Case study 7: Data-sharing request
SYNTHETIC Fictional partner request for training only.
Scenario
A research partner emails: “Please upload your registration dataset to our new AI analytics platform so we can identify gaps faster. The platform uses secure AI and will delete data after 30 days.”
The dataset includes names, locations, and vulnerability flags for 2,400 households.
Your task (10 minutes)
- Apply the seven-step screen (purpose, people, data, tool, verification, human control, monitoring).
- List minimum information you need before sharing.
- Green, amber, or red?
- What consultation is required?
Model answer
| Step | Assessment |
|---|---|
| Purpose | Gap analysis may be valid; manual methods exist |
| People | Affected households likely did not consent to this platform |
| Data | High sensitivity; registration + vulnerability |
| Tool | Unapproved; unclear processing location and sub-processors |
| Verification | No clarity on how AI outputs will be validated |
| Human control | No named approver on partner side for this upload |
| Monitoring | “Delete after 30 days” is not sufficient alone |
Decision: Red until organizational data-sharing agreement, DPIA or equivalent, tool approval, and consent/legal basis review.
Consultation: Privacy lead, protection adviser, affected community representatives per policy (real consultation, not classroom role play).
Common errors
- Accepting “secure AI” marketing without contracts
- Anonymizing incompletely while keeping vulnerability flags + village
- Sharing because the partner is trusted socially
Principle taught
Data sharing and partnerships: AI platforms do not replace data-responsibility assessments. Speed is not a legal basis.