AI for Customer Support
Aware · M20 · lesson 20 of 26 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Responsible Data Handling for Support Agents
📖
now learning

Responsible Data Handling for Support Agents

10 min

Why Data Handling Matters

Lecture URL: https://skillsclinic.org/support/responsible-data-handling-for-support-agents.php

Responsible Data Handling for Support Agents

L1.5.2—Data Privacy and Protection

Level 1: Awareness

Welcome to lesson L1.5.2: Responsible Data Handling for Support Agents. This lesson addresses one of the most important responsibilities you have when using AI in customer support: protecting customer data.

When customers contact support, they often share sensitive information: account numbers, payment details, personal circumstances, health information, financial details. This information is entrusted to you.

When you use AI, you're potentially sharing that information with systems you don't fully control. Understanding how to handle data responsibly when using AI is not optional—it's essential to your professional integrity and your organization's legal compliance.

The Data Handling Imperative

Before you use AI with customer information, ask: What data am I about to share with this AI system? Where will that data go? Who might have access? Is this appropriate?

Many agents think AI is internal and safe. It's not. When you paste customer information into an AI tool—especially public tools—that information leaves your organization's control.

Personally Identifiable Information (PII)

PII is information that can identify an individual:

  • Names
  • Email addresses
  • Phone numbers
  • Mailing addresses
  • Social security numbers
  • Driver's license numbers
  • Passport numbers

PII should generally not be shared with external AI systems without explicit organizational approval.

Financial Information

Highly sensitive and regulated:

  • Bank account numbers
  • Routing numbers
  • Credit card numbers
  • Payment information
  • Account balances
  • Transaction history
  • Financial account credentials

This should never be shared with external AI unless required by law and handled with extreme care.

Health Information

Protected under regulations like HIPAA (in the US) and similar laws elsewhere:

  • Medical diagnoses
  • Medication information
  • Hospital/clinic visits
  • Mental health information
  • Any health-related concerns customers mention

This requires special protection and should only be handled by AI systems specifically designed for healthcare support.

Types of Sensitive Data

Information about the organization's operations, finances, or strategy:

  • Internal pricing
  • Unreleased product plans
  • Strategic decisions
  • Employee information
  • Internal processes
  • Financial performance

This should never be shared with external AI systems.

Data Minimization Principle

The core principle of responsible data handling: share the minimum information necessary to accomplish the task.

If you need to ask AI to draft a response, you don't need to include the customer's full account history. You need only the relevant context.

Example: Wrong way

Customer message: "I'm frustrated with your billing. My account number is 782945-B. I was charged twice for my subscription last month. My email is [customer email]. I live at [address]. I have three kids and lost my job last month so I'm under financial stress."

Agent to AI: "[Entire message]"

This shares PII, financial information, and personal details that don't matter for drafting a response.

Example: Right way

Agent to AI: "Customer reports being charged twice for subscription. Subscription costs $49/month. Customer is frustrated about the duplicate charge. Please draft a response acknowledging the error, apologizing, and promising a refund."

This shares only the information needed, no PII, and enables AI to help without exposing sensitive data.

Organizational Data Policies

Your organization should have policies about what data can be shared with AI. Common policies:

Policy Type 1: No External AI

No customer data can be shared with external AI systems. Agents can only use AI with information they make up or general knowledge.

Policy Type 2: De-Identified Only

Customer data can be shared with AI only if all PII is removed. Instead of "John Smith," write "customer." Instead of specific account numbers, write "customer's account."

Policy Type 3: Approved Systems Only

Agents can only use AI systems the organization has vetted and contracted. These systems have data handling agreements that protect customer information.

Policy Type 4: Restricted Categories

Certain data (financial, health, legal) can never be shared with AI. Other data can be shared with approved systems.

Know your organization's policy. If you're unsure, ask before using AI.

The GDPR and CCPA Context

Two major regulations affect how organizations can handle customer data with AI:

GDPR (General Data Protection Regulation) - applies to EU customers and their data:

  • Individuals have a right to know what data is collected
  • Organizations must protect data
  • Organizations can't transfer data outside the EU without protection measures
  • Individuals can request data deletion

CCPA (California Consumer Privacy Act) - applies to California residents:

  • Individuals have a right to know what data is collected
  • Organizations must protect data
  • Individuals can request deletion

If your organization serves EU or California customers, you must handle their data extra carefully. Sharing customer data with an external AI system might violate these laws.

Anti-Pattern 1: Assuming AI is Safe Because It\'s Cloud-Based

Just because AI is accessed through the internet doesn't mean it's safe for customer data. Cloud systems can be hacked. The AI company can have a data breach. Your data could be subpoenaed.

Don't assume cloud = safe.

Anti-Pattern 2: Treating All Data the Same

Some data is more sensitive than others. A customer's name is less sensitive than their bank account number. Treat them differently.

