
35 / 58
Data in ChatGPT
Keep business data safer when you use ChatGPT
Training defaults differ on consumer vs Business plans. Minimize what you paste; read OpenAI’s privacy help—not a fake compliance badge.
What you will be able to do
You will know what not to paste into ChatGPT, how consumer vs Business/Enterprise training defaults differ at a high level, and where to read OpenAI’s own help—without treating a blog post as a compliance certificate.
The honest answer
Business data in ChatGPT is only as safe as:
- What staff paste or connect
- Which plan and settings you use
- What OpenAI’s current terms say for that product
- How your shop behaves on a busy Friday
No chat tool makes careless pasting safe. Clear rules do.
Training defaults (verify on OpenAI’s pages)
Business / Enterprise / Edu: OpenAI’s help for Projects and GPTs states that for these commercial plans, data is not used for training by default. Business pricing pages also describe “no training on your business data by default.” Re-check OpenAI’s current Enterprise privacy and Data Controls articles before you set shop policy.
Consumer plans (Free / Go / Plus / Pro): OpenAI’s GPT and Projects help state that for consumer plans, data may be used for training depending on whether you have opted out (for example via “Improve the model for everyone” / Data Controls). Read the current Data Controls FAQ in OpenAI’s help center.
Defaults can change. Re-check OpenAI’s help before you set shop policy.
What not to paste
Same postcard rule as customer data and AI tools:
- Card numbers, bank logins, passwords
- Full medical charts or unnecessary health details
- Children’s data, government IDs, unrestricted HR files
- Secrets you would not put in a shared email
Prefer: role + facts needed for the draft; redact names when the job does not need them; use approved apps/connectors with least access — see Drive / Microsoft 365.
Business and Enterprise controls (high level)
Commercial plans add organization-side controls such as admin management of apps/connectors, central billing, SSO/MFA, and (on higher tiers) deeper retention and role features as listed on pricing. Owners should decide:
- Which apps/connectors are allowed
- What data classes are forbidden in chat
- Who may share Projects or custom GPTs
- How long chats are retained under your agreement
What this article is not
It is not a HIPAA, SOC 2, or legal opinion for your practice. OpenAI may list enterprise privacy and compliance offerings—that is their product surface, not automatic coverage for your clinic. Confirm contracts with OpenAI and your counsel. For the Claude twin, see Is business data safe in Claude?.
Try this job: write a one-page ChatGPT data rule
- List red data (never paste).
- List yellow data (ok only on Business/Enterprise with admin approval).
- List green data (approved templates, public pages, anonymized examples).
- Name who may connect Drive/Microsoft 365.
- Pin the page in the staff handbook; review quarterly against OpenAI’s current privacy and Data Controls articles.
Short close
Minimize what you paste, match the plan to the sensitivity, and read OpenAI’s current privacy docs—not a remembered rumor.
Keep these
The working rules
Safety is paste habits + plan + vendor terms. Consumer training opt-out differs from Business/Enterprise defaults; verify on OpenAI help pages.
Floor vote
Where are you with this job?
One vote per device. Change it any time.
Loading votes…
Field check
Field check
Four questions. Honest answers. No score sent anywhere but this page.
01 / 04
Can you name the one job this piece is for, in one sentence?