AI Data Privacy Checklist: 12 Questions to Ask Before Uploading a File

Uploading a file to an AI tool can feel like a small action. In reality, it can change who processes the information, where it is stored, and what happens to it next.

You do not need a long legal review before every prompt. You do need a repeatable way to make a sensible decision.

Use this checklist before uploading a document, note, spreadsheet, transcript, or folder to an AI tool.

1. What is in this file?

Start with the contents, not the file type.

Does it include personal information, client details, financial data, internal decisions, commercially sensitive plans, health information, passwords, or security material? The more valuable the context, the more care it deserves.

2. Who is responsible for the information?

You may own a personal note. You may be responsible for a client document. You may be one of many people trusted with an internal report.

Responsibility changes the standard. Do not make a sharing decision for information that belongs to someone else without knowing the rules.

3. Would I put this in a public document?

This is the fastest useful test.

If the answer is no, do not treat the input as disposable. Use a tool with clear privacy, access, and data-handling boundaries.

4. What exact job am I asking AI to do?

Be specific.

Are you looking for a summary, a comparison, a set of actions, a missing detail, or a first draft? A clear job helps you decide what material is actually necessary.

5. Do I need to upload the whole file?

Often, no.

Use only the pages, notes, or documents relevant to the task. Reducing unnecessary context improves both privacy and answer quality.

6. What does this tool say about data handling?

Look for clear, practical answers.

Where is the information processed? Is it retained? Is it used beyond your workspace? Can you remove it? Do different plans or settings change the answer?

Do not rely on a reassuring headline. Look for the operating details.

7. Who can access the workspace?

If the work is shared, access should be deliberate.

Check whether the right people have access and whether anyone else can discover, reuse, or export the information. A shared workspace should follow the project, not the path of least resistance.

8. Can I keep this project separate from other work?

Separate workspaces reduce accidental exposure and make later review much easier.

A client project, personal research, internal strategy, and a team knowledge base should not automatically sit in one pool of context.

9. Can I verify the answer against the source?

AI should help you find and understand information. It should not make the source disappear.

For important work, use a workflow that lets you see where an answer came from before you act on it.

10. What happens if the answer is wrong?

Consider the consequence.

A weak first draft for a public post is easy to fix. An incorrect summary of a contract, a customer promise, or a sensitive report can create a much larger problem. The higher the consequence, the more source checking and human review you need.

11. Can I remove the file later?

A useful tool should make it clear how you manage, remove, and review information over time.

Temporary work should not become permanent storage just because nobody chose a clean-up point.

12. Could I explain this choice to the people affected?

This is the final test.

Could you explain to a colleague, client, customer, or manager why this information was shared with this tool and what protections apply?

If the answer is unclear, pause and choose a better workflow.

The goal is not less AI

The goal is better judgement.

AI can make documents easier to understand, compare, organise, and act on. It becomes most valuable when people can use it without guessing what they are giving up in return.

What Is Private AI? A Practical Guide for People and Teams sets out the broader principles behind this checklist.

Use the checklist as a default, not a barrier. Public material can move quickly. Information that matters deserves a tool built to handle it with care.