Learnery
EN
Opening in September
All articles

What Not to Share With ChatGPT: A Data Safety Guide for Work

Key takeaways

  • Never paste customer personal data, credentials, contracts, unreleased financials, colleague data, or trade secrets into ChatGPT.
  • Consumer AI tools may retain inputs and use them for training, which creates GDPR and confidentiality exposure.
  • Safe alternatives: anonymize the text, use an approved business account, or ask before pasting anything sensitive.
  • Article 4 of the EU AI Act requires staff AI literacy; national authorities begin supervising the rules on 2 August 2026.

One careless paste can hand your company's private information to a system you do not control. So what should you not share with ChatGPT? Keep six things out of every consumer AI chat: customer personal data, credentials and keys, contracts, unreleased financials, colleague data, and trade secrets. Since 2 February 2025, Article 4 of the EU AI Act has also required employers to make sure staff can make exactly these judgment calls.

What should you never paste into ChatGPT?

Six categories of information should never enter ChatGPT or any other consumer AI chatbot. Each one carries its own distinct risk:

  • Customer personal data. Names, emails, phone numbers, order histories, complaint threads, payment or health details. Anything that identifies a real person is personal data under GDPR.
  • Credentials and keys. Passwords, API keys, access tokens, database connection strings, internal URLs. A pasted key is a copied key.
  • Contracts and legal documents. NDAs, supplier agreements, settlement terms, and anything a lawyer marked confidential. Summarizing a contract in a chatbot can itself breach that contract.
  • Unreleased financials. Revenue figures, forecasts, margins, board materials. If the number is not public yet, it does not belong in a public tool.
  • Colleague data. Salaries, performance reviews, medical notes, HR complaints. Your coworkers never consented to that processing.
  • Trade secrets. Source code, formulas, pricing models, product roadmaps, customer lists. These are the assets competitors would pay for.

A simple test covers all six categories: if you would not email it to a stranger, do not paste it into a chatbot.

Why is it risky to paste company data into ChatGPT?

Pasting company data into ChatGPT is risky for three reasons: the tool may keep it, data protection law may punish it, and your contracts may forbid it. Consumer versions of AI chatbots can retain conversations and, depending on account settings, use them to improve future models. Once text is submitted, you cannot reliably recall or delete it. So when someone asks whether it is safe to paste data into ChatGPT, the honest answer is: only when the data is public or fully anonymized.

The legal exposure is concrete. Under GDPR, feeding customer or colleague personal data into a third party tool is processing that needs a legal basis and appropriate safeguards. Confidentiality clauses in NDAs and employment contracts usually prohibit disclosing protected information to any outside party, and an AI provider is an outside party. None of this requires bad intent; a helpful employee summarizing a client email is enough.

The risk grows when staff use private accounts the company cannot see. That pattern, known as shadow AI at work, means sensitive data leaves the building through tools nobody approved, logged, or configured.

Which data belongs on the red list and which is on the green list?

The red list covers data that must never enter a consumer AI chat; the green list covers what is generally safe to type. Share this table with your team or turn it into a policy page.

Red list: never pasteGreen list: generally safe
A customer's name, email, or complaint threadAn anonymized scenario, such as a customer disputing a late delivery
Passwords, API keys, and access tokensThe text of an error message with identifiers removed
Signed contracts, NDAs, settlement termsA generic legal question, such as what an indemnity clause usually covers
Unreleased revenue, forecasts, board materialsFigures already published in your annual report
A colleague's salary or performance reviewA general HR question with no names attached
Source code, pricing models, product roadmapsPublicly documented code patterns and published product information

The green list assumes a consumer tool. An approved business account with data controls may safely handle more, but that is a decision for company policy, not for the individual at the keyboard.

What are the safe alternatives when a task involves sensitive data?

You can get AI help with almost any task without exposing sensitive data by building three habits: anonymize, use approved accounts, and ask first.

Anonymize before you paste. Replace names with placeholders like Customer A, strip emails and account numbers, round or remove financial figures, and generalize the situation. "A customer in Germany is disputing an invoice" gets you the same quality of answer as the real thread.

