Is ChatGPT Safe for Confidential Information? What Irish Businesses Need to Know

AgentHub.ie logo
Dr. Shadi Ghaith Founder, AgentHub.ie ·

Not on the free or Plus tiers, where your inputs may be used to train OpenAI's models by default. On Team, Enterprise and the API, training is off and OpenAI will sign a data processing agreement. But on every tier the file still leaves your building — and that journey is the part your GDPR assessment has to justify.

Confidential client folders pasted into a chat window, then travelling out of an office building to a distant cloud
The question is not whether the tool is trustworthy. It is whether you can describe, on paper, where the document went.

Is ChatGPT Safe for Confidential Information?

It is a Tuesday in late October, which in an accountancy practice means month-end has collided with a filing deadline. A senior on the audit side has 40 pages of a client's management accounts and eleven minutes before a call. So she copies the lot into ChatGPT and asks for a summary of the movements since Q2.

She gets a good summary. That is the awkward part of this whole subject: it works, it saves her forty minutes, and nothing visibly bad happens. Nobody is being careless in the way that word usually means. She is being efficient with a tool that is genuinely useful, and the only person who would object is a data protection officer who was not in the room.

So: is ChatGPT safe for confidential information? Honestly, it depends on three things — which tier she was signed into, whose account it was, and what the material actually was. Those three answers vary enormously, and most guidance collapses them into a single yes or no.

What actually happens to what you type

OpenAI's handling of your content is not uniform across its products. The distinction that matters is between the consumer tiers, where training on your inputs is the default behaviour, and the business tiers, where it is contractually excluded. Everything below is from OpenAI's own published policy on how your data is used.

TierTrains on your content?Data processing agreement?Where processing happens
Free / Plus / ProYes, by default — can be turned off in data controlsNoOpenAI's servers
TeamNoYesOpenAI's servers
Enterprise / EduNoYes, with negotiated terms, SSO and audit logsOpenAI's servers
API platformNoYesOpenAI's servers
Model on your own hardwareNo — nothing is sent anywhereNot needed for the AI stepYour building

Read down the third column and the shape of the problem appears. Four of the five rows solve the training question and none of the first four solves the location question. On a business tier your material is confidential because a company has promised in writing that it is, which is a perfectly normal basis for commerce — it is how your bank and your payroll bureau work too. It is just not the same thing as the file never leaving the office.

The real risk is the account, not the settings

Here is the finding that reframed this for me. Cyberhaven's 2026 AI Adoption & Risk Report, published in February 2026, measured actual data flows across its customers rather than asking people what they do. Two numbers stand out: 39.7% of all AI interactions involve sensitive data, and 32.3% of ChatGPT use happens through personal accounts rather than corporate ones.

That second number is the one that should worry a practice owner. A third of the usage is invisible to you. It is not on your tenancy, not in your audit logs, not covered by whatever tier you are paying for, and not recoverable if a client asks what happened to their file. You can buy Enterprise for everyone and still have a third of the traffic going out through a Gmail-linked login on someone's phone.

The same firm found back in 2023 that 11% of what employees paste into ChatGPT is confidential, with client data and source code near the top of the list. The behaviour is not new and it has not slowed down. What has changed is that it is now measured.

Two incidents worth knowing about

Two events give this some weight beyond the theoretical.

In March 2023 a bug in a caching library let some ChatGPT users see titles from other users' conversation histories. OpenAI's own post-incident write-up confirmed it also exposed payment details — name, email, billing address, card expiry and last four digits — belonging to 1.2% of ChatGPT Plus subscribers active in a nine-hour window. Well-run companies still have bugs. That is not a scandal; it is the ordinary risk of putting things on somebody else's computer.

The second is regulatory. In December 2024 the Italian data protection authority fined OpenAI €15 million, of which €320,000 was specifically for failing to notify that March 2023 breach to the authority. The rest concerned training on personal data without an adequate legal basis. It was the EU's first large fine against a generative AI provider, and it establishes something useful: these systems are squarely inside GDPR, and the regulators are not treating them as a special case.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

What Counts as a Breach, and the Four Ways to Fix This

Pasting a client document into a chatbot can be a personal data breach, and it does not require anything to go wrong afterwards. The test is disclosure, not harm. Once you know that, the four available fixes sort themselves into an obvious order — and one of them is missing from almost every guide on this topic.

The legal test is narrower than most people assume

GDPR Article 4(12) defines a personal data breach as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data". Note what is absent: no requirement that anyone suffers, no requirement that a hacker is involved, no threshold of seriousness. Unauthorised disclosure is enough on its own.

The word doing the work is unauthorised. If you have appointed a provider properly, it is authorised. Article 28 sets out what appointing properly means: you may use "only processors providing sufficient guarantees", the arrangement must be "governed by a contract or other legal act", and the processor may act "only on documented instructions from the controller". A staff member's personal ChatGPT login satisfies precisely none of that.

