Track group: Manage AI in the Organization Track: AI Vendor Evaluation

Data Handling

Know what data the vendor receives or stores.

◷ 5 minPracticalVendor Review

What is it?

Data handling means how a vendor collects, uses, stores, shares, protects, or deletes data when an AI feature is used. It includes prompts, files, outputs, logs, transcripts, user activity, and system metadata.

Why it matters

AI features often need data to be useful. But the data may include customer records, employee information, business plans, contracts, code, or support conversations. Leaders need to know where that data goes before they enable the feature.

How it works

Ask what data enters the AI feature, where it is processed, whether it is stored, whether it is used to improve models, who can access it, and how long it is retained. The answer should be documented, not guessed from the user interface.

InputWork or question enters the tool.
ProcessThe AI or team follows a pattern.
OutputThe result is reviewed before use.

Analogy

Data handling is like sending documents to an outside service. You would want to know who receives the documents, what they do with them, how long they keep them, and whether they send them anywhere else.

Example usage

A document collaboration tool may add AI summaries. That sounds harmless until you ask whether the AI feature can read confidential board papers, customer contracts, or employee data. The feature may be useful, but it needs boundaries.

How to use this

Create a vendor data question set. Ask about input data, output data, logs, retention, training use, access controls, and deletion. Match the answer to the sensitivity of the work.

Common mistake

The common mistake is checking the main product privacy policy and assuming the AI feature works the same way. AI features may have separate settings, subprocessors, or data flows.

Question to ask

Input

What data enters the AI feature?

Storage

Is the data stored, logged, or retained?

Training

Can the data be used to improve models or services?

Access

Who can access prompts, files, outputs, or logs?

Quick quiz

What should you check before enabling a vendor AI feature?

Flashcard

Learn this another way

Audio brief, podcast version, mind map, and visual summary.

Data flow questionsVendor review cardApproval checklist