Skip to main content
Deliberate AcademyProfessional AI Education

What Data Can You Put Into ChatGPT at Work? A Practical Checklist

8 min readDeliberate Academy Editorial Team

Most guidance on this topic lands on the same vague instruction: "don't put sensitive data into AI tools." That is technically correct and almost entirely useless. Every professional working with AI needs a more specific answer, because the range of data you handle at work is wide — and so is the range of risk.

This article gives you a concrete framework: a category-by-category breakdown of what data is generally safe to use with AI tools, what is not, why each category carries its own specific risk, and a five-question test you can run before pasting anything into a chat window.

Key takeaways
  • Consumer AI tools (ChatGPT.com, Claude.ai) and enterprise versions carry fundamentally different data risk profiles
  • PII, client data, health records, and trade secrets are high-risk in any consumer AI tool
  • Publicly available information, anonymised data, and your own drafts are generally safe to work with
  • GDPR, HIPAA, and financial services regulations impose specific restrictions that apply regardless of your employer's internal policy
  • A five-question self-test can stop most data mistakes before they happen

The tool you are using changes the risk entirely

Before the data categories, one distinction matters more than any other: the difference between a consumer AI tool and an enterprise version.

Consumer AI tools — ChatGPT.com on a free or ChatGPT Plus account, Claude.ai on a personal account, Google Gemini without a Workspace agreement — process your inputs through the provider's systems under consumer terms of service. Depending on your settings, inputs may be used to improve the model. Even where training opt-outs exist, your data has still left your organisation's environment.

Enterprise versions — ChatGPT Enterprise, Microsoft Copilot integrated into your organisation's Microsoft 365 tenancy, Claude for Enterprise, Google Gemini for Workspace — operate under separate data processing agreements negotiated at the organisation level. These agreements typically include commitments that your data will not be used for model training, specify data retention limits, and establish who can access what.

The same data that is high-risk to paste into ChatGPT.com may be entirely acceptable to process through ChatGPT Enterprise or Microsoft Copilot — if your organisation has the appropriate agreements in place.

Note

If you are not sure which version you are using, check with your IT or compliance team before proceeding. Accessing ChatGPT through a browser at chatgpt.com — even if your employer pays for it — is not the same as ChatGPT Enterprise. Enterprise deployments are typically provided through a separate URL or a company-managed account.

Data category checklist

Off-limits: personally identifiable information (PII)

PII includes names, addresses, email addresses, national identification numbers, passport numbers, dates of birth, phone numbers, and any combination of attributes that could identify a specific individual.

Inputting PII into a consumer AI tool is a data protection risk in most jurisdictions. Under GDPR, processing personal data requires a lawful basis, and sending it to a third-party AI provider without a data processing agreement in place will not satisfy that requirement. In the UK, the ICO has been explicit that organisations using AI tools must ensure appropriate safeguards are in place before personal data enters those systems.

Practical example: An HR manager copy-pasting a spreadsheet of employee names, salaries, and performance ratings into ChatGPT to ask for analysis is not a grey area — it is a data protection breach under GDPR, regardless of whether the data ends up in a training set.

Safe alternative: Anonymise the data first. Replace real names with labels (Employee A, Employee B), remove identifying numbers, and strip any field that is not needed for the analysis you are trying to run.

Off-limits: client and customer data

Client data includes client names, contact details, contract terms, usage data, behavioural data, and any information provided by a client in the course of a business relationship.

Most business contracts include confidentiality clauses. Many include explicit data handling requirements. Entering a client's data into a consumer AI tool without the client's knowledge or consent — and without your organisation having a data processing agreement with the AI provider — is likely a breach of your contract with that client, not just an internal policy issue.

For marketing agencies, law firms, accountancies, and consultancies in particular, client data is the core of the trust relationship. A single incident of client data appearing in an AI context is a relationship-ending event.

Safe alternative: Describe the scenario without naming the client or including identifying details. "We have a manufacturing client with three regional warehouses who wants to consolidate logistics" gives an AI enough context to help without exposing client identity.

Off-limits: health and medical data

Health data is among the most protected categories in every major regulatory framework.

In the United States, HIPAA (the Health Insurance Portability and Accountability Act) imposes strict requirements on how protected health information (PHI) is handled, transmitted, and stored. Using a consumer AI tool to process PHI — patient records, diagnoses, treatment histories, prescription data — is a HIPAA violation. Healthcare organisations using AI must ensure that any AI tool they use has signed a Business Associate Agreement (BAA) with them. Most consumer AI tools have not done this.

