1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →
How do you protect sensitive data (PII) when using third-party LLM APIs?
30-second answerSay your answer out loud first, then reveal.

Considerations
- Detection quality: Indian identifiers (Aadhaar, PAN, GSTIN, IFSC), names in multiple scripts, free-form addresses. Combine regex, NER models and allow/deny lists, and evaluate recall.
- Pseudonymisation vs masking: consistent placeholders preserve meaning ("PERSON_1 called PERSON_2"), so the model can still reason. Pure masking (
[REDACTED]) loses relationships. - Context leakage: retrieved documents and tool outputs also contain PII, so apply the same pipeline to them.
- Logs and traces: often the biggest leak. Redact before logging; restrict access; apply retention limits.
- Contracts and settings: data processing agreements, no-training clauses, retention settings, data residency (e.g. India region for regulated sectors).
- Output checks: ensure responses don't expose other users' data.
Related
Little by little, you're building something great.