3) Data Protection and Security When using commercial generative AI services, data entered as prompts may be stored on the servers of AI service providers, creating security risks such as unauthorized access or data breaches. In addition, if such data are used for model retraining, there is a risk that personal data or confidential information could be exposed through outputs generated for other users. Care must therefore be taken to prevent the processing of personal data without a lawful basis and to avoid the disclosure of the organization’s confidential information. ① Personal data such as resident registration numbers, credit card numbers, passwords, or sensitive information (e.g. biometric data, sexual orientation) shall not be entered into prompts. ② Where the analysis of personal data using generative AI is necessary, such data must be pseudonymized. ③ Confidential materials requiring a high level of security—depending on their security classification (e.g. victim interviews, non-public meeting minutes, accounting records)—shall not be uploaded via prompts. ④ The terms of service, privacy policy, and security policies of generative AI services shall be reviewed to understand data retention periods; whether prompt data are used for AI training; compliance with relevant laws such as data protection legislation; security measures such as encryption; and differences in security levels across pricing plans. Where possible, options or plans that allow users to opt out of training data use should be selected. ⑤ Data shared through generative AI services shall be regularly backed up and deleted. ⑥ When generative AI services are integrated with other applications Generative AI Guide for Civil Society

Select target paragraph3