Skip to content
CyberTECTDigital operations control
All resources

What Business Data Should Never Be Entered Into ChatGPT?

Keep client-identifying, privileged, financial, identity, security, employee, health, transaction and proprietary information out of unapproved AI tools. Approval must cover the exact tool, account, use and information—not merely the brand name.

The short answer

Unless the exact tool, account, use case, settings, and information category have been approved, staff should not enter client-identifying information, privileged or confidential communications, government identification, banking or trust information, passwords or security details, employee or health records, unreleased transaction documents, or proprietary business information. Removing a name does not always make the information safe or anonymous.

Key takeaways

  • Approval must cover the exact tool, service plan, account, use case, users, settings, and information—not merely the product name.
  • Client identifiers extend beyond names; an address, transaction amount, distinctive facts, or several details together may reveal the person or matter.
  • Business and enterprise plans can improve data-use and administrative controls, but they do not automatically authorize privileged or confidential inputs.
  • Use synthetic examples, minimum necessary excerpts, competent human review, and the official business record for approved low-risk work.
  • If restricted information was entered, report and assess it promptly; deleting the visible chat is not a complete incident response.

The most useful workplace rule is not ‘never use ChatGPT’ and it is not ‘never enter anything confidential into any AI system under any circumstances.’ Both are too blunt to govern real work. The practical rule is that sensitive business information stays out by default until the organization has approved the specific task, service plan, account, settings, users, and safeguards.

That distinction matters because the name on the screen does not tell you the complete data-handling arrangement. A personal account and a company-controlled business workspace may have different training defaults, administration, retention, and security controls. Even inside a business service, connected apps, shared GPTs, feedback, exports, and user permissions can change the risk.

The Office of the Privacy Commissioner of Canada advises organizations using generative AI to limit the sharing of personal, sensitive, or confidential information and to remain accountable under existing privacy laws. For law firms, the Law Society of Ontario also identifies confidentiality, competence, supervision, accuracy, and other professional obligations that must be considered when generative AI is used.

Eight information categories to keep out by default

01 Client-identifying and matter-specific information

Names are not the only identifiers. A client may be recognizable from an address, property, employer, transaction amount, family relationship, court file, unusual fact pattern, email excerpt, document metadata, or combination of details.

Do not paste a real client email, intake summary, meeting transcript, file chronology, or document merely because the name was removed. Ask whether the person or matter could still be identified and whether the same task could be completed using a generic example or synthetic information.

02 Privileged, confidential, or professionally protected communications

Legal advice, client instructions, internal strategy, settlement positions, work product, confidential accounting or insurance discussions, and similar communications should not enter an unapproved AI service. The fact that a tool is convenient does not change the office’s duty to protect the information.

For legal work, privilege and confidentiality require matter-specific judgment. A firm should obtain appropriate professional guidance before approving any workflow that sends protected client content to an AI provider or connected service.

03 Government identification and identity-verification data

Driver’s licences, passports, health cards, social insurance numbers, dates of birth, signatures, identity-verification reports, security questions, and copies of identification create fraud and privacy exposure if mishandled.

Do not upload an ID image to extract text, ‘clean up’ a scan, or summarize an identity report unless the workflow has been formally approved for that purpose. Cropping the image may leave identifying data or metadata behind.

04 Banking, trust, payment, tax, and transaction information

Bank account details, wire instructions, trust ledgers, payout statements, credit information, tax records, payment-card data, mortgage details, and transaction histories are high-consequence inputs. A single error or disclosure can affect money movement, fraud response, and professional obligations.

Staff should not use an unapproved chatbot to verify wire details, draft payment instructions from real account data, reconcile a trust discrepancy, or explain a client’s tax information. Use established systems and independently verified processes for financial work.

05 Passwords, authentication data, and security details

Passwords, recovery codes, API keys, session tokens, private keys, one-time codes, firewall configurations, vulnerability details, and live incident evidence do not belong in general AI prompts. They can provide direct or indirect access to systems.

Do not paste a suspicious email with live reset links or full technical headers into an unapproved service if it contains internal addresses, tokens, or incident indicators. Use an authorized security workflow and preserve evidence appropriately.

06 Employee, applicant, payroll, and health information

Resumes, performance notes, accommodation requests, medical details, payroll records, disciplinary information, background checks, and employee complaints contain personal information and can influence consequential decisions.

AI should not be used to rank, profile, discipline, or make employment decisions without a defined, reviewed process. De-identification, purpose limitation, fairness, accuracy, human oversight, and applicable employment and privacy obligations all require consideration.

07 Unreleased agreements, filings, reports, and decision material

Draft contracts, pleadings, closing documents, financial statements, valuations, insurance applications, board material, investigation notes, and expert reports may be confidential even when they contain little personal information.

The exposure can involve negotiation strategy, accuracy, intellectual property, contractual restrictions, or premature disclosure. The document should be classified before anyone asks an AI service to summarize, compare, translate, or rewrite it.

