Follow the data after it leaves the form
A privacy review that stops at the source file misses much of the risk. Prompts, retrieved passages, model inferences, logs, support access and human decisions can all create another copy or another use of personal information.
Our F-104 map follows each data copy and assigns a concrete question and control, including unsupported inferences and retained logs.
The map is meant for the design stage, while a team can still remove fields, narrow access or change a vendor term without rebuilding the project.
Keep in mind: It is a working method, not a legal opinion. The privacy office or regulator responsible for the organization must decide what its rules require.
In this article6 sections
Editorial note: The F-104 workflow is fictional and the data map is a planning aid. Canadian privacy duties depend on the organization, jurisdiction and facts, so the responsible privacy office or qualified adviser must assess a real project.
The prompt is only one place to look
An AI service can create several records from a single request: the original document, extracted text, a prompt, retrieved passages, a generated inference and operational logs. A review that checks only the uploaded file can miss the copies that are harder to find later.
Canadian privacy obligations depend on the organization, activity and applicable jurisdiction. The privacy commissioners’ generative-AI principles stress lawful authority, appropriate purposes and necessity, including attention to inferred information about identifiable people. The map below is our design method for exposing those questions. It is not a legal opinion or a substitute for the assessment required by your organization.
Start by removing the need for a real person’s record
Our fictional request F-104 asks for help drafting a plain-language explanation of an invoice status. The task needs the status and a neutral description of the next step. It does not need a customer’s name, address, payment card, medical circumstance or the surrounding email history.
First test the drafting task with invented facts. If the organization later proposes using real records, identify why each field is necessary and who authorizes that use. Replacing a name with F-104 does not make the record anonymous if someone can reconnect the identifier or recognize the unusual circumstances. Keep that distinction in the assessment.
A data-flow map with decisions attached
For each copy, record purpose, access, retention and deletion or correction handling. “The vendor manages it” is a destination, not an answer. Obtain the applicable product terms and actual configuration; consumer and organizational offerings can have different arrangements.
Scroll the table sideways to see every column.
| Data location | Question before use | Proposed control |
|---|---|---|
| Source email | Which facts are necessary for drafting? | Keep the source in its approved system; prepare a minimal extract. |
| Prompt | Can the task work without an identifier? | Use a fictional or non-identifying example where possible. |
| Retrieved material | Could unrelated personal records enter the answer? | Restrict retrieval to authorized, relevant material. |
| Generated output | Did the system infer something about the person? | Remove unsupported personal inferences before use. |
| Logs and support | Who can inspect prompts and for how long? | Confirm access and retention rather than assuming chat deletion is enough. |
| Final record | Where will a correction have to propagate? | Keep the source-to-output relationship and assign a correction owner. |
An inference can create a new privacy problem
Suppose the fictional source says “payment is pending while documentation is checked.” A draft that calls the customer financially distressed adds a personal inference the source did not establish. Even if nobody uploads a new field, the output now says something new about an identifiable person.
Our design response is to keep the draft tied to the status, reject the inference and prevent it from becoming a searchable customer note. The privacy commissioners’ principles say to treat inferences about identifiable people as personal information, use them for specified purposes and assess their accuracy. That guidance does not by itself decide which law applies to this fictional business. A reviewer should ask whether the sentence is accurate and whether the use is authorized.
Questions to send a provider before connecting records
Ask which service and agreement govern this exact account. Identify processing and storage locations, support access, subprocessors where relevant, training uses, retention settings and how those settings are enforced. Record the answer’s date and source. A sales summary should not silently replace the contractual or technical document.
Also ask what happens when an employee leaves or a source permission changes. A previously indexed copy or cached answer may outlive the access that permitted it. Your assessment needs an answer for the copied material, not just the original folder.
five procurement evidence requestsAsk for inspectable records before connecting a supplier to personal information.
For this product, account configuration and data category, which copies of our input and generated output are retained, who can access them, and what documented process removes or corrects each copy? Please identify any exceptions rather than answering only for the visible chat history.Turn unknowns into a release decision
A useful assessment can end with “do not connect the records yet.” List the missing evidence, its owner and what work can safely continue with synthetic data. Do not mark an unanswered retention question as low risk just because the demonstration worked.
For F-104, the narrow drafting exercise can proceed with invented facts. Real customer access remains outside this exercise. The transferable result is a map that connects every data copy to a purpose and a responsible decision, making the eventual privacy review more specific and easier to challenge.
Continue with the original sources
These claim-relevant primary and first-party references support the reporting above. Open them for technical detail, current requirements and subsequent updates.
- priv.gc.caCanadian privacy authorities: Principles for generative AI ↗Supports the discussion of legal authority, necessity, inferred personal information and differences across Canadian privacy regimes. The F-104 data map is our fictional design exercise.
- canada.caGovernment of Canada guide on generative AI ↗Federal operational guidance used for examples of data handling, privacy, security and human-review risks in generative-AI work.
- nist.govNIST AI Risk Management Framework ↗A voluntary risk-management framework used to structure governance, mapping, measurement and management steps; it does not replace Canadian privacy requirements.
Finished reading? Save that here without waiting for a timer.
Correction, September 23: narrowed the description of the privacy commissioners’ guidance on inferences; see the correction record.
See something we should fix or clarify? Read the corrections policy or tell the newsroom. Material changes are noted here.
