Not on a free or personal plan. On those, the provider keeps your chats, may read them and may train its models on them, and you have no contract covering client data. On a business plan (ChatGPT Business or Enterprise, Copilot Chat signed in with your work account, Claude Team, Gemini in Google Workspace) your data isn't used for training and you get a data processing agreement. Even then, some data shouldn't go in at all.
Last checked 10 October 2026. AI providers change their terms often, so check the current terms before relying on them. This is general information, not legal advice.
The short answer
Is ChatGPT safe to use at work?#
It depends on which ChatGPT you mean. There are two very different products behind the same name.
Personal plans (Free, Go, Plus, Pro). You sign up with your own email. OpenAI is the controller of what you type: it decides what happens to it. By default your chats can be used to train future models; you can switch that off under Settings › Data controls › “Improve the model for everyone”, but giving a thumbs up or down still sends that chat for training. Chats are kept until you delete them, then removed within 30 days. OpenAI staff and contractors can read conversations for abuse checks and support. UK users of these plans contract with OpenAI's US company.
Business plans (Business, formerly Team; Enterprise; the API). Your business signs up. OpenAI acts as your processor under a data processing agreement (DPA), and doesn't train on your data unless you opt in. Admins control who has access, and on Business the workspace admins can view and export members' chats.
So the honest answer: a personal ChatGPT account is fine for public information and general questions, and not fine for client or personal data. A business plan is safe for most internal and client work, provided the client's contract allows it and you follow a few rules. The same split applies to Copilot, Claude and Gemini.
Turning off training on a personal account doesn't fix it. You still have no contract with the provider, reviewers may still read flagged chats, and your chats can be swept into legal disputes: a US court ordered OpenAI to preserve consumer chats during the New York Times case in 2025 (business Enterprise accounts were exempt). The UK's judicial AI guidance puts it bluntly: treat anything typed into a public chatbot as “published to all the world”.
Plan by plan
Which ChatGPT, Copilot, Claude or Gemini plan keeps your data private?#
Here is what each plan does with what you type, from the providers' own terms as of October 2026. “DPA” means the provider signs a data processing agreement and acts as your processor under UK GDPR.
| Plan | Trains on your chats? | Who can read them | Contract (DPA) | OK for client data? |
|---|---|---|---|---|
| ChatGPT Free / Go / Plus / Pro | Yes, unless you switch it off | OpenAI staff and contractors | No | No |
| ChatGPT Business | No | Your workspace admins; OpenAI for abuse checks | Yes | Yes, with the rules below |
| ChatGPT Enterprise | No | Limited, with your permission | Yes, plus UK data storage | Yes |
| Copilot with a personal Microsoft account | It can; check the privacy setting | Microsoft reviewers | No | No |
| Copilot Chat signed in with a work account | No | Not reviewed by Microsoft | Yes (Microsoft is processor) | Yes, with the rules below |
| Microsoft Copilot (paid add-on) | No | Not reviewed by Microsoft | Yes | Yes, once file permissions are tidy |
| Claude Free / Pro / Max | If “Help improve” is on | Flagged chats only | No | No |
| Claude Team / Enterprise | No | Flagged chats only | Yes (US storage) | Yes, with the rules below |
| Gemini with a personal Google account | Yes, by default | Human reviewers (kept up to 3 years) | No | No |
| Gemini in Google Workspace (Business Standard and above) | No | No human review | Yes (US or EU storage) | Yes, with the rules below |
Three things the table doesn't show:
- Price. Copilot Chat (work account) and Gemini in Workspace Business Standard come at no extra cost with those Microsoft 365 and Google Workspace plans. ChatGPT Business is £15 per user per month billed annually, or £18 monthly, for teams of 2 to 200. Claude Team is priced in US dollars at the time of writing: $20 per user per month billed annually ($25 monthly), about £15 (£19) at the October 2026 exchange rate, plus tax, with a two-seat minimum. Microsoft's paid Copilot Business add-on is £16.10 per user per month on an annual plan (ex VAT). For comparison, ChatGPT Plus, a personal plan, is £20 a month including VAT.
