AI Security

Is ChatGPT Safe for Confidential Information? What Each Plan Does With Your Data

It depends on the plan. This explainer sets out what OpenAI states for Free, Plus, Business, Enterprise and the API on training, retention, admin controls and data residency, the risks that remain on every plan, and when a private deployment is the safer choice.

Is ChatGPT safe for confidential information? It depends on the plan. On Free, Go, Plus and Pro, conversations can be used to improve OpenAI models unless the user opts out, and the employer has no admin control. ChatGPT Business, Enterprise and the API exclude business data from training by default and add admin and contractual controls, but the data is still processed in OpenAI's cloud.

The short answer, plan by plan

OpenAI publishes its data terms across its plan comparison, its help centre and its enterprise privacy commitments. As of October 2026, they say:

PlanTraining on your contentRetentionAdmin and identityResidency and certifications
Free, Go, Plus, ProCan be used; each user can opt outDeleted chats removed within 30 days; temporary chats kept up to 30 days for safetyNothing for the employer; no SAML SSONo residency option; SOC 2 not listed for these plans
BusinessNot by defaultAdmins control retention; deleted chats removed within 30 daysSAML SSO, MFA and an admin console; no SCIM or RBACSOC 2 Type 2; a storage-region option is rolling out, and a non-US region still leaves a US copy for abuse monitoring
EnterpriseNot by defaultAdmins set retention; deleted chats removed within 30 daysSAML SSO, SCIM, RBAC, enterprise key management, IP allowlisting and a Compliance APIStorage in ten regions and inference residency in the EU, US and UAE; SOC 2 Type 2 and ISO 27001, 27017, 27018 and 27701
APINot by defaultUp to 30 days for abuse monitoring; zero data retention for eligible use casesYour application controls user accessResidency for eligible customers; SOC 2 Type 2; BAA possible with Modified Retention

Two caveats apply to every row. Plans and terms change often, so re-check them before you sign. And all of this describes what OpenAI does with data it receives. None of it limits what your staff paste in or connect.

What OpenAI commits to on business plans

OpenAI’s enterprise privacy page, last updated in January 2026, covers ChatGPT Business, Enterprise, Edu, for Healthcare and for Teachers, and the API Platform. The commitments that matter most for confidential data:

  • No training by default. Business data is excluded from model training unless your organisation explicitly opts in, for example through feedback.
  • Ownership. You own your inputs and outputs where the law allows.
  • Retention. Admins control how long conversations are kept, and deleted conversations leave OpenAI’s systems within 30 days unless the law requires otherwise.
  • Encryption. AES-256 at rest and TLS 1.2 or higher in transit.
  • Processing terms. OpenAI will sign a data processing addendum for Business, Enterprise and API use.
  • Access by OpenAI. Business content can be reached by authorised employees and by specialised contractors who review for abuse. For Enterprise, OpenAI limits staff access to incidents, recoveries you approve and legal requirements.

The same page notes that automated classifiers and safety tools may run over business data on all of these plans.

Risks that remain on every plan

Staff using personal accounts

A company workspace protects only the work done inside it. When staff paste into personal Free or Plus accounts, the employer has no logs, no retention control and no processing agreement, and training stays on unless each person opts out. OpenAI’s plan comparison also shows that Plus and Pro accounts can connect apps to internal tools, so a personal account can reach work systems if your identity settings let users approve third-party apps themselves. This is what shadow AI looks like day to day.

In May 2023, Samsung temporarily restricted generative AI tools on company-owned devices and internal networks after employees accidentally leaked sensitive internal data to ChatGPT the month before, TechCrunch reported, citing Bloomberg. Samsung’s stated concern was that data sent to external AI services is hard to retrieve and delete.

Retention promises carry a legal exception, and it has been used. In 2025 a court order in the New York Times lawsuit against OpenAI required the company to keep consumer ChatGPT and API content indefinitely, including chats users had deleted. ChatGPT Enterprise and Edu were excluded, as were API customers on zero data retention. OpenAI says the obligation ended on 26 September 2025 and that it still stores limited April to September 2025 data under legal hold. Deletion settings describe normal operations; litigation that your company is not a party to can still override them.

Connectors, apps and actions

Every connector widens the data flow. OpenAI states that apps respect your existing permissions and that data accessed through apps is not used for training by default. Information sent to an external app, an MCP server or a web provider, though, is handled under that provider’s own storage, privacy and residency terms. A GPT action can also pass data to a third party that may keep it for longer than 30 days. Treat each connector as a new processor to review.

Residency covers storage, not processing

Data residency settings answer where content is stored at rest. For ChatGPT Business, the region option covers storage only, not where requests are processed. If you pick a region outside the United States, a copy of every prompt and response is still kept in the US for a limited time for abuse monitoring. Enterprise can add inference residency, but only in Europe, the United States and the UAE, and CPU-side steps such as extracting text from files and routing requests can still run elsewhere. The same gap between sovereignty and residency comes up in every AI procurement.

Regulated and privileged data

Some data classes carry rules that a vendor’s privacy page cannot settle for you:

  • GDPR special categories. Article 9 prohibits processing data that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, as well as genetic data, biometric data used to identify a person, health data and data about sex life or sexual orientation, unless an exception applies. Article 28 allows only processors that give sufficient guarantees.
  • Protected health information. HHS treats a cloud provider that stores or processes ePHI for a covered entity as a business associate, even if the data is encrypted and the provider holds no key, so a BAA is required. OpenAI signs BAAs only for its listed HIPAA-eligible products, and a standard Business workspace is not one of them. Our guide for healthcare CIOs covers the options.
  • Client confidentiality and privilege. ABA Formal Opinion 512, issued in July 2024, applies a lawyer’s duty to keep client information confidential to generative AI use, unless the client gives informed consent. The law firm guide looks at what that means for tooling.

