Is ChatGPT Safe for Confidential Information?
It is a Tuesday in late October, which in an accountancy practice means month-end has collided with a filing deadline. A senior on the audit side has 40 pages of a client's management accounts and eleven minutes before a call. So she copies the lot into ChatGPT and asks for a summary of the movements since Q2.
She gets a good summary. That is the awkward part of this whole subject: it works, it saves her forty minutes, and nothing visibly bad happens. Nobody is being careless in the way that word usually means. She is being efficient with a tool that is genuinely useful, and the only person who would object is a data protection officer who was not in the room.
So: is ChatGPT safe for confidential information? Honestly, it depends on three things — which tier she was signed into, whose account it was, and what the material actually was. Those three answers vary enormously, and most guidance collapses them into a single yes or no.
What actually happens to what you type
OpenAI's handling of your content is not uniform across its products. The distinction that matters is between the consumer tiers, where training on your inputs is the default behaviour, and the business tiers, where it is contractually excluded. Everything below is from OpenAI's own published policy on how your data is used.
| Tier | Trains on your content? | Data processing agreement? | Where processing happens |
|---|---|---|---|
| Free / Plus / Pro | Yes, by default — can be turned off in data controls | No | OpenAI's servers |
| Team | No | Yes | OpenAI's servers |
| Enterprise / Edu | No | Yes, with negotiated terms, SSO and audit logs | OpenAI's servers |
| API platform | No | Yes | OpenAI's servers |
| Model on your own hardware | No — nothing is sent anywhere | Not needed for the AI step | Your building |
Read down the third column and the shape of the problem appears. Four of the five rows solve the training question and none of the first four solves the location question. On a business tier your material is confidential because a company has promised in writing that it is, which is a perfectly normal basis for commerce — it is how your bank and your payroll bureau work too. It is just not the same thing as the file never leaving the office.
The real risk is the account, not the settings
Here is the finding that reframed this for me. Cyberhaven's 2026 AI Adoption & Risk Report, published in February 2026, measured actual data flows across its customers rather than asking people what they do. Two numbers stand out: 39.7% of all AI interactions involve sensitive data, and 32.3% of ChatGPT use happens through personal accounts rather than corporate ones.
That second number is the one that should worry a practice owner. A third of the usage is invisible to you. It is not on your tenancy, not in your audit logs, not covered by whatever tier you are paying for, and not recoverable if a client asks what happened to their file. You can buy Enterprise for everyone and still have a third of the traffic going out through a Gmail-linked login on someone's phone.
The same firm found back in 2023 that 11% of what employees paste into ChatGPT is confidential, with client data and source code near the top of the list. The behaviour is not new and it has not slowed down. What has changed is that it is now measured.
Two incidents worth knowing about
Two events give this some weight beyond the theoretical.
In March 2023 a bug in a caching library let some ChatGPT users see titles from other users' conversation histories. OpenAI's own post-incident write-up confirmed it also exposed payment details — name, email, billing address, card expiry and last four digits — belonging to 1.2% of ChatGPT Plus subscribers active in a nine-hour window. Well-run companies still have bugs. That is not a scandal; it is the ordinary risk of putting things on somebody else's computer.
The second is regulatory. In December 2024 the Italian data protection authority fined OpenAI €15 million, of which €320,000 was specifically for failing to notify that March 2023 breach to the authority. The rest concerned training on personal data without an adequate legal basis. It was the EU's first large fine against a generative AI provider, and it establishes something useful: these systems are squarely inside GDPR, and the regulators are not treating them as a special case.