Under GDPR, health data is a "special category" that requires explicit consent and specific safeguards before it can be processed. The bar for sharing health data with any third party is materially higher than for standard personal data.

Practical example: A practice manager who pastes a list of patients and their appointment types into an AI scheduling tool has created a potential HIPAA violation, regardless of whether the intent was administrative efficiency.

Off-limits: trade secrets and proprietary strategy

Trade secrets — product roadmaps, pricing models, acquisition targets, unreleased research, formulas, proprietary processes — represent competitive advantage. Their value depends on them remaining confidential.

Sending trade secrets into a consumer AI tool creates risk on two fronts: the data leaves your organisation's control, and depending on the provider's terms and your account settings, it may be retained or reviewed. The legal protection afforded to trade secrets under laws like the US Defend Trade Secrets Act (DTSA) or the EU Trade Secrets Directive can be weakened or lost if reasonable steps are not taken to maintain secrecy.

Practical example: A product manager drafting a competitive strategy document for a new product launch and using ChatGPT to refine the strategy is sharing details about product plans, target markets, and competitive positioning — all potentially qualifying as trade secrets — with a third-party provider.

Off-limits: financial records and non-public financial information

Analysts, finance professionals, and executives often have access to non-public financial information: quarterly results before announcement, M&A discussions, investor data, internal forecasts.

In regulated financial markets, using or disclosing material non-public information (MNPI) is subject to securities law. Entering MNPI into a consumer AI tool is a potential regulatory breach regardless of the output you are trying to generate. Even without MNPI concerns, detailed internal financial data entering a consumer AI tool creates audit trail and data governance problems.

Practical example: A financial analyst asking ChatGPT to help draft commentary on unpublished quarterly results, including actual figures, has created a securities compliance issue.

For finance professionals, the AI Strategy for Leaders course covers how to think about AI governance and data risk at an organisational level.

Proceed with caution: internal documents and communications

Internal emails, meeting notes, strategy presentations, and policy documents occupy a middle ground. They are not client data, and they may not contain PII, health data, or trade secrets — but they are still internal to your organisation and may be subject to confidentiality obligations.

The key question is whether the document contains any of the higher-risk categories above. A meeting agenda is low risk. A board presentation discussing an acquisition is not.

The practical approach: before pasting an internal document into any AI tool, review it for PII, client references, financial figures, and strategic information. Strip or redact those elements before proceeding.

Generally safe: publicly available information

Information that is already publicly available — news articles, published research, publicly filed documents, product descriptions from public websites — carries no additional risk when used with AI tools. You are not creating any new disclosure by processing public information.

This is a wide and productive category. Using AI to summarise industry reports, analyse competitor positioning from public sources, or synthesise published research is low-risk and high-value.

Generally safe: your own drafts and thinking

Drafts of documents you are creating — provided they do not contain the higher-risk data categories — are generally safe to work with. If you are drafting a proposal for a client and the draft does not include the client's name, proprietary data, or sensitive financial information, using AI to improve the structure and language is a low-risk task.

The same applies to your own analysis, notes, and thinking. Working through a framework, developing an argument, or testing an approach with AI as a thinking partner creates limited data risk if the content is your own.

Tip

A useful working habit: create a "scrubbed" version of any document before using AI on it. Remove names, specific figures, client identifiers, and strategic details, replacing them with neutral placeholders. You get the AI assistance you need, and no sensitive data leaves your organisation.

The five-question self-test

Before pasting any data into an AI tool at work, run through these five questions:

1. Does this data identify a real person? If yes, it is PII. Do not paste it into a consumer AI tool without first checking whether your organisation has an approved enterprise agreement that covers this data type.

2. Is this data confidential to a client or third party? If yes, check your contract and your organisation's AI policy before proceeding. When in doubt, anonymise before you act.

3. Am I in a regulated industry, and does this data fall under sector-specific rules? Healthcare professionals with patient data, financial professionals with MNPI, legal professionals with privileged information — all face additional obligations on top of standard data protection requirements.

4. Does this data give a competitor an advantage if it left my organisation? If yes, it is likely a trade secret or commercially sensitive. Treat it accordingly.

5. Am I using an enterprise-approved AI tool with appropriate data agreements? If you cannot confirm this, apply the most conservative interpretation: treat the tool as a consumer product and do not input anything that would not be safe in that context.

If you answer yes to any of questions 1–4 and no to question 5, stop. Anonymise the data or use an approved enterprise tool.

Warning

If your organisation does not have a published AI use policy, the absence of a policy is not permission to use AI without restriction. Apply your existing confidentiality, data protection, and professional conduct obligations as the baseline. The Samsung example — where employees pasted proprietary source code into ChatGPT, which then appeared in the training data — is a useful reminder that the consequences of getting this wrong are real and not reversible.

