Data confidentiality in data annotation is a principle that ensures information is protected from unauthorized access, use, disclosure, or distribution.
This is especially important when working with personal or sensitive data, where mistakes can lead to data leaks and legal consequences.
In the context of data annotation, this means:
- Access on a Need-to-Know Basis: Annotators should only access the data necessary for completing their tasks. They must not share this data with others or use it outside the scope of the project.
- Limiting Distribution Data: especially if it includes human faces, addresses, numbers, or internal documents—must not be copied, published, or used for unrelated purposes.
- Compliance with Non-Disclosure Agreements (NDAs): Many projects include agreements requiring annotators to keep information confidential. Violating such agreements can lead to serious consequences.
Why Data Confidentiality Matters for Annotators
The consequences of a confidentiality breach extend well beyond the immediate incident. They affect your legal standing, your professional reputation, and your long-term career trajectory.
Legal Responsibility
Annotators who work with personal or sensitive data can be held legally accountable if that data is leaked or misused.
This is not a theoretical risk. If your work is governed by a contract or NDA, which it almost always is on professional projects, a breach can result in financial penalties, immediate termination, and civil or criminal action from the client.
The legal framework that applies depends on where the data originates, not where you are located. Working remotely does not reduce your exposure.
Professional Reputation
A data leak caused by an annotator can seriously damage their reputation as a professional:
- the client may choose not to work with them again,
- the information may be shared with other employers or platforms,
- access to new projects—especially confidential or high-paying ones—may be restricted.
In a field where work is largely referral-based and reputation travels quickly, a single incident can close doors that take years to reopen.
Violation of Professional Ethics
Data annotation requires precision and responsibility. Leaks undermine trust from:
- the client who provided the materials,
- the team that expects mutual rule-following,
- the individuals depicted in the data (e.g., photos or videos of people).
Annotation data often contains real faces, voices, medical records, or personal documents. Handling it carelessly is not just a policy violation. It is a breach of trust toward the client who provided the materials, the team that relies on everyone following the same rules, and the individuals whose information you are working with.
Impact on Career Growth
Confidentiality is one of the clearest signals of professional maturity. Annotators who consistently handle data responsibly:
- gain access to more complex and restricted projects,
- may be promoted to validator or team lead roles,
- are more likely to receive referrals.
Maintaining confidentiality is not just a formality. It’s the foundation of trust in the annotation profession, a way to protect yourself and your team from complications, and a chance to demonstrate competence and reliability.
What Kind of Data Is Considered Confidential in Annotation?
Confidential data refers to information that must not be disclosed, copied, used outside the project, or shared with third parties. Such data may involve both personal and commercial secrecy.
Main types of confidential data in annotation projects:
Personal and Identifiable Information
The most common category across annotation projects is faces in photos and video, names and addresses, phone numbers, license plates, ID documents, and account details.
Personal information does not need to be sensitive to be protected. Recognizability alone is enough, as the legal frameworks below make clear.
Medical and Financial Data
Medical data annotation is among the most regulated work in the field: scans, diagnoses, and any patient data are protected by law, and datasets are typically collected under informed consent that strictly limits how they may be used.
The same caution applies to financial data such as statements, card numbers, and transaction records.
Projects in these domains usually come with additional rules that must be followed.
Data Related to Secured Facilities or Restricted Areas
This category covers physical infrastructure and security information that may compromise user identity, for example:
- building plans, secured zones, security systems,
- location of surveillance cameras or guards,
- license plates of service vehicles.
This data is confidential because it maps the vulnerabilities of a physical space. In the wrong hands, even a single annotated image showing camera placement or access points could be used to bypass security at a real facility.
Data Related To Commercial and Intellectual Property
Clients will share business-sensitive material under the assumption that it will be handled with the same discretion as any trade secret. This includes:
- product prototypes, logos, project names,
- documents marked as “confidential” or “internal use only,”
- elements not yet released to the public (e.g., products in development).
This data is confidential because its value depends entirely on it remaining private. A leaked prototype, an early product name, or an internal document reaching a competitor or the public before launch can cause significant financial and reputational damage to the client.
Important to Remember: Even if the data "doesn’t seem important," it might still be confidential. If you’re unsure, it’s always best to consult your team lead or project manager for guidance on handling specific types of data.
How Annotators Can Ensure Data Confidentiality
Protecting confidential data is not just about avoiding obvious mistakes. It requires deliberate habits around where you work, what devices you use, and how you handle project material at every stage.
1. Work Only in a Trusted Environment
Your physical and digital environment is the first line of defence. Working from an unsecured location or on an unapproved device creates unnecessary exposure, regardless of how carefully you handle the data itself.