- “Business” doesn't mean “in the UK”. UK data storage is only offered on ChatGPT Enterprise and OpenAI's API. Claude stores data in the US, and Google Workspace offers US or EU regions. That's usually lawful with the right transfer safeguards, which the providers' DPAs set out, but some client contracts require UK hosting.
- Web searches leave the contract. When Copilot searches the web, the query goes to Bing, where Microsoft is not acting as your processor. Your IT provider can switch web search off if that matters.
Which AI has the most privacy? None of the brands is private by default on a personal plan, and all four are reasonable on a business plan. The best option for most UK small firms is the one you already pay for: Copilot Chat if you're on Microsoft 365, Gemini if you're on Google Workspace.
Copilot vs ChatGPT
Is Copilot more secure than ChatGPT?#
Not automatically. It depends on how you sign in.
Copilot Chat with your work account (look for the green shield and “enterprise data protection”) is covered by your existing Microsoft contract. Prompts aren't used to train models, chats are stored in your own Microsoft 365 tenant, your retention rules apply, and Microsoft has opted it out of human abuse review. For a Microsoft 365 business, that makes it the easiest safe default: no new supplier, no new contract, no extra cost.
Copilot with a personal Microsoft account is a consumer product, much like free ChatGPT. Staff who use it for work data are in the same position as staff pasting into personal ChatGPT.
The paid Microsoft Copilot add-on adds a different risk. It can read everything the user can open in SharePoint, OneDrive, Teams and email. If your file permissions are loose (the “everyone in the company” share from 2019 that holds the payroll export), Copilot will find it and summarise it for whoever asks. Tidy permissions before you switch it on. Your IT provider can run a sharing review and use Microsoft Purview to keep labelled files out of Copilot.
ChatGPT Business is a sound choice if you're not a Microsoft shop or your team prefers it. Note that it has no UK data storage and its apps (connections to Google Drive, email and so on) are on by default, so ask whoever runs it to switch off the ones you don't use.
Sort information into three colours before it goes anywhere near an AI tool. If you're not sure which colour something is, treat it as red.
| Colour | What it covers | Examples | Where it can go |
|---|---|---|---|
| Green | Public or harmless | Your published website copy, a general how-to question, an anonymised example, a blank template | Any approved tool |
| Amber | Internal or client business information | Quotes and pricing, supplier rates, internal process notes, client company names and business emails, draft proposals | Approved business plans only, signed in with a work account |
| Red | Personal, sensitive or contractually protected | Payroll exports, bank and sort-code details, National Insurance numbers, HR and sickness notes, health information, passwords and API keys, client source code, anything under an NDA, unreleased accounts or results | Not in AI, unless the policy owner has approved it in writing for a specific tool and the client contract allows it |
For accountants and bookkeepers: client payroll files, HMRC correspondence, bank statements and anything with a UTR or NI number are red. The tax professional bodies' joint guidance (January 2026) says putting client data into publicly available AI tools “is likely to constitute a breach of client confidentiality, unless the client has consented”, and suggests a line about AI use in your engagement letter. Treat AI output like work from “a less experienced junior colleague”: useful, but checked. More on this in AI for accountants.
For IT providers and MSPs: passwords, API keys, firewall configs, client tenant details and logs pasted from support tickets are red. Logs are the easy one to miss: they're full of usernames, IP addresses and email addresses.
A quick test before pasting anything: would you be comfortable if this appeared in a stranger's chat history? Would the client be? If not, it's not green.
Removing names first helps but isn't a free pass. A client can often be identified from details alone (“the only scaffolding firm in a small market town”), and the ICO is clear that pseudonymised data is still personal data.
Safer alternatives
If the answer is no, what can you use instead?#
Telling staff “don't use ChatGPT for that” without offering anything else just moves the problem out of sight. The NCSC's guidance on unapproved AI (September 2026) is clear that bans drive it underground, and that you should give people an approved, secure alternative. Here are the options, roughly in order of effort.
- Use the business plan you already pay for. Copilot Chat with a work account (Microsoft 365) or Gemini in Workspace (Business Standard and above). Setup takes minutes: tell everyone which account to sign in with, and have your IT provider block personal-account sign-ins if you want to enforce it. Good for amber data.
