Before someone pastes a customer contract into ChatGPT, settle two questions: which account is approved for the task, and which data may go into it? Public or made-up content is enough for an initial test. Real customer, employee or contract data should wait until the service’s terms and settings have been checked for that purpose.
A paid subscription alone does not settle this. A personal plan, a business workspace and an API may have different training, retention and administration rules. Assess the specific combination of tool, data and task.
Same task, different data, different approval
Consider a sales team drafting a response to a complaint. A fictional case and a public product description can test tone and structure. The real customer email might also include names, order numbers, payment details or confidential terms. It needs separate approval. Removing a name is not enough if the remaining details still identify the person.
Start by defining which tasks are allowed with public or synthetic data. Keep personal and confidential material out until the responsible people have reviewed the intended data flow. The team can test useful work while outstanding privacy questions are resolved.
How ChatGPT plans differ
According to OpenAI, data from ChatGPT Business, Enterprise and the API is not used for model training by default. OpenAI also offers a data processing agreement for these products. These are relevant checks, but they do not approve every type of company data.
Personal ChatGPT accounts can disable training use for new chats through Data Controls. That setting does not replace company approval or a review of contracts, retention and access. Check connected apps and external services too: approval for a chat does not automatically extend to every recipient it can connect to.
“No model training” does not mean “no storage”. Record training use, retention periods and access separately.
What to resolve before approving personal data
The GDPR requires an appropriate legal basis and a defined purpose. Consent is not the only possible legal basis. Limit inputs to necessary data, set access and deletion rules, and check transparency obligations. Processing on your behalf requires an Article 28 agreement; third-country transfers also need to meet Chapter V requirements.
Health information and other special categories require a separate Article 9 assessment. Processing likely to create a high risk may require a data protection impact assessment. Involve the people responsible for data protection before approving these cases. Customer contracts and trade secrets can also protect data that is not personal.
An AI policy people can use
The policy should support specific decisions: which tools and accounts are approved? Which data may be used for which tasks? Who checks results before they reach customers? Where should staff report an accidental submission? Who reviews new features and integrations?
Write the answers around real tasks. “No confidential data” is too vague on its own if people do not know whether a quote or support ticket counts. One allowed and one excluded example per task makes the boundary clearer. AI output still needs professional review: ChatGPT can invent facts and sources.
When another tool makes sense
If the chosen chat service cannot meet your requirements, assess a different setup: a business service with suitable terms, a controlled API integration or a locally operated model. Our guide to AI hosting in the EU explains what location and self-hosting actually change.
A temporary restriction on particular tools or data types can be appropriate. Name the unresolved requirement and the route to reassessment. A clear permitted alternative gives the team more useful guidance than a vague request to be careful.
Turn the rules into a working process
You can start the inventory yourself: tools in use, typical tasks and the types of data involved. If you need to turn that inventory into team practices, an AI workshop can help us work through specific tasks with you, compare tools and develop practical usage rules. Coordinate legal approval with your data protection leads.
Tell us which tools you use and one or two tasks where approval is unclear. We do not need confidential content for the initial enquiry. Discuss AI use in your team.