Company Data in ChatGPT: What Employees May and May Not Paste

The short answer: ChatGPT on a personal account is no place for customer and employee personal data, credentials, contracts, source code, or anything covered by an NDA or trade secret — with consumer accounts, conversations may by default be used to improve the models, and your company loses control over them. The safe route has three steps: a business plan with training switched off and central account management, simple traffic-light rules (what may go out freely, what only anonymised, what never), and for genuinely sensitive work, local AI that data never leaves at all. A blanket ban does not work — people will find their way to AI with or without you, just outside your control.

The question „what are we allowed to paste into ChatGPT" now lands on the desk of every managing director who has discovered that their people have been using AI for ages. This text is the practical answer: where the pasted text travels, where the legal line runs, and how to write rules your team will not work around.

Your employees already use ChatGPT. The question is how

You do not need surveys — just ask around the office. Someone is having a supplier e-mail translated, someone is summarising a long contract, someone is polishing a client quote. Usually on a personal account they set up themselves, and usually with no idea what happens to the pasted text next.

This is called shadow AI, and it is today’s quietest channel for company data leaking out. Not out of malice — out of a simple desire to get the work done faster. We unpacked it in our article on what it costs a company when employees can’t use AI: if a company gives its people no safe route, they will beat their own path.

That this is not a theoretical risk was clear as early as 2023. Samsung internally restricted the use of ChatGPT after employees pasted internal source code into the chatbot. And in the same year, the Italian data protection authority temporarily restricted ChatGPT in Italy over concerns about the processing of personal data. The services have moved on since then, but the principle has not: once you send something out, you no longer control it.

Where text from a chatbot travels

When an employee pastes text into ChatGPT, it goes to the provider’s servers — outside your company and typically outside Europe as well. What happens to it next depends mainly on the type of account.

Personal accounts (Free, Plus). By default, OpenAI may use conversations to improve its models. You can switch this off in the data controls, but hand on heart: how many of your people have actually done that? On top of that, conversations stay in the history of an account the company has no access to whatsoever — when an employee leaves, their „company" history leaves with them.

Business plans (ChatGPT Business, Enterprise) and the API. Here OpenAI states that it does not use business data to train its models by default. Central management comes with it: you know who is using the tool, you set the rules for them, and when someone leaves the company you simply delete the account. You will find a comparison of business plans and their pricing in the article on what AI costs a company.

Three things get underestimated regardless of the plan:

  • Shared links. A conversation can be shared via a public link — and in 2025 some of the conversations shared this way, where users had allowed them to be discoverable, showed up in search engine results before the provider pulled the feature. A link to a conversation containing company data is simply a public address.
  • Memory and history. ChatGPT can remember information across conversations. Convenient for the user, treacherous for the company — a sensitive detail pasted in January can surface in an answer in June, on a completely different question.
  • Deleting is not disappearing. A deleted conversation does not vanish from the servers immediately; the provider may retain data for a certain period, among other things because of legal obligations.

What does not belong in a public chatbot

A red list that fits on a single page of a policy:

  1. Customer and employee personal data — names in the context of a case, contact details, national ID numbers, salaries, health information. GDPR territory, see below.
  2. Credentials — passwords, API keys, VPN configurations. Anything that opens the door to your systems.
  3. Contracts and documents under NDA — you promised the client confidentiality, not the chatbot provider.
  4. Price calculations, margins, quotes in progress — the company’s most competitively valuable numbers.
  5. Source code and internal technical documentation — exactly the case Samsung had to deal with.
  6. Strategy, plans, HR matters — anything that is not meant to leave the management meeting.

A rule of thumb that works better in practice than any list: before you paste the text, imagine it being read by your competitor and a regulator at the same time. If that thought makes you squirm, it does not belong in a public chatbot.

What you can paste

The point of the rules is not to sour people on AI, but to give them certainty. Without much risk, you can typically paste the following into a public chatbot:

  • general questions and explanations („explain the difference between a backup and an archive"),
  • texts with no identifying details — e-mail templates, document structures, draft procedures,
  • publicly available information — text from your website, product data sheets, public standards,
  • brainstorming and style work („rewrite this more clearly„, „suggest a training outline").

