Skip to content

Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support

Leadership guide/Decisions/Data privacy & security

Data privacy & security

Protect the information people entrust to you.

Make the rule specific enough for someone facing an actual document, conversation or student record.

Download this brief↓

HumanSkills recommendation · September 2026

In this guideRecommended positionYour local choicesA campus situationWho is responsibleLanguage to useEvidence of implementationSupporting sourcesDownload PDF→

Read, share and use with your team.

A considered starting position.

HumanSkills recommendationApply institutional data classifications to prompts, uploads, retrieved records, outputs and logs. Permit protected information only through an explicitly approved tool and use case with appropriate legal, contractual and technical controls. Minimize information and permissions.

Removing a name may leave enough context to identify someone. A meeting transcript can mix student, employee and partner information. A connector can expose more than a user intended to upload. Privacy review and security review must cover the entire information flow.

What the evidence supportsCarteret restricts protected information in public AI tools. Purdue ties sensitive-data use to approval. FERPA provides the official starting point for education-record obligations; applying it requires attention to the specific information and disclosure.

What your institution decides.

The right arrangement depends on the purpose, consequences, applicable requirements and capacity of your institution. Use these options to make the choice explicit.

Public or approved synthetic information

Consider this when: The task can be completed without real confidential records.

The tradeoff: Confirm the material is genuinely suitable for the intended use; public availability does not settle intellectual-property rights.

Protected information in a controlled use

Consider this when: There is an approved need and the required safeguards are established.

The tradeoff: Requires review of authority, agreements, configuration, access and monitoring.

Keep the information out

Consider this when: The purpose, authority or controls cannot be established.

The tradeoff: Offer a workable approved alternative and a review route so staff can complete the underlying task.

Walk through the situation.

Illustrative campus caseAn AI note-taker joins a student-support meeting.

A staff member invites a note-taker to help prepare an action summary. The conversation includes disability accommodations, academic progress and a partner placement.

Convenience does not resolve who may receive the information, how the recording is used or what participants were told.

  1. Check the approved meeting use, information categories and recording requirements before enabling it.
  2. Confirm participation choices, retention, access and any applicable consent or disclosure requirements with responsible offices.
  3. If approval is unresolved, use an authorized human note-taking process and share only the necessary action summary.

What the team produces: A usable meeting rule and a documented information-handling decision.

Put responsibility in the right place.

Board & trustees

Ask how leadership knows that protected information is kept within approved uses.

Institutional leaders

Make data ownership and incident authority explicit, with resources to enforce them.

AI task force

Connect plain-language rules to privacy, security, records, procurement and partner requirements.

Apply these roles within your institution’s actual governance and delegated authority.

Language to build on.

Illustrative model clause

Users must not place protected institutional information in an AI system unless the tool and the specific use are authorized for that information. Approval must address permitted processing, access, retention, vendor reuse, subcontractors, deletion and incident response. Only the information and permissions needed for the approved purpose may be provided.

Copy the clause

Review this clause with the full policy and local requirements. It is an implementation starting point, not a statement of measured consensus.

Model policy §5→Model policy §9→Model policy §11→

Know whether it is working.

When to reconsiderReassess when information categories, connectors, retention, vendor reuse or the people with access change.

Read the supporting sources.

Selected precedents and guidance supporting this chapter. These sources do not imply institutional endorsement of HumanSkills or agreement with every recommendation.

Source review: 24 September 2026. Read the editorial approach.

Continue the workKeep a person answerable.

→

See the wider
evidence and choices.

Read the research comparisons and explore the annotated library across US colleges, universities and international institutions. Use the model language as a starting point for your own decision.

Protect institutional information.→Make the policy yours→

Put this decision into practice.

Open the operating guide and working record→