Colorado repealed its AI Act — the ADMT law that replaced it starts January 1, 2027See what changed →
The chrome lion guarding a vault of organizational records
🔒 Data management

The real question is what goes into the tool

Client records, donor details, health information, employee files. Most AI trouble starts with data going somewhere nobody decided it could go. Write the rule down, attach it to each tool, and you've removed the guesswork.

Four plain rules

What your data management policy says

What may go in

Public and internal material, yes. Client, donor, health, and employee records, only in named tools with an agreement in place.

Where it ends up

Whether the vendor keeps it, trains on it, or sends it elsewhere. Recorded per tool, in your inventory.

How long it stays

A retention answer per tool, so “delete our data” is a request you can actually fulfil.

Who to ask

A named owner per tool, so staff have somewhere to go instead of guessing.

Looking for HIPAA, GDPR or CCPA?

Those are privacy obligations rather than data management, and they have their own page — with a crosswalk for each and the deletion clocks tracked for you.

Privacy & the three laws →

Find out what's leaving your building

The free scorecard asks what data your team puts into AI tools, and shows you the gaps.

Take the free scorecard →