People Intelligence: privacy, limits and responsible use
People Intelligence describes employees, so the limits are part of the product rather than a disclaimer attached to it. This article sets out what is protected, what is deliberately withheld, and what no Insight is allowed to do.
Insights are computed, not generated
This is the first thing to be clear about, because it is frequently assumed otherwise.
People Intelligence Insights are produced by deterministic code running inside the GFoundry platform. They are queries, aggregations and rules. No language model is involved in producing an Insight, and no employee data is sent to an external AI provider in order to draw one. The same inputs always produce the same card.
That makes them different from Gi's AI agents, which do use an external provider under a contractual no-training clause and with pseudonymised identifiers. Both are safe; they are safe in different ways, and it is worth knowing which one you are discussing when the question comes up.
The one place the two meet
Your dashboard can also hold charts you pinned from the Data Analyst Agent. Those are worth separating out precisely, because the honest answer is not a flat yes or no.
The numbers in a pinned chart were computed inside the platform, scoped to your organisation, exactly like an Insight's.
The conversation that produced it went through the external AI provider, with employee references replaced by pseudonymous identifiers before the prompt left your environment. The provider received structured attributes, not names, emails, manager names or free text.
So a dashboard made only of catalogue Insights involves no AI provider at all. A dashboard that includes pinned charts involves one, at the moment the chart was created, under the terms described in the Data Analyst Agent article. If your DPO asks the question, this is the distinction to give them.
Excel exports carry real names
The Data Analyst Agent can also produce Excel files. Unlike anything on the dashboard, those files do contain real employee names, because a file you are going to act on is useless without them. The names are resolved inside your environment and never pass through the AI provider. The files are scoped to your organisation, stored encrypted, and removed after the retention window configured for your tenant.
Practically, an export is the point at which employee data leaves the platform's controls and enters your laptop, your email and your shared drives. Treat it the way you treat any other HR file, because after the download that is exactly what it is.
Small groups in anonymous surveys
Insights built on anonymous responses, which is eNPS, wellbeing by team, the team health index and the organisational dimensions, will not render for a segment that is too small. The card says the segment is too small and the calculation is not run at all.
The reason is specific. If someone can filter an anonymous survey down to a four-person team, the promise of anonymity made to those four people is gone, and the next survey will be answered accordingly. This protection is enforced where the data is computed. It cannot be filtered around in the interface.
Insights that list named employees work differently. They do not apply a minimum group size, because naming people is what those cards are for and a count threshold would protect nobody. What governs them is who is authorised to open them. If you believe a colleague can see a nominative Insight they should not, raise it with us straight away: that is a permissions matter, not a display preference.
What is deliberately withheld
Several things the platform technically holds are kept out of People Intelligence on purpose.
Free text people wrote. Development plan action content, goal titles and feedback content are counted and tracked but never displayed. An employee writing a development goal is not writing a dashboard entry.
Successor names. Succession coverage appears as a structured status, never as a free-text name.
Manager names carried in the wrong column. Potential review coverage is shown only at organisation level, not per team, because in some organisations that source's team column contains managers' names. Breaking it down would expose personal data through a field that was never meant to carry it.
Behavioural patterns whose wording harms the person described. A defined set of sensitive patterns is never surfaced on a profile, regardless of whether the underlying signal is present.
Individual exit-risk patterns. A set of exit-risk patterns is withheld on profiles because the model behind them was withdrawn. When withholding leaves a card with nothing, the card says the patterns were withheld. "Nothing detected" and "some withheld" are different facts, and presenting the second as the first would be a quiet all-clear the data does not support.
No Insight decides anything
Nothing in People Intelligence produces an outcome for an employee. There is no automated scoring that feeds a promotion, a pay decision, a performance rating or an exit. Every Insight is an input to a decision made by a person who is accountable for it.
Three consequences worth stating explicitly:
Diagnostic Insights are never sufficient on their own for a decision about an individual. They describe a pattern in platform behaviour. Platform behaviour is a partial view of a working life, and it is partial in ways that correlate with role, seniority, shift patterns, leave and accessibility needs.
Experimental Insights carry the strongest version of the same rule. The Manager Index Insights are development instruments. Using one to assess or penalise a manager is a misuse of the Insight, and the card says so.
Behavioural profiles are not personality assessments. They summarise activity over time. They are not psychometric instruments, they are not stable traits, and a person's profile changes when their behaviour does.
Your organisation is the boundary
Insights are computed within your organisation's data and are never mixed with another organisation's. Behavioural scores are normalised inside your own population, which is also why they are not a benchmark: a participation score of 70 in your organisation and 70 in another are two different measurements, and the product does not invite you to compare them.
Honest absence rather than a confident blank
A recurring design rule, and one that has privacy consequences worth naming: an Insight with nothing to show says so, rather than disappearing or rendering an empty chart.
A card that vanishes when it has no data teaches people to read a gap as an answer. A card that says "your organisation has no data for this" is honest about what is missing, keeps the reader from inferring a result that was never computed, and makes it visible when a data feed has broken rather than letting silence pass for good news.
Questions a works council or DPO usually asks
Is any employee subject to automated decision-making? No. No Insight produces an outcome. All decisions are made by people.
Is employee data sent to an AI provider to build these dashboards? Not for the Insights in the catalogue, which are computed in the platform with no model involved. A pinned chart is the exception: it came from a conversation with the Data Analyst Agent, which does use an external provider, with pseudonymised identifiers and under a no-training clause.
Do any of these outputs contain employee names? Nominative Insights show names to authorised users inside the platform. Excel exports contain names in the file. Nothing sent to an AI provider does.
Can a manager browse any employee's profile Insights? Access is governed by backoffice permissions, which your organisation configures. The Insights themselves do not widen anyone's access.
Can anonymous survey answers be traced to a person? Not through People Intelligence. Segments too small to protect respondents are refused before the calculation runs.
How do we know what a number means? Every catalogue Insight carries a versioned contract stating its population, exclusions, sources, thresholds and limitations. Ask us for the contract of any Insight in your catalogue. A pinned chart has no contract, which is a reason to keep the important measures in the catalogue rather than on pins.
Where is the data held and under what terms? See Understanding Compliance on GFoundry: Security, Terms, and Data Protection. The Data Processing Agreement, including the list of sub-processors, is available on request.
Advice for rolling this out internally
Decide who gets access before you decide which Insights to use. The access list is the real privacy control, and it is yours to set.
Tell employees the capability exists. Organisations that explain People Intelligence up front get better survey participation than organisations where people discover it later.
Agree what each Insight triggers. An Insight with no agreed follow-up becomes either noise or, worse, an informal judgement nobody has to justify.
Set a rule for exports. They are the one artefact that leaves the platform carrying names. Decide who may generate them and where they are allowed to live.
Review the board periodically. An Insight that has not informed a decision in six months is a card to remove, not a card to keep for completeness.
