The question "may this data be used in AI" is often answered by looking at the content: is there a name in it, an amount, a diagnosis. That is not the core of the issue. What is usually decisive is the origin of the data: under what conditions was it collected, for what purpose, and on what legal basis. The same text — for example, a customer email containing an address — may be processed without any problem by an AI application in one system and not in another, depending on how that data was ever obtained and what has been agreed or recorded about it.
This is the reason why a general list stating "these types of data may never be used in AI" does not exist and would not be useful either. What does exist is a number of areas of attention within which the origin and purpose of data must be examined with extra care before it goes into an AI application.
With personal data, the primary question is not whether something is personal data, but what it was collected for. Data that was gathered for a specific purpose — for example, to process an order — may not simply be used for another purpose, such as training a model or being run through an AI tool that falls outside the original context. Whether that is permitted depends on the legal basis on which the data was ever obtained, on any consent given, and on what is stated about it in the organisation's own processing agreements and privacy statements. The exact conditions are governed by the applicable statutory regulations; the current text of these can be consulted via the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the applicable privacy legislation.
Within personal data there is a separate category subject to a stricter regime: data concerning health, origin, religion, sexual life, criminal records and comparable categories. Additional conditions apply to this data, irrespective of whether an AI application could handle it well. Here too, origin is decisive: was the data collected within a framework that allows processing by an AI system, and is there a legal basis that covers that use.
Apart from personal data, confidentiality that does not stem from privacy legislation but from contracts also plays a role. Information from customers, suppliers or partners that was shared under a confidentiality clause cannot simply be entered into an AI tool, especially not if that tool processes the data outside the organisation itself or uses it for model training. This comes up, for example, when processing email: when assessing can AI take over triaging a general email inbox, it is not only relevant whether an AI tool can technically read and sort messages, but also whether the content of those messages falls under a confidentiality agreement with a third party. The same mechanism applies to telephony: when considering whether can AI take over answering and transferring phone calls, it must also be examined what data is recorded and processed during a call, and under what agreements this happens.
Another point of attention is not the content of data but its status over time: data subject to a statutory or contractual retention period must be managed in a specific manner, and deploying an AI application does not change that obligation in any way. Anyone looking into this for archiving processes often ends up naturally at the question of how can AI take over archiving documents and checking them against retention periods relates to the organisation's own retention obligation: an AI system may be helpful in recognising periods, but responsibility for correct compliance does not shift as a result.
Entering data into a new AI application sometimes also touches on employee participation (medezeggenschap), particularly when it concerns systems that process data about employees' performance, behaviour or presence. Whether and when consent from the works council is required is a separate question, distinct from the privacy question; more on this can be found on the page about when the works council is involved. Even apart from a formal consent procedure, it can be useful to consider how informing the works council about AI is set up, precisely because data use and the deployment of AI applications often arise together within an organisation.
This page describes the mechanism by which data may or may not be used in an AI application. Decisions about the design of roles, work processes or personnel policy resulting from AI deployment are subject to their own statutory requirements and their own considerations, for which this page offers no substantiation.
The key question for any data you want to use in an AI application is not "is this sensitive" but "under what conditions did this ever come in, and does that legal basis also cover this use". Working that out is a task for the organisation itself, possibly together with a legal adviser. If you would first like an indication of which part of your tasks is suitable for AI takeover at all, separate from the data question, you can fill in ftetoai's free quickscan: twelve questions, no account required, with an indication of what proportion of the hours in your profile could be taken over by AI today. The full work scan, which takes this kind of data question into account per task, is still under construction.
Vraag maar. Ik ken de kennisbank van deze site; wat ik niet weet, zeg ik erbij.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.