The Irish regulator has said the same thing in plainer language. In its guidance on AI, large language models and data protection of 18 July 2024, the Data Protection Commission tells controllers they "should first understand what personal data it uses, how it uses it, where the personal data goes", that a DPIA may be required "especially where the technology or processing is new to you", and warns that without a retention schedule you risk breaching the storage limitation principle. Where the personal data goes. That is the whole question in six words.

What someone didBreach?Why
Pasted a named client's accounts into a personal free-tier accountYesDisclosure to a processor never appointed, assessed or contracted
Same document, on the firm's Enterprise tenancy with a signed DPANoAuthorised processing by an appointed processor
Asked a general question with no client identifiersNoNo personal data left the firm
Uploaded a redacted document that is still re-identifiableProbablyPseudonymised data is still personal data
Ran the same summary on a model installed in the officeNoNo disclosure occurred — nothing left your systems
Diagram contrasting a document leaving an office to a cloud provider with the same document staying inside the building
Every control in the cloud column is a promise about what happens after the file leaves. The last option removes the journey.

Option one: ban it

The instinct of most managing partners, and the least effective thing available. A ban does not remove the deadline that made the paste attractive; it removes your visibility of it. That third of usage on personal accounts is what a ban produces. You end up with the same exposure and no logs.

Option two: consumer tier, plus a policy

Cheap and better than nothing. Turn off training in the data controls, write two pages saying what may and may not be entered, train everyone once a year. This is a reasonable answer for a firm whose confidential material is commercial rather than personal — a builder's quotes, say. It is a weak answer for anyone holding client files under a professional duty, because it relies entirely on judgement in the moment, and the moment is always eleven minutes before a call.

Option three: pay for the business tier

The right answer for most firms, and the one the rest of the internet stops at. Team or Enterprise gives you no training on your content, a data processing agreement under Article 28, single sign-on so the accounts are yours, and audit logs so you can answer the question "what did we send". Budget for the licences and for shutting down the personal accounts, because the second is the part that actually works.

Two things it does not do. Your material still crosses to a third-party processor you must appoint, assess and keep under review, and it still leaves the jurisdiction, which drags in the Chapter V transfer questions. And conversations are still retained on OpenAI's systems, accessible to a limited set of authorised staff for abuse investigation and legal compliance. All normal. All things you have to write down.

Option four: run the model on your own hardware

The one nobody lists. Open-weight models — the ones published so you can download and run them yourself — became good enough for ordinary office work somewhere around 2025, and a single machine can now serve a small firm. Put one in the building and the confidentiality question stops being a question about contracts and becomes a question about your own front door, which you already know how to answer.

The honest trade: the largest cloud models are still ahead on hard novel reasoning, and a local machine is slower. For summarising, drafting, extracting and answering questions about your own documents — which is the overwhelming majority of what an office actually does with AI — the gap is small and shrinking.

Question you have to answerBan itConsumer + policyBusiness tierModel in your building
Is training on your content excluded?n/aOnly if switched offYesYes
Third-party AI processor to appoint?n/aYes, unappointedYes, appointedNone
International transfer to justify?n/aYesYesNone
Can you prove what was sent?NoNoYes, audit logsYes, it is your machine
Does deletion actually delete?n/aNo third-party copy controlPer contractYes, your retention policy
Works when the broadband is down?n/aNoNoYes

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

How Local AI Works in an Irish Practice

Local AI is our answer to option four: a dedicated machine installed at your premises, running open-weight models, with private chat, document search and custom assistants on it. Nothing goes to an AI provider because there is no AI provider in the path. We supply the hardware, set it up, train your team and keep it updated.

It launched this month, so I am not going to dress up a twelve-month client result I do not have. What I can tell you is exactly what gets installed and what we have measured ourselves — we have been running these models in-house for our own document work while building the service.

What actually gets installed

One machine, sized for your team after a short call, sitting on your network in your building. On it:

  • Private chat. A ChatGPT-style assistant. Ask questions, upload documents and images, work through drafts — none of it leaving the box.
  • Document spaces. Contracts, files and reports organised into collections you can search, summarise and compare across, with citations back to the page an answer came from.
  • Your existing sign-in. Single sign-on with Microsoft 365 or Google Workspace, so people use the accounts they already have and you keep control of who gets access.
  • Custom assistants. Built around the jobs you repeat — the monthly report, the standard memo, the checklist someone runs by hand.

The only outbound connection is to your own Microsoft or Google account, for sign-in. If the line drops, the AI keeps working, which is a small thing until the week your provider has an outage.

