Your data science team plans to fine-tune a large language model using historical customer support transcripts containing PII. The business wants the model deployed organization-wide for internal use. As the CISO, what is the MOST appropriate action BEFORE training begins?
A. Encrypt the training dataset at rest and restrict access to data scientists
B. Apply data minimization and de-identification techniques to the training corpus
C. Require model output filtering to prevent PII disclosure in responses
D. Obtain renewed customer consent for the new processing purpose