Week 15: Personal Data, GDPR, and A–P–K
Welcome to Week 15 of the AI Literacy Course.
Imagine that a teacher wants help writing a support plan. They prepare this prompt:
“Write a plan for a 16-year-old student at North School who has ADHD, frequent absences, family financial problems, and a recent disciplinary warning.”
The student’s name is missing, but classmates or staff may still recognise the person. The prompt also contains sensitive and confidential information.
Should the teacher enter it into an AI tool?
This lesson gives you a practical way to decide when to proceed, minimise information, use another method, or ask for help. It is educational material, not individual legal advice. Organisations are responsible for approving tools and deciding how personal data may be processed.
The central rule is:
Check approval, identify people, minimise information, and stop when risk remains.
Learning goals
By the end of this lesson, you should be able to:
identify direct and indirect personal data;
recognise sensitive and confidential information;
apply A–P–K before using AI;
minimise or replace risky information;
distinguish pseudonymisation from anonymisation;
follow organisational procedures when something goes wrong.
1. Privacy protects people
Data protection is not only about files and databases. It protects people’s dignity, safety, autonomy, and ability to influence how information about them is used.
Information entered into an AI tool may affect:
a learner;
an employee;
a customer or client;
a patient;
a family member;
a person mentioned in a document;
someone described without being named.
Before using AI, ask:
What am I trying to achieve?
Is AI needed for this task?
Can I complete it without information about a real person?
Is this tool approved for the task?
What could happen if the information reached the wrong people?
Sometimes the safest choice is not to enter the information at all.
2. What is personal data?
Personal data is information relating to an identified or identifiable living person.
Some information identifies a person directly:
name;
personal identity number;
personal email address;
telephone number;
photograph;
recognisable voice;
account or device identifier.
Other information can identify someone indirectly.
Consider this description:
“The only 67-year-old mathematics teacher in the evening programme.”
It contains no name. However, colleagues and learners may know exactly who it describes.
A person may be identifiable through a combination of:
age;
role or occupation;
school or workplace;
location;
dates and events;
rare experiences or conditions;
membership of a small group;
photographs, voices, or video;
details about relatives;
writing style or account history.
Ask a practical question:
Could a colleague, classmate, neighbour, or local reader work out who this is?
If the answer is yes—or you are uncertain—treat the information as personal data.
3. Personal data can appear in many places
Personal data is not limited to words typed into a prompt.
It may appear in:
uploaded documents;
spreadsheets;
screenshots;
photographs;
audio or video recordings;
meeting transcripts;
filenames;
comments and revision history;
chat history;
information generated in an AI response.
A document may look anonymous on the first page while still containing names or identifying details elsewhere.
Entering, uploading, analysing, storing, changing, or sharing personal data are all examples of processing. A temporary prompt is still processing even if you do not save it on your own device.
4. Some information needs stronger protection
The GDPR gives additional protection to certain special categories of personal data.
These include information about:
health;
racial or ethnic origin;
political opinions;
religion or philosophical beliefs;
trade-union membership;
genetic data;
biometric data used to identify someone uniquely;
sex life or sexual orientation.
Other information may also be confidential or highly harmful even when it is not a formal GDPR special category.
Examples include:
information about children;
assessments and grades;
learning needs;
disciplinary cases;
financial problems;
employment conflicts;
security information;
confidential business information;
allegations or suspected wrongdoing;
personal family circumstances.
Do not assume that information is safe simply because it does not appear on the special-category list.
5. Use A–P–K before entering information
A–P–K is a Swedish memory aid for pausing before using AI with information about people.
It is not legal approval. It helps you recognise when you should stop, minimise information, or contact a responsible person.
A — Arbete: Is this an approved work context?
Ask:
Is this task connected to my school, workplace, or organisation?
Is the AI tool approved for this task?
Am I using the approved account and configured service?
Do local rules permit this type of information?
A paid account, private mode, or “do not train” setting does not automatically mean that an organisation has approved the tool.