To keep your environment secure:
- Use only official accounts and devices approved for the project
- Do not download or store data on personal phones, laptops, or USB drives unless explicitly permitted
- Avoid working in public places such as cafes or co-working spaces, particularly on open Wi-Fi networks
If you are unsure whether a device or location is approved, ask your team lead before you start, not after you have already accessed the data.
2. Do Not Take Screenshots or Record the Screen for Personal Use
Project data should never leave the annotation environment in an uncontrolled way.
Saving images, videos, or screenshots of the interface to a personal device, even with no intent to share them, constitutes a potential data breach and is strictly prohibited.
To handle screen capture correctly:
- Do not save any part of the project interface, data, or annotations to personal storage
- Take screenshots only with explicit permission from your team lead, and only for work-related purposes such as reporting an error or asking a question
- Always send any permitted screenshots through official project communication channels, not personal messaging apps
The distinction between personal use and work use matters here. A screenshot sent to a colleague via a personal chat app is still a breach, even if the intent was innocent.
What to Do If You Suspect a Data Leak
Suspecting a breach is stressful, and the instinct is often to wait and see whether it turns out to be nothing. That instinct is wrong. The steps below exist because early action consistently limits damage, and because doing nothing is itself a decision with consequences.
1. Report It Immediately to the Responsible Person
If you notice anything suspicious, such as unauthorized access, unknown copies of data, a team member behaving unethically, or a file appearing somewhere it should not be, report it to your team lead or project manager right away. Do not investigate on your own or wait until you are certain something is wrong.
Leadership needs to know as early as possible so they can assess the situation and respond before the problem spreads. A false alarm is far less damaging than a real breach that went unreported for too long.
2. Pause Work with Suspicious Data or Devices
If you suspect a file, platform, or device has been compromised, stop using it immediately and wait for guidance from your team lead. Continuing to work with potentially compromised material risks spreading the breach further.
A brief pause is far less costly than the alternative. You will not be penalised for stopping work on something that turns out to be fine. You may be held responsible for continuing when you had reason to stop.
3. Maintain Confidentiality While Discussing the Incident
Keep details of the suspected breach within the small group responsible for project security. Do not discuss it in team chats, personal messaging apps, or social media, even in vague terms.
Premature or wide disclosure can cause panic, spread misinformation, and make the situation harder to contain. The people who need to know will be told by the team lead. Everyone else should not be involved.
4. Cooperate Fully with Any Investigation
If an internal investigation is initiated, provide complete and honest information: access logs, details of your work with the data, and anything else that is relevant. Partial cooperation slows the process and can make you appear more culpable than you are.
The goal of an investigation is to find the source of the problem and fix it. Your cooperation is what makes that possible, and it is also the clearest way to demonstrate that you acted in good faith throughout.
Why Is Proper Response Important?
How you respond to a suspected breach matters almost as much as whether the breach actually occurred. Clients and employers do not only judge whether something went wrong.
They judge how the people involved handled it. A calm, protocol-driven response demonstrates professionalism and limits the damage. A panicked or evasive one compounds it.
Follow the correct steps when a breach is suspected:
- Minimises damage and reduces the risk of similar incidents in the future
- Maintains client trust and protects the team's reputation
- Ensures compliance with applicable laws and the company's internal policies
Annotators who respond correctly to a suspected breach, even one they did not cause, demonstrate exactly the kind of judgment that leads to greater responsibility and more trusted roles. The way you handle a difficult situation is often more visible to a team lead than the quality of your day-to-day work.
Legal Aspects of Data Confidentiality for Annotators: USA and Europe
Modern data annotation requires strict compliance with privacy regulations, especially when handling personal or sensitive information.
Annotators working with projects from the US or Europe must understand the core legal frameworks governing data protection to avoid serious legal consequences and ensure data security.
Europe — General Data Protection Regulation (GDPR)
What is GDPR?
The General Data Protection Regulation (GDPR) is the main data protection law in the European Union. Enforced since 2018, it is one of the strictest privacy laws in the world and applies to any data involving EU citizens, regardless of where the annotator is located.
Examples of data considered confidential under GDPR:
- Photos and videos with recognizable faces — these are biometric data.
- IP addresses and cookies, if they can be used to identify a user.
- Voice recordings — even short clips may qualify as personal data.
- Medical records — including scans, diagnoses, and prescriptions.
- Automated user profiles — such as classifications based on interests or behavior.
What annotators need to know about GDPR:
- Even if a person in a video is not named, if they are recognizable, it qualifies as personal data.
- GDPR requires anonymization or pseudonymization of data before processing.
- Annotators may not use data outside the project — not even for portfolios or training purposes.
United States — Sector-Specific and State-Level Regulations
Unlike the EU, the US does not have a single, unified law like GDPR. Instead, it follows industry-specific and state-level regulations. The three most relevant to annotation work are below.
