Is Our Company Data Safe If Employees Use ChatGPT?

Quote Card Reading &Quot;It Is Not A Technology Question. It Is A Contract Question.&Quot; By Thomas Anglero, Strategic Ai Advisor
The risk is the personal account, not the AI.

 

Your company data is safe if your people are on a business account. It is not safe if they are on personal ones, and that is where most companies are right now. The answer to this question is not a technology question. It is a contract question, and you can resolve it in a week.

The real risk is the personal account, not the AI

Here is the part almost nobody explains to leadership. On consumer tiers, the ones your employees pay for themselves, conversations are used to improve the models unless the user has gone into settings and switched it off. Compliance researchers describe personal consumer subscriptions as the dominant unmanaged risk in any organisation with knowledge workers, and it is not only about training. Free and personal paid tiers come with no data processing agreement, which means running client or employee personal data through them does not meet your obligations under GDPR in the first place.

Now connect that to the previous question every leader asks: your employees are already using AI, quietly, on those exact accounts. That is the breach risk. Not the model. The absence of a contract.

What changes on a business account

Move the same people onto business, team or enterprise tiers and the position reverses. The major providers contractually commit not to train on business customer content, a data processing agreement is included, retention becomes configurable, and you gain administrative visibility over who is using what. The work your people were doing anyway is now covered by an agreement your legal team can point to.

This is also why the budget structure matters. Paying for company seats instead of leaving people on personal plans is not only a cost-control decision. It is your data protection decision, made with the same signature.

If your data must stay in Europe, the choice narrows

Here is where it becomes concrete, and where I would tell any Nordic or European leader to pay attention. If you have promised clients that their information does not leave the EU, you must be able to prove it, and the providers differ significantly on this point.

OpenAI offers European data residency for ChatGPT Enterprise and for API projects, with in-region processing. Microsoft’s Azure OpenAI service allows you to route processing through EU regions under Microsoft’s existing agreements, which is often the smoothest path for organisations already inside that ecosystem. Anthropic’s Claude, on its own first-party business tiers, is hosted in the United States, with EU-region processing available through AWS Bedrock or Google Cloud Vertex AI rather than directly. None of this makes any provider unsafe. It means residency is a specific contractual feature you must ask for by name, and verify in writing, rather than assume.

Match the tier to the sensitivity. General knowledge work runs perfectly well on standard business seats. Client-confidential material, regulated data and anything you have made promises about belongs on the tier that gives you residency, zero retention and audit rights.

Two laws, two fines

Be precise about the exposure, because leaders routinely blur these. Data leaving the EU without a lawful basis is a GDPR matter, with penalties reaching EUR 20 million or 4 per cent of global turnover. The EU AI Act is a separate law with its own obligations and its own penalties, up to EUR 35 million or 7 per cent. They stack. That is the double loss: you lose control of the data, and you are fined for the failure that let it happen.

Communicate at every stage

The plan itself is straightforward, and the communication around it is what earns you the credit:

  • Proceed carefully. Decide the tiers and the residency requirement before rolling anything out.
  • Communicate before you start. Tell employees what is changing and why the company is paying for proper accounts instead of leaving them exposed on personal ones.
  • Communicate while you implement. Train people on what belongs in which tool.
  • Communicate to the market afterwards. Tell clients where their data lives and what protects it.

Very few companies have done this properly yet, which is precisely the opportunity. Do it and your board sees a leader who moved before being asked, your legal team gets an answer they can defend, your employees stop hiding, and your clients hear something most of their suppliers cannot say. That is one board question you never have to fear again.

Frequently asked questions

Is company data safe if employees use ChatGPT?

On a company business, team or enterprise account, yes: the major providers contractually commit not to train on business customer content and include a data processing agreement. On personal consumer accounts, no. Those conversations may be used for model improvement unless the user opts out, and they carry no processing agreement at all.

Does ChatGPT train on my company’s data?

Not on business and enterprise plans or the API, where providers contractually exclude training on customer content by default. Consumer tiers are different: personal subscriptions have historically defaulted to using conversations for model improvement unless the individual changes the setting.

Can I keep our AI data inside the EU?

Yes, but it is a specific contractual feature you must request and verify. European data residency is available on OpenAI’s enterprise and API offerings and through Azure OpenAI’s EU regions. Anthropic’s first-party business tiers are US-hosted, with EU-region processing available via AWS Bedrock or Google Vertex AI.

What are the fines if employee AI use breaches data rules?

Two separate regimes apply. GDPR penalties for unlawful processing or transfers reach EUR 20 million or 4 per cent of global turnover. The EU AI Act carries its own obligations with penalties up to EUR 35 million or 7 per cent. A single failure can trigger both.

Thomas Anglero is a Strategic AI Advisor, keynote speaker and author of Intro to Artificial Intelligence. He has delivered over 450 keynotes across 30 countries for organisations including IBM, the WHO, the World Government Summit and the European Commission. He founded the IBM Watson AI Lab for Cancer at the Oslo Cancer Cluster and closed over $500 million in enterprise transformation deals as CTO and Chief Innovation Officer at Cognizant.

If you are leading your organisation through this, I work with a limited number of senior leaders each quarter. Get in touch at Anglero.com.

Thomas Anglero
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.