What to decide before staff use ChatGPT

  1. Classify the data. Public, internal, confidential and regulated, where regulated covers special-category, health, privileged and export-controlled material.
  2. Map each class to a tool. Decide which classes may go into an approved company workspace and which must never leave your infrastructure.
  3. Approve one workspace. Choose the plan whose controls match the most sensitive class you will allow, sign the data processing addendum and set retention.
  4. Close the personal-account gap. Tell staff that work data never goes into personal accounts, and back the rule with proxy or DLP controls once an approved tool exists.
  5. Review connectors. Switch on only the connectors your admins have approved, and record each one as a processor.
  6. Write it down. Publish an acceptable-use policy and train people on it. Under Article 4 of the EU AI Act, AI literacy duties have applied since 2 February 2025.
  7. Read the logs. Use the audit tooling your plan provides, such as the Compliance API on Enterprise, and review it on a fixed schedule.

When a private deployment is the safer answer

A business plan with good terms covers a lot of everyday work. A private deployment, where the model and the documents stay on infrastructure you control, is the safer answer when:

  • Contracts, client terms or a regulator say the data must not go to a third-party processor at all.
  • You need a guarantee about where processing happens, beyond where data is stored.
  • Auditors expect to see every prompt, retrieved document and answer under your own retention policy.
  • The network is air-gapped, or security policy forbids outbound traffic.
  • The work is privileged or client-confidential, and asking every client for consent is impractical.

A private deployment moves responsibility to you: security, patching, model quality and uptime become your job. The private AI overview explains the deployment options. To weigh building an assistant against buying seats, see three routes to an internal ChatGPT, and for the switch itself, the private ChatGPT for business page maps the migration.

How VDF AI fits

VDF AI Chat runs a ChatGPT-style assistant on your own infrastructure: on-premises, in a sovereign cloud region or air-gapped. Conversation history, uploaded files, retrieval indexes and audit logs stay in storage you control, and usage is never passed to a vendor for model training. Retrieval follows each source’s permissions, and every turn is logged with the user, the model version and the documents used.

Commercial model APIs can be enabled per agent where your policy allows, or switched off entirely for on-premises and air-gapped deployments. For health data, that means PHI stays on infrastructure you operate: when you host the model yourself, there is no cloud AI vendor whose BAA has to stretch to cover it. VDF AI runs inside your environment, so your existing controls and assessments apply to it.

Sources

Frequently asked questions

Does ChatGPT use company data for training?

It depends on the plan. OpenAI says content from its services for individuals, which include Free, Go, Plus and Pro, may be used to train its models unless the user turns off Improve the model for everyone in Data controls. Rating a reply with a thumbs up or down can still send that whole conversation for training. Inputs and outputs from ChatGPT Business, Enterprise, Edu and the API are not used for training by default.

Is ChatGPT Enterprise safe for confidential business data?

Enterprise carries OpenAI's strongest controls: no training on business data by default, retention set by your admins, SAML single sign-on, SCIM, role-based access, enterprise key management, a Compliance API and data residency in ten regions. OpenAI lists SOC 2 Type 2 and ISO 27001, 27017, 27018 and 27701 for it. Your data is still processed by OpenAI under contract, so the deciding question is whether your data class, client contracts or regulator allow that.

Is it safe to paste client information into ChatGPT?

Only if your policy allows that data class in an approved company workspace with a data processing agreement in place. Personal accounts sit outside company control and, by default, can contribute to model training. Some data needs more than a policy. The American Bar Association's Formal Opinion 512 applies a lawyer's duty of confidentiality to generative AI tools, so client information may need informed consent or a tool that keeps it in-house.

Is ChatGPT GDPR compliant?

OpenAI offers a data processing addendum for ChatGPT Business, Enterprise and the API to support GDPR compliance, and Enterprise customers can store content at rest in Europe. Compliance still depends on how you use it: a lawful basis, the Article 9 rules on special categories such as health or biometric data, transfer safeguards, retention and records. Work done in personal consumer accounts falls outside that addendum altogether.

Can ChatGPT be used with patient data under HIPAA?

Only on specific products. OpenAI lists ChatGPT for Healthcare, ChatGPT Enterprise with a Regulated Workspace, ChatGPT for Clinicians, ChatGPT FedRAMP and the API with Modified Retention as HIPAA-eligible with a business associate agreement, and excludes some features within them. A standard Business workspace is not on that list. HHS guidance treats a cloud service that stores or processes ePHI for a covered entity as a business associate that needs a BAA.

Are deleted ChatGPT conversations really deleted?

OpenAI says deleted chats are removed from its systems within 30 days unless it is legally required to keep them. That exception has been used. In 2025 a court order in the New York Times lawsuit required OpenAI to preserve consumer ChatGPT and API content, deleted chats included. Enterprise and Edu were excluded, and the obligation ended on 26 September 2025, but OpenAI still holds some April to September 2025 data under legal hold.

Filed under
AI securitydata sovereigntyAI governanceAI complianceprivate AIregulated AI
AI Governance

Is your AI governance audit-ready?

Get a readiness review of your AI controls — policy, oversight, audit trails, and EU AI Act evidence — mapped against what production actually requires.

Keep reading