Personal Data in LLM Prompts: Enterprise Redaction, Logging and Retention Workflow
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
2-minute summary
- LLM prompts can contain customer, employee, vendor or transaction data even when users think they are entering “just context”.
- Redaction must happen before submission, not after the model has received the prompt.
- Enterprise logging should record enough for security and audit without recreating the same personal-data exposure in telemetry.
Current position
Control and evidence map
| # | Control / evidence requirement | |
|---|---|---|
| 1 | Define prohibited prompt classes such as full identity documents, credentials, health records or unredacted customer case files unless specifically approved. | |
| 2 | Use deterministic masking/tokenisation for names, account numbers and identifiers before prompt submission. | |
| 3 | Restrict enterprise AI to contracted tools with known retention/training settings; block unmanaged consumer accounts for sensitive work. | |
| 4 | Design logs to capture user/tool/purpose and risk events without storing full prompt text by default. | |
| 5 | Create an exception process for cases that genuinely require identifiable data and document the reason. | |
Worked example
A support analyst wants help summarising a complaint and pastes a full KYC packet into a public AI chat. A safer workflow extracts the complaint facts, substitutes customer identifiers with tokens and uses an approved enterprise tool whose retention and training settings have been reviewed. The mapping back to the customer remains inside the company system.
Common mistakes
- Redacting only the final AI answer.
- Logging every prompt forever for “audit”.
- Assuming enterprise branding means the vendor never trains on data.
- Allowing browser extensions to send page content to unapproved models.
Frequently asked questions
When should redaction occur?
Before data is submitted to the model.
Should full prompts always be logged?
No; logging itself should follow data-minimisation and security principles.
Are all DPDP processing duties live in October 2026?
No.
What is the first control?
Approved-tool policy plus technical blocking/redaction for high-risk data classes.
Official sources
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Act, 2023 (Act 22 of 2023; 2023-08-11)
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E); 2025-11-13)
- Ministry of Electronics and Information Technology - DPDP Act commencement notification (G.S.R. 843(E); 2025-11-13)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.