Back to insights
AI privacyprivacysmall businesscompliance

When an Employee Pastes Client Data Into ChatGPT

Someone on your team pasted client data into ChatGPT. Here is what happened to it, your likely exposure, and what to change so it does not happen again.

Elements AI 9 min read
Key Takeaways
  • By default, consumer and Plus ChatGPT accounts use conversations to improve OpenAI's model. Toggling that off in settings stops future data from being used, but does not affect anything already submitted.
  • After deleting a conversation, OpenAI retains the data on its systems for up to 30 days. Deleting is not the same as erasing from the training pipeline.
  • If the data falls under HIPAA, attorney-client privilege, or PCI scope, a disclosure obligation may have already triggered, regardless of whether any harm occurred.
  • ChatGPT Enterprise and Teams accounts do not train on your data by default. Consumer and Plus accounts do unless the user explicitly opts out.
  • The real fix is a written AI policy with concrete examples, in place before the next team member runs the same experiment, not a one-time conversation after the fact.

The first thing to settle is what actually happened to the data. When a team member types client names, health details, financial records, or confidential case notes into a standard ChatGPT account, that content goes to OpenAI’s servers. On consumer and Plus plans, it can be used by default to improve the model. The window to address some of that exposure is narrow, and several decisions cannot wait for a slower internal review. Whether you are looking at a mandatory disclosure depends on the industry you are in and the type of data involved, not just on how sensitive it felt in the moment.

What ChatGPT actually does with what your team types

The answer depends on which plan your employees are using. Consumer and Plus accounts share conversation data with OpenAI for model improvement by default. Each user can turn that off in account settings under Data Controls by toggling off “Improve the model for everyone.” The toggle applies to that user’s future conversations. It does not reach back to conversations that already happened, and it applies per user, not per account. If your employees use personal accounts or accounts your business has not centrally provisioned, you cannot assume any one toggle covers the team.

ChatGPT Enterprise and Teams accounts work differently. OpenAI does not use those conversations for training by default. If your business has a formal Enterprise contract, the data stays out of the training pipeline. If your employees are using personal free or Plus accounts, that protection does not apply.

89 percent of small businesses now use AI in some form, according to Capsule CRM and the SBE Council in 2026. The gap between that adoption rate and the number of businesses with a written AI data policy is where most of these incidents originate. The tool is everywhere. The rules around it are not.

How long is the data actually retained?

Conversations on standard accounts are saved to the user’s account until they delete them. After deletion, OpenAI’s policies indicate the data remains on their systems for up to 30 days. That window matters for two reasons.

First, a delete action does not undo model training that may have already occurred. Second, the 30-day window is relevant if you receive a legal or regulatory inquiry, because the data may still technically be present and retrievable during that period.

There is a temporary chat mode that behaves differently. Conversations in that mode are not used for training and are scheduled for deletion within 30 days automatically. Most employees using standard ChatGPT are not in temporary chat mode unless they specifically enable it each session. Checking which mode your team is actually using is one of the first useful things to know. We covered how ChatGPT handles your data in detail, including what OpenAI retains and for what purpose, in an earlier post on where your business data goes when you use ChatGPT.

Not every incident triggers a mandatory formal action. But certain data types carry their own disclosure rules, and those rules do not wait for the business to decide how serious the incident feels.

Protected health information. If your business is a covered entity under HIPAA or works with covered entities as a business associate, sending protected health information to a service without a signed business associate agreement is a potential disclosure. Standard ChatGPT accounts do not come with a BAA from OpenAI. The obligation to assess and potentially report is triggered at the moment of disclosure, not the moment of provable harm. Whether it rises to a reportable breach depends on a required risk assessment, not a judgment call. We covered the HIPAA and AI data privacy angle for healthcare and legal practices in more depth in this earlier post on AI data privacy for regulated industries.

Attorney-client and professional privilege. Law offices, accountants, and financial advisors operate under professional conduct rules that govern disclosure of client information to third parties. Submitting client files or case details to an AI tool that routes through a third-party server is a disclosure. The professional conduct rules in most states do not have an accidental exception.

Payment card data. PCI DSS scope covers systems that store, process, or transmit cardholder data. If an employee submitted card numbers or CVV codes to ChatGPT, there is a separate reporting and remediation path under PCI requirements, independent of what the employee intended.

This is where the advice “figure out what was in the conversation” is harder than it sounds. Most employees who submit data to AI tools are not logging what they typed. The conversation history in the account may still show it if it has not been deleted, which is why one of the early decisions is about preserving that record rather than removing it.

What “I deleted the conversation” does and does not do

A deleted conversation is removed from the account view and scheduled for deletion from OpenAI’s systems. That is meaningful, and it is not a complete erasure.

What deletion does not do: it does not reverse model training that occurred before the deletion. It does not satisfy a regulatory audit on whether a disclosure happened, because it did. It does not erase the conversation from OpenAI’s logs during the 30-day retention window that follows deletion.

