MMODZ.digitalGet a quote
04 Aug 2026 · Barry Connolly
AI

What not to paste into ChatGPT: a data-safety guide for small teams

AI tools are brilliant until someone pastes a customer list into one. Here's a sensible, plain-English guide to what stays out of public AI tools.

Most of your team are probably already using ChatGPT or something like it. That's fine. The risk isn't the tool, it's what gets pasted into it at 4pm on a Friday when someone just wants a quick summary.

The short list of things to keep out

Personal data about customers or staff: names with contact details, health information, HR issues, anything under data protection rules. Passwords, API keys and access tokens. Unreleased financials and commercially sensitive contracts. Anything covered by a confidentiality agreement with a client. If you wouldn't email it to a stranger, don't paste it into a public tool.

Know which version you're using

Free consumer accounts, paid team plans and business or API offerings treat your data differently. Some use conversations to improve their models by default unless you switch it off; business tiers generally don't. Read the provider's current terms for the plan you actually use rather than assuming.

Anonymise first

You can often get the value without the risk. Swap names for 'Customer A', strip out account numbers, and describe the problem rather than pasting the document. For many tasks, such as drafting or restructuring text, the AI doesn't need the real details at all.

Give people a safe option

Banning AI rarely works; people use it on their phones instead. Better to approve a tool, set simple rules, and where you need AI to work with your own documents, build it properly so the data stays under your control. Our plain guide to RAG explains how that works.

Want AI that respects your data?

We build AI tools that work with your own information in a controlled way. Happy to talk through what's sensible for your team.

Start a conversation →

Frequently asked questions

Is it illegal to paste customer data into ChatGPT?

Not automatically, but it is personal data processing and needs a lawful basis, appropriate safeguards and a suitable agreement with the provider. If you aren't sure, don't do it and get advice.

Do paid plans keep my data private?

Business and API plans typically offer stronger commitments than free accounts, but terms differ and change. Check the current terms for your plan.

What should we do first?

Write a one-page rule set, tell everyone about it, and choose one approved tool. That covers most of the risk for a small team.

AIData protectionSecurityPolicy