life; genetic data; criminal history records; biometric information; and information relating to race or ethnicity. Second, the preceding principle highlights the particular risks associated with unique identifiers and sensitive personal data, but it does not imply that other types of personal data are safe to upload. As a general rule, it is advisable not to upload personal data of any kind. Where analysis of personal data is unavoidable, such data should be pseudonymized. Pseudonymization refers to a process in which certain personal identifiers—such as names or personal identification numbers—are removed or replaced with encrypted strings, so that individuals cannot be identified without additional information that would allow the data to be re-linked to the original source. Third, even if data does not constitute personal data, particular caution is required with respect to information that requires a high level of security depending on its classification—namely, confidential materials whose disclosure could cause harm if leaked. Such information should not be entered into prompts. Examples include interviews with victims, non-public minutes of meetings concerning important decisions, and financial or accounting records. Decisions about how to define security classifications, the degree of trust that can be placed in AI providers, and the organization’s tolerance for risk will necessarily vary depending on each organization’s specific circumstances. 76 77

Select target paragraph3