Skip to content

Client Data in ChatGPT: You Are Reading the Wrong Document

You can put client data into ChatGPT. Whether you should is not decided by the training toggle, which is the only control most agencies check. On a personal ChatGPT account OpenAI is an independent controller of whatever you paste, not a vendor processing data on your instructions, and no data processing contract exists between you and OpenAI. The document that governs you is the one you signed with your client.

The training toggle is a fact about what the vendor does. Your client contract is a fact about what you are allowed to do. Only one of them has your signature on it.

The mistake: you audited the vendor and not yourself

Here is the sequence I watch play out in agency after agency. Someone asks whether it is safe to use AI on client work. A senior person opens Settings, finds the model training control, switches it off, and the question is treated as answered. I have sat in that meeting.

That control is real and it does something. It is also an answer to a different question from the one that was asked. Training describes what the vendor does with your text after it arrives. Your client contract decides whether the text was allowed to leave your building in the first place. Switching training off does not touch that second question, and the second question is the one you can be sued over.

The reflex

We turned off model training, so client data is fine in ChatGPT now.

That setting describes what the vendor does after the data arrives. It says nothing about whether your client agreed the data could go there.

The check first

Open the client agreement. Find the confidentiality clause and the subprocessor clause. Read them before you open Settings.

If those clauses require written permission or a named list, no vendor setting can supply it for you.

What the toggle covers, and three places it leaks

Read the edges of that control. They are documented, and not where people assume.

Feedback is a channel the opt-out does not close. OpenAI's own wording: if you choose to provide feedback, the entire conversation associated with that feedback may be used to train its models. A thumbs up on a good answer submits the conversation that produced it. Anthropic's feedback path stores the whole related conversation too.

Temporary is only temporary while it stays temporary. OpenAI states that a Temporary Chat will not be used to improve its models while it remains temporary, and that if you save it, it becomes a regular chat and follows your account level data controls. The exemption belongs to the chat's status, not to the moment you started it.

It is per product, not per person. OpenAI says adjusting your settings in the ChatGPT interface will not affect your Sora settings.

The asymmetry nobody mentions: connector safe, clipboard not

This is the detail I have not seen written up anywhere, and it sits in plain sight in Anthropic's consumer privacy documentation.

Content Claude reads through a connector, described as raw content from connectors such as Google Drive, including remote and local MCP servers, is not included in the data used to improve its models. Then comes the clause: data may be included if it is directly copied into your conversation with Claude.

Same document. Same account. Same person. Two routes in, and the route decides the outcome. Connect the drive and the contract stays out. Open the file, select all, paste, and it is ordinary conversation content. The variable is the clipboard.

Two limits, because this gets overstated the moment it is repeated. It is a consumer tier rule, and it only bites if model training is switched on. Anthropic does not train on Claude for Work or API traffic by default, and OpenAI's Services Agreement commits in contract language that it will not use customer content to improve the services unless the customer agrees. The trap is the person doing client work in a personal account at 11pm.

0 days
Consumer Claude retention if you decline model training
0 yrs
Retention on new or resumed chats if you allow it instead
0
Data processing agreements covering a personal account

The fork that decides how bad this is

There are two versions of this problem and most write ups only describe the milder one.

Version one, a business tier with a signed agreement. The vendor is processing on your instructions. That is the comfortable case, and it still carries a condition: your client's contract almost certainly required written permission first.

Version two, a personal account. The vendor is not processing on your instructions, because nothing is instructing it. OpenAI's European privacy policy says plainly that OpenAI Ireland is the controller and is responsible for the processing of your personal data. So the failure is not that you added a link to the chain without asking. It is that client data went to an independent company running its own purposes, with no processing contract in existence.

If you handle a client's California consumer data as their service provider, Civil Code section 1798.140(ag)(2) says what should have happened: a service provider that engages another person to assist in processing shall notify the business, and the engagement shall be pursuant to a written contract binding that person to the same requirements. A personal account gives you neither.

