AI and clients’ personal data in Panama: before uploading

Starting point

Before uploading client information to an AI tool, review what data it contains, its intended use, who will have access and the provider’s terms. A tool’s ability to accept attachments does not make it suitable for every business document.

Process improvement must include information handling. A summary may save time, but that benefit does not remove confidentiality commitments or the obligation to assess personal-data processing. Panama’s general framework consists of Law 81 of 2019 and Executive Decree 285 of 2021, with ANTAI acting as the supervisory authority.

My first rule is simple: if the team does not know what will happen to information inside the tool, it should not upload real client data. The team can learn and test with fictional cases while the provider, account and available controls are reviewed.

Apply Law 81 before using the tool

Entering, summarizing, classifying or analyzing personal data with an AI tool forms part of processing that data. The business should identify who determines the purpose and means of processing, who acts as provider or custodian, and which responsibilities remain with the business even when technology operations are entrusted to a third party.

Review these points before using real information:

  1. Lawful condition. Identify which condition under article 6 permits the processing. Consent is one possibility, but not the only one: the Law also contemplates, among other grounds, performance of a contractual obligation, compliance with a legal obligation or authorization under a special law. Consent should not be treated as blanket permission for every use.
  2. Purpose and transparency. Define why the data will be used and verify what the data subject was told. Later use for an incompatible purpose requires a new review.
  3. Proportionality and minimization. Enter only data necessary for the task. Before uploading an entire file, ask whether selected fields, disassociated data or a fictional case would suffice.
  4. Security and confidentiality. Restrict access, use the approved account type, record who may use it and define the response to an incident. Confidentiality duties apply to people involved throughout the processing.
  5. Retention and rights. Check how long prompts and files are retained, how they can be deleted and how the business will handle applicable requests for access, rectification, cancellation, objection and portability.

ANTAI’s data-protection FAQ explains lawful conditions, information duties and data-subject rights. A specific assessment should also consider sector-specific rules and professional duties applicable to the business.

Classify information before choosing the tool

Distinguish public information, internal information, personal data and documents subject to special confidentiality commitments. Some items fall into several categories. A contract may contain names, signatures, bank details and commercial terms that should not circulate without prior review.

This practical classification does not replace legal analysis of data categories. It helps the team recognize when to stop and consult rather than improvise according to urgency.

Six questions about the provider and configuration

  • How will it use the files and instructions you enter?
  • How long does it retain information?
  • Who can access it inside and outside your organization?
  • What controls does the account you actually use provide?
  • What terms govern transfers, deletion and incident management?
  • Who in your company may authorize use for this kind of task?

Answers should be based on current terms and settings. Do not assume a personal account has the same conditions as another plan or that a marketing promise covers every situation.

Verify where the data is processed

A tool may receive information in Panama while processing or storing it through providers in other countries. Review stated locations, subprocessors, onward transfers and applicable contractual terms.

In 2026, ANTAI approved model contractual clauses for international transfers of personal data through Resolution ANTAI-DG-003-2026. Their existence does not automatically authorize every transfer: the transfer, lawful condition and safeguards applicable to the particular case must first be identified.

Document the decision before implementing the use. For processing that could significantly affect people, a prior assessment of purpose, necessity, risks and controls helps determine whether the use case should be changed, limited or rejected.

Start with fictional examples or minimal information

Use fictional data to learn report structures or practice instructions. If a real task requires client information, assess which parts are necessary and what processing is permitted before entering it. Removing a name may be insufficient if other details identify the person.

Hypothetical example: a team wants to summarize a file. It can first test the output structure with an invented case: facts, dates, outstanding matters and questions. That assesses usefulness without exposing the actual file. The team must then determine whether an appropriate route exists for the intended use.

Retain human review and a decision record

The responsible person should check output against sources and look for omissions. Well-written answers can contain errors. Define which outputs may be used internally and which need approval before being sent to a client.

NIST’s generative AI risk-management resources provide context. They do not replace local obligations or make a tool suitable for sensitive data simply because that framework is mentioned.

Related reading

Your next step

Your next step

Explore practical AI training for professionals. Carolina can help organize use cases, review criteria and information boundaries within the agreed scope. Share the work objective first, without sending confidential files through an open channel.

Explore practical AI training for professionals →