- Buy a business plan. ChatGPT Business (£15 per user per month billed annually) or Claude Team (about £15 at current exchange rates; priced in dollars). An hour or two to set up, including switching off apps and connectors you don't need. Good for amber data, and red data only where the client contract allows and you've done a DPIA (see the law section).
- Remove the sensitive parts first. Replace names, numbers and identifying details with placeholders, ask the question, then put the details back into the answer yourself. Free, and fine for lots of drafting work. It reduces risk rather than removing it, because redaction tools miss things.
- Have your IT provider stop the leaks. Microsoft Purview with Edge for Business, or Chrome Enterprise Premium, can block pastes and uploads into personal AI sites while allowing your approved tool. It needs managed devices, and is the backstop behind everything else here.
- Run AI under your own cloud contract in the UK. AWS Bedrock in London, or Azure AI in UK South, with a simple chat front end. Prompts aren't used for training, and Bedrock stores no prompts by default. This needs an IT provider or developer to set up, plus running costs from tens to a few hundred pounds a month depending on the model and usage.
- Run a model on your own computer. Tools like LM Studio or Ollama keep everything on the device. Fine for one or two people working on sensitive text with a well-specced laptop; the answers are noticeably weaker than the big cloud models. (If you use Ollama, switch off its cloud models, which run on its servers.)
- Connect AI to your systems through a controlled link instead of copying and pasting. For a task that repeats (answering questions from your job records, CRM or accounts), a small tool can give the AI read-only access to just the data it needs, with a log of what it looked at. Worth it for repeated, data-heavy work; overkill for occasional drafting. Our free guide to connecting AI to your business safely covers how to set this up.
- Don't use AI for it. The right answer for health and other special category data by default, and wherever a client contract says no third parties.
| Type of data | Personal AI account | Business AI plan | Own cloud or controlled tool | Model on your own computer |
|---|---|---|---|---|
| Public | Yes | Yes | Yes | Yes |
| Internal business information | Avoid | Yes | Yes | Yes |
| Confidential client information | No | If the client contract allows | Yes | Yes |
| Personal data (names, contact details) | No | Yes, with a DPIA screening | Yes, with a DPIA screening | Yes |
| Payroll, health, special category | No | Only after a DPIA | Only after a DPIA | Best AI option, or don't use AI |
| Source code and trade secrets | No | Enterprise plans only | Yes | Yes |
| Passwords and access keys | Never | Never | Never | Never |
It's happened
What to do if someone has already pasted confidential data into ChatGPT#
It happens. What matters is what you do in the next hour.
- Don't panic and don't hide it. Tell the person who reported it they did the right thing. A policy that punishes honest reporting gets you fewer reports, not fewer mistakes.
- Delete the chat and, on a personal account, switch off training. Deleted chats are removed within about 30 days on most services.
- Write down what was shared, which tool and plan, which account, and when.
- Tell the policy owner the same day (the template below says within 24 hours).
- Decide whether it's a personal data breach. If personal data went into a personal or consumer account, it is likely to count as an unauthorised disclosure. Every breach must be recorded internally. You must report it to the ICO within 72 hours of becoming aware only if it's likely to put people at risk, and tell the people affected if the risk is high. Sensitivity, volume, and whether training was on all count. If in doubt, take advice.
- Check client contracts and NDAs for a duty to notify the client.
- Change any passwords or keys that were pasted, straight away.
- Fix the cause. Usually it's that the approved tool was harder to reach than the personal one.
The law
Do you need an AI policy? What UK law says#
No law says “you must have an AI policy”. But several laws apply to what staff type into AI tools, and a short written policy plus training is your evidence that you took reasonable steps. There is no single UK AI Act, and none was announced in the May 2026 King's Speech. These are the rules that bite:
- UK GDPR and the Data Protection Act 2018. Pasting personal data into AI is processing, and your business is responsible for it. You need a lawful reason, you should only use the personal data you need, and a new AI tool handling personal data belongs in your privacy notice and records. The ICO says that “in the vast majority of cases” using AI involves processing likely to be high risk, which means a data protection impact assessment (DPIA). For low-risk uses, a short written screening decision is enough.
