Lesson 6.2 · D6 Governance, Risk & Responsible Use · 8 min
Apply data-sensitivity, regulatory and privacy rules
Classify the data and confirm the tool is approved for it before anything goes into Claude.
What the exam tests
Choosing the right action when personal, health, financial, client or controlled data is involved, and recognising the relevant regulation.
Key ideas
- Two checks first
- What is the data's classification? Is this Claude workspace approved for that classification?
- Minimise
- Remove or pseudonymise identifiers you don't need; use placeholders and complete details in approved systems.
- GDPR
- Personal data of people in the EU: lawful basis, data minimisation, purpose limitation; involve the privacy team or DPO.
- HIPAA
- US protected health information: only in environments approved for it, with the required agreements such as a business associate agreement.
- PCI DSS
- Payment card data stays out of tools not approved for it. Masking part of a number isn't enough.
- FedRAMP
- US federal government use of cloud services requires appropriate authorisation.
- Other controls
- Export-controlled drawings, privileged legal material, client data under contract terms, children's data, consent scope for research participants.
- What doesn't fix it
- Deleting the chat afterwards, using a personal account, pasting “only half”, or keeping initials with full details.
Common traps
- “It's for the customer's benefit, so it's fine.”
- Treating partial redaction as de-identification.
Remember
Classify → check approval → minimise. Clean-up afterwards doesn't make it compliant.