If the tool or task is not approved—or you are uncertain—stop and ask.
P — Personuppgifter: Does it contain personal data?
Ask:
Is anyone named?
Does it contain a face, voice, contact detail, or identifier?
Could several details identify someone indirectly?
Does an uploaded file contain hidden or overlooked personal information?
Could the AI output create new statements about a person?
If personal data is involved, identify what is actually necessary and remove what is not.
K — Känsligt: Is it sensitive, confidential, or potentially harmful?
Ask:
Does it contain special-category data?
Is it about a child?
Is it confidential?
Could it affect someone’s education, employment, safety, reputation, finances, or access to a service?
Would disclosure cause embarrassment, discrimination, or another form of harm?
If the information is sensitive, confidential, or high-risk, do not enter it unless the organisation has explicitly authorised that use.
When uncertain, stop and escalate.
6. Minimise information before prompting
Data minimisation means using only the information necessary for a defined purpose.
Start by defining the task. Then ask whether each detail is genuinely needed.
Ways to reduce risk include:
removing unnecessary details;
replacing exact ages with broad age groups;
removing dates and locations;
using ranges instead of exact numbers;
combining information into totals;
using a blank template;
creating a fictional or synthetic example;
asking a general question;
choosing another method;
not using AI for the task.
Compare these prompts.
Risky prompt
“Write an intervention plan for Ahmed, a 16-year-old at North School who has ADHD, frequent absences, family financial problems, and a disciplinary warning.”
Safer alternative
“Create a general support-plan template for a fictional upper-secondary learner experiencing attendance difficulties. Include sections for goals, supportive actions, responsibilities, follow-up, and learner participation. Do not diagnose the learner.”
The safer prompt removes the real person, school, diagnosis, family circumstances, and disciplinary information. It still meets the purpose of creating a template.
However, changing only the name would not be enough. A distinctive combination of details could still identify the student.
7. Pseudonymisation is not anonymisation
Suppose a researcher replaces participant names with numbers:
Fatima becomes Participant 14.
Johan becomes Participant 27.
A separate file connects the numbers to the names.
This is pseudonymisation. It can reduce risk, but the people can still be identified using the separate file. The information remains personal data.
Anonymisation means transforming information so that people are no longer reasonably identifiable in the relevant context.
Reliable anonymisation is difficult, especially with:
free text;
small groups;
unusual events;
detailed timelines;
photographs;
voices;
video;
location information.
Removing names is not the same as anonymising information.
When in doubt, continue to treat the material as personal data.
8. Approval is more than a privacy setting
An organisation must consider the whole information flow, including:
why the data is being used;
which information is necessary;
who can access it;
how long it is retained;
whether the provider may use it for other purposes;
where it is processed;
which subcontractors are involved;
how it is protected and deleted;
how people can exercise their rights.
An individual teacher, employee, learner, or manager should not invent a legal basis or independently approve a new AI workflow.
Consent is not a simple solution. In education or employment, people may have little genuine choice. Asking someone for permission does not automatically make an unapproved tool or unsafe process acceptable.
Follow the organisation’s instructions and ask the responsible manager, data-protection contact, IT or security function when necessary.
9. AI output can create new personal data risks
Even a carefully written prompt can produce an unsafe output.
An AI system may:
invent facts about a person;
make unsupported inferences;
confuse two people;
describe someone unfairly;
suggest a diagnosis;
assign a risk level;
reproduce personal information from the input.
Do not treat an AI-generated statement about a person as established fact.
Human review must be meaningful. The reviewer needs enough knowledge, time, and authority to question, correct, or reject the output.
Decisions affecting education, employment, healthcare, finances, or access to services require especially careful procedures. A person should not merely approve an AI recommendation without understanding the evidence and consequences.
10. Privacy, confidentiality, and security
These ideas are connected but not identical.
Privacy and data protection concern how information about people is collected, used, shared, retained, and protected.
Confidentiality means preventing information from being disclosed to unauthorised people.
Security includes the technical and organisational measures used to protect systems and information.
