You can put client data into ChatGPT. Whether you should is not decided by the training toggle, which is the only control most agencies check. On a personal ChatGPT account OpenAI is an independent controller of whatever you paste, not a vendor processing data on your instructions, and no data processing contract exists between you and OpenAI. The document that governs you is the one you signed with your client.
The training toggle is a fact about what the vendor does. Your client contract is a fact about what you are allowed to do. Only one of them has your signature on it.
The mistake: you audited the vendor and not yourself
Here is the sequence I watch play out in agency after agency. Someone asks whether it is safe to use AI on client work. A senior person opens Settings, finds the model training control, switches it off, and the question is treated as answered. I have sat in that meeting.
That control is real and it does something. It is also an answer to a different question from the one that was asked. Training describes what the vendor does with your text after it arrives. Your client contract decides whether the text was allowed to leave your building in the first place. Switching training off does not touch that second question, and the second question is the one you can be sued over.
We turned off model training, so client data is fine in ChatGPT now.
That setting describes what the vendor does after the data arrives. It says nothing about whether your client agreed the data could go there.
Open the client agreement. Find the confidentiality clause and the subprocessor clause. Read them before you open Settings.
If those clauses require written permission or a named list, no vendor setting can supply it for you.
What the toggle covers, and three places it leaks
Read the edges of that control. They are documented, and not where people assume.
Feedback is a channel the opt-out does not close. OpenAI's own wording: if you choose to provide feedback, the entire conversation associated with that feedback may be used to train its models. A thumbs up on a good answer submits the conversation that produced it. Anthropic's feedback path stores the whole related conversation too.
Temporary is only temporary while it stays temporary. OpenAI states that a Temporary Chat will not be used to improve its models while it remains temporary, and that if you save it, it becomes a regular chat and follows your account level data controls. The exemption belongs to the chat's status, not to the moment you started it.
It is per product, not per person. OpenAI says adjusting your settings in the ChatGPT interface will not affect your Sora settings.
The asymmetry nobody mentions: connector safe, clipboard not
This is the detail I have not seen written up anywhere, and it sits in plain sight in Anthropic's consumer privacy documentation.
Content Claude reads through a connector, described as raw content from connectors such as Google Drive, including remote and local MCP servers, is not included in the data used to improve its models. Then comes the clause: data may be included if it is directly copied into your conversation with Claude.
Same document. Same account. Same person. Two routes in, and the route decides the outcome. Connect the drive and the contract stays out. Open the file, select all, paste, and it is ordinary conversation content. The variable is the clipboard.
Two limits, because this gets overstated the moment it is repeated. It is a consumer tier rule, and it only bites if model training is switched on. Anthropic does not train on Claude for Work or API traffic by default, and OpenAI's Services Agreement commits in contract language that it will not use customer content to improve the services unless the customer agrees. The trap is the person doing client work in a personal account at 11pm.
The fork that decides how bad this is
There are two versions of this problem and most write ups only describe the milder one.
Version one, a business tier with a signed agreement. The vendor is processing on your instructions. That is the comfortable case, and it still carries a condition: your client's contract almost certainly required written permission first.
Version two, a personal account. The vendor is not processing on your instructions, because nothing is instructing it. OpenAI's European privacy policy says plainly that OpenAI Ireland is the controller and is responsible for the processing of your personal data. So the failure is not that you added a link to the chain without asking. It is that client data went to an independent company running its own purposes, with no processing contract in existence.
If you handle a client's California consumer data as their service provider, Civil Code section 1798.140(ag)(2) says what should have happened: a service provider that engages another person to assist in processing shall notify the business, and the engagement shall be pursuant to a written contract binding that person to the same requirements. A personal account gives you neither.
None of this depends on European law. Your master services agreement binds you in Ohio exactly as it does in Ireland. But if a client or their customers touch the EU or UK it stops being an analogy. Article 28(2) says the processor shall not engage another processor without prior specific or general written authorisation of the controller. And Article 28(10) is aimed at you rather than the vendor: a processor that infringes the Regulation by determining the purposes and means of processing shall be considered a controller for that processing. Route client data into an AI tool on your own initiative and you can step out of the processor role and into full controller liability.
A footnote that matters when you search your own paperwork: Article 28 never uses the word subprocessor. It says another processor. The ICO has to add the familiar word in brackets when it explains the rule, so searching your contracts for the word everyone says out loud can miss the clause that binds you. Some work carries a professional duty on top of the contract, which is why AI intake for law firms is a different build.
Three moves this week
Get client work off personal accounts
Move it to a business tier and execute the data processing agreement. OpenAI offers one for ChatGPT Business, Enterprise and the API, and Anthropic incorporates its own into its Commercial Terms so accepting those terms accepts the agreement. Neither covers a personal login, which is the whole point. This is the cheapest part of an AI automation programme and the part most teams skip.
Name the vendor to your client, in writing
Add it to your subprocessor list and send the notice. Under the California rule the notice and the written contract are both required, and under Article 28 a general authorisation still obliges you to tell the controller about intended additions and give them the opportunity to object. Notice is the cheap half of compliance and the half that gets forgotten.
Stop pasting, start plumbing
If the data reaches the model through an API call inside a workflow you control, it is not sitting in somebody's chat history, the retention is defined, and you can point at the exact step in an audit. Rebuilding a paste habit as a real automation usually takes less time than the meeting about whether pasting is allowed.
The bottom line
I want to be honest about the size of this, because the scary version sells better and it is not true. For most agencies reading this the exposure is contractual, not criminal. You are probably not facing a regulator. You are facing the confidentiality and subprocessor clauses in an agreement you signed, and a client who finds out during a security review that eighteen months of their customer data went through somebody's personal account.
The fix is cheap. Move to a business tier, execute the data processing agreement, add the vendor to your list, send one email. That is an afternoon and close to no money, which is why it is worth doing before a client asks, not during the conversation where they do. The skill was never knowing which toggle to flip. It is knowing which document governs, and that one is not published by the vendor.