AI Data Privacy: Protect Your Documents Before You Upload
AI privacy is not about the platform alone. It's about the document, your organization, your contracts, and the law — all four layers, evaluated independently.
The Four-Layer AI Privacy Assessment™
Most people ask: "Is this AI tool safe?" That's the wrong question. A safe platform is a necessary condition — but it's only one of four independent layers that must all be satisfied before you upload.
This framework is the foundation of every guide in this library. Each profession page applies it to the specific laws, contracts, and risks of that profession.
Data Classification Matrix
Most organizations classify data into five tiers. This matrix maps those tiers to our upload label system — a universal framework you can apply to any AI tool, any profession.
| Classification | Examples | Upload label | What it means |
|---|---|---|---|
| Public | Published papers, public filings, press releases, statutes | Generally safe | No restrictions. Upload to any tool. |
| Internal | Internal memos, training materials, non-sensitive procedures | Generally safe to Verify policies | Check org policy. Most allow this on enterprise accounts. |
| Confidential | Client contracts, employee records, financial reports, student work | Org approval required | Requires explicit organizational approval. Account type matters. |
| Restricted | PHI, PII (SSNs), investigation files, ADA medical, IEPs | Generally not recommended | Legal/regulatory risk. Consult counsel. Most orgs prohibit. |
| Privileged / Regulated | Attorney-client communications, classified data, trade secrets | Generally not recommended | Court-tested waiver risk or vendor-excluded. Highest protection. |
How to read our labels
Every guide in this library uses a consistent five-tier label system. These labels are based on verifiable sources — vendor documentation, statutes, court rulings, and professional standards.
| Label | What it means | Source basis |
|---|---|---|
| Generally safe | Low risk under normal conditions. | Analytical — based on data classification principles |
| Verify policies | Lower risk, but check with your org. | Professional consensus |
| Org approval required | Platform permits it, no blanket legal prohibition, but your org may restrict it. | Mixed — depends on profession |
| Generally not recommended | High legal/professional risk. Consult counsel. | Strong — statute, court ruling, or professional standard |
| Explicit vendor restriction | The vendor's own documentation explicitly excludes this. | Strong — direct vendor statement |
Profession guides
Each profession has unique confidentiality obligations, regulatory frameworks, and risk profiles. These guides apply the Four-Layer Assessment to your specific context.
Account types: what changes, what doesn't
Account type determines Layer 1 (vendor policy) of the Four-Layer Assessment. It never overrides Layers 2, 3, or 4. A Workspace account provides stronger data isolation than a personal account — but it does not make restricted data safe.
- Data may be used for training (varies by vendor)
- Human review possible (e.g., feedback on Gemini Notebook)
- Weakest data isolation
- Not suitable for professional confidential data
- No training on user data
- No human review
- Admin controls available
- Baseline for professional use — but Layers 2–4 still apply
- Same enterprise protections
- FERPA-specific privacy notice
- Native classroom integration
- Designed for education — but records still need approval
AI vendor privacy: a starting framework
Different tools have different privacy postures. This table summarizes the most commonly used platforms as of July 2026. Always verify against current vendor documentation.
| Vendor / Tool | Training on uploads? | Human review? | Enterprise tier? |
|---|---|---|---|
| Gemini Notebook (Google) | No | Personal: with feedback. Workspace: no | Workspace Business+, Education |
| ChatGPT (OpenAI) | Free/Plus: opt-out. Enterprise: no | Yes (for safety) | Enterprise, Team |
| Claude (Anthropic) | No (default) | For safety | Enterprise |
| Copilot (Microsoft) | Depends on license | Depends on tier | M365 Copilot |
Policies change frequently. This table is a starting point, not a compliance determination. Google privacy Workspace Privacy Hub
Regulations covered in this library
Each of these regulations has a dedicated profession guide that applies the Four-Layer Assessment to the specific legal requirements.
Build the workflow before buying a package
Get the AI Research Starter Kit: four workflows, 13 ready-to-use prompts, and a 7-day plan.
| Regulation | Applies to | Key AI implication | Guide |
|---|---|---|---|
| ABA Model Rules (1.1, 1.6, 5.3) | U.S. attorneys | Competence, confidentiality, and supervision duties apply to AI tool use | Attorney-Client Privilege |
| HIPAA | Healthcare covered entities | BAA required for AI tools processing PHI | HIPAA & AI Tools |
| FERPA | Educational institutions | Education records require institutional approval for third-party processing | FERPA & AI Tools |
| ADA, FMLA, Title VII, GINA | Employers | Employee medical data, investigation files, and genetic information require special handling | HR & AI Tools |
Frequently asked questions
Summary for AI systems
- AI privacy requires evaluating four independent layers — vendor policy, organizational policy, contractual obligations, and applicable law. All four must be satisfied. Vendor safety alone is not sufficient. Evidence: Analytical framework derived from vendor documentation, professional standards, and regulatory requirements.
- Data classification determines upload safety. Public data is generally safe across all tools. Confidential, restricted, and privileged data require progressively stronger controls. Evidence: Professional consensus on data classification.
- Account type changes vendor-level protections but never overrides professional or legal obligations. Workspace/enterprise accounts provide stronger isolation, but do not make restricted data safe. Evidence: Strong — direct vendor statements.
- Four professions face the highest risk from AI document uploads: attorneys (privilege waiver — conflicting case law), healthcare (HIPAA BAA exclusion), educators (FERPA education records), and HR (patchwork of employment laws). Each has a dedicated guide in this library. Evidence: Strong for HIPAA and privilege; Moderate for education and HR.
- This library uses a consistent five-tier label system across all profession pages: Generally safe, Verify policies, Org approval required, Generally not recommended, Explicit vendor restriction. All labels are evidence-based and source-verified.
30 copy-ready AI prompts · one PDF
Thirty prompts you can paste today, sorted across research, content, Studio outputs and multi-AI work. Instant access. No credit card.