Governance, Ethics & Legal Practical insights
Write a usable agency policy for client data in AI
Set practical agency rules for client data in generative AI, with approved environments, permission checks, escalation routes and onboarding examples.
An agency AI policy should help a colleague decide what to do with a client file at the moment of use. A broad instruction to ‘be careful with confidential data’ leaves too much interpretation. Connect the rule to the client agreement, the information involved and the approved environment.
Classify the actual work
Create examples for common tasks: rewriting public website copy, summarizing an unpublished launch plan and analyzing a customer export. State which tool and account may be used for each. Public content can still include personal data or third-party rights, so ‘available online’ should not automatically mean unrestricted reuse. The EDPB’s AI opinion reinforces the need for context-specific privacy assessment. [1]
Check authority before uploading
Identify the client owner authorized to approve a use and the agency staff responsible for checking contractual restrictions. Where the agency acts as a processor, consider the documented instructions and relevant GDPR obligations. [2] A colleague’s access to a folder is not, by itself, permission to send its contents to another supplier.
Make the approved path convenient
Provide a short intake form covering purpose, data fields, provider, retention and intended output. Offer an approved alternative when a tool is unsuitable, such as a redacted brief or company-level dataset. Name the escalation contact and expected review process. Staff are more likely to follow a rule when they can still complete the client task.
Teach the boundary with examples
Use fictional materials in onboarding and ask staff to explain their decision. Include freelancers, shared accounts, browser extensions and connected agents. Record policy exceptions with an owner and expiry, then review them when the client contract or vendor terms change. A good policy creates consistent decisions and visible exceptions instead of a document everyone acknowledges once and interprets differently afterward.
Sources and evidence
- EDPB opinion on AI models and personal data
- GDPR primary text — principles and processor instructions
Sources checked on 4 October 2026. Proposed workflows and hypothetical examples are editorial analysis.
From insight to practice
