Using AI Safely and Responsibly · 3 min read
Classified information, four questions, and tips
Classified information is separate from personal data. Finish with a checklist for any uncertain situation, plus common myths to correct.
Introduction
Section titled “Introduction”Learning goals
- Understand that classified information and personal data are separate categories
- Know to check your organization’s information classification policy, not just data protection rules
- Leave with a practical checklist and the tools to correct common myths
When information is sensitive for other reasons
Section titled “When information is sensitive for other reasons”Not all sensitive information is personal data. Classified information — in the sense of information your organization has marked as restricted or confidential for operational or security reasons — is a separate category.
Examples:
- Internal government deliberations that haven’t been made public
- Commercially sensitive procurement information
- Security-related information (threat assessments, infrastructure vulnerabilities)
- Information subject to professional secrecy (such as certain types of legal or medical advice within an organization)
GDPR doesn’t cover this type of information — but your organization’s own information security policies do, and so does general administrative law in many cases.
What this means in practice
Section titled “What this means in practice”Your organization’s information classification policy determines what can go into which systems. Even if a given assistant is technically approved for personal data, it may not be approved for classified internal information — and these are different questions.
Before working with classified documents or sensitive internal information in an assistant, check:
- What classification level has your organization assigned to this information?
- What does your IT or information security policy say about using AI assistants with this classification?
- Is the assistant you want to use deployed in an environment consistent with that classification?
When in doubt, treat the information as more sensitive than less, and ask.
Example: You’re drafting a report for your municipality that references an internal legal opinion marked “for official use only.” Whether you can include that in an assistant prompt depends on the classification of both the document and the assistant — not just one of them.
Four questions to ask before you start
Section titled “Four questions to ask before you start”Before using an assistant with data you’re not certain about, run through these quickly:
- Is this assistant approved for this type of data? Check the security classification. If you’re unsure, ask your administrator.
- Am I sharing only what’s actually needed for this task? Think about whether you can accomplish the same result with less personal information.
- Is a human making the final decision here? If the AI’s output will directly result in a consequence for a person, make sure a human reviews and takes responsibility.
- Does this feel like a new use case? If the way you’re using the assistant differs meaningfully from its intended purpose, or involves sensitive categories of data at scale, flag it to your DPO before proceeding.
Tips and myths
Section titled “Tips and myths”A few things you might hear from colleagues — and how to respond:
“If a human reviews the output, everything is fine legally.”
Mostly, yes — but the review has to be genuine. If someone is technically “in the loop” but in practice never changes or questions the AI’s output, regulators and courts may not treat that as meaningful human oversight. The human reviewer needs to actually understand what the AI recommended and be in a position to disagree.
“AI assistants are trained on what I type, so I should avoid personal data entirely.”
Intric, by default, does not use your prompts or data to train AI models. Your data stays yours. This is one of the key differences between a platform like Intric and a consumer AI product. That said, this doesn’t mean anything goes — data protection requirements apply regardless of training.
“A DPIA is a massive legal project — we can’t do one every time we use AI.”
A DPIA isn’t required for every use of AI. It’s triggered by specific circumstances (as described in the previous section). For many everyday uses of an assistant — drafting, summarizing, researching — no DPIA is needed. What matters is recognizing when the threshold is crossed.
“The AI Act and GDPR say the same thing, so I only need to think about one of them.”
They’re related but distinct. GDPR is about protecting personal data. The AI Act is about the safety and trustworthiness of AI systems. They often point in the same direction, but they have different requirements and different triggers. For AI Act obligations specific to your organization, see the AI Act course.
There is a lot of myth and uncertainty circulating about AI and data protection. When in doubt, go to your administrator or data protection officer, check your organization’s internal guidelines, or read primary sources — you’ll get a more accurate picture than from most online summaries.
Test your knowledge
Question 1 of 3
Is classified internal information the same thing as personal data?