Skip to content
AZGARD
security

Is ChatGPT safe for company data in Australia? The account decides

Is ChatGPT safe for company data? The account tier, not the model, decides whether your prompts train it, how long they are kept and who can read them.

Angus McDonald · 25 Aug 2026 · 12 min read

written for Australia ● also for United States, United Kingdom, Canada, New Zealand

Is ChatGPT safe for company data in Australia? The account decides

ChatGPT is safe for some company data and not for other company data, and the account tier decides which, not the model. On a personal consumer account, free or Plus or Pro, OpenAI may use what you paste to train its models. On a business