Lesson status
Not completed
Mark lesson complete
Not completed
Saved only in your browser. Return to the course index to see overall progress.
Lesson 3 • Governance
Data Boundaries & Privacy (Non-negotiables)
In community settings, privacy is trust. Governance must define what data is never allowed in AI tools and how data is handled when it must be used.
Key concepts
- Define prohibited data (PII, PHI, case notes, sensitive identifiers).
- Prefer de-identified, aggregated, or synthetic examples.
- Document retention, deletion, and access rules.
Practice Exercise
Draft your ‘Do Not Paste’ list (10 items) and your ‘Allowed with conditions’ list (5 items).
Template (copy/paste)
ROLE: You are my governance assistant. TASK: Draft a data boundary policy for AI tools. OUTPUT: Do/Don't lists + safe redaction rules + staff checklist. CONSTRAINTS: Keep it practical; include examples.
Governance note: policies should be enforceable, reviewed regularly, and owned by accountable roles—not “everyone.”