What good AI data hygiene looks like in practice

A marketing manager preparing a campaign brief can use AI to help structure the brief, improve the copy, and generate headline options — as long as they remove the client name and any proprietary client information from the document before sharing it with the tool.

An HR professional running a salary benchmarking exercise can use AI to analyse market data from published sources and help structure the analysis — but should not paste the internal salary spreadsheet, which contains employee names and individual pay data, into a consumer AI tool. If their organisation uses Microsoft Copilot under an appropriate data agreement, the risk calculation changes.

A finance analyst drafting a quarterly commentary can use AI to improve the writing, structure the narrative, and suggest clearer language — but should not include the actual unpublished figures until those figures are public.

The pattern is consistent: AI is most valuable as a thinking and drafting partner. The data risk is highest when you treat it as a data processing system.

For HR professionals who want a structured approach to AI use in people management contexts, the AI for HR and People Managers course covers the specific data handling considerations that apply to HR work, including what AI can and cannot appropriately do in recruitment, performance, and people analytics.

Regulatory overview: what you actually need to know

GDPR (EU and UK): Personal data of EU or UK residents requires a lawful basis for processing. Sending personal data to a third-party AI provider constitutes processing. Your organisation needs a Data Processing Agreement (DPA) with the AI provider before this is permissible. Most enterprise AI agreements include a DPA; consumer products do not.

HIPAA (US healthcare): Protected Health Information (PHI) cannot be shared with any third-party vendor that has not signed a Business Associate Agreement (BAA) with your organisation. No standard consumer AI product has done this. Assume all patient-related data is off-limits in consumer AI tools.

Financial services regulations: In the US, SEC and FINRA rules govern how non-public information is handled. MiFID II in the EU imposes similar requirements. Many financial institutions have internal policies that are more restrictive than the regulatory minimum. Check your firm's specific policies.

Sector-agnostic: Professional conduct rules for lawyers, accountants, and other regulated professionals typically include confidentiality obligations that apply to client data regardless of how it is processed. Using an AI tool does not suspend those obligations.

For a broader look at using AI responsibly at work — including how to build habits that keep you on the right side of policy and regulation — the article How to Use AI at Work Without Getting in Trouble covers the full professional risk landscape.

The line is not between AI and no AI. It is between AI use that is careful and AI use that is careless. Knowing exactly which data categories carry which risks is the foundation of getting that right.

Frequently asked questions

My employer pays for ChatGPT. Does that make it an enterprise tool?

Not necessarily, and this is the distinction that catches people out. Reaching ChatGPT through a browser at chatgpt.com is a consumer product under consumer terms even if your employer is paying the subscription. Enterprise deployments are normally provided through a separate URL or a company-managed account and sit under a negotiated data processing agreement. If you cannot tell which you are using, ask IT or compliance before proceeding.

Which data categories are simply off-limits in a consumer AI tool?

Five. Personally identifiable information; client and customer data; health and medical data; trade secrets and proprietary strategy; and non-public financial information. Each carries a distinct risk — data protection breach, contractual breach, HIPAA exposure, loss of trade secret protection, and securities compliance respectively — but the practical rule is the same for all five.

How do I use AI on data I am not allowed to paste?

Scrub it first. Replace real names with labels, remove identifying numbers, strip any field the analysis does not need, and describe a client scenario without naming the client. "A manufacturing client with three regional warehouses consolidating logistics" gives the model enough to work with and exposes nothing. Making a scrubbed copy a standing habit is more reliable than deciding case by case.

What is the five-question test before pasting anything?

Does this identify a real person; is it confidential to a client or third party; am I in a regulated industry where sector rules apply; would it advantage a competitor if it left the organisation; and am I on an enterprise-approved tool with the right agreements. If any of the first four is yes and the fifth is no, stop and either anonymise or switch tools.

Which uses are genuinely low risk?

Publicly available information and your own drafts and thinking. Summarising industry reports, analysing competitor positioning from public sources and synthesising published research create no new disclosure at all. Working through a framework or improving the language of a draft that contains none of the high-risk categories is similarly low risk, and this is where most of the day-to-day value sits.

What if my organisation has no AI policy at all?

The absence of a policy is not permission. Fall back on your existing confidentiality, data protection and professional conduct obligations as the baseline, and apply the most conservative reasonable reading of them. Professional conduct rules for lawyers, accountants and other regulated professionals are not suspended by the choice of tool.

Enjoyed this article?

Browse our free AI courses →