Data Handling Rules
- Check organizational policy before pasting or uploading.
- Identify sensitive data: personal, health, financial, credentials, confidential material.
- Anonymize or redact before upload, including identifiers in free text.
- If policy is silent or unclear, escalate.
Telling Claude not to retain or use data is not a control. Controls act before the data is shared.
Decision Table
| If the question says... | The answer is likely... |
|---|---|
| Customer data with names and account numbers needs analysis | Anonymize first, then analyze |
| "Instruct Claude not to retain the data" | Not a control. Anonymize before upload |
| Request to integrate Claude with company systems | Escalate to the team that builds and secures integrations |
| Policy does not cover the case | Ask the policy owner before proceeding |
| Claude's output informs hiring or discipline | A person decides and is accountable |
| Regulated data is involved | Follow policy and regulation; escalate when unsure |
| Public information summarized for internal use | Generally appropriate, still verify |
Traps
| Trap | Correct Answer |
|---|---|
| It can do it, so it is allowed | Capability is not permission |
| Paste now, check policy later | Policy before paste |
| Claude is accountable for its output | The person using the output is accountable |
| Disclosure never matters | Decide deliberately based on audience, context, and policy |
| Redact only the obvious columns | Check free text for identifiers too |
If You Remember Nothing Else
- Anonymize or redact before upload; instructions are not a control.
- Capability does not equal permission.
- Escalate system integrations and unclear policy cases.
- Accountability stays with people.