An AI workflow may create problems in more than one area. For example, uploading an employee report to an unapproved system may involve personal data, break confidentiality, and create a security risk.
11. If something goes wrong
Imagine that you accidentally enter personal data into an unapproved AI tool.
Do not hide the incident or quietly delete the chat and assume the problem is solved. Deleting something from the visible interface may not immediately remove every retained copy or system record.
Instead:
Stop entering or sharing more information.
Preserve the relevant facts, such as what was entered, which tool was used, and when it happened.
Follow the organisation’s incident procedure.
Report the incident internally without delay.
Contact the designated manager, data-protection contact, IT, or security function.
The responsible organisation will assess the risk and decide what further action is legally required. Not every incident must be reported to the data-protection authority, but that is an organisational decision—not one an individual user should make alone.
Prompt internal reporting helps the organisation reduce harm and meet any deadlines that apply.
Classroom activity: Apply A–P–K
Your teacher will provide three fictional scenarios. Do not use real personal information from your school, workplace, or private life.
For each scenario:
Define the purpose of the task.
Decide whether AI is needed.
Apply A–P–K.
Identify direct personal data.
Identify details that could reveal someone indirectly.
Mark sensitive, confidential, or potentially harmful information.
Check whether the tool and task are approved.
Decide what to remove, generalise, aggregate, fictionalise, or replace.
Write a safer version if AI use is appropriate.
Explain whether you should proceed, use another method, or escalate.
Use this table:
| Purpose | Personal data | Higher-risk information | Approved? | Safer option | Escalation needed? |
|---|
“Do not use AI for this task” is a valid conclusion.
Reflection questions
Could someone identify a person even though their name is missing?
Could an uploaded file contain personal data outside the visible text?
Is the information a GDPR special category, confidential, or otherwise potentially harmful?
Is AI necessary for the task?
Is the tool approved for this specific use?
What information can be removed without losing the purpose?
Is the material pseudonymised, genuinely anonymous, fictional, or still identifiable?
Could the AI output create a new inaccurate claim about someone?
Who has authority to approve or assess this use?
What should you do after an accidental exposure?
Key vocabulary
Personal data:
Information relating to an identified or identifiable living person.
Special-category data:
Personal data receiving additional GDPR protection, including information about health, racial or ethnic origin, beliefs, political opinions, trade-union membership, genetics, certain biometric identification, or sex life and sexual orientation.
Processing:
Actions performed on personal data, including entering, uploading, analysing, storing, changing, generating from, sharing, or deleting it.
Data minimisation:
Using only the personal data necessary for a defined purpose.
Pseudonymisation:
Replacing identifying details while retaining a possible route back to the person.
Anonymisation:
Transforming information so people are no longer reasonably identifiable in the relevant context.
Confidentiality:
Protecting information from unauthorised disclosure.
A–P–K:
A Swedish pause tool: Arbete—approved work context; Personuppgifter—personal data; Känsligt—sensitive, confidential, or potentially harmful information.
Escalate:
Stop and ask an authorised person or function to assess the situation.
Summary
In Week 15, we learned that personal data includes more than names. People can be identified through combinations of roles, locations, events, images, voices, and other details.
Before using AI, apply A–P–K:
Is this an approved work context?
Does it contain personal data?
Is the information sensitive, confidential, or potentially harmful?
Define the purpose, remove unnecessary information, and remember that changing a name does not make data anonymous.
Use approved tools and follow organisational procedures. If information is accidentally exposed, stop further sharing and report the incident internally without delay.
Good AI literacy includes knowing when to proceed, when to minimise, when to choose another method, and when to stop.
Check approval, identify people, minimise information, and stop when risk remains.
Official guidance
European Data Protection Board: Anonymisation and pseudonymisation
Swedish Authority for Privacy Protection: Personal data breach notification
Lesson 15 Interactive Quiz: Personal Data, GDPR, and A–P–K
Choose one answer for each question. Then select Check my answers. This practice quiz does not collect names or scores.