← Back to blog

Is It Safe to Put Client Data into ChatGPT?

Sometimes, and the answer turns on two things: which tier of data you mean, and which version of the tool you are on. A customer's personal file pasted into a free consumer account is a real problem. The same task on a business account, with a data processing agreement in place, model training switched off, and a written rule about what may go in, is ordinary processing that most businesses can justify without difficulty. The question worth answering is which data may go where, under what conditions, and who decided.

Most businesses answer it once and badly, in one of two directions. Some ban the tools, which moves the usage onto personal phones where nobody can see it. Others say nothing at all, which produces the same outcome with less honesty about it. Both are decisions. Both are worse than one page of rules that takes an afternoon to write.

What actually happens to what you paste in?

The single biggest factor is which plan you are on, and the gap between tiers is wider than most people assume.

Consumer and free tiers are built for individuals. Historically they have defaulted to using submitted content to improve the models, they offer no data processing agreement, they give an employer no visibility of what staff have submitted, and they say little about where processing happens. Business, team and enterprise tiers are built for organisations. They typically offer a data processing agreement, exclude your content from training, give administrators control over retention, and make commitments about processing location. API access usually goes further, including arrangements with no retention at all.

Two things are worth knowing beyond the marketing. Content is often retained for a period for abuse monitoring even where training is excluded, so deletion is rarely instantaneous. And a chat interface holds conversation history, which means a paste from three months ago is still there unless somebody removed it.

None of that is unique to ChatGPT. Ask exactly the same questions of Copilot, Gemini, Claude, and of the AI features quietly switched on inside software you already pay for. That last category is where most businesses have exposure they have never assessed.

Do not take any blog's word for the current position, including this one. Vendor terms change. The answer that counts is the one attached to the plan your business actually pays for, on the day you check it, in writing.

Which data can go into which tool?

This is the part that turns an anxious debate into a decision. Classify the data, classify the systems, then write down which tiers may meet.

Four tiers work for most businesses.

Tier one, public. Anything already published. Your website copy, your brochures, public regulations and standards, published research. There is no meaningful restriction. Use whatever tool does the job well.

Tier two, internal and non-personal. Process notes, draft policies, anonymised operational data, internal templates. Commercially sensitive but about nobody in particular. These belong in a business-tier account under a data processing agreement, and not in a free consumer account.

Tier three, personal data. Names, contact details, account references, anything identifying a customer, a supplier contact or an employee. This goes only into a system with a signed data processing agreement, training excluded, a known processing location, a lawful basis you can state, and a record that the decision was made. Much of the value here comes from noticing that the task rarely needs the identifiers at all.

Tier four, sensitive and restricted. Health information, financial hardship, anything about a child, HR investigation material, anything under legal privilege or a confidentiality undertaking to a third party. Nothing in this tier moves without a documented assessment and a specific, named decision. For most businesses the honest answer for tier four is that it stays out of general-purpose assistants entirely.

The step most people skip is pseudonymisation on tier three. If you want help drafting a difficult customer email, the model does not need the customer's name, address or account number to do it well. Replace them with placeholders, get the draft, put the details back yourself. That one habit moves a large share of everyday work from tier three to tier two, which is where the friction disappears.

Then write down what triggers a formal data protection impact assessment before it happens rather than after: any new use involving tier four data, any large-scale processing of personal data, anything that scores or ranks people, anything that makes a decision affecting someone with no human in the loop. Deciding the triggers in advance is what stops the assessment becoming a thing you were supposed to have done.

We run all of this on our own estate. Every system we use sits on a register naming the tier of data it may receive, our own data moves through that routing framework, and the impact assessment triggers are written down rather than judged case by case. We deploy nothing for a client that we have not been willing to run on ourselves, and the full method is set out on our how we build page.

What does GDPR actually require?

Five things, and none of them are exotic.

A lawful basis. You need a reason to process the personal data that you could state to the person it belongs to. Using a tool to draft a response to a customer's own query is straightforward. Feeding a customer database into an assistant to see what it comes up with is not.

Processor terms. Under Article 28 the provider is your processor and needs a contract to match. Consumer terms of service are not that contract. This alone rules out the free tier for anything in tier three.

Transparency. Your privacy notice should reflect what you actually do. If AI tools process customer data, say so.

Minimisation. Only the data the task needs. This is the same principle as the pseudonymisation habit above, and it is the cheapest control available, because it limits the damage when something does go wrong rather than trying to prevent every possible failure.

Transfers and records. Know whether processing happens inside the EEA, and if not, what mechanism covers it. Keep a record of the decision. Our post on using AI without breaching GDPR goes through this in more detail.

Does the EU AI Act change the answer?

Not for most everyday use. Drafting, summarising and searching your own documents sit in the Act's minimal risk band and carry no specific obligation.

What does apply from 2 August 2026 is the transparency duty. If AI interacts with people on your behalf, they have to know. If you publish AI-generated content, in most cases it has to be marked. We have written on what the Act means for a small Irish firm, including which dates moved in the May 2026 omnibus agreement and which did not.

What goes wrong in real businesses?

Five patterns, in rough order of how often we find them.

Shadow use. Staff using personal accounts because the business never gave them an approved one. The work is happening either way. The only question is whether it happens somewhere you can see.

Whole documents where a paragraph would do. Somebody pastes an entire file because selecting the relevant part takes thirty seconds longer.

Assuming the tool forgets. Conversation history persists, and so does anything pasted into it.

Testing with real data. A new tool gets evaluated on live customer records because that is what was to hand. Trials are exactly when nothing is agreed and nobody is watching.

No record of who approved what. The business may have made entirely sensible decisions and have no way to show it, which is a problem the first time somebody asks.

How do you put this in place?

An afternoon, in this order.

  1. Inventory what is in use. Every AI tool, including the free ones nobody approved and the AI features already switched on inside software you pay for. Most businesses find roughly twice what they expected.
  2. Write the four tiers on one page, with examples from your own business rather than generic ones. Real examples are what make it usable.
  3. Fix the accounts. Move approved work onto business-tier accounts with a data processing agreement, and turn training off. This removes most of the risk in a single step.
  4. Name who approves what, and write down the impact assessment triggers before you need them.
  5. Tell people, with examples. A rule nobody has read changes nothing. Show two things staff may do freely and two things they may not.
  6. Review it quarterly. Vendor terms move, and so does your tool list.

The businesses that do this properly usually get more than a compliance file out of it. The inventory shows where AI is already saving time, where it is being used in ways that should stop, and where the opportunity nobody had got to yet actually sits.

Where to start

If you want an honest picture of where your business stands before committing to anything, our free AI Readiness Self-Assessment takes ten minutes. A dploy.ai AI Operations Assessment covers this ground properly and maps where AI pays back for your business, for a fixed €999 within seven days. Or book a short call and talk it through first.

This is practical guidance rather than legal advice. A business with a genuinely difficult tier four question should take its own.

Want to know where AI fits in your business?

We run a structured assessment that identifies your highest-value AI opportunities. Fixed price. Seven days. Guaranteed results.

Book a free 15-minute call