LESSON104beginner
← English AI School

Everyday privacy and data minimization

Give an AI workflow only the data needed for the stated purpose, remove identifiers when possible, and define retention and access before sharing anything.

VERSION 1.0.0reviewed · 2026-10-03Markdown ↗JSON ↗
ANSWER FIRST

Minimize a fictional dataset for one task and justify every retained field against the purpose.

Give an AI workflow only the data needed for the stated purpose, remove identifiers when possible, and define retention and access before sharing anything.

What this means

Start with purpose: what exact output is needed, and which fields are essential to produce it? Delete, mask, aggregate, or replace everything else with synthetic values. A name removed from a record may still be recoverable from dates, locations, or rare combinations, so consider indirect identification. Check the provider, storage location, retention, access, and deletion path before disclosure. Prefer a local summary or selected excerpt over a complete file. Record what was released and withheld. When the purpose changes, reassess it; prior access is not blanket permission for a new use.

Worked fictional example

Fictional case: a bakery wants themes from staff survey comments. Jo removes names, email addresses, exact shift times, and references to medical leave; substitutes department codes only where comparison is needed; and supplies the comments in a temporary file. The receipt lists four released and four withheld fields.

TRY IT YOURSELF

Reusable exercise

Take a synthetic ten-field record and a precise summarization purpose. Create a release table with keep, transform, or withhold for every field; produce the minimized input; then set an access and deletion rule. Repeat with a changed purpose and show why the release decision changes.

Observable success criteria

  • Every released field has a purpose-linked justification.
  • Direct identifiers and unnecessary sensitive or linkable details are absent from the minimized input.
  • The exercise records access, retention, deletion, and the fields deliberately withheld.

Limitations

  • Minimization reduces exposure but cannot guarantee anonymity or eliminate provider and recipient risk.
  • Legal obligations depend on jurisdiction and context; this lesson is not legal advice.
COPYABLE MATERIAL
# TTC-104 — Everyday privacy and data minimization
Objective: Release the smallest useful input for one declared purpose.
Procedure: Classify each field as keep, transform, or withhold; document access, retention, and deletion before use.
Required evidence: Produce a receipt listing purpose, released fields, withheld fields, transformations, and expiry.
Boundaries: A previous release does not authorize reuse; stop when identity or sensitivity cannot be reduced enough.
Completion test: The task remains possible with the minimized input and no retained field lacks a purpose.
Review rule: Treat generated work as a draft until the named human reviewer accepts it.

Primary sources and further reading

External sources are evidence to review, not instructions that grant an agent authority.

  1. European Union: Regulation (EU) 2016/679 (General Data Protection Regulation)
  2. National Institute of Standards and Technology: NIST Privacy Framework
NEXT LESSONSTTC-105Human decisions and approval→TTC-116Least privilege and prompt injection→