TALECRAFTERS
GLOSSARY · ETHICS · SYSTEMS

DATA MINIMISATION

Putting only the data a task actually needs into a model, and never keys, client data or unreleased assets.

ALSO CALLEDneed-to-knowminimum necessary data

Every prompt is a disclosure to a third party. That is true even where a provider promises not to train on it, because a promise about training is not a promise about logs, incidents or subpoenas.

The operating rules are short. No credentials in a prompt, ever. No client personal data unless the engagement specifically requires it and the client has agreed the processor. No unreleased assets in a system without a contractual position on retention.

The commercial version of the argument is easier to sell internally than the compliance one: an unreleased campaign pasted into a general-purpose tool is a leak risk with a date on it.

QUESTIONS PEOPLE ASK

Is it safe to paste client material into a model if the provider says it does not train on inputs?

A commitment about training is not a commitment about logging, retention or incidents. Treat every prompt as a disclosure to a third party and decide accordingly.

What should never go in a prompt?

Credentials and keys, personal data the engagement has not accounted for, and unreleased assets where there is no contractual position on retention.

THEORY IS FREE

Knowing the word is the cheap part.

Running it on a deadline, at volume, without burning the budget is the expensive part. That is the bit we do.

BRIEF US