Use the account your company approved. Business tiers of AI tools typically offer stronger data controls than free consumer accounts. If your employer provides one, use it, and use only that account for work tasks.

Ask before pasting. When you are unsure, thirty seconds with your manager or data protection lead beats months of cleanup. Companies can remove the guesswork by publishing clear rules for everyone; a practical starting point is this AI usage policy template.

Does the EU AI Act require employees to know this?

Yes in practice. Article 4 of the EU AI Act (Regulation (EU) 2024/1689) has applied since 2 February 2025: providers and deployers of AI systems, including ordinary companies whose staff use tools like ChatGPT at work, must take measures to ensure sufficient AI literacy of their staff. There is no exemption for small businesses, and national authorities begin supervising and enforcing the rules on 2 August 2026.

Two nuances matter. First, the 2026 Digital Omnibus softened Article 4 into an obligation of effort, so companies must take appropriate measures to support the development of AI literacy rather than guarantee a result; the duty itself remains in force. Second, the European Commission's AI literacy Q&A states that instructions for use alone are not sufficient; training is the expected practical measure, and internal training records suffice as evidence (a certificate is convenient, never a legal mandate). Penalties are set by each Member State and must be proportionate, and there is no fixed curriculum or hour count; measures should match role, context, and risk. Knowing what not to share with ChatGPT is core AI data safety, exactly the kind of literacy regulators expect staff to have.

How do you train a whole team to make these calls?

The fastest way to make every employee fluent in ChatGPT data privacy at work is short, role specific training with a completion record. Learnery is a browser based AI training platform that certifies employees in around eight hours for 39 euros per seat as a one time payment. The seminar runs in twelve steps: steps 1 to 3 cover AI foundations, safe use at work (the material in this article), and everyday prompting, while steps 4 and 5 adapt to your industry and exact role. Learners practice on live AI in a prompt lab, and completion earns a certificate with a verifiable code anyone can check online, which doubles as your Article 4 training record.

Learnery covers 35 industries in six languages, and volume discounts start above 10 seats. If you want to see what eight hours of training is worth against the cost of one bad paste, run the numbers in the free ROI calculator or create an account and invite your team from the dashboard.

Frequently asked questions

Is it safe to paste customer data into ChatGPT?
No. Customer names, emails, order histories, and complaint threads are personal data under GDPR. Pasting them into a consumer ChatGPT account processes that data through a third party without clear safeguards, and the tool may retain the input. Anonymize the text first or use an approved business account with data controls.
Does ChatGPT use what I type to train its models?
Consumer AI chatbots may retain conversations and, depending on account settings, use them to improve future models. Business tiers typically offer stronger data controls. The safe assumption at work is that anything pasted into a personal account could persist, so treat every prompt as permanent and keep sensitive data out of it.
Can pasting data into ChatGPT violate GDPR?
Yes, it can. If a prompt contains personal data about customers or colleagues, you are processing that data through a third party provider. Without a legal basis, a processing agreement, and appropriate safeguards, that can breach GDPR. The simplest protection is to strip all names and identifiers before asking your question.
What is safe to share with ChatGPT at work?
Public information, generic questions, and fully anonymized scenarios are generally safe to share with ChatGPT. Examples include drafting a template email with placeholder names, explaining a concept, or rewriting text that contains no identifiers, secrets, or unreleased numbers. For tasks that need real data, use the tool your company approved.
Does the EU AI Act require companies to train staff on AI data safety?
In effect, yes. Article 4 of the EU AI Act has required providers and deployers to ensure sufficient AI literacy of staff since 2 February 2025, with no SME exemption. National authorities begin supervising the rules on 2 August 2026. Training is the expected measure, and internal records or certificates evidence it.

Ready to train your team on AI?

Over 8 hours per person, a certificate at the end, and pricing that fits every team size.

Opening in September Talk to sales

Keep reading

How to Train Employees on ChatGPT Without Boring Them AI Usage Policy Template: 9 Clauses and the Step Everyone Skips