3) Data Protection and Security
When using commercial generative AI services, data entered as prompts
may be stored on the servers of AI service providers, creating security
risks such as unauthorized access or data breaches. In addition, if such
data are used for model retraining, there is a risk that personal data or
confidential information could be exposed through outputs generated
for other users. Care must therefore be taken to prevent the processing
of personal data without a lawful basis and to avoid the disclosure of the
organization’s confidential information.
① Personal data such as resident registration numbers, credit card
numbers, passwords, or sensitive information (e.g. biometric data,
sexual orientation) shall not be entered into prompts.
② Where the analysis of personal data using generative AI is necessary,
such data must be pseudonymized.
③ Confidential materials requiring a high level of security—depending
on their security classification (e.g. victim interviews, non-public
meeting minutes, accounting records)—shall not be uploaded via
prompts.
④ The terms of service, privacy policy, and security policies of
generative AI services shall be reviewed to understand data retention
periods; whether prompt data are used for AI training; compliance
with relevant laws such as data protection legislation; security
measures such as encryption; and differences in security levels
across pricing plans. Where possible, options or plans that allow users
to opt out of training data use should be selected.
⑤ Data shared through generative AI services shall be regularly backed
up and deleted.
⑥ When generative AI services are integrated with other applications
Generative AI Guide for Civil Society