At the benefits desk. In the civil registry office. At the planning department. Before lunch, a local-government officer handles more personal data than a small business will see in an entire month. A birth certificate. A welfare claim. A building permit. A safeguarding report. Behind every file there is a resident who never chose their counterparty and who, by default, simply trusts the town hall. AI then shows up to draft a refusal letter or a committee minute, and the temptation is to paste the file in as-is. That is the moment. That is exactly where public responsibility is decided.
Citizen data everywhere
Civil registry, social benefits, tax or school records: every service handles personal data.
Heightened responsibility
The public sector is the guardian of trust. A leak is even less acceptable here than elsewhere.
Anonymize before AI
The rule that protects the citizen: no identifying data goes to a third-party tool.
Resident data, in every department
Civil registry, welfare, social services, planning, schools, local taxation. Almost no department works without handling identifiable information. A welfare file, for its part, reveals income, family circumstances and sometimes a health status that no one outside the service should ever get to read. A building permit carries the exact address and the applicant's identity. This data is not yours to spend. You are its custodian, on behalf of the public interest.
Heightened public responsibility, a duty to set the example
A resident can switch banks. They can switch insurers. They cannot switch town halls. That absence of choice creates a particular duty, one that binds an administration held to a higher standard, because it is untenable to demand that companies respect data-protection law while sending residents' files into a consumer tool hosted outside the European Union. A leak here is not a mere technical incident. It is a breach of the trust between the citizen and the service.
Where AI genuinely helps: letters, minutes, council papers
Notifying a decision. Rephrasing a reasoned refusal. Summarizing committee minutes, preparing a note for a council paper or framing a procurement document: across all these repetitive drafting tasks, AI saves real, measurable time. The trap is not the tool. It is what you feed it. A letter template needs neither the name, nor the address, nor the file number of the resident to produce well-turned prose.
What to pseudonymize, what you can keep
To mask: residents' names and contact details, file numbers and administrative identifiers, precise addresses, social or health data. To keep, so the output stays useful: amounts, relative dates, the nature of the request, regulatory references. The goal is not to blind the AI. It is to strip away whatever points to a real person.
The method, without exposing a single resident
You pseudonymize the file up front. The AI works on the masked version. Then you re-identify locally, at the very moment you print the letter or add the document to the file, so that the resident's identity never once leaves the authority for a third-party service. The pseudonymization stays reversible on the officer's side. Never on the provider's.
Safe-Doc masks files before the AI. The layout holds. Everything is processed in the European Union, then purged. See the ChatGPT and GDPR at work guide.
Protect first the people you serve. Pseudonymize before the AI.