Develop judgment about data sensitivity. Share less sensitive data more freely. Restrict highly sensitive data.

Anti-Pattern 3: "De-Identifying" But Still Including Identifying Information

You remove the customer's name but include account number, email, and three details that together make the person identifiable. That's not de-identification.

Real de-identification means removing all information that could identify the specific person.

Anti-Pattern 4: Not Deleting Sensitive Data

You ask AI to help with a sensitive issue. AI provides suggestions. You delete the draft but assume the AI system deleted the data too.

Most AI systems retain data. Your sensitive information might still be there, accessible by the AI company or in backups.

If handling sensitive data, you need to use systems where your data won't be retained—and you need to verify this in writing.

Anti-Patterns: Data Handling Failures

You sign up for a free ChatGPT account to help with work. You share customer information with your personal account.

The problem: the AI company owns that data. Your organization has no control. If the AI company is hacked, customer data is exposed. You've created liability for your organization.

Always use an organization-approved AI system with a work account, not a personal account.

1. Evaluate the Sensitivity

Before using AI, ask: How sensitive is this data? Would customer be upset if it were exposed? Is it regulated data?

Sensitivity matrix:

  • Not sensitive: General questions about products/services
  • Low sensitivity: Customer's concern/issue (without PII)
  • Medium sensitivity: Customer names, account information (without financials)
  • High sensitivity: Financial information, health data, legal information
  • Restricted: Passwords, payment details, security information

2. Check Organizational Policy

Know whether your organization allows sharing this data with AI. If unsure, ask before using AI.

3. Minimize the Data

Share only what's necessary. Remove PII, account numbers, and identifying details unless essential.

4. Use Approved Systems

Use only AI systems your organization has approved and vetted. If your organization hasn't approved any, ask IT before using external AI.

5. Verify Data Handling Terms

If your organization uses a particular AI system, the contract should specify:

  • How long the AI company retains data
  • Whether your data is used to train future AI models
  • Whether data can be transferred outside your country
  • What happens if the AI company is hacked

If these terms aren't clear, raise concerns with your organization.

6. Never Paste Sensitive Data

Don't paste customer data directly into AI. Instead:

  • Rephrase it without PII
  • Summarize the issue without details
  • Describe the situation generically

7. Delete Drafts

If you ask AI to help with sensitive data, delete the draft conversation. Don't leave sensitive information accessible.

Best Practices for Data Handling

If you accidentally share sensitive data with an unapproved system, report it immediately to your IT or compliance team. Speed matters in breach response.

Practice Prompts

Prompt 1: The Sensitivity Assessment

A customer mentions they're on disability and asks about accommodations. Is this sensitive data? Why or why not? Could you share this with AI?

Prompt 2: The De-Identification Challenge

A customer writes: "I'm Sarah Chen, account 849203, and I'm upset because I was double-charged." Rewrite this for AI without PII but with enough information for AI to help draft a response.

Prompt 3: The Policy Question

Your organization hasn't published a clear policy on AI use. A colleague is using AI with customer account numbers. What should you do?

Prompt 4: The Breach Scenario

You accidentally pasted a customer's payment information into a public AI system before realizing what you'd done. What's your immediate action?

Key Takeaways

One. Before using AI, ask: What data am I about to share? Where will it go? Is this appropriate?

Two. Never share financial information, health information, payment details, or passwords with external AI.

Three. Apply data minimization: share only the information necessary for the task.

Four. Understand the difference between PII (names, contact info) and other sensitive data (financial, health).

Five. Use only AI systems your organization has approved and vetted.

Six. If your organization hasn't approved AI systems, ask IT before using external tools.

Seven. If you accidentally share sensitive data, report it immediately.

Glossary

PII (Personally Identifiable Information): Information that can identify an individual, like name, email, phone, or address.

Sensitive Data: Information that requires protection, including financial, health, legal, or personal information.

De-Identification: Removing all information that could identify a specific person from a message or record.

Data Minimization: Sharing only the information necessary for a specific task, no more.

GDPR: European regulation protecting customer data rights and requiring organizational accountability.

CCPA: California regulation giving residents rights over their personal data.

Data Retention: How long an AI system keeps the data you share with it.

Reflection Exercise

Reflect on this: In your current work, where are you sharing customer information with AI? Is that information sensitive? Does your organization approve this? What would change if you applied stricter data minimization?

Closing Remarks

Responsible data handling is not a compliance checkbox. It's respect for the customers who trust you with their information. When you use AI, you're responsible for ensuring that trust isn't violated.

In our next lesson, L1.5.3, we'll expand our ethical perspective to discuss broader ethical considerations in AI-assisted support.

A SkillsClinic initiative.

Key Takeaways

Five. Use only AI systems your organization has approved and vetted.

Seven. If you accidentally share sensitive data, report it immediately.

Glossary

Reflection Exercise

Closing Remarks

A SkillsClinic initiative.