ModelCharter
ModelCharter Team

Is ChatGPT Safe for Work? A Tier-by-Tier Guide

Person using an AI chatbot on a laptop computer for work

Photo: Matheus Bertelli / Pexels

Key takeaways

  • ChatGPT's data promise splits sharply at the tier line: Free and Plus can train on your inputs by default, Team, Enterprise and the API don't.
  • GDPR still applies the moment personal data goes into ChatGPT; you need a lawful basis and ideally a DPA.
  • Approve a business tier for work use and ban secrets, client data and unreleased plans from consumer AI tools.
  • Write the rule into your AI usage policy so it survives staff turnover, not just a Slack message.

Is ChatGPT safe for work? The honest answer is: it depends entirely on which version your team is using, and what they type into it. A personal, free ChatGPT account and ChatGPT Enterprise are built on very different data promises, even though they look almost identical on screen. Get the tier wrong and a stray customer name or unreleased product plan can end up shaping OpenAI's next model. Get it right, and ChatGPT is one of the better-governed AI tools around, with contracts, admin controls and retention settings that satisfy most enterprise buyers. Here's exactly where the line sits.

Free and Plus: built to learn from you

On the consumer tiers, Free and Plus, OpenAI may use your conversations to improve its models unless you switch that off in Data Controls, a setting most people never open. That means anything typed into a personal ChatGPT account, a client's marketing brief, a chunk of your codebase, a draft of next quarter's pricing, can be reviewed and absorbed into future versions. It isn't malicious. It's simply the default business model of a free consumer product, the same pattern you'll find across Google Gemini and other assistants built for a mass market rather than a boardroom. This isn't unique to OpenAI, it's the norm for any consumer AI product that doesn't charge enough to fund itself outright.

Team, Enterprise and the API: a different contract

ChatGPT Team, ChatGPT Enterprise and API access run on a different promise: OpenAI states it does not train its models on your business data or conversations by default on these tiers (OpenAI, business data privacy). Enterprise adds SSO, admin-managed retention and audit logs; the API lets you set your own retention window. For any organisation handling client data, source code or unreleased plans, this is the tier that actually matches what most people assume 'safe' means. OpenAI also publishes a SOC 2 report for these tiers and will sign a Data Processing Agreement on request, two things a personal account never gets you. If your team's current setup is 'everyone bought their own Plus subscription', that alone is worth fixing before you write a single policy clause.

Does ChatGPT train on my data?

Only if you let it. Training happens by default on Free and Plus unless you opt out; it does not happen by default on Team, Enterprise or the API (OpenAI, enterprise privacy). If nobody on your team can say with confidence which setting applies to their account, assume the worst case and lock it down. Custom GPTs and browsing add another wrinkle: a custom GPT built by someone outside your company can log what you send it regardless of your own account settings, so treat third-party GPTs as their own risk category, not an extension of your ChatGPT plan.

Is ChatGPT GDPR compliant for a UK or EU business?

ChatGPT can be used in a compliant way, but compliance is your responsibility as the data controller, not something the tool grants automatically. If personal data of EU or UK residents ever touches ChatGPT, you need a lawful basis and, ideally, a Data Processing Agreement with OpenAI, plus a clear line in your policy about what staff may and may not paste in. The ICO's guidance on AI and data protection is a solid primer if this is new territory. In practice, most small teams get this right by doing two things: routing anything involving customer or employee personal data through the business tier with a signed DPA, and keeping a short record of that decision in case a data-protection query ever lands on your desk.

What actually goes wrong

Picture a 12-person design studio that adopted ChatGPT for briefs and copywriting. Everyone signed up with personal Plus accounts, because it was faster than waiting for IT to sort out a Team licence. Six months later a client asked, reasonably, whether their unreleased packaging concepts had ever been typed into a public AI tool. Nobody could say for certain, because there was no record of who'd used which account for what, the exact shadow-AI blind spot governance is meant to close. The fix wasn't complicated: one paid Team workspace, a rule that personal accounts are for personal use only, and a line in the policy confirming it. It should have existed from day one.

The practical rule to set

Approve a business tier at minimum, require staff to use it rather than personal logins for anything work-related, and ban secrets, client data and unreleased plans from any consumer AI tool, ChatGPT included. Write it down. A rule that lives only in a Slack message gets forgotten within a month; one written into a proper policy survives staff turnover and holds up in a customer security review. Cover browser extensions and third-party plugins in the same breath: an unofficial ChatGPT extension can route your prompts through a server OpenAI has never heard of, so 'use ChatGPT' has to mean the sanctioned app or website, not whatever a browser add-on store turns up.

A short rollout checklist

Putting this into practice takes an afternoon, not a project plan. Pick the tier: Team for most small businesses, Enterprise once you need SSO and admin-managed retention. Move everyone off personal logins and onto the paid workspace, with IT or a founder as the account owner. Turn off training in Data Controls for anyone who still has a personal account for occasional use. Add one line to onboarding: work data goes in the company workspace, never a personal account. None of that needs a lawyer, just someone willing to own it.

Check before you approve

Before rolling ChatGPT out further, check its current data-handling profile in our AI Tool Risk Directory, which rates 60+ tools on training, retention, SOC 2, DPA and BAA status straight from vendors' own policies. Then turn the rule above into a document your team can actually follow: our free AI usage policy generator builds one in a few minutes.

TierTrains on your data by default?Admin controlsBest for
FreeYes, unless opted outNonePersonal use only
PlusYes, unless opted outNonePersonal use only
TeamNoWorkspace admin, retention controlsSmall business work
EnterpriseNoSSO, audit logs, admin-managed retentionRegulated or larger organisations
APINoConfigurable retention windowDevelopers building on top of it
ChatGPT tiers and data handling at a glance
We do not train our models on your business data or conversations by default for ChatGPT Team, ChatGPT Enterprise, and our API platform.
OpenAI, Business Data Privacy

Frequently asked questions

Is ChatGPT Free safe for work?
Not for anything sensitive. Free accounts may be used to train OpenAI's models by default, so a client's confidential brief or a snippet of internal code shouldn't go anywhere near a personal Free account.
What's the real difference between ChatGPT Plus and Team for business use?
Plus is still a personal, consumer account that can train on your data unless you opt out. Team is a business product: OpenAI doesn't train on it by default, and it adds workspace admin controls, which Plus doesn't have.
Does ChatGPT keep a copy of everything I type, even on paid tiers?
Some retention applies on every tier for safety and abuse monitoring, but Enterprise and the API let admins set their own retention window, while Free and Plus don't give you that control.
Can I use ChatGPT with client data?
Only on Team, Enterprise or the API, with a signed Data Processing Agreement in place, and only for data your contract with the client actually permits you to process this way. Check your own contract with that client too, some agreements restrict sending their data to any third-party AI tool at all, regardless of ChatGPT's own settings.
Is ChatGPT HIPAA compliant?
Only ChatGPT Enterprise (via a signed Business Associate Agreement) is positioned for protected health information. Free, Plus and Team are not appropriate for PHI. Even then, the BAA covers OpenAI's handling of the data, not how your staff use it, so a written policy on what can and can't be pasted still matters.

Put this into practice

Generate a free AI usage policy for your team, then see which of your tools are safe to use.

Open the generator