Contact centre, customer service and claims operations leaders

Can contact centre agents use AI to draft replies that contain customer personal information?

Sources verified Sanitized Ai Team

The short answer

Agents can use AI to improve tone and structure, but customer identifiers, account numbers, card data and health or claim details should not go into a public AI tool. The organization remains accountable for customer information it hands to any third party, and a personal AI account comes with no contract that protects it. The practical answer is to keep AI in the workflow while removing personal information before a prompt is submitted.

The situation

An agent on a claims support line has a customer who has emailed three times about a delayed water damage claim. The latest message is angry and long. The agent copies the whole thread into ChatGPT and asks for a calm, empathetic reply that explains the next steps. The thread includes the customer's full name, home address, policy number, claim number, a description of a family member's respiratory condition aggravated by mould, and the last four digits of the card used for the deductible.

The reply that comes back is genuinely better than what the agent would have written in the same time. That is exactly why the same thing happens every day across contact centres in banking, insurance, telecom, utilities and retail. The customer's information now sits with an AI provider under that provider's terms, which can permit retention and sub-processing, and it cannot be recalled.

What the rules actually say

There is no Canadian rule written specifically for AI-drafted customer replies. The obligations come from privacy law and, where cards are involved, from the payment card industry's standard.

Accountability follows the data

Under PIPEDA Schedule 1, clause 4.1.3 makes an organization responsible for personal information it transfers to a third party for processing, and requires it to use contracts or other means to secure a comparable level of protection. Principle 4.5 limits use and disclosure to the purposes the customer was told about, and principle 4.7 requires safeguards appropriate to the sensitivity of the information. Clause 4.7.4 asks organizations to make their employees aware of the importance of confidentiality.

An agent's personal AI account has no contract with your organization at all. Health details in a claim, financial account numbers and complaint histories are the kind of sensitive information that calls for stronger safeguards, not weaker ones. In Quebec, the private-sector act as amended by Law 25 applies to customer information, and the Commission d'accès à l'information treats an unauthorized communication of personal information as a confidentiality incident to be recorded and, where serious injury is a risk, reported.

The federal, provincial and territorial privacy commissioners' generative AI principles are guidance rather than law, but they recommend limiting personal information in prompts and not entering sensitive or confidential information without authorization.

Card data has its own rules

PCI DSS is a contractual standard that card brands apply through acquirers, not a statute. It requires organizations to protect cardholder data across every system that stores, processes or transmits it. The PCI Security Standards Council is clear that sensitive authentication data, such as card verification codes, must not be kept after authorization. A public AI tool is not part of any scoped cardholder environment. If card numbers appear in transcripts or emails, speak with your acquirer or qualified security assessor about how AI use affects your compliance.

If you run an outsourced contact centre, your client agreements commonly restrict where customer data may go and which subcontractors may process it. Read those clauses with AI in mind. Confirm your specific obligations with privacy counsel.

Why policies and bans fall short

Contact centres are among the most policy-dense workplaces there are: scripts, quality scoring, clean-desk rules, and often a no-phones rule on the floor. AI use still slips through, because the pressure is on handle time and customer satisfaction, and the AI draft improves both.

A policy telling agents not to paste customer details into AI is read once at onboarding. It is not present at 4:45 on a Friday when the queue is full and a message needs a careful answer. Blocking AI sites pushes the same behaviour onto phones, where a photo of the screen carries even more data and leaves no trace. Our post on visibility without blocking explains why the blind spot grows when tools are banned.

Sanctioned tools help, but they do not settle the question on their own. Business accounts change the contractual picture, as our post on whether ChatGPT trains on company data describes, yet agents still reach for personal accounts when the approved tool is slower or less familiar. LayerX's 2025 research found that 71% of generative AI connections use personal, non-corporate accounts.

What a practical control looks like

  1. Define what never goes into AI. Card numbers and verification codes, account and policy numbers, government identifiers, health and claim details, and full names with contact details. Put this on the agent desktop, not only in the policy binder.
  2. Provide an approved assistant for drafting. A business AI account, or AI features inside your contact centre software, covered by contract and a privacy impact review.
  3. Teach the placeholder habit. Agents describe the situation ("customer with a delayed water damage claim, frustrated after three emails") rather than pasting the thread.
  4. Keep card data out of free text. Use payment capture methods that keep card numbers off screens and out of notes wherever possible.
  5. Coach through quality assurance. Add AI use to QA reviews and team huddles, with real examples of what should have been stripped.
  6. Set an incident path. Decide who assesses a disclosure, how it is recorded, and when a client, customer or regulator is informed.

Sanitized Ai is a browser extension that works at the step where policies usually fail. When an agent pastes or uploads content containing personal information, financial data such as card or account numbers, or health information into a major AI assistant, it redacts or blocks that content before submission and tells the agent in plain language what was flagged and why. The agent still gets a better draft; the customer's details stay out of the prompt. Each catch doubles as a short coaching moment, which fits naturally alongside QA.

Team leads and privacy officers see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never the prompt content. That produces audit-ready records without reading agents' prompts, which can support client audits and safeguards reviews. For insurers and claims teams, our insurance page shows how this fits into existing controls, and payroll and HR operations facing the same problem can read the companion guide on SINs and payroll data in AI.

Frequently asked questions

Is it acceptable if the agent removes the customer's name before pasting?

Removing the name helps, but it is rarely enough. Account numbers, policy or claim numbers, addresses, dates of birth and the details of a claim or complaint can identify the customer on their own or in combination. Agents should replace identifiers with placeholders and describe the situation in general terms before asking for a draft.

Does PCI DSS say anything about AI tools?

PCI DSS is written in technology-neutral terms rather than naming AI tools. It requires organizations to protect cardholder data wherever it is stored, processed or transmitted and prohibits keeping sensitive authentication data, such as card verification codes, after authorization. A card number pasted into a public AI tool ends up somewhere outside the environment you have scoped and secured, so talk to your acquirer or assessor before allowing any card data near AI tools.

We are an outsourced contact centre. Whose rules apply?

Both. Your client remains accountable for its customers' information under privacy law, and it normally meets that duty through its contract with you, which often limits where data may go and which subcontractors may touch it. An agent's personal AI account is almost never an approved subcontractor. Check your client agreements and data processing terms before any AI use.

Can we give agents an approved AI assistant instead?

Yes, and many organizations do. A business AI account with contractual commitments on data use is a far better basis than personal accounts. It still helps to keep unnecessary personal information out of prompts, because privacy regulators recommend minimizing personal information in prompts even with approved tools.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading