Fine-Tuning, Distillation and Custom ModelsTraining data: design, synthesis and safety · Lesson 5 of 16

Training data safety, licensing and privacy

Article · 15 min · 8 min lecture

Video lecture

Training data safety, licensing and privacy

15 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 15

Data safety, licensing, privacy

  • Memorization is real
  • Rights and minimization
  • Redaction, licenses, safety tests

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Training data is a liability as well as an asset

Once data is baked into weights it is hard to remove. A fine-tuned model can memorize and later reproduce training examples, including personal data or confidential text, especially rare or repeated strings. Deleting a record from your database does not delete it from a model. So the safest training data is data you are entitled to use, minimized to what the task needs, and scrubbed of what it does not. This lesson is practical guidance, not legal advice.

Four questions for every dataset

  1. Rights: Are we allowed to use this data for training? Consider privacy law (lawful basis and purpose), customer contracts, platform terms, copyright and database rights, and dataset licenses.
  2. Minimization: Does the task need personal data at all? An intent classifier does not need names, phone numbers or account numbers.
  3. Security: Where is training data stored, who can access it, and where does training happen (your GPUs, a cloud region, a hosted API)?
  4. Retention and deletion: How long do we keep raw data, cleaned data and models, and what happens when someone exercises a deletion right?

Privacy frameworks you will meet

  • GDPR / UK GDPR: lawful basis, purpose limitation (training may be a new purpose relative to why data was collected), data minimization, transparency, and data subject rights. Regulators such as the UK ICO and EU data protection authorities have published guidance on AI and personal data.
  • Saudi PDPL and UAE PDPL (plus DIFC and ADGM regimes): rules on processing, consent or other legal bases, and cross-border transfer that affect where you can train.
  • Sector rules (health, finance, telecom) often go further.

Where training involves significant personal data or high-impact decisions, conduct a data protection impact assessment before you start.

PII handling in practice

  • Detect and redact with a tool such as Microsoft Presidio plus custom recognizers for local identifiers (CNIC, Emirates ID, Saudi national ID formats, IBANs).
  • Replace, don't just delete: swap real values for consistent fake ones ("Ayesha" → "Customer_A", account numbers → a fake format) so the model still learns structure.
  • Check redaction quality on a sample; recognizers miss things, especially in Arabic, Urdu and mixed scripts.
  • Keep a mapping only if necessary, stored separately with strict access, or not at all.
# redact.py (pip install presidio-analyzer presidio-anonymizer; also install a spaCy English model per Presidio docs)
from presidio_analyzer import AnalyzerEngine, Pattern, PatternRecognizer
from presidio_anonymizer import AnonymizerEngine
from presidio_anonymizer.entities import OperatorConfig

cnic = PatternRecognizer(supported_entity="PK_CNIC", patterns=[Pattern("cnic", r"\b\d{5}-\d{7}-\d\b", 0.9)])
emirates_id = PatternRecognizer(supported_entity="AE_EID", patterns=[Pattern("eid", r"\b784-\d{4}-\d{7}-\d\b", 0.9)])

analyzer = AnalyzerEngine()
analyzer.registry.add_recognizer(cnic)
analyzer.registry.add_recognizer(emirates_id)
anonymizer = AnonymizerEngine()

def redact(text: str) -> str:
    results = analyzer.analyze(text=text, language="en")
    return anonymizer.anonymize(text=text, analyzer_results=results, operators={
        "DEFAULT": OperatorConfig("replace", {"new_value": "<REDACTED>"}),
        "PERSON": OperatorConfig("replace", {"new_value": "<NAME>"}),
        "PK_CNIC": OperatorConfig("replace", {"new_value": "00000-0000000-0"}),
        "AE_EID": OperatorConfig("replace", {"new_value": "784-0000-0000000-0"}),
    }).text

print(redact("I'm Ayesha Khan, CNIC 42101-1234567-1, email ayesha@example.com"))

Test on your own languages; add recognizers and review samples until the miss rate is acceptable.

  • Customer-generated content, scraped web text, purchased datasets and open datasets all come with terms. CC BY requires attribution; CC BY-SA adds share-alike; NC licenses forbid commercial use.
  • Copyright law on AI training differs across jurisdictions and is still evolving through courts and legislation. Prefer data you created, licensed explicitly for training, or that your contracts permit.
  • The base model's license also applies to your fine-tuned derivative (Module 1 of the open-weight course): attribution, naming and use policies carry through.

Regulation touchpoints for fine-tuners

Under the EU AI Act, providers of general-purpose AI models have obligations (documentation, copyright policy, training-content summary). Guidance from the European Commission indicates that only substantial modifications (assessed with a compute-based indicator) make a downstream modifier a GPAI model provider; typical small LoRA fine-tunes are far below that level, but check the current guidance for your case. Separately, your use case may be high-risk or trigger transparency obligations regardless of how you trained.

Safety of the tuned model

Fine-tuning can erode a base model's safety behavior, even with benign data. Include safety evaluations (refusal of harmful requests, no leakage of training PII, jailbreak resistance) in your before/after tests, and mix in safety examples if needed.

Worked example: a clinic network in Pakistan

A clinic network wants a model that drafts follow-up reminders from appointment notes. They minimize first: the model needs appointment type and timing, not diagnosis details. They redact names and CNICs with custom recognizers, keep training on their own servers, run an impact assessment, and add a memorization test (prompting with the start of real notes and checking that the model does not complete sensitive details). Patient notices are updated to reflect the use of data for service improvement where the law requires it.

Pitfalls

  • "We anonymized it" when only names were removed (quasi-identifiers remain).
  • Training on customer data without checking contracts and notices.
  • Forgetting that deletion requests may require retraining or removing a model.
  • Skipping safety evaluation after tuning.

How to measure success

A completed rights review, a data card with PII handling and measured redaction miss rate, an impact assessment where required, and safety plus memorization tests in your evaluation suite.

Key takeaways

  • Fine-tuned models can memorize training data; removal after training is hard
  • Ask four questions: rights, minimization, security, retention/deletion
  • Redact and replace PII with tested recognizers, including local ID formats
  • Check copyright, dataset licenses and the base model license
  • Re-run safety and memorization tests after fine-tuning

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Why is deleting a customer record from your database not enough after fine-tuning?
  2. Which PII approach preserves learning value best?
  3. Your fine-tuned model now answers some harmful requests the base model refused. What should you add?

Put it into practice

Run the redaction script (with local recognizers) on 100 of your training examples, review misses manually, and record the miss rate in your data card.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.