Whether data may be processed with AI depends on content, purpose, legal basis, contract, provider, storage, access and technical settings. A blanket rule such as “no personal data” is insufficient.
What the concept actually means
Data classification translates protection need into action: permitted, approved environment only, anonymise first or prohibit entirely.
Why it matters in the enterprise
Data minimisation remains effective: provide only passages and attributes needed for the task. Test data and abstracted examples reduce risk during development and training.
A controlled method
The CTPM practice framework for controllable AI applications uses seven stages: understand the task, clarify context and data, apply AI deliberately, review professionally, handle deviations, approve accountably and document transfer. It is a transparent working framework, not a certification.
- Define task and impact
- Clarify data, context and permissions
- Review against domain criteria
- Control deviations, approval and evidence
CTPM practice example
CTPM practice example: For an HR analysis, names and direct identifiers are removed, sensitive free text is excluded and only aggregated criteria are processed in a contractually approved environment.
Quality and test criteria
The following criteria make quality observable for this use case:
- Data class and purpose are recorded before use.
- Provider, storage and training settings are reviewed.
- Access follows need to know.
- Deletion and incident handling are defined.
Risks and common misconceptions
Anonymisation can fail through context. Pseudonymous data remains personal. Copy-and-paste bypasses technical controls, requiring clear work rules and training.
Example transfer artefact
Transfer artefact: a data-approval matrix with class, permitted environment, minimisation, retention, owner and review evidence.
Sources and references
- NIST: NIST Privacy Framework (2020)
- NIST: Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (2024)
- European Commission: Regulatory framework for Artificial Intelligence (AI Act) (2024)
- OWASP GenAI Security Project: OWASP Top 10 for LLM Applications 2026 (2026)