- The Data (Use and Access) Act 2025. Its main changes took effect on 5 February 2026. Automated decisions about people (for example, AI shortlisting CVs) are now allowed for ordinary personal data, but only with safeguards: tell the person, let them challenge it, and give them a human review. Since 19 June 2026 you also need a way for people to complain about how you use their data. The ICO became the Information Commission on 30 September 2026.
- Confidentiality. Client contracts, NDAs and the common-law duty of confidence apply whatever tool you use. A business AI plan doesn't automatically satisfy a contract that says “no disclosure to third parties”. In 2026 the Upper Tribunal said that uploading a client's documents into ChatGPT breached confidentiality and could waive legal privilege.
- Professional rules. If you're regulated, your body's rules come on top. The tax bodies' joint AI guidance (January 2026) and ICAEW both treat client data in public AI tools as a likely confidentiality breach. The SRA warned solicitors about AI misuse in August 2026. RICS members have had a mandatory AI standard since March 2026, requiring written client consent before confidential data goes into AI.
- Employment law. You're usually responsible for what staff do with AI in the course of their work. If you monitor AI use, you must tell staff. AI used in hiring or HR decisions must not discriminate under the Equality Act 2010.
- Accuracy. Using AI doesn't lower the standard of care you owe clients. UK courts have already dealt with fake AI-generated case citations (Ayinde v Haringey, 2025). The CMA says you're responsible for what an AI agent tells customers, just as you would be for an employee.
- The EU AI Act. It doesn't cover a UK firm using AI internally for UK work. It can apply if AI output is used in the EU, for example a chatbot serving EU customers. Its rules for high-risk uses such as recruitment have been pushed back to December 2027.
One more reason to keep it simple: the government consulted on an “AI Management Essentials” tool for businesses, and dropped it in 2026 after small firms said they wanted plain templates instead. That's what the template below is.
The essentials
What should an AI policy include?#
For a business of 5–100 people, a useful AI policy covers these points and fits on a few pages:
- Who it applies to, and who owns it
- Which tools are approved, on which plan, signed in how
- What information can go into which tool (the traffic light)
- Client confidentiality and contracts
- Personal data and when to do a DPIA
- Checking AI output before anyone relies on it
- Being open with clients and customers about AI
- No AI-only decisions about people
- Intellectual property and trade secrets
- Security: accounts, connectors, meeting notetakers, browser extensions, leavers
- What to do when something goes wrong
- Training, monitoring, and how often you review it
What to skip: AI governance boards, bias-audit programmes and risk-scoring frameworks. They appear in templates written for large companies and will stop a small firm from ever finishing the policy.
Copy and adapt
Free AI policy template for UK small businesses#
Download the AI policy template as a Word document (free, no sign-up), or copy the template below into a document. Replace the [square-bracket] parts and delete anything that doesn't apply. It has four parts: a one-page version for everyone to read, the full policy, an approved-tools register, and a staff acknowledgement. Free to use and adapt. It's a starting point, so take legal advice if you're regulated or handle sensitive data at scale.
Part 2: AI acceptable use policy
[Company name]: Artificial intelligence (AI) use policy
Version [1.0] · Approved by [name, role] on [date] · Next review: [date, six months on] · Policy owner: [name, role]
1. Purpose. We want everyone to use AI tools where they save time and improve our work, without putting client, staff or company information at risk. This policy says which tools to use, what can go into them, and what to do when something goes wrong.
2. Who this applies to. All employees, contractors, temporary staff and anyone working on our behalf, on any device, including personal devices used for work. It covers chat assistants (such as ChatGPT, Copilot, Claude and Gemini), AI features inside other software, AI meeting notetakers, AI browser extensions, and AI agents that can act in our systems.
3. Ownership and review. [Policy owner] owns this policy, keeps the approved-tools register up to date, and is the contact for questions and incidents. We review the policy at least every six months, and sooner if a provider changes its terms, the law changes, or we start using AI in a new way. This policy is not part of your contract of employment and we may update it at any time.
