Language: English
When you connect an AI assistant to ActivityInfo, the assistant reads data from your database and sends it to the company that runs the assistant. That company processes your data on your behalf. Whether this is acceptable is a data protection decision for your organisation, not a technical one, and it has to be settled before anyone connects an assistant to a database that holds sensitive data.
Sensitive data in ActivityInfo usually means personal data about the people a programme serves: names, contact details, household composition, locations, health information, protection cases, or free text that identifies someone indirectly. This article describes what to check, in the order to check it.
What leaves ActivityInfo
An assistant acts with the permissions of the user who authorised it, as described in Understanding permissions for AI assistants. Within those permissions, the data that reaches the AI provider includes:
- the names and descriptions of databases, folders, forms and fields,
- the values in the records the assistant retrieves, including free text,
- the results of the analyses it runs, and
- the questions you ask and the answers it gives, both of which repeat data back.
Treat everything an assistant reads as data your organisation has disclosed to the provider. Assume it is stored in the conversation history, and that it may be read by the provider's staff under the conditions its terms describe.
Use a business or enterprise account
A consumer account and a business account from the same provider are often governed by different terms.
Consumer accounts, including free accounts and individual paid subscriptions, commonly:
- allow the provider to use the content of conversations to improve or train its models,
- offer no Data Processing Agreement, only consumer terms,
- give your organisation no administrative control over who connects what, and no control over how long conversations are kept, and
- make no commitment about where the data is processed.
An account on a business, team or enterprise plan, bought by your organisation rather than by an individual, normally offers a Data Processing Agreement, administrative controls and retention settings. Terms differ between providers and change over time, so read the terms that apply to the specific plan on the date you buy it, rather than relying on a summary.
Do not connect a database that holds personal data using a consumer account.
Review the Data Processing Agreement (DPA)
Under the GDPR and similar legislation in other countries, your organisation is the controller of the data in your ActivityInfo database, and an AI provider that processes it becomes a processor. A written agreement is required, and your organisation should review it before connecting. Check that it:
- names the provider as a processor and limits processing to providing the service to you,
- states that your inputs and outputs are not used to train or improve the provider's models,
- lists the sub-processors and says how you are told when they change,
- states how long inputs and outputs are kept, and how they are deleted,
- describes the security measures that apply,
- commits the provider to notifying you of a personal data breach,
- gives your organisation a right to audit or to receive audit reports, and
- sets out the legal mechanism for any processing outside your own region.
Keep the signed agreement with your record of processing activities, together with a note of which databases the decision covers. If a provider offers no Data Processing Agreement, do not connect a database that holds personal data.
Keep sensitive data out of model training
A model trained on your records can reproduce fragments of them in answers given to other people. Deleting a conversation, closing an account or invoking a right to erasure does not remove data from a model that has already been trained on it.
So confirm two separate things:
- Training exclusion. The Data Processing Agreement, or the terms for your plan, should state that your content is not used for training. Where the provider also offers a setting for this, check the setting as well, and check it again after any change of plan or after the provider changes its terms.
- Human review and retention. Providers commonly retain conversations for a period to monitor for abuse, and staff may read flagged conversations. This is separate from training, is often not something you can switch off, and is a disclosure of the data in its own right. Find out the retention period and who can read the data during it.
Consider where the data is processed
Moving personal data across borders often requires a lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses together with an assessment of the risk in the destination country. Most large AI providers process data in the United States, or across several regions.
Establish, in writing:
- the regions where the model runs and where conversation history is stored,
- the locations of the sub-processors,
- whether the plan offers a data residency commitment, and whether that commitment covers processing as well as storage, and
- which transfer mechanism the agreement relies on.
Record the assessment. For some categories of data, the conclusion may be that no transfer is acceptable and the data should stay out of any database that an assistant can reach. Data revealing health, data about protection or gender-based violence cases, and any data that could put a person at risk if it were disclosed belong in that category unless your data protection adviser says otherwise.
Consider local providers
The leading AI providers OpenAI and Anthropic, are based in the United States. However, they are not the only options to consider.
Mistral AI is established in France and states that it hosts data in the European Union by default. Its assistant supports custom MCP connectors, so it can connect to ActivityInfo in the same way as the other assistants described in this manual. See Connecting Mistral to ActivityInfo.
For an organisation that has to keep personal data within the European Union, an EU-based provider removes the international transfer question rather than requiring you to manage it. It does not remove the other checks: review the Data Processing Agreement, confirm the training exclusion for the plan you buy, and use an organisational account rather than a personal one.
Reduce what an assistant can reach
Once your organisation has decided that a provider is acceptable, limit the exposure to what the work actually needs:
- Turn on the MCP server only for the databases that need it. The setting is per database and off by default.
- Grant read access only, unless the assistant needs to make changes.
- Connect with an account whose role grants only what is needed. A role limited to the relevant folders, or limited by a condition to part of a form, limits the assistant in the same way. Avoid connecting with an administrator account out of convenience.
- Leave direct identifiers out of forms where the purpose does not require them. A form that does not need a name or a phone number to serve its purpose should not collect one.
- Keep the most sensitive data in a separate database that has the MCP server switched off.
Decide who may connect, as an organisation
The switch is per database, and the person who turns it on makes the decision for everyone who has access to that database. That makes it an organisational decision rather than an individual one.
Write down and circulate:
- which databases may be connected to an assistant, and which may not,
- which providers and which plans are approved,
- who approves a new connection, and
- how often existing authorisations are reviewed.
Ask users to review the assistants they have authorised periodically and to revoke the ones they no longer use, as described in Reviewing and revoking connected assistants.