Illustration of a dedicated AI machine in an office with documents circulating inside the building and the cloud outside
One machine, one team, one clearly defined job. That is how a first deployment should look.

Start with one team, not the firm

Most practices should begin with a single team and one well-defined use — the contracts folder, the tender inbox, the month-end pack. Once that team is using it daily you know what to size the rollout for, and adding people becomes a configuration change rather than a second project.

It is a matter of weeks rather than months, and there is no server project for your IT person to inherit. That is deliberate: most firms this size do not have an IT person, they have a person who is good with computers and already has a job.

What it does to your paperwork

This is the part that tends to sell it, and it is worth being precise. No product makes a business GDPR-compliant, and anyone telling you otherwise is selling something. What running the model locally does is remove specific items from your assessment:

  • No third-party AI processor. Nothing to appoint, assess or review under Article 28 for the AI step.
  • No international transfer. The Chapter V questions — standard contractual clauses, transfer impact assessments — do not arise, because nothing crosses a border.
  • A shorter Article 30 record. One fewer processor and one fewer transfer to describe and keep current each year.
  • Erasure means erasure. Deletion follows the retention policy you already have, because there is no third-party copy to chase.

You remain the data controller throughout. We act as a processor only for the support access you grant us, and we will sign a data processing agreement covering exactly that. Bring your DPO or your advisers to the call — those are the questions we would rather answer early than late.

And to be plain about where this does not fit: if what you want is phone answering, inbox triage or lead follow-up, our cloud Email Manager and the other hosted agents are faster to set up and cost less. Local AI earns its keep on document-heavy, confidential work. Both are good answers to different questions, which is why we sell both. Our own privacy policy sets out how we handle data on the cloud side.

Need Help with AI Solutions?

Get in touch with our team or try our AI assistant.

ChatGPT and Confidential Information: Frequently Asked Questions

Is ChatGPT safe?

Safe for what is the better question. For general questions, drafting and learning, it is as safe as any well-run cloud service. For confidential client material it depends entirely on the tier and the account: free and Plus inputs may be used to train models by default, and a personal account sits outside whatever controls your business has.

Is ChatGPT confidential?

Not by default on the consumer tiers. On Team, Enterprise and the API, OpenAI does not train on your content and will sign a data processing agreement, which makes it contractually confidential. It is still processed on OpenAI's servers, so confidential is a promise you are relying on rather than a physical fact.

Is ChatGPT safe to use for work?

Yes, on a business tier, with a written policy saying which categories of material may go into it. The risk in most small firms is not the tool but the account: staff signed in with personal logins, on the free tier, with no record of what was sent.

Is ChatGPT safe for privacy?

Your conversations are transmitted to and retained by OpenAI on every tier, including the business ones, and a limited number of authorised staff can access them for abuse investigation and legal compliance. That is normal for a cloud service. It is only a privacy problem when the content is material you are not free to send anywhere.

Does ChatGPT train on my business data?

On the free and Plus tiers it may, unless you turn training off in the data controls. On ChatGPT Team, Enterprise, Edu and the API platform, OpenAI does not use your inputs or outputs to train models by default. The default is what matters, because defaults are what staff actually use.

Is putting client data into ChatGPT a GDPR breach?

It can be. Article 4(12) defines a personal data breach as unauthorised disclosure of or access to personal data. Sending a client file to a processor you never appointed, assessed or contracted with is an unauthorised disclosure, whether or not anything bad then happens to it.

Does ChatGPT Enterprise make us GDPR compliant?

No product makes you compliant. Enterprise gives you the pieces you need: a data processing agreement under Article 28, no training on your content, and audit logs. You still have to appoint the processor properly, justify the transfer, update your Article 30 record and be able to honour erasure requests.

What is the safest way to use AI on confidential documents?

Run the model on hardware you own. If the document never leaves the building there is no third-party processor to appoint for the AI step and no international transfer to justify, and deletion follows the retention policy you already have. You trade a little capability and speed for that.

So what should you actually do?

Start by finding out what is already happening. Ask your team, without any threat attached, what they have been using and on which login. You will almost certainly discover more usage than you expected, on more personal accounts than you expected, and that is the useful baseline — not a disciplinary matter.

Then match the fix to the material. Commercial-but-not-personal information: a business tier and a short policy will do. Client files held under a professional duty, or anything that would embarrass you in a regulator's letter: put the model where the files already are.

Back in that practice on the Tuesday, the senior with eleven minutes still gets her summary. She gets it in about the same time, from a machine in the room next door, and nobody has to have a conversation afterwards about what left the building. The deadline was never the problem. The route was.

If you want to talk through which of the four options fits your firm, book a Local AI consultation — I read every enquiry myself — or open the chat on this page and ask it something awkward. That one is a cloud agent, and we will tell you exactly what it does with what you type.