None of this depends on European law. Your master services agreement binds you in Ohio exactly as it does in Ireland. But if a client or their customers touch the EU or UK it stops being an analogy. Article 28(2) says the processor shall not engage another processor without prior specific or general written authorisation of the controller. And Article 28(10) is aimed at you rather than the vendor: a processor that infringes the Regulation by determining the purposes and means of processing shall be considered a controller for that processing. Route client data into an AI tool on your own initiative and you can step out of the processor role and into full controller liability.

A footnote that matters when you search your own paperwork: Article 28 never uses the word subprocessor. It says another processor. The ICO has to add the familiar word in brackets when it explains the rule, so searching your contracts for the word everyone says out loud can miss the clause that binds you. Some work carries a professional duty on top of the contract, which is why AI intake for law firms is a different build.

Three moves this week

01

Get client work off personal accounts

Move it to a business tier and execute the data processing agreement. OpenAI offers one for ChatGPT Business, Enterprise and the API, and Anthropic incorporates its own into its Commercial Terms so accepting those terms accepts the agreement. Neither covers a personal login, which is the whole point. This is the cheapest part of an AI automation programme and the part most teams skip.

02

Name the vendor to your client, in writing

Add it to your subprocessor list and send the notice. Under the California rule the notice and the written contract are both required, and under Article 28 a general authorisation still obliges you to tell the controller about intended additions and give them the opportunity to object. Notice is the cheap half of compliance and the half that gets forgotten.

03

Stop pasting, start plumbing

If the data reaches the model through an API call inside a workflow you control, it is not sitting in somebody's chat history, the retention is defined, and you can point at the exact step in an audit. Rebuilding a paste habit as a real automation usually takes less time than the meeting about whether pasting is allowed.

The bottom line

I want to be honest about the size of this, because the scary version sells better and it is not true. For most agencies reading this the exposure is contractual, not criminal. You are probably not facing a regulator. You are facing the confidentiality and subprocessor clauses in an agreement you signed, and a client who finds out during a security review that eighteen months of their customer data went through somebody's personal account.

The fix is cheap. Move to a business tier, execute the data processing agreement, add the vendor to your list, send one email. That is an afternoon and close to no money, which is why it is worth doing before a client asks, not during the conversation where they do. The skill was never knowing which toggle to flip. It is knowing which document governs, and that one is not published by the vendor.

Frequently Asked Questions

It depends entirely on which product you are in, and the difference is large. For consumer ChatGPT, OpenAI says the service improves by further training on the conversations people have with it unless you opt out, and the control is the Improve the model for everyone setting under Settings and then Data Controls. For ChatGPT Business, Enterprise and the API, OpenAI says it does not train on inputs or outputs by default, and its Services Agreement puts that in contract language. So the honest answer to a client asking this question is not yes or no, it is which account was used.
Safety and permission are two different questions and only one of them is about the vendor. A business tier under a signed data processing agreement is a defensible technical setup. It still does not answer whether your client agreed that a new company could receive their data, which is what your confidentiality and subprocessor clauses cover. Check the contract first, then the account type, then the settings, in that order. Reversing the order is how agencies end up technically careful and contractually exposed.
If you are handling personal information on their behalf, very probably yes, and in writing. California Civil Code section 1798.140(ag)(2) requires a service provider engaging another person to assist with processing to notify the business and to have a written contract binding that person to the same restrictions. Under GDPR Article 28(2) a processor cannot engage another processor without prior specific or general written authorisation, and on the general route you must inform the controller of intended additions and let them object. Beyond any statute, most master services agreements contain a confidentiality clause that requires it anyway.
No, and this is the most common mistake I see. Turning off training changes what the vendor does with the data once it has it. Compliance is mostly about whether the data was permitted to go there, who is contractually responsible for it, and whether you told the client. On a personal account there is no data processing agreement at all, so there is no contract to be compliant under. The toggle is a useful control sitting inside a question it cannot answer.

Using AI on client work without a subprocessor story

If you are running client data through AI tools and cannot say today which account, which agreement and which notice covers it, that is a fixable afternoon and worth fixing before a client asks. I will look at what you are actually doing and tell you the shortest route to a setup you can defend.

Book a 30-Minute Call

Or email [email protected].