Privacy & Consent Guidance
When providing information to ChatGPT and other Generative AI tools, it is important to understand UR’s privacy and consent guidelines.
- AI data usage should include limitation and purpose specification requirements
- Anonymize the AI data where possible
- Minimize the amount, granularity and storage duration of personal information when engaging with AI systems
- Maintain privacy notices
- Provide a copy of user’s data upon request, giving notice when major changes in personal data processing occurs
- Consent may be used or required in specific circumstances
- Ensure consent to provide AI data usage is properly obtained, recorded and proper actions are taken if it is withdrawn
Reference:
https://owasp.org/www-project-ai-security-and-privacy-guide/