In a webinar Jen Miller and I hosted for about 20 HR leaders, we ran through a scenario with a benefits coordinator I’ll call Maria. All week Maria had used ChatGPT like a pro: drafting emails, summarizing a policy, cleaning up a clunky memo. Then open enrollment hit, and she pasted the renewal census into her personal account to fix the formatting and summarize some data. She had no idea she’d done anything wrong, and someone on your team is doing a version of it right now.
So, is it safe to put company data into ChatGPT? Generally no, not on a consumer account. The second that file lands there, you’ve lost control of it, you may have breached a contract with a client, a vendor, or even your employees, and depending on what’s in it, you may owe someone a notification.
In 2023, within about three weeks of letting employees use ChatGPT, Samsung engineers pasted source code, a defect-detection algorithm, and an internal meeting transcript into it. Once Samsung leaders were alerted, they immediately revoked all access and set up an enterprise version a few weeks later.
What Actually Happens to the Data You Paste In
“We don’t train on your inputs” is not “we don’t keep them.” And neither one is “no human ever reads them.”
Google spells this out on its own help page. Consumer Gemini saves your chats, uses them to improve Google’s products, and has human reviewers read a subset. The chats a human reviews don’t get deleted when you delete your activity. Google keeps them up to three years, and warns you not to enter anything confidential you wouldn’t want a reviewer to see. You don’t get to know which chats got pulled.
People point to ChatGPT as the counterexample. In the New York Times copyright case, a court ordered OpenAI to preserve consumer logs it would otherwise have deleted, then affirmed an order to produce roughly 20 million of them, over OpenAI’s privacy objection, because users had voluntarily handed their messages over.
That hold has since lifted, and consumer ChatGPT now deletes on a roughly 30-day cycle by default. Consumer ChatGPT also trains on your inputs by default unless someone dug into the settings and turned it off, and almost nobody does.
Whatever the tool keeps becomes a record someone can demand. Prompts and outputs are discoverable in litigation like any other electronic file. Cc’ing legal doesn’t fix it. Courts have shielded attorney-drafted prompts built for litigation strategy. What your staff types on a Tuesday is fair game.
The Exposures Most Teams Never Screen For
The lawsuits you’ve read about target the AI companies, not employers, though there are some examples where employees have been sued because of the actions of employees. But equally worrisome are contracts you’ve already signed.
The NDAs and data processing agreements (DPAs) you have with clients and vendors restrict where their data can go, and a personal ChatGPT account probably isn’t on the approved list. That paste can breach a deal you signed.
A breach with no provable loss might cost only nominal damages. But a client fires you when they learn their data went where the contract said it couldn’t. A for-cause clause lets them walk. An indemnification clause puts you on the hook for their legal bills.
Trade secret is shakier ground for whoever’s suing. Federal law only protects a trade secret if you took reasonable measures to keep it secret. Hand your secret to someone under no obligation to protect it and you can lose the right entirely.
That’s the logic a court used in Trinidad v. OpenAI, dismissing a trade secret claim after the plaintiff fed her own frameworks into ChatGPT and took no steps to keep them secret. It’s a self-represented plaintiff on odd facts, and whether a paste generally forfeits a secret is unsettled.
Breach-notification is the one owners overestimate. Every state has a breach-notification law, but the trigger is narrow and the duty isn’t automatic. And if Maria was on your team, you might be required to notify all your employees.
It usually takes a name plus something like a Social Security number, a driver’s license number, or a financial account number. A salary or a birthday alone usually won’t trip it. HIPAA almost certainly doesn’t cover your HR records, because the law excludes employment records you hold as an employer, though the ADA and FMLA still reach that paperwork. So whether a paste becomes a notification depends on what was in the file and where your people sit.
Strip the names first, then paste. It’s better than nothing. But it isn’t a clearance.
De-identification reduces risk. It doesn’t move the risk off your books. NIST, the federal standards body, says some de-identified data can be re-identified, and the risk climbs with exactly the file a small company hands its benefits broker. A 40-person census still carries salary band, job title, department, ZIP code, and dependent count.
“Director, engineering, Austin, two dependents, top salary band” is one person at a 40-person company, and your org chart or their LinkedIn names them in seconds. Strip the name column and the rest still points at one human.
If It Already Happened, and How to Stop the Next One
If you found out it happened, don’t delete anything. Deleting can look like destroying evidence once a dispute is reasonably on the horizon, and that duty to preserve can attach before anyone files.
Figure out exactly which data elements were involved, because that drives everything downstream. Call your own counsel before you decide it’s nothing, because whether it’s a notifiable breach is fact-specific and not yours to wing.
Write the timeline down while it’s fresh. You don’t need an incident-response function. You need to slow down for an afternoon instead of reacting in five minutes.
To stop the next one, give people a path instead of a wall. Plenty of workers are pasting sensitive material into AI tools, and a lot of companies still have no policy at all.
A ban doesn’t fix that. It pushes the tool onto personal accounts where you can’t see it. Carefully vet and implement one sanctioned tool with a no-training agreement so nobody’s driven to a personal account.
Be clear to your team about what’s okay and what isn’t. Give a few plain examples. Rewriting an email, fine. Pasting the census, writing up someone’s discipline file, dropping in a client contract, not fine.
And make it safe to report a mishap, so the next Maria tells you on day one instead of hiding it for a month. You only get one chance to get your reaction right. The first time it happens, you correct the act and celebrate the transparency from the employee.
Need help creating practical AI policies and compliance safeguards for your organization? Reach out to me at Bryan Driscoll for AI compliance to make sure your team can use AI without putting sensitive company, client, or employee data at risk.
FAQ
We pay for enterprise ChatGPT, so we’re fine, right? Safer, not automatically safe. Team and Enterprise tiers aren’t used for training by default and run under a data processing agreement, and where you’re eligible, asking for zero data retention closes most of the remaining concerns. A governed tool with a no-training contract also starts to look like the reasonable measures trade secret law wants. But retention, abuse monitoring, and the client contracts you already signed still apply.
What kinds of data are the real problem? Anything tied to a specific person or covered by a promise you made. Social Security numbers, salaries, health elections, discipline records, client data under an NDA or DPA, source code, deal terms. The everyday question, rewrite this email, summarize this article, is fine. Feeding the tool the actual sensitive file is the line you don’t cross on a consumer account.
Can’t I just ban ChatGPT and be done? No. A ban drives the tool onto personal accounts where you have zero visibility, which is worse than a managed risk. One sanctioned tool plus a one-page rule people actually follow beats a ban you can’t enforce. You’re not trying to stop people from using AI. You’re keeping your data secure.


