Privacy & responsible AI
AI Privacy for BC Small Businesses: A PIPA-Aware Starting Point
A plain-language checklist for using generative AI with customer, employee, and confidential business information in British Columbia.
Generative AI can help a small team draft, summarize, search, and organize work, but it also makes it easy to move information into a tool before anyone has asked where that information goes or whether it should be there.
This guide is an operational starting point, not legal advice. British Columbia private-sector organizations should understand their obligations under the Personal Information Protection Act and seek qualified advice for their circumstances.
Begin with an information rule people can remember
A short default rule is more useful than a long policy nobody can recall. The policy can then explain approved accounts, data classes, exceptions, and the person responsible for questions.
Map the data flow before approving the workflow
- What information enters the workflow?
- Is any of it personal, confidential, regulated, or contractually restricted?
- Which account and service receive it?
- Where is it stored, for how long, and for what purposes?
- Can the provider use inputs or outputs to improve its models?
- Who can access the tool, conversation history, and connected systems?
- Can the information and logs be deleted when required?
Use business accounts and settings intentionally
Consumer and business offerings may have different administrative, retention, training, and access controls. Confirm the terms and settings that apply to the exact plan your team uses. Do not assume that a familiar product name means the same data handling across every tier.
Central administration, access removal, logging, and approved integrations become more important as soon as the tool moves beyond individual experimentation.
Minimize before you prompt
- Remove names and direct identifiers when they are not needed.
- Use representative or synthetic examples for training and testing.
- Send only the fields required for the task.
- Keep source documents in the approved system when retrieval can provide a small relevant excerpt.
- Avoid pasting entire inboxes, customer files, or financial exports into a general chat.
Keep consequential decisions with accountable people
AI can prepare a summary, identify an exception, or propose a draft. Decisions that materially affect a customer, employee, patient, tenant, or financial record need an appropriate person, reliable source information, and a reviewable reason.
Human review must be real. A person needs enough time, context, authority, and source visibility to disagree with the system.
Create a lightweight approved-use register
- Workflow name and business owner
- Approved tool, plan, and settings
- Allowed and prohibited information
- Purpose and expected users
- Human review and escalation step
- Source-of-truth systems
- Review date and shutdown owner
Train people on realistic situations
A useful privacy workshop uses examples employees actually face: summarizing a customer email, drafting from a confidential proposal, analysing a spreadsheet, or connecting an inbox. People need to practise recognizing the boundary before the convenience of the tool takes over.
Review the workflow as tools and terms change
AI services change quickly. Revisit material workflows when the provider, plan, model, integrations, retention terms, business purpose, or information class changes. An approval is for a defined workflow, not a permanent approval of every future use of the brand name on the tool.