4. Approved tools. Use only the tools and plans listed in the approved-tools register, signed in with your work account. Do not use personal AI accounts (free or paid) for any work information. To request a new tool, ask [policy owner], who will check: (a) whether the provider uses our data for training; (b) whether it signs a data processing agreement; (c) where data is stored; (d) who at the provider can see it; and (e) what admin controls we get.
5. What can go into AI tools. Classify information before using it:
Green, public or harmless information: any approved tool.
Amber, internal or client business information (quotes, pricing, supplier rates, internal documents, client business contact details): approved business tools only.
Red, personal data beyond basic business contact details, special category data (health, ethnicity, religion and similar), payroll, bank and card details, National Insurance numbers, passwords and access keys, source code, trade secrets, unreleased financial results, and anything covered by an NDA or a client contract restricting disclosure: not to be entered into any AI tool unless [policy owner] has approved that use in writing for a named tool.
If you are unsure, treat information as red and ask.
6. Client confidentiality. Before using AI on client work, check that the client's contract, engagement letter or NDA allows it. Where it doesn't, or where it requires consent, get the client's consent in writing first. [If you are regulated: our professional body's rules on confidentiality and AI also apply, including [ICAEW / ACCA / AAT / SRA / RICS] guidance.] Our client terms explain how we use AI tools.
7. Personal data. Only use the minimum personal data needed, and remove names and identifying details where you can (bearing in mind that people can often be identified from other details). Before we use AI in a new way that involves personal data, [policy owner] will carry out a data protection screening and, where the risk is high, a data protection impact assessment (DPIA). We keep our privacy notice and records of processing up to date with the AI tools we use.
8. Checking AI output. AI tools can produce confident, wrong answers. Treat output as a first draft from a junior colleague. Check facts, figures, calculations, quotes, legal or tax references and citations against a reliable source before using them. A named person is responsible for every piece of work that goes to a client or is published, whether or not AI helped.
9. Being open about AI. Tell clients how we use AI where it affects their work. Customer-facing chatbots or AI agents must say they are AI and offer a way to reach a person. Never use AI to write fake reviews or testimonials. Label AI-generated images, audio or video where people could be misled. If AI output will be used for customers, staff or markets in the EU, check with [policy owner] first.
10. Decisions about people. AI must not make decisions about people on its own, including recruitment, pay, performance, discipline, dismissal, credit or individual pricing. A person must review and be able to change any AI-assisted decision before it takes effect. Any use of AI in recruitment or HR must be approved by [policy owner] and checked for fairness under the Equality Act 2010. We do not use AI tools that claim to detect emotions in staff.
11. Intellectual property. Do not enter trade secrets, source code, pricing models or unreleased plans into anything other than an approved tool cleared for red data. Check AI output for content that could belong to someone else (text, images, logos, code) before using it externally. Work that we need to own and protect, such as brand assets, must involve real human authorship.
12. Security. Use multi-factor authentication on every AI account. Do not connect AI tools to email, files, calendars or other systems, install AI browser extensions, or invite AI notetakers to meetings without approval from [policy owner]. Approved connections get the least access needed. Be aware that content an AI tool reads (an email, a web page, a document) can contain hidden instructions, so don't let AI act on untrusted content without checking. When someone leaves, we remove their access to company AI accounts, and they must not keep company information in any AI account.
13. When something goes wrong. If you put information into an AI tool that you shouldn't have, or AI produces something harmful or wrong that has been relied on, tell [policy owner] as soon as possible and within 24 hours. Reporting promptly will not, by itself, lead to disciplinary action. [Policy owner] will: delete the content where possible; record what happened; decide whether it is a personal data breach and, if it is likely to put people at risk, report it to the ICO within 72 hours of becoming aware; check whether any client must be told; change any exposed passwords or keys; and fix the cause.
14. Training. Everyone completes our AI training before getting access to approved tools, and a refresher every year. We keep a record of who has completed it.
15. Monitoring. [Our approved AI tools keep logs of use, which [policy owner / IT provider] can review to keep our information secure and check this policy is followed.] [Delete if you don't monitor.]
