Safeguarding and protection module (Session 3)

10 minutes within the Session 3 teach block. Insert after policy vs convenience slides and before the decision block. Uses synthetic discussion only.

Not legal advice. Direct operational questions to your organization’s safeguarding, protection, and PSEA focal points.

Learning objectives

Participants can:

  1. Name why child protection and GBV-related information require extra caution with AI tools.
  2. Describe facilitator and staff actions when a disclosure occurs in a training or workplace setting.
  3. Locate organizational escalation contacts (provided by the hosting organization before training).

Teach script (facilitator)

AI tools are a poor fit for child protection case notes, GBV survivor records, and other highly sensitive information unless your organization has explicit approval, secure systems, and trained staff.

Why:

Primary sources: ICRC Handbook on Data Protection in Humanitarian Action (3rd ed.); IASC Operational Guidance on Data Responsibility (2023) (do-no-harm, dignity).

Default classroom rule: red for entering such information into any unapproved or public AI tool.

2. Disclosure handling in training (4 minutes)

If a participant shares a real disclosure during a session:

Do Do not
Pause the exercise Ask for more detail in plenary
Refer to org safeguarding or PSEA focal point Promise specific outcomes
Remove identifying chat content with co-host Copy content into personal notes
Follow hosting org escalation card Investigate or counsel in the facilitator role

PSEA (Protection from Sexual Exploitation and Abuse) commitments require reporting routes to be known before incidents occur. Confirm contacts in the participant handbook.

3. Pair reflection (2 minutes)

Prompt: “Where would you escalate an amber or red data decision in your organization?” Write one role title only (no names of survivors or colleagues).

Pilot charters must include stop thresholds for privacy or safeguarding incidents. Session 3 worksheet failure / stop threshold row applies here.

Participant takeaway

Write one line: If sensitive information appears in AI workflow, I will stop and contact [role] at [organization].

Hosting organizations should supply the role and contact on a local insert; the kit does not invent org-specific numbers.

Facilitator materials

Debrief questions (if time)

  1. Why is “anonymized” GBV data still often red?
  2. How is a training disclosure different from a community feedback channel?
  3. What PSEA commitment applies to staff using AI on the job?