Data and AI literacy: a guide for CDOs and DPOs

Data and AI literacy for CDOs, data leaders and DPOs: drive good practice, reduce risk on personal data and track skills with trustworthy scores.

Admins4 min read

You lead data or AI in your organisation (CDO, head of data, AI lead), or you protect its personal data (DPO, CISO). You know that data and AI projects rarely fail for lack of technology, and often for lack of adoption or because of mistakes in use. This page explains how a literacy programme built on short games can help, and how to track its effect.

Which risks does a literacy programme reduce?

The most common AI and data incidents are failures of habit:

Risk Habit to build Game that trains it
Personal or confidential data pasted into an AI tool protecting personal data AI or Not AI?
A decision with consequences delegated to a model keeping a human accountable AI or Not AI?
Generated text published without review reviewing before publishing AI or Not AI?
An invented fact or source copied into a document spotting hallucinations, knowing when to verify Hallucination Hunter
A biased answer presented as neutral detecting bias Hallucination Hunter
A vague prompt producing unusable output giving context, setting constraints Prompt Quest
A wrong table caused by duplicates or blank cells data quality Data Cleaning Rush

For a DPO, the first two rows are often the priority: they are as much a GDPR matter as an AI one.

How do you drive good practice without stifling innovation?

A policy that only says "no" pushes use into the shadows. An effective programme also shows where AI fits: rewording, summarising a non-sensitive text, drafting a first version. That balance is what AI or Not AI? trains: about a third of the requests in its default content are genuinely good jobs for AI, and answering "NOT AI" to everything does not earn a good score.

The same principle applies to data: a data literacy programme does not try to turn every employee into an analyst, but to give them the habits that prevent costly mistakes.

How do you track skills, not just participation?

Each game measures skills from a closed taxonomy shared by every game: context, constraints and examples in a prompt; duplicates, missing values, formats and outliers; hallucination, bias, verification; appropriate use of AI, personal data, human accountability, review, choosing a script. Each game's report shows, for each skill, the number of answers and the share of correct ones, for the period and group you choose.

Two guarantees make these figures usable:

  • The server's score is the one that counts: it is recalculated from the answers and the published version of the game. A score sent by the browser is ignored.
  • Reports are comparable: the same skills recur from one game to another and from one fork to another.

See reading game statistics and, for your own analysis, CSV export and the public API (Pro and Enterprise plans).

What the DPO will want to check

  • Hosting: data is hosted in the European Union.
  • Minimisation: a player without an account on a public game provides no personal data (the leaderboard nickname is optional and stays attached to the play session).
  • Pseudonymised reports by default, with a pseudonym specific to each organisation.
  • k-anonymity: a report filtered by group shows no figures below 5 players.
  • Retention: play-level detail is deleted after 13 months; only aggregates remain.
  • Traceability: changes to access, to the reporting mode and every export are written to the organisation's audit log.
  • Documents: privacy policy and data processing agreement.

And the AI Act?

Article 4 of the EU AI Act asks organisations that use AI systems to take measures to support their staff's AI literacy, taking context into account. A programme of games adapted to your use cases and measured by skill is one such measure; on its own, it is not a compliance programme. See Article 4 of the AI Act.

Adapting the games to your cases

The most convincing approach is often to replay your own situations: your approved tools, your data types, your internal rules. A fork lets you rewrite a game's cases without code, then publish a frozen version for your teams (see the studio). On the Enterprise plan, the Maketools team can also build a bespoke game or customise your forks.

Get started

Play a game of Data Cleaning Rush and AI or Not AI? from the catalogue, no account needed, then share the 30-day AI literacy plan with your L&D team.

Edit this page on GitHub (opens in a new tab)