematic discipline — because the biggest risks of using AI in personal productivity are not speed or quality, but leaked data and unverified falsehood. One incorrect email can be corrected; Customer data that has been sent to the server cannot be retrieved. A made-up number presented in a confident tone will disprove a decision if not noticed. That's why privacy and authentication are foundations of efficiency that are built from the ground up, not "added in later."

Terms. Personal data is information that identifies a person — name, ID number, email, health, location. KVKK/GDPR are the laws that regulate the protection of personal data (KVKK in Türkiye, GDPR in the EU). Data classification is the act of labeling information according to its sensitivity (public, internal, confidential). Anonymization is the removal of personally identifiable elements from data. Verification is verifying the accuracy of an output with an independent source.

Privacy: what to paste, what not to paste

Everything you type into the AI ​​tool, in most cases, goes to a server and is stored in some service or can be used to train the model. So the basic question is: are you willing to give this information to an unknown third party? If the answer is no, don't give it to AI either.

Use a simple classification:

class

example

Does it fall into AI?

General

Published information, draft text

free

interior

Process note, generic meeting summary

By anonymizing

secret

Customer data, financial record, strategy

Only institution-approved vehicles

critical

Password, API key, contract, health

never

Practical protections: anonymize personal data (make names “Person A”, company “Company X”); use your institution's approved AI tool (enterprise versions often guarantee not to use the data in training); and read your AI use policy — otherwise default to caution.

Caution: The "I deleted the chat, it's now safe" assumption is wrong. Deleting removes it from the interface, but does not restore the record on the server or the data involved in the training. Protection begins before bonding; not after.

Validation: a systematic habit

Make verification a reflex rather than "I'll do it if I think of it." Here's a practical verification discipline:

  1. Mark the facts. Every name, date, number, quote, piece of legislation, claim in the printout — these will be verified.
  2. Go to the source. Confirm every fact with an independent, reliable source. Open the source given by AI and read it; Does it exist, does it contain that information?
  3. Scale according to risk. Slight control on a low-risk internal note; Complete control of a high-stakes presentation or external communication.
  4. Accept the uncertain. If the AI ​​says “not sure” or the information cannot be confirmed, do not fill in the blank with fabrication; Leave it as "unverified".

Key distinction: You can generally trust the AI's language work (fluent sentence, neat structure, appropriate tone). Never blindly trust AI's claims of fact (this number, this date, this source). Validation is separating the two.

Ethics: transparency and responsibility

Using AI for efficiency isn't an ethical issue — but how you use it might be. Three principles: Transparency — in some contexts (academic work, journalism, official document) you may need to indicate that you are using AI. Attribution — taking someone else's idea through AI and presenting it as your own is plagiarism, even if the medium changes. Responsibility — everything you post is your responsibility; "AI wrote it" is not an excuse.

Step by step: secure AI workflow control

  1. Sort before pasting. In which class is this data? Stop if secret/critical.
  2. Anonymize. Remove personal items if not necessary.
  3. Produce and mark the facts. Identify the items in the output to validate.
  4. Verify. Risk-scaled, source-based confirmation.
  5. Own it. Retouch with your own voice, take responsibility.
  6. Know your mark. Keep track of what you pasted where and which tool stores the data.

Four copyable security/authentication templates

Anonymize the following text before giving it to AI:- Change names to "Person A/B" and companies to "Company

List all the facts that need to be verified in this AI output:- Make a separate bullet point for each name, date, number, statistic, quote, and claim.- Ask “how do I verify?” for each. Suggest (which source).- Flag unverifiable/doubtful ones. Output: """[paste]"""

Verify the following claim according to the source you gave: Claim: [number/fact].- Is this claim really included in the source you mentioned?- Otherwise, say "I couldn't verify it in this source", make it up.- If you are not sure, do not speak as if you are sure.

Check what privacy risks there are in this task:Task: [The work I intend to do with AI, with what data].- Which data class does it fall into (public/internal/confidential/critical)?- Should it go into a public AI tool or not?- If not, what is the safe alternative?

Weak prompt / Strong prompt

Weak: “Summarize that customer complaint email.” (It includes the customer's name, order ID, maybe phone — it all goes directly to the server.)

Strong: First anonymize the text ("Customer A, order [id hidden], complains about this product"), then say "summarize this anonymized text". Same efficiency, zero personal data leaks. The difference is not in the output, but in maintaining the input.

three mini cases

Case 1 — Irreversible leak. An employee pasted the entire customer list (name, phone, spend) into a generic AI tool to “segment them.” The institution evaluated this as a violation of KVKK; the data was now on the third party server and could not be retrieved. The same analysis could be done risk-free with anonymized data or an enterprise tool.

Case 2 — It gives the verification reflex. One journalist made it a rule to fact-check every statistic and quote given by the AI ​​at its original source before publication. In one week, he found that 2 out of 5 “facts” given by the AI ​​were fake. This reflex prevented possible false news and loss of reputation.

Case 3 — The "AI wrote it" excuse didn't work. A consultant sent an AI-generated report to the client without verifying it; The false legal claim in it misled the customer. The “it came from AI” defense did not hold water with either the customer or the regulator; The responsibility was on the consultant. Lesson: the tool changes, the responsibility does not.

Common mistakes

  • Pasting confidential/critical data: The most expensive and irreversible mistake; classify first.
  • Thinking "I deleted it, I'm safe": Deletion does not undo the server registration; protection before pasting.
  • Confusing fact with language: Trust the language, verify the fact—separate the two.
  • Not opening the source given by the AI: May produce fake imprint; see source.
  • Putting the blame on the tool: "AI wrote it" is no excuse.
  • Not knowing the policy: Read the organization's AI usage policy; Otherwise, be cautious.
Tip: Give yourself a simple personal rule: "I don't paste anything confidential or critical into the public AI tool; I verify every figure and source before sending it." This two-sentence rule cuts most of the risks in this module right off the bat.

In summary

  • The biggest AI risks are not speed or quality, but leaked data and unverified inaccuracy.
  • Classify data (public/internal/confidential/critical); Don't give the confidential and critical to public AI tools, anonymize it.
  • Deletion is not protection; Protection begins before gluing.
  • Turn verification into a reflex: flag facts, go to the source, open the source of the AI, scale according to risk.
  • Trust the language of AI, trust its facts; The responsibility does not fall on the vehicle, it is always yours.

Application task

Take an actual text that you will give to the AI ​​this week. With the fourth template, first determine the privacy class; If there is confidential data, anonymize it with the first template. After receiving the AI ​​output, have the second template list the facts to be verified and confirm at least one of them at the original source. Write yourself a two-sentence privacy-verification rule and post it somewhere.

checklist

  • [ ] I classified the data before pasting it.
  • [ ] I did not provide confidential/critical data to the public AI tool; I anonymized it if necessary.
  • [ ] I verified every fact (name, date, number, source) in the output.
  • [ ] I opened the source given by AI and checked if it actually contains it.
  • [ ] I made sure I knew the corporate AI policy.
  • [ ] I took responsibility for the final output.