16. Breaking this policy. Breaches may be dealt with under our disciplinary procedure. Deliberately putting red information into a personal AI account, or hiding a mistake, may be treated as serious misconduct.
Part 3: approved-tools register (an example; replace with your own)
| Tool and plan | Sign in with | Approved for | Notes |
|---|---|---|---|
| Microsoft Copilot Chat | Work Microsoft 365 account only | Green and amber | Check for the shield icon (enterprise data protection) |
| [ChatGPT Business] | Work email via the company workspace | Green and amber | Unused apps and connectors switched off |
| [Tool approved for red data, if any] | [ ] | Red: [named uses only] | Written approval [date, by whom] |
| Any personal AI account (ChatGPT, Claude, Gemini, Copilot) | n/a | Not approved for any work information | |
| AI meeting notetakers | n/a | Only with approval and attendees told | |
| AI browser extensions | n/a | Not approved unless listed here |
Putting it in place
How to roll out an AI policy in a week#
- Day 1: pick the owner and the tool. One named person, not a committee. Choose the approved tool, ideally the business plan you already pay for.
- Day 2: fill in the template. Replace the brackets, delete what doesn't apply, and fill in the register. If you're regulated, add your professional body's rules.
- Day 3: check client terms. Look at your standard engagement letter or terms and your biggest clients' contracts for anything about third parties or AI, and add a short line about how you use AI.
- Day 4: switch things on and off. With your IT provider: approved tool on, unused connectors off, multi-factor authentication on, personal-account blocking if you want it.
- Day 5: 30 minutes with the team. Walk through the one-pager with three real examples from your own work (one green, one amber, one red), then collect signed acknowledgements.
Then put the review date in the diary. AI terms change fast: Anthropic changed its consumer training rules in 2025, and Microsoft renamed its Copilot products in 2026.
Frequently asked questions
Can employees use ChatGPT under UK GDPR?
Yes, for work that doesn't involve personal data, and on a business plan for work that does. Your business is responsible for the personal data staff put in, so it needs a lawful reason, should use only what's necessary, and should use a tool with a data processing agreement. Personal ChatGPT accounts don't have one.
Does turning off training make ChatGPT safe for client data?
No. It stops your chats being used for training, but you still have no contract with the provider, flagged chats can still be read, and the data still leaves your control. For client or personal data, use a business plan.
Is ChatGPT Business enough for confidential client data?
For most client work, yes: OpenAI doesn't train on it and signs a data processing agreement. Check the client's contract first, because some forbid third-party processing or require UK hosting, which Business doesn't offer. Keep red data (payroll, health, credentials) out unless you've done a DPIA and approved it.
Do we need a data protection impact assessment (DPIA) for AI?
If AI will process personal data in a way that's likely to be high risk, yes, and the ICO says most AI use involving personal data is. For low-risk uses, such as drafting a generic email with no personal data, write down a short screening decision instead.
Does the EU AI Act apply to UK small businesses?
Not to a UK firm using AI internally for UK work. It can apply if your AI output is used in the EU, for example a chatbot serving EU customers, or AI used on EU-based staff or job applicants.
Is an AI policy the same as an acceptable use policy?
An AI policy is usually a type of acceptable use policy focused on AI tools. Small firms can add it as a section of their existing IT or acceptable use policy, as long as it names the approved tools and the data rules.
How often should we review our AI policy?
At least every six months, and whenever a provider changes its terms, you adopt a new tool, or the law changes. The ICO's new code on AI and automated decisions is expected in late 2026.
Keep reading
How much does bespoke software cost in the UK?
What bespoke software costs in the UK, what moves the price, what it costs to run, and when a per-user subscription is the cheaper choice. The sums are shown.
9 October 2026 ReadAI for business: a practical guide for UK small businesses
Your team is probably already using AI. Here's how to bring it under control, which assistant suits a UK SME, what it costs, and why the answers depend on the systems behind it.
6 October 2026 ReadBusiness process mapping: how to map a process in an afternoon (and spot what to automate)
A practical guide to business process mapping for UK SMEs: what it is, how to map a process in an afternoon, a worked example you can open as a flowchart, and how a clear map shows what to automate.
6 October 2026 Read