Track 04Operational GuardrailsLocked by prerequisiteRequired

Data Privacy & Confidentiality

Make data classification an automatic reflex before any AI interaction, so that personal, confidential and proprietary information never leaves its permitted boundary.

5 lessons · 5 frameworks · 3–4 hours · 0/5 complete · 0/5 exercises recorded

Locked by prerequisite

This track opens once its prerequisites are complete. Prerequisites are sequenced deliberately: each one supplies a competency this track assumes you already hold.

  • Track 01 — AI Fundamentals
  • Track 02 — AI Governance & Regulatory Expectations

Orientation

Why this matters

An AI prompt is a disclosure. Once patient data, trial results or proprietary process detail has been sent to a system that was not authorised to receive it, no amount of subsequent care undoes the transfer.

What you will be able to do (5)

  • Recognise the categories of sensitive data handled in life sciences
  • Classify data before it is entered into any AI system
  • Apply privacy-preserving practices such as minimisation and de-identification
  • Protect confidentiality and intellectual property in third-party AI contexts
  • Recognise and escalate a data exposure immediately

Aligned with (5)

GDPR — lawful basis, minimisation and special category dataHIPAA — protected health informationEU GMP Annex 11 and 21 CFR Part 11 record controlsISO/IEC 27001 — information security managementICH E6(R3) — participant confidentiality

Maps to published expectations. Competency demonstrated through assessment.

Regulatory alignment indicates that curriculum topics map to published regulatory expectations. It does not constitute agency approval, certification, legal advice or a determination of organizational compliance.

View source evidence, status and applicability

GDPR — lawful basis, minimisation and special category data

Binding lawEuropean Economic Area
Regulation (EU) 2016/679 — General Data Protection Regulation
Relevant provisions
Articles 5, 6, 9, 13–14, 22, 25, 32 and 35
Status and date
27 April 2016. Applicable since 25 May 2018 when material and territorial scope are met.
Why it maps
Supports the track's stated mapping to GDPR — lawful basis, minimisation and special category data without transferring duties beyond the source's scope.
Applicability limit
The relevant duties depend on personal-data processing, role, lawful basis, location and data-subject context.

Primary source last verified 2026-08-24

HIPAA — protected health information

Binding lawUnited States
45 CFR Part 164 — HIPAA Privacy and Security Rules
Relevant provisions
45 CFR §§ 164.308, 164.312 and 164.502
Status and date
Current electronic Code of Federal Regulations. Applies to covered entities, business associates and protected health information within rule scope.
Why it maps
Supports the track's stated mapping to HIPAA — protected health information without transferring duties beyond the source's scope.
Applicability limit
HIPAA is not a general confidentiality law for every life-sciences dataset. Entity status and PHI determine scope.

Primary source last verified 2026-08-24

EU GMP Annex 11 and 21 CFR Part 11 record controls

GMP requirementEuropean Union GMP
EudraLex Volume 4, Annex 11 — Computerised Systems
Relevant provisions
Sections 7–9 and 11–12 — storage, printouts and audit trails
Status and date
Revision January 2011. Current Annex 11; came into operation 30 June 2011.
Why it maps
Supports the track's stated mapping to EU GMP Annex 11 and 21 CFR Part 11 record controls without transferring duties beyond the source's scope.
Applicability limit
Applies to computerised systems used as part of GMP-regulated activities. Applicability follows the regulated process and intended use.

Primary source last verified 2026-08-24

Binding lawUnited States
21 CFR Part 11 — Electronic Records; Electronic Signatures
Relevant provisions
§§ 11.10, 11.30, 11.50, 11.70 and 11.100–11.300
Status and date
Current electronic Code of Federal Regulations. Applies when predicate-rule records are maintained or submitted electronically and Part 11 scope is met.
Why it maps
Supports the track's stated mapping to EU GMP Annex 11 and 21 CFR Part 11 record controls without transferring duties beyond the source's scope.
Applicability limit
Part 11 does not make every electronic output a regulated record. Predicate rules and record use determine applicability.

Primary source last verified 2026-08-24

ISO/IEC 27001 — information security management

Consensus standardInternational consensus standard
ISO/IEC 27001:2022 — Information security management systems
Relevant provisions
Clauses 4–10 and Annex A information-security controls
Status and date
October 2022. Voluntary unless adopted by contract, policy or certification scheme.
Why it maps
Supplies a recognised management or assurance practice; it is identified as non-binding unless separately adopted.
Applicability limit
Provides an information-security management system. Specific privacy, GxP and AI duties still require separate applicability analysis.

Primary source last verified 2026-08-24

ICH E6(R3) — participant confidentiality

Harmonised guidelineICH regions; implemented through regional frameworks
ICH E6(R3) — Good Clinical Practice
Relevant provisions
Principles and Annex 1 provisions on roles, data governance, records and oversight
Status and date
Principles and Annex 1, Step 4, 6 January 2025. Implementation depends on regional adoption and the clinical-trial activity.
Why it maps
Supports the track's stated mapping to ICH E6(R3) — participant confidentiality without transferring duties beyond the source's scope.
Applicability limit
Applies to clinical trials within its scope. It should not be transferred to manufacturing or other domains without an independent basis.

Primary source last verified 2026-08-24

Full source register and editorial method →

Credential

AI Data Privacy and Confidentiality Badge

Duration

3–4 hours

Audience

  • All personnel handling personal, clinical or proprietary data
  • Clinical, safety and regulatory professionals
  • Anyone using AI tools with documents they did not author

Prerequisites

  • Track 01
  • Track 02

Behaviours practised (3)

UnderstandApplyEscalate
A safety associate needs help drafting a narrative and pastes an individual case safety report — name, date of birth, indication and free-text medical history — into an assistant. The assistant is approved. The data class is not. This track is about the seconds before that paste.

Badge requirements (5)

  1. Complete all five lessons and their knowledge checks
  2. Achieve at least 80% across the final badge assessment
  3. Answer every safety-critical question correctly
  4. Produce a minimised request and a complete data-exposure record
  5. Select the correct escalation route for every exposure scenario

Lessons (5)

Final badge assessment

AI Data Privacy and Confidentiality Badge

  • Sensitive-data identification

    Select all that applySafety-critical

    Identify every category of sensitive information across four mixed life-sciences documents.

  • Classification decisions

    Scenario classificationSafety-critical

    Apply the highest-classification rule and tool permissions to six proposed AI interactions.

  • Exposure escalation

    Choose the correct escalation pathSafety-critical

    Select correct immediate actions and routing for three exposure and near-miss situations.

  • Practical exercise — minimised request

    Practical exercise

    Rewrite a clinical request so that no participant data is transmitted while the assistance remains useful.

Next recommended track

← All tracks