Skip to content
Is there an AI for this?

FDE ACADEMY · MODULE 04 · LESSON 01

Personal data and confidential material are different duties

Two obligations that overlap without being the same, why the confidential one is usually binding for professional-services firms, and the copies an AI deployment creates that nobody’s retention schedule covers.

Effort
About two hours with a real scenario in front of you.
Skills
compliance-governance

Free and self-paced. No certification is offered.


01Two duties, one deployment

Data protection law governs personal data: information about identifiable people. Confidentiality governs material somebody entrusted to the organisation, whether or not a person is identifiable in it. A commercial contract between two companies may contain almost no personal data and still be the most sensitive object in the building.

The practical consequence is that the privacy analysis can come back clean while the deployment is still unacceptable. For law firms, accountancy practices, medical practices and anyone holding client files, the confidentiality duty is usually the one that decides whether documents may reach a third-party model — and it comes from retainers, the common law and professional rules rather than from a privacy statute.


02The copies you just created

An AI deployment does not simply read documents. It creates derivatives: extracted text, chunks, embeddings, cached answers, prompt and response logs, evaluation sets, and backups of all of the above. Each is a copy of the source material in a different shape, held in a different system, usually outside the retention schedule that governs the original.

Inventory them at design time. The question "when this matter closes, what has to be deleted and can we delete it" is one you should be able to answer with a list and a transaction, which is the work you did in module 02 lesson 04.

  • Extracted text and chunks — derived from the source, and readable.
  • Embeddings — derived, not reversible in general, and still governed by the same purpose limits.
  • Prompt and response logs — often contain more sensitive material than the documents.
  • Backups and snapshots — the copy people forget when they promise deletion.

03Issue-spotting, not conclusions

The form to write in is “this principle requires practicable steps to protect personal data; for this architecture that usually means access control, encryption at rest and audit logging — here is what we have and here is what is missing”. The form to avoid is “this deployment is compliant”.

The first is useful to counsel and to the customer. The second is a claim you are not in a position to make and that will be read as advice.


04Do this

PRACTICAL TASK

Work a jurisdiction’s common issues against a real scenario

Take one concrete deployment scenario and work through the five common enterprise issues published for its jurisdiction, producing a named artefact or an explicit gap for each.

What you need

  • A scenario: pick a forty-person professional-services firm deploying the flagship recipe, or use your own customer
  • The constraints record from module 01 lesson 03 if you have one

Steps

  1. 01

    Read the five common enterprise issues on the Hong Kong page in full, including the summary under each title.

    Hong Kong — common enterprise issues

  2. 02

    For each issue write two lines: what it means for your scenario specifically, and what artefact would answer it — a policy, a contract clause, a configuration, a log, a deletion procedure.

  3. 03

    Read the flagship recipe’s eight compliance notes and match each to one of your issues. Note the ones with no matching note; those are yours to handle.

    Private knowledge base — compliance considerations

  4. 04

    Run the same scenario against a hosted vendor and read what the assessment reports, including what it says it cannot determine.

    Claude in Hong Kong

  5. 05

    Write your one-page issue list. Mark every line as a legal requirement, a recommended practice or your own recommendation, and never leave one unlabelled.

You are done when

  • Five issues, each with a scenario-specific consequence and a named artefact or an explicit gap.
  • Every line is labelled requirement, recommended practice, or recommendation.
  • Nowhere in your page does the word “compliant” appear as a conclusion about the deployment.

05Where these facts live

This lesson does not restate anything that is already recorded with its evidence elsewhere on the site. These are the pages it leans on.

  • Hong Kong

    Framework, regulators, instruments with their status, and the five issues that recur in enterprise deployments.

  • Jurisdiction index

    The other jurisdictions covered here, each with the same structure and its own primary sources.

  • Handing over an AI system responsibly

    The confidentiality duties that outlast an engagement, and who holds them once you have gone.

Ticks are stored in your browser only. They are not sent anywhere, they are not attached to an account, and clearing your browser data removes them.