
Last updated 17 July 2026
Using ChatGPT with business data is safe only under the right plan and rules. On free and personal plans, content you enter may be retained and used to improve the model, so confidential data should never go in. Enterprise and team plans add contractual protections — no training on your data, admin controls and encryption — which makes them suitable for most business use. For regulated or highly sensitive data, a private AI instance you control is the safer option.
What actually happens to data you type into ChatGPT?
On consumer plans, the prompts and files you submit can be stored and, depending on your settings, used to help train future models. That is fine for general questions, but it means pasting a client contract, patient record or unreleased financial result into a personal account is a genuine data-exposure risk. Business, team and enterprise plans change this: the vendor commits not to train on your content and provides administrative oversight.
What are the real risks for a business?
- Data leakage — staff pasting confidential information into unmanaged personal accounts ("shadow AI").
- Compliance exposure — sending personal data to an offshore service without checking your obligations under the NZ or Australian Privacy Act.
- Loss of control — no central visibility of what data is being shared, by whom, or where it goes.
- Accuracy risk — treating confident-sounding output as fact without human review.
How do we let staff use AI safely?
The answer is rarely a ban — bans just drive usage underground. The safer path is to provide an approved, governed tool (an enterprise plan or a private instance), publish a short AI-use policy that says what data is and isn't allowed, and give staff basic training on the difference. Most data incidents come from good people using the wrong tool because no sanctioned option existed.
When is ChatGPT not enough, and you need private AI?
If you handle regulated data, must guarantee where information physically resides, or operate under strict client-confidentiality obligations, even an enterprise plan may not satisfy your requirements, because processing still happens on shared vendor infrastructure. A private AI instance keeps data inside your own boundary and is often the only approach that passes a serious governance review.
What does the Privacy Act 2020 require when using ChatGPT?
New Zealand’s Privacy Act 2020 does not ban AI, but it still applies to any personal information you put into a tool. Two duties matter most. Information Privacy Principle 5 requires you to keep personal information secure, which is hard to demonstrate if staff are pasting it into unmanaged accounts. And when a tool processes data offshore, you remain accountable for how that information is handled — disclosing personal information to an overseas provider carries obligations you cannot outsource. If a breach occurs and it poses a risk of serious harm, you are legally required to notify the Office of the Privacy Commissioner. Using an enterprise plan or a private instance makes those duties far easier to meet.
How do we know if staff are already using AI unsafely?
Assume they are, then check. The pattern is consistent: staff adopt whatever tool helps them get work done, well ahead of any policy. Look for AI-generated drafts in your documents, ask teams candidly what they use, and review whether any sanctioned option exists. If the honest answer is that people are using personal ChatGPT accounts for work because nothing approved is available, that is the risk to fix — not by punishing them, but by giving them a governed alternative.
Frequently asked questions
Not for anything confidential. Assume anything entered on a free or personal plan could be retained. Use it only for non-sensitive, general tasks.
No — OpenAI states it does not train on business, team or enterprise data, and provides admin controls and encryption. That makes it suitable for most business use, though not necessarily for the most sensitive regulated data.
Shadow AI is staff using unsanctioned AI tools without oversight. It signals real demand, but it is also where most data-exposure incidents happen. Providing an approved alternative is the fix.
SOVATA