HIPAA (Health Insurance Portability and Accountability Act)
HIPAA governs the handling of health-related data in the US. It applies to medical institutions and anyone who processes health data on their behalf, which can include annotation contractors.
What is considered confidential?
- Patient names
- Medical images (e.g., MRI, X-rays)
- Medical record numbers
- Photos where a patient can be identified
For annotators:
If you work with US medical imagery, you must not interact with, record, or retain any personal identifiers. When in doubt about whether something qualifies, treat it as protected and ask your team lead.
COPPA (Children’s Online Privacy Protection Act)
COPPA protects the privacy of children under 13. It applies to anyone collecting or processing data that involves minors, including annotation teams working with datasets that contain children.
Examples of confidential data:
- A child's face in a photo or video
- Their voice, name, or location
- Any account activity related to a child
For annotators:
Data involving children requires a higher level of care than almost any other category. Parental consent is typically required before this data can be processed, and it should never be stored, copied, or discussed outside the project.
California Consumer Privacy Act (CCPA) and CPRA
The CCPA and its amendment, the CPRA, protect the personal data of California residents. Because California is the most populous US state, many large-scale datasets include California users, making this regulation widely relevant.
Examples of confidential data:
- Names, email addresses
- Geolocation
- Online purchase and behavior data
- Biometric information
User rights under CCPA/CPRA:
- Know what data is collected
- Opt out of data selling
- Request deletion of their data
For annotators:
If your project involves users from California, it is critical not to store, share, or replicate data unnecessarily. The user rights built into CCPA/CPRA mean that every unnecessary copy of this data is a potential liability.
Key Takeaways for Annotators
- It doesn’t matter where you are located — what matters is where the data originates.
- If you process data from EU citizens, you are required to follow GDPR.
- If you work with US-based data, make sure you understand the relevant sectoral and state-level regulations.
- Security and confidentiality are not optional — they are core professional responsibilities.
Data Breaches: Real Cases and Consequences
Heart of England NHS Foundation Trust Employee
An employee accessed medical records of 14 individuals, including family and friends, without authorization. She was found guilty of violating the UK Data Protection Act and fined £1,000, plus court costs.
RAC Employee
An employee unlawfully collected and passed client data to third parties, which led to unwanted phone calls. She received an 8-month suspended prison sentence and was ordered to pay £25,000.
Carlos Lopez & Associates Employee
An employee accidentally emailed a spreadsheet with personal data of 130 current and former employees, including Social Security numbers and addresses, to 65 colleagues. Despite no proven misuse, three victims filed a class-action lawsuit claiming a risk of identity theft. The court ruled that even potential harm is grounds for legal action.
WM Morrison Supermarkets Data Leak
In 2014, an internal audit employee working remotely copied and leaked personal data of nearly 100,000 employees on a public file-sharing platform. He was sentenced to 8 years in prison. The company also faced a collective lawsuit from affected employees.
These cases underscore the importance of following security protocols and raising awareness among team members. Unauthorized access — even accidental — can lead to severe consequences.
Scale AI - Confidential Client Data Left Publicly Accessible (2025)
In June 2025, it was reported that Scale AI had left at least 85 Google Docs publicly accessible, exposing thousands of pages of confidential AI training materials tied to clients including Meta, Google, and xAI.
The documents included internal labeling guidelines, proprietary prompts, audio examples marked "confidential," and contractor performance data with private email addresses. Several files were not only viewable but also editable by anyone with the link.
No malicious actor was required. The data was simply left open. The incident raised immediate questions about access control, contractor management, and what happens when annotation infrastructure is treated as a low-risk part of the pipeline. Clients, including Google and OpenAI, reportedly began distancing themselves from Scale AI within days.
For a deeper breakdown of what went wrong and what enterprise teams should do differently, see What ML & AI Teams Should Learn from the Scale AI Data Leak.
Key Takeaways From This Lecture
Data confidentiality is not a background concern. It is an active, daily responsibility that affects how you access data, where you work, what you say, and what you do when something goes wrong. Before moving on, here are the core points from this lecture:
- Confidentiality obligations apply the moment you access project data, not only when you sign an NDA.
- The regulation that applies depends on where the data originates, not where you are located.
- Most real-world breaches are caused by individual decisions, not system failures. The cases in this lecture are proof of that.
- If you suspect a breach, stop work and report it immediately. Early escalation limits damage.
- Annotators who handle data responsibly earn access to more complex, higher-value projects and build the kind of reputation that generates referrals.
The first three lectures have covered what data annotation is, who does it, and the professional obligations that come with the role. From here, the academy moves into the practical skills: the annotation tools, techniques, and quality standards you will use on every project.

.png)
.png)