AI and Data Privacy: The Questions Every SMB Should Ask

Category: blog

AI tools are being added to business workflows

Common examples

  • Chatbots
  • Copilots
  • Meeting transcription
  • Document analysis
  • CRM automation
  • Code assistants
  • Customer service tools
  • AI features inside email and cloud platforms

The privacy risks are connected to data handling

Before approving any AI tool, document the answers to the questions below

Questions

1. What data will enter the AI system

Identify every data type processed

  • Prompts
  • Uploaded files
  • Customer records
  • Employee information
  • Email content
  • Meeting recordings
  • Source code
  • CRM data
  • Cloud storage files
  • Metadata
  • Usage logs
  • AI outputs
  • Embeddings and indexes

Classify the information

  • Public
  • Internal
  • Confidential
  • Personal
  • Regulated

Do not assume that the prompt is the only stored data

Connected AI tools may retrieve files, process account information, record activity, and create additional data artifacts

A data flow should be documented before deployment

Business data moving through controlled AI workflow layers with permissions gates and security controls

2. Is business data used for model training

Ask directly

  • Is our data used to train models
  • Is training enabled by default
  • Are prompts and outputs used for model improvement
  • Are uploaded files used for testing or human review
  • Is data shared with another model provider
  • Can training be disabled at the tenant or account level
  • Is the restriction stated in the contract

The same vendor may apply different rules to

  • Consumer accounts
  • Business subscriptions
  • Enterprise accounts
  • API services
  • Reseller platforms
  • Embedded software features

A business plan should not be approved based on the vendor name alone

The specific service and account type must be reviewed

Training exclusions should be confirmed in vendor documentation and contract language

The FTC states that AI companies must honor privacy and confidentiality commitments

3. What is retained

Retention must be reviewed by data type

Ask how long the vendor retains

  • Prompts
  • Outputs
  • Uploaded files
  • Conversation history
  • Recordings
  • Transcripts
  • Logs
  • Support tickets
  • Embeddings
  • Search indexes
  • Fine-tuning data
  • Backup copies
  • Security investigation records

Ask whether retention can be configured

Possible settings may include

  • No content retention
  • Short-term retention
  • Seven days
  • Thirty days
  • Ninety days
  • Custom retention
  • Indefinite retention

Content retention and log retention may use separate settings

A tool may delete user-visible conversations while retaining security logs or backup copies

The policy should state

  • Default retention period
  • Configurable retention options
  • Deletion process
  • Backup deletion process
  • Legal exceptions
  • Verification method
  • Responsible vendor contact

Terms such as zero retention require technical clarification

Ask what the term means for prompts, outputs, logs, backups, and support access

4. Can specific data be deleted

Deletion requests should be operational

Ask

  • Can one user record be deleted
  • Can one uploaded file be deleted
  • Can a complete workspace be deleted
  • How quickly is deletion completed
  • Are replicas and backups included
  • Are embeddings and indexes removed
  • Are support copies removed
  • Is deletion verified in writing

The contract should define deletion timelines

The process should be tested before sensitive data is connected

Deletion must also be considered during employee offboarding and customer privacy requests

5. Where is the data stored and processed

Document the vendor’s data locations

Ask

  • Which countries process the data
  • Which cloud providers host the service
  • Is regional storage available
  • Are cross-border transfers performed
  • Which subprocessors receive data
  • Can subprocessor changes be reviewed
  • Are data residency restrictions supported

A vendor may use separate locations for

  • Primary processing
  • Disaster recovery
  • Support operations
  • Monitoring
  • Backups
  • Model hosting

Each location may have different legal and contractual requirements

A cloud migration assessment should include AI data flows when AI services are connected to cloud storage or business applications

6. Who can access the data

Access must be limited to business requirements

Ask whether the platform supports

  • SSO
  • MFA
  • Role-based access
  • Least privilege
  • Admin approval
  • IP restrictions
  • Session controls
  • Privileged access management
  • User offboarding
  • API key controls

Review access for both employees and AI agents

An AI agent may access more information than the user operating it if permissions are configured incorrectly

Confirm

  • Which systems the agent can access
  • Which folders and records are available
  • Whether write access is enabled
  • Whether actions require approval
  • Whether access is logged
  • Whether service accounts are used

Vendor personnel access should also be documented

Ask

  • Who can view prompts or files
  • When support access is permitted
  • Whether approval is required
  • How access is recorded
  • How long access logs are retained

