WEAR YOUR POSITION.
Shipping & returnsLinkedIn
PRIVACYAF
PRIVACYAF / PRACTITIONER WORKSPACE

Bring a better brief.
Make a better decision.

Turn an AI or surveillance proposal into questions, evidence and assigned next actions. Free to use. No account required.

Find official sources

Your entries stay in this page’s memory. Reloading clears them. Download your brief before leaving. Changing the scenario keeps your entries; clear the brief before starting a different project.

AI VENDOR REVIEW / 1 OF 6

What problem does this solve, and what less intrusive option was considered?

Define a specific use. “Improve efficiency” is not enough to explain whose information is needed or why.

Evidence to look for

Business purpose, expected benefit, alternatives and reasons for rejection.

ASK THE VENDOR / ASK THE TEAM

Questions for this conversation.

  1. Does each account tier have the same data terms?
  2. Can prompts, uploads, outputs and logs follow different retention rules?
  3. Which subprocessors or people can access the material?
  4. How are model updates and changes to terms communicated?
METHOD / REVIEWED OCTOBER 6, 2026

An inspectable foundation.

This PrivacyAF question set draws on impact-assessment and AI risk-management practices. It is a discussion aid, not a complete assessment template or a substitute for local requirements.

NIST AI RMF PlaybookVoluntary AI risk management resourceICO: How do we do a DPIA?United Kingdom regulator guidance; check current revisionsNCCoE: Agent identity and authorisationExploratory US standards project, not a certificationHelp improve the questions
PRIVACYAF COMMUNITY / PRIVACY AT WORK

Take the question beyond the worksheet.

Discuss a general challenge or method with other privacy-minded people. Keep project notes, client details and confidential evidence out of public posts.

Explore the discussion