What you do not put in an AI chat, when you work in HR
Echipa HR 365 · reviewed 2026-09-05 · 5 min read
The simple rule that covers most situations: do not send anything you would not email to somebody outside the company. From a data point of view, a chat with a language model is exactly that — a transfer to an external vendor.
What you do not send
- Exported tables with names, salaries, identification numbers or contact details.
- Whole CVs. They contain addresses, dates of birth, sometimes a photograph and family details.
- Medical certificates, even for “a quick summary”.
- Notes from a disciplinary conversation or a review, with the person’s name in them.
- Screenshots from the HR system. They are data, even though they do not look like a file.
How you get the same result without the real data
Almost every useful task needs no real data. You need structure, not identifiable content — and structure can be described.
| Task | What you used to send | What you send instead |
|---|---|---|
| Summarising a conversation | The notes with names and details | The notes with names replaced: “the manager”, “the employee” |
| A difficult email | The real situation, with names | The situation described generically, with nothing identifiable |
| Analysing a table | The exported table | The column structure and a description of what you want calculated |
| Drafting a job description | The old description with the incumbent’s name | The requirements and the real work, without the person |
| Checking a document | The document with real data | The document with data replaced by placeholder values |
The table row deserves attention: to get a formula or a calculation method you do not need to send the data. You describe the columns and ask for the method, then apply it to the real data yourself, locally. The result is the same and nothing left.
The anonymisation that does not work
Replacing the name is not enough when the remaining details identify the person anyway. “The only person in procurement who works part-time” is a complete identification in a company of fifty, even with no name.
The practical test: if the text reached a colleague inside the company by mistake, could they work out who it is about? If so, there are more details to remove.
What you ask the vendor, if you use an AI tool
- What happens to what I send: is it used for training, is it retained, and for how long?
- Where is it processed, geographically, and who has access to the content?
- Can I turn off history retention, and is it off by default or does it have to be requested?
- What happens to the data if I close the account?
The difference between a business tool and a consumer one usually lies exactly in the answers to the first two. Worth checking before building a team habit around a tool.
Where to start
Write a one-sentence rule and send it to the team: what would not go out by email does not go into a chat either. It is easier to remember than a policy and covers most cases.
Then check which tool the team actually uses. It is usually a consumer one, personal, chosen because it was to hand — and that is where the first investment is worth making.
How you discuss this with the team, without banning it
A blanket ban does not work and produces the worst possible outcome: people use it anyway, but from personal accounts where you have no visibility and no settings. The position that works is the opposite — say what is allowed and provide an acceptable tool.
| The message | Why it works |
|---|---|
| Use AI for drafts, it is encouraged | It removes the guilt and brings the practice out of hiding |
| Do not send employee or candidate data | A simple rule, easy to remember and to apply |
| Use the company account, not your personal one | It brings the practice onto a tool whose settings you control |
The third line requires a company account to exist. If it does not, the first two messages are good intentions: people will carry on with personal accounts, because the work has to get done.
What you check in a generated text
- Figures and dates. A model produces plausible numbers as easily as correct ones.
- References to internal rules or procedures. If the text asserts something about how your company works, verify it.
- The tone. A text that is correct and wrong in tone does more harm than one that is clumsy and authentic.
- What is missing. Models usually omit the exceptions and the edge cases — exactly the part the reader is looking for.
But what if the vendor says they do not train on my data?
That is a genuine improvement and it does not change the basic rule: it remains a transfer to a third party, with all the questions that follow. The difference is that a business tool with clear settings is a possible conversation; a consumer one, on a personal account, is not.
How do I check that the team follows the rule?
Not through surveillance, which does not work anyway. By offering a good alternative and making the rule easy to remember. A complicated rule gets broken through inattention, not bad faith.
AI features run inside the platform, on the data already there
Generation and summaries happen without copying data into an external chat, and usage stays visible on your own dashboard, per feature and per user.
Free account, every module for 7 days, no card required.