7. Can activity be audited

AI use should be traceable

Ask what audit logs include

  • User identity
  • Timestamp
  • Prompt activity
  • Files accessed
  • Systems queried
  • Outputs generated
  • Actions performed
  • Approvals
  • Configuration changes
  • Administrative access
  • Export activity

Ask whether logs can be

  • Searched
  • Exported
  • Sent to a SIEM
  • Retained under company policy
  • Reviewed during an incident

Monitoring should identify unusual activity

Examples

  • Bulk document access
  • Repeated requests for customer data
  • New integrations
  • Unexpected downloads
  • Use outside approved departments
  • Changes to retention settings
  • API key activity from unknown locations

AI security should be included in the wider network security review

AI data lifecycle showing encrypted records, storage layers, backups, and automated deletion

8. What happens when the contract ends

The offboarding process should be written before deployment

Ask what happens to

  • Customer data
  • Prompts
  • Outputs
  • Uploaded files
  • Logs
  • Backups
  • Embeddings
  • Indexes
  • Fine-tuned models
  • Credentials
  • API keys
  • Access tokens
  • Integrations

Define

  • Export format
  • Export deadline
  • Deletion deadline
  • Backup expiration
  • Credential revocation
  • Access termination
  • Written deletion confirmation

The business should retain usable copies of required records

Copies should be stored under company-controlled retention and backup policies

X-Tek’s backup and business continuity guidance covers recovery planning, restoration testing, and system redundancy

9. Does the AI use match privacy obligations

AI processing may change how personal information is handled

Review

  • Customer privacy notices
  • Employee privacy notices
  • Data processing agreements
  • Retention schedules
  • Consent requirements
  • Contract restrictions
  • Industry requirements
  • Data subject request procedures

Ask whether the business can locate and remove an individual’s information across

  • Prompts
  • Outputs
  • Logs
  • Connected applications
  • Knowledge bases
  • Backups
  • Search indexes

The NIST AI Risk Management Framework provides a structure based on

  • Govern
  • Map
  • Measure
  • Manage

The NIST Generative AI Profile identifies data privacy as a generative AI risk category

SMBs can apply the framework through a smaller operating process

10. What data should never be entered

Create prohibited data categories

Examples may include

  • Passwords
  • API keys
  • Payment card data
  • Social Security numbers
  • Health information
  • Unredacted employee records
  • Legal correspondence
  • Customer credentials
  • Trade secrets
  • Unreleased financial information
  • Full customer databases

Data minimization should be applied

Remove unnecessary

  • Names
  • Account numbers
  • Email addresses
  • Identifiers
  • Contract terms
  • Internal project names
  • Unrelated file content

Use synthetic or anonymized data for testing where possible

A simple rule can be applied

If the information would not be sent to an unknown third party by email, it should not be entered into an unapproved AI tool

Managed AI Services

AI privacy requires ongoing administration

Not only initial vendor approval

X-Tek managed AI services can support the operational controls around AI adoption

Service activities may include

  • AI tool inventory
  • Shadow AI discovery
  • Vendor risk review
  • Data classification
  • Retention policy review
  • Account configuration
  • SSO and MFA deployment
  • Role and permission review
  • SaaS AI feature review
  • Endpoint and network monitoring
  • Logging and alerting
  • Employee policy support
  • Incident response planning
  • Backup and recovery review
  • Periodic security assessments

AI tools should be reviewed as part of the existing IT environment

They should not operate outside identity management, endpoint protection, email security, network controls, backup, and incident response

The AI security mistake review from X-Tek covers shadow AI, personal accounts, embedded features, API keys, monitoring, and response planning

Managed AI services represented by monitored cloud systems, identity controls, backup nodes, and human oversight

SMB Review Checklist

Before approving an AI tool

  • Is the business purpose documented
  • Is every data source identified
  • Is personal data involved
  • Is confidential data involved
  • Is model training disabled or contractually restricted
  • Are retention periods documented
  • Can deletion be verified
  • Are storage locations known
  • Are subprocessors listed
  • Is a DPA required
  • Are SSO and MFA supported
  • Are permissions limited
  • Are agent actions logged
  • Can logs be exported
  • Are personal accounts prohibited
  • Are embedded AI features reviewed
  • Is human approval required for high-impact actions
  • Are backups included in the recovery plan
  • Is AI use included in incident response
  • Is the vendor reviewed periodically

Any unanswered question identifies a control gap

The response should be documented before rollout

The tool should be classified as

  • Approved
  • Conditional
  • Prohibited

AI adoption can continue within defined data, access, retention, and monitoring controls

Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075