If you are in a regulated industry, deleting the conversation as a first response can complicate a subsequent legal review. The instinct to clean up before assessing the situation is understandable. It can also work against you. Preserving a record of what was submitted and when is often more useful than immediate deletion, particularly if an attorney or compliance officer needs to understand the scope of what was shared.

The decisions that come up in the next 48 hours

The questions that arise quickly are harder to resolve than they look from the outside.

Does the data fall under a mandatory reporting regime? That requires knowing what was in the conversation, which regulation applies, and what a risk assessment concludes. Getting to a real answer in 48 hours typically requires someone with legal or compliance background who knows your specific industry, not just general knowledge of AI data practices.

Do affected clients need to be told? In many regulated contexts, the notification question is not discretionary. The threshold is whether a disclosure occurred and what data was involved, not whether harm is provable.

Who else in the organization needs to know? IT, legal, and leadership often need to be in the conversation earlier than feels comfortable. Each has different obligations once they have actual knowledge of a potential incident.

Does the employee’s account need to be reviewed? If the data was submitted from an active account that is still retaining conversations, there may be other sensitive submissions in the history.

64 percent of small businesses are likely to expand formal AI training in 2026, according to Business.com, and only about 14 percent of workers are advanced AI users right now. The gap between tool access and user understanding is exactly where these incidents live. None of these decisions require technical expertise to recognize. Most of them require professional judgment to resolve.

What changes for the business after this

The immediate incident is one problem. The structural one is that the employee who did this was probably not cutting corners. They were working faster. The tool is accessible, the workflow made sense, and nobody had told them where the line was.

The change that prevents the next incident is a written policy with examples specific enough that an employee recognizes their own workflow in them: what data can go into general AI tools, what cannot, what to do when a client’s name naturally comes up while the tool is already open. Our post on what an AI policy for a small team actually needs to include covers the practical structure.

The harder version of the question is whether some of your workflows need a different tool entirely. A general-purpose consumer AI tool is the wrong fit for workflows that involve sensitive client data, regardless of what a policy says. The alternative is either a platform built with data controls suited to regulated use, or a private model that does not route through a third-party server at all. Our AI training service helps teams understand which workflows benefit from AI and which ones carry data exposure their current setup cannot address. For businesses where data not leaving the building is the real requirement, our private AI service builds that infrastructure.

The gap between “we use ChatGPT” and “we use AI safely for our client relationships” is real. It does not close by telling people to be more careful next time.

Frequently asked questions

Does ChatGPT use what my employees type to train its AI?

On consumer and Plus accounts, yes by default. OpenAI uses conversations to improve its model unless the user toggles off “Improve the model for everyone” in Data Controls settings. That setting only affects future conversations, not what was already submitted. Enterprise and Teams accounts are excluded from training by default.

Can I get client data deleted from ChatGPT after it was submitted?

Deleting a conversation removes it from the account and schedules it for removal from OpenAI’s systems, typically within 30 days. What cannot be reversed is any use of that data in model training that already occurred before deletion. The data is gone from the product, but its influence on the model is not reversible.

Is it a HIPAA violation if an employee sent patient data to ChatGPT?

It depends on your status as a covered entity and whether OpenAI has signed a business associate agreement with your organization. Standard ChatGPT accounts do not include a BAA. Sending protected health information to a service without a BAA is a potential disclosure, and the obligation to assess and potentially report it triggers at the moment of disclosure, not harm.

What is the difference between ChatGPT and ChatGPT Enterprise for data privacy?

ChatGPT Enterprise and Teams accounts do not use your conversations to train OpenAI’s models by default. Consumer and Plus accounts do unless the user explicitly opts out. For businesses handling client data regularly, the distinction matters: a team using free accounts faces a different data exposure than a team using verified Enterprise accounts.

How do I stop this from happening again without banning AI entirely?

A short, concrete written policy does more than a blanket ban. The policy needs to name what is off-limits in any AI tool, give real examples employees recognize from their own work, and explain why. Pair it with a short training session so people understand the reasoning, not just the rule. Prohibition without explanation tends to go underground rather than go away.


The part most businesses miss is not the incident itself. It is the gap between the incident and having a clear policy, and how long that gap stays open. The next person on your team to paste something into ChatGPT has probably not thought about data exposure at all. They have thought about getting their work done. Whether your current setup leaves that same window open is the question worth sitting with before the next person finds out by accident.

VK is an AWS Certified Solutions Architect. Elements AI is a Castle Rock, Colorado studio. The free 30-minute call is where we typically map which workflows in your business put client data at risk with the tools you already use, and what a safer setup looks like for your specific situation. Book a free 30-minute call.

Ready when you are

Want this kind of thinking applied to your business?

A free 30-minute call. We'll listen, ask questions, and tell you the truth about what would actually move the needle.

Call (720) 663-0299