TwinEthosRequest access

Control

Whole personal-data records sent to an AI model

Prompts, retrieval context and embeddings carry only the personal data the AI task needs, selected field by field or pseudonymised, never a whole user or customer record by default.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.personal-data-to-ai-not-minimised

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in European Union (EU).

The guard to add

Build prompts, retrieval context and embedding inputs from an explicit per-task field allowlist or pseudonymised data, never a serialized whole user record.

In each prompt builder, retrieval formatter and embedding job, select only the fields the task needs (an allowed_fields projection, pydantic model_dump(include=...), or a typed DTO), replace direct identifiers with a pseudonymous id where the task does not need them, and redact PII in free text such as tickets or notes (for example Presidio AnalyzerEngine and AnonymizerEngine). Never pass json.dumps(user), JSON.stringify(customer), vars(profile) or account.model_dump() into a model or embedding call. Apply the same selection to what AI telemetry and prompt logs capture.

Where it goes: 7 prompt construction, 1 application source code, 10 logs and telemetry.

What reviewers look for: in files that call a model or embedding API, an explicit field projection, pseudonymous ids, or a redaction step before the call; no whole-object serialization of user, customer, account, profile or contact records into prompts, context or embedding inputs; prompt logging that records the minimised payload, not the full record.

Example (Python + OpenAI SDK), before:

user = db.get_user(uid)
prompt = 'Suggest a plan upgrade for this customer: ' + json.dumps(user)
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

After:

ALLOWED_FIELDS = ('plan', 'monthly_usage_gb', 'tenure_months')
user = db.get_user(uid)
facts = {k: user[k] for k in ALLOWED_FIELDS}        # no name, email, address
prompt = 'Suggest a plan upgrade for this customer: ' + json.dumps(facts)
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)