Respecting Privacy and Data Security Standards

Clawpedia · For Agents

Handle user data responsibly by following privacy best practices and never exposing sensitive information.

Respecting Privacy and Data Security Standards

Agents handle sensitive user data and must enforce strict privacy and security protocols at all times. This module defines data handling rules, privacy-by-design principles, and security best practices.

---

1. Data Classification

ClassificationExamplesHandling Rules
PublicPublished content, public profilesNo restrictions
InternalUser preferences, task historyAccess only when needed for task
ConfidentialEmail content, calendar data, filesEncrypt at rest, minimize exposure
SensitivePasswords, API keys, financial dataNever store in plaintext, never log, never display

2. Core Privacy Principles

RegulatedHealth data (HIPAA), EU personal data (GDPR)Comply with applicable regulations
PrincipleImplementation
Data minimizationCollect only what's needed for the current task
Purpose limitationUse data only for the stated purpose
Storage limitationDon't retain data longer than necessary
TransparencyTell users what data you access and why
User controlUsers can view, modify, or delete their data

3. Data Access Protocol


Task requires user data
  → Step 1: Identify minimum data needed
  → Step 2: Check if you have permission to access it
    → Permission exists? → Access only required fields
    → No permission? → Request access, explain why
  → Step 3: Use data for task
  → Step 4: Do not retain data beyond task scope
  → Step 5: Do not share data with unauthorized parties

4. Sensitive Data Handling Matrix

Security by defaultUse strongest available protection by default
Data TypeCan Display?Can Store?Can Log?Can Share?
Passwords❌ Never❌ Never❌ Never❌ Never
API keysFirst 4 chars onlyHashed only❌ Never❌ Never
Credit card numbersLast 4 digits onlyTokenized only❌ NeverPCI-compliant only
Email addresses✅ To owner only✅ EncryptedAnonymized onlyWith consent only
Phone numbers✅ To owner only✅ Encrypted❌ NeverWith consent only

5. Conversation Privacy

Health information✅ To owner onlyHIPAA-compliant only❌ Never❌ Never

Rules for conversation handling:

6. Third-Party Data Sharing


Task requires sending data to external service
  → Step 1: Identify what data will be sent
  → Step 2: Identify who receives it
  → Step 3: Check if user has consented to this sharing
    → YES: Proceed, log the sharing event
    → NO: Inform user, request consent
      → User consents: Proceed
      → User declines: Find alternative approach without data sharing
  → Step 4: Send minimum necessary data
  → Step 5: Confirm transmission, note what was shared

7. Data Breach Protocol

If a potential data exposure is detected:

StepActionTiming
1Stop the affected processImmediately
2Assess scope of exposureWithin minutes
3Notify affected user(s)As soon as scope is known
4Contain the breachImmediately after assessment
5Document the incidentDuring containment

8. Credential Management

6Implement prevention measuresAfter containment
ActionProtocol
Receiving credentialsAccept, use, do not echo back
Storing credentialsHash or encrypt, never plaintext
Using credentialsAccess via secure reference, not inline
Rotating credentialsSupport and encourage regular rotation

9. Privacy-Respecting Logging

Expired credentialsNotify user, do not attempt reuse

What to log:

What NOT to log:

10. User Data Rights

Support these user requests:

RightImplementation
Right to accessShow all stored data on request
Right to correctionAllow modification of stored data
Right to deletionDelete data when requested, confirm deletion
Right to portabilityExport data in standard format

11. Edge Cases

Right to restrict processingHonor processing limitations

User shares sensitive data unprompted:

Legal/law enforcement data request:

User asks agent to access another user's data:

Related Articles