Using AI at Work: A Data Privacy Checklist for Sri Lanka

Published · By App Dev Sri Lanka
Reading time: 4 min read
Editorial illustration: a Sri Lankan team separating public sample documents from a closed confidential folder beside a laptop

Before using an AI tool for workplace material in Sri Lanka, decide what information the task really needs. A request to improve an email rarely requires an entire customer database or a confidential meeting archive.

This checklist helps you make a practical data decision. Your organisation's policies, contracts and applicable requirements still determine what you may share.

Classify the information

Information type Practical starting point
Public material Confirm relevance and permission to reuse
Fictional sample Prefer for demonstrations and testing
Internal routine material Check the approved tool and policy
Personal or client data Share only through an authorised workflow
Credentials or secrets Do not place in prompts or public examples

A document can contain several categories at once. A public report with a private annotation is no longer just public material.

Read the actual content before uploading it. Filenames do not reliably describe sensitivity.

Check the account and service

Identify whether you are using a personal account, a managed workplace account or an API. Do not assume they have identical data terms.

The Gemini Apps Privacy Hub is one example of product-specific information about data handling and settings. Use the equivalent official documentation for the service you choose and check the terms that apply to your account.

Look for retention, model-improvement use, administrator controls and sharing behaviour. If you cannot establish whether the tool is approved for the material, ask the responsible person before uploading it.

Minimise the input

Replace real names, account references and amounts with fictional values when the task allows it. Summarise the problem instead of sharing a full thread.

For a formula question, a five-row invented table may be enough. For an email rewrite, a short factual brief can replace private customer correspondence.

Remember that removing a name may not fully anonymise a document. A detailed combination of dates, roles and events can still identify someone.

Protect credentials and access

Keep API keys, passwords and recovery codes out of prompts, screenshots and repositories. Google's Gemini API key guidance explicitly advises keeping keys confidential and out of source control.

Use the account-security controls your organisation requires. Check who can view shared conversations, generated documents and connected files.

Before sharing an AI-generated output, inspect it for copied private information. The output may contain sensitive details from the input even when the summary is shorter.

Plan the review and retention

Decide who approves the result and where the final document belongs. Do not leave important work scattered across personal accounts without a clear owner.

Follow the organisation's retention and deletion process. Deleting a local file does not automatically establish what happened to a copy uploaded to a service.

Keep a record of the tool, account context and approval when the workflow requires it. A repeatable process helps colleagues make consistent decisions.

Is a paid AI plan automatically approved for confidential work?

No. Check the actual account terms and your organisation's approval. Price alone does not establish suitability.

Can you paste an API key to ask why it fails?

Use an error message with the secret removed. Troubleshooting should not expose the credential.

Is fictional data always enough?

It is often enough for prototypes and examples. Some real workflows need real information, but that requires the appropriate authorised setup.

What should you do after an accidental upload?

Stop further sharing, preserve the relevant facts and follow your organisation's incident process. Use the service's official controls and support information as appropriate.

What is the simplest useful rule?

Share the minimum information needed through a tool that is approved for that information.

Browse the Sri Lanka work and technology guides for more practical application, AI and workplace projects.

About the author

App Dev Sri Lanka prepared this guide with AI assistance, original examples and the linked primary sources. The collection was informed by Google Trends research for Sri Lanka on 2 September 2026. Illustrations depict fictional people. Examples are educational; this article is not a live vacancy notice or an employer endorsement.

Learn more about App Dev Sri Lanka

Ready to transform your digital presence?

Contact us today to learn more about our services and how we can help your business grow.

Get Started
App Dev Sri Lanka

App Dev Sri Lanka transforms your digital presence with our expert web and app development services in Sri Lanka.

Services
Company
Get Social

© 2026 App Dev Sri Lanka.

Built with

Next.js Logo