CCAO-F · Study Guide

← Domain 6: Governance, Risk, and Responsible Use

6.2 · Lesson 2 of 4

Data Sensitivity, Privacy, and Regulation

What you need to know

Protect sensitive data before it reaches Claude. The reliable pattern is anonymise first, then analyse. Telling Claude not to retain or reuse information is not a control; removing the sensitive details beforehand is.

What counts as sensitive

Personal identifiers, health and financial records, confidential business information, credentials, and anything under regulation or contract. When the workflow is regulated, keep a record of what was shared and why.

Anonymise, then analyse

  • Replace names, IDs, and identifying details with placeholders or stable codes.
  • Scan free-text comments — identifiers hide there too.
  • Analyse the anonymised version; map results back to real records outside the chat.

Worked example

A mock feedback file has names, emails, account numbers, and free-text comments. Mark every identifying field, mask with stable codes, verify nothing remains in comments, then ask Claude for themes. The control is the anonymisation step — not a retention instruction in the prompt.

Exam traps

  • Instruct Claude not to retain the data

    Not a control. Prevention happens before the data is shared.

  • Redact only the obvious columns

    Check free text for names, emails, and account numbers too.

  • Share more data than the task needs

    Less data shared means less risk. Use only what the analysis requires.

  • Skip policy checks for “anonymised-ish” real data

    Know which regulations apply and check with the responsible team when unsure.

Practice scenario

Customer feedback with names, emails, and account numbers needs theme analysis. What is the correct control?

Choose one answer

Build exercise

Anonymize Sensitive Data Before You Analyze It

6.2 · Intermediate · ~35 min · claude.ai

What you will practise

  • Why you remove or mask identifiers before upload.
  • Why telling Claude not to retain data is not a privacy control.
  • What counts as sensitive: personal, health, financial, and confidential business data.
  • How to keep the analysis useful after masking.

Run the Domain 6 anonymisation exercise on invented data and explain why an instruction is not a control.

Open Domain 6 exercises

Path: /learn/claude-associate/exercises/6-governance-risk-responsible-use

Sources

View progress