Privacy
The two sentences from the privacy regulator your staff have not read
In June 2023 Japan's Personal Information Protection Commission told every business handling personal data two things about generative AI. Check that any personal data in a prompt is within the stated purpose of use. And before entering personal data, check how the provider handles it, because if it is used for anything beyond answering you, consent is needed. Three years on, many companies still have no written rule that says either.
On 2 June 2023 the Personal Information Protection Commission published a short notice on generative AI. It is three pages. It is addressed to businesses that handle personal information, to public bodies, and to ordinary users. Few people outside legal departments have read it, and it says exactly what a company needs to write into its own rules.
What it tells a business
Two points, and they are worth quoting closely.
First: when a business enters a prompt containing personal information into a generative AI service, it must confirm that the use is within the scope needed to achieve the purpose of use it has specified for that information.
Second: if a business enters personal data into a generative AI service without the person's prior consent, and the service handles that data for any purpose other than producing the response, the business may be in breach of the Act on the Protection of Personal Information. So before entering such prompts it must confirm that the provider does not use the data for machine learning or similar purposes.
In plain terms. The purpose you told the customer their data was for still applies inside the chat window. And how the vendor handles your inputs, training included, is not a technical footnote. It has to be checked before anyone pastes.
What it tells everyone else
The notice also speaks to individual users, and this part is the one to put in a training slide. Personal information typed into a generative AI service can be used to train it and can come back out, combined with other data, accurate or not. Responses can contain inaccurate personal information because the text is generated from statistical correlation. And users should read the provider's terms and privacy policy before deciding what to enter.
Why this is a design problem
The companies we talk to about this tend to share the same problems. Staff are using generative AI. There is no written rule. Nobody has checked the training setting on the accounts in use. And the customer data most at risk sits in the department that adopted AI fastest, often sales or support.
Telling people "be careful" does nothing. What works is boring. Approved tools with training on inputs switched off, and that setting checked in writing by a named person. A one page list of what never goes into a prompt: full names with addresses, health information, ID numbers, anything the customer would not expect. A place inside the workflow where personal data is stripped before the model sees it, so the rule is enforced by the tool rather than by memory. And a half day per department so people know why the rule exists.
The reason to do it now
The regulator wrote this in 2023, early in the adoption curve. If your staff use generative AI today, "we did not know" is not a defence and "we had a rule" is a weak one unless the rule was built into how the work is done. The notice is short. Turning it into approved tools, a one page list and a data stripping step takes about a week. We do it at the start of every AI rollout we run. If yours has already started without it, that is the first week we would book.