CCAO-F Prep0/30
Lesson 6.2 · D6 Governance, Risk & Responsible Use · 8 min

Apply data-sensitivity, regulatory and privacy rules

Classify the data and confirm the tool is approved for it before anything goes into Claude.

What the exam tests

Choosing the right action when personal, health, financial, client or controlled data is involved, and recognising the relevant regulation.

Key ideas

Two checks first
What is the data's classification? Is this Claude workspace approved for that classification?
Minimise
Remove or pseudonymise identifiers you don't need; use placeholders and complete details in approved systems.
GDPR
Personal data of people in the EU: lawful basis, data minimisation, purpose limitation; involve the privacy team or DPO.
HIPAA
US protected health information: only in environments approved for it, with the required agreements such as a business associate agreement.
PCI DSS
Payment card data stays out of tools not approved for it. Masking part of a number isn't enough.
FedRAMP
US federal government use of cloud services requires appropriate authorisation.
Other controls
Export-controlled drawings, privileged legal material, client data under contract terms, children's data, consent scope for research participants.
What doesn't fix it
Deleting the chat afterwards, using a personal account, pasting “only half”, or keeping initials with full details.

Common traps

  • “It's for the customer's benefit, so it's fine.”
  • Treating partial redaction as de-identification.
Remember

Classify → check approval → minimise. Clean-up afterwards doesn't make it compliant.

Practise D6 questions