08 Proprietary business, vendor, pricing, and deal information

Supplier pricing, margins, tender responses, product plans, internal procedures, source code, customer lists, acquisition discussions, non-public forecasts, and vendor security details may be commercially sensitive or protected by contract.

A prompt can disclose competitive information even without attaching a file. Staff need examples that reflect the office’s actual work so ‘confidential business information’ is not left as an abstract phrase.

Why redaction is not a complete solution

Removing a client’s name may reduce risk, but it does not automatically de-identify the information. Addresses, dates, unique events, job titles, transaction amounts, document wording, or several facts taken together may identify a person or matter.

Redaction also does not solve privilege, contractual confidentiality, intellectual property, accuracy, retention, or account-control concerns. Use the minimum information necessary, replace real facts with synthetic examples where possible, and obtain approval when the task still depends on sensitive context.

A safer prompt pattern for approved low-risk work

For an approved tool and low-risk task, separate the structure of the work from the real record. Ask for a neutral template, checklist, tone adjustment, or generic explanation, then complete and verify the work inside the office’s controlled system.

  • Describe the task without naming a client, employee, property, account, or matter.
  • Use invented names, amounts, dates, and facts when an example is required.
  • Paste only the minimum excerpt needed; do not upload a complete file by default.
  • Review the output for invented facts, unsuitable assumptions, confidentiality, and professional accuracy.
  • Store the final approved work in the official matter, client, or business record—not only in chat history.
Prompt contains Default action Safer alternative
Client or employee identifiers Stop and remove them Use synthetic names and generic facts
Complete confidential document Do not upload by default Ask for a blank structure or use a minimum approved excerpt
Passwords, wire data, or ID Do not submit Use the authorized security, banking, or verification workflow
Public or generic information Use only in an approved account and task Verify accuracy and save final work in the official system

What to do if restricted information was already entered

Do not conceal the mistake or assume deleting the visible conversation ends the issue. Promptly record what was submitted, which account and service were used, when it occurred, who may have access, and what settings, apps, or shared links were involved. Notify the person responsible for privacy, security, professional obligations, or management.

The organization can then preserve necessary evidence, review the vendor’s retention and deletion controls, revoke connections or access where appropriate, contact the provider if needed, assess legal or professional notification obligations, correct affected work, and update training or controls. The response should match the information and consequence involved.

A useful interim staff rule

If the information identifies a client, employee, account, transaction, legal matter, security control, or confidential business decision, stop before submitting it. Use only the organization’s approved tool and approved workflow, or ask the designated owner.

Frequently asked questions

Does ChatGPT train on everything employees enter?

No single answer applies to every ChatGPT service and setting. OpenAI states that it does not train on business data from ChatGPT Business, Enterprise, and its API by default, while consumer data controls and opt-in choices differ. The office must verify the exact product, account, settings, and current terms rather than relying on the brand name.

Is ChatGPT Business safe for confidential client information?

A business workspace may provide stronger contractual, administrative, and data-use controls, but it does not automatically authorize every confidential use. The organization must still assess professional duties, privacy, necessity, account access, retention, apps, user behaviour, and the specific information involved.

Can staff enter information after removing the client’s name?

Only if the remaining information is genuinely appropriate for the approved use. Removing a name may not prevent identification from an address, date, transaction, distinctive facts, or combined details, and it does not resolve privilege or contractual confidentiality.

Can AI be used to improve a client email?

It can be a low-risk use when the approved workflow uses no client-identifying or protected content and the result is reviewed by a competent person. Pasting the real message or full thread into an unapproved account is a different and higher-risk activity.

Should a professional office ban ChatGPT entirely?

A temporary restriction may be reasonable while the office inventories use and sets controls, but an unworkable blanket ban can push activity out of sight. A clearer long-term approach identifies approved tools, permitted tasks, prohibited information, human review, and a question-and-incident path.

Replace ‘be careful’ with a usable information rule

Staff cannot apply a policy they have to interpret from scratch during every task. Give them recognizable categories, realistic examples, approved alternatives, and a clear person to ask. The rule should be stricter where disclosure could affect privilege, identity, money, safety, employment, or a client’s rights.

CyberTECT helps professional offices inventory AI use, classify information, review tools and accounts, define acceptable-use rules, establish human review, and connect AI decisions to the wider controls around Microsoft 365, vendors, backups, continuity, and incident response.

Start with the level of review you need

Take the 90-second Digital Operations Control Check for an immediate directional result. For an evidence-based review of accounts, files, Microsoft 365 backups, vendors, AI use, and continuity, discuss the Digital Operations Checkup or the complete AI & Digital Operations Review. Scope and fees are confirmed before work begins.

General information only. This article does not provide legal, privacy, professional-conduct, or regulatory advice. Organizations should obtain appropriate advice for their sector, jurisdiction, information, and intended AI use.

Related CyberTECT services and checks

Authoritative sources and further guidance

Using this guidance

CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.

Discover more from Cybertect

Subscribe now to keep reading and get access to the full archive.

Continue reading