The grey area is anonymisation. You can paste a customer e-mail with the name removed — but anonymisation is more than deleting a name. If the context („our biggest bearing customer from Kuřim") gives away who it is, the text is not anonymous.

GDPR. By pasting personal data into a chatbot, you are processing it through another party. As the controller, the company needs a legal basis and a data processing agreement with the provider — OpenAI concludes one for business plans and the API, not for an employee’s personal account. A personal account holding customer data is therefore an indefensible arrangement from a GDPR standpoint: the data goes to an entity the company has no contractual relationship with.

Trade secrets. The Czech Civil Code (občanský zákoník, § 504) protects a trade secret only where its owner adequately ensures that it remains secret. A company that lets employees paste calculations and production procedures into public tools without any rules is arguing against itself — in any subsequent dispute, it will struggle to claim that secrecy was ensured.

AI Act. On top of that, Article 4 of the European AI Act has applied since 2 February 2025: companies that use AI are required to ensure a sufficient level of AI literacy among their people. Rules for handling company data in chatbots are exactly the kind of knowledge that counts towards this.

Rules your team will actually follow

Two certainties from practice: nobody will read a twenty-page policy, and a blanket ban lasts until the first deadline where AI saves someone an hour. What works is a simple traffic light plus an approved route:

  1. Green — general questions, texts with no identifying details, public information. Use freely.
  2. Amber — internal texts after genuine anonymisation. Only on a company account with data controls switched on.
  3. Red — personal data, credentials, contracts, code, calculations. Never into a public chatbot; these belong solely in tools the company has explicitly approved.

Three organisational steps go with the traffic light: a business plan instead of personal accounts (training off, central management), one specific person people can ask „am I allowed to do this?", and a few hours of hands-on training where the team tries the rules out on their own documents. That is exactly how we build our AI training for companies — not a tour of buttons, but habits and rules applied to your real processes, including what may go where. We describe in detail what a team should be able to do after such training in our article on AI training for companies.

Sensitive work: AI that data never leaves

For some kinds of work, even a business cloud plan is the wrong answer — payroll, accounting, health data, client files, manufacturing know-how. There it makes no sense to negotiate who you send the data to and on what terms. It makes sense not to send it at all.

The answer is local AI: an open model running on a server inside your company, optionally connected to your documents. No text leaves the building, no data processing agreement with an outside party, no arguments about training. It is not for everyone — it has upfront costs and needs administration — but for companies with sensitive data it is the only option where the question „what may employees paste" stops making sense, because the data stays home. We run local AI ourselves and build it for clients too; you will find a cost comparison with the cloud in the article on AI pricing mentioned above. And if you are not sure which data falls into the red category at your company, get in touch — we will go through it with you on your actual workflows.

Frequently asked questions

Is ChatGPT trained on our company data?

With personal accounts (Free, Plus), conversations may by default be used to improve the models; you switch this off in the data controls. For business plans and the API, OpenAI states that it does not use business data for training by default. But even a business plan does not cancel out GDPR and contractual confidentiality — it only improves the default terms.

Is it enough to anonymise the data before pasting it?

Only if the anonymisation is genuine. Deleting a name is not enough when the context — the industry, the town, the role, the amounts — still identifies the person or the company. With truly sensitive material, it is safer not to paste the document into a public chatbot at all and to process it on local AI instead.

Can we simply ban ChatGPT for employees?

You can, but the result is usually not zero usage — it is covert usage, on personal phones and accounts you cannot see. It is safer to give people an approved route, a company account and a clear traffic light of what may go where.

What should we do if someone has already pasted sensitive data?

Find out what, when and on which account. Delete the conversation, switch off the use of data for training, change credentials immediately. If personal data was involved, assess the incident from a GDPR standpoint, including any notification duty — and above all, adjust the rules so the situation does not repeat itself.

Does this apply only to ChatGPT?

No. The same logic applies to any cloud AI tool: chatbots, online translators, meeting transcription and AI features in browsers. Write your rules for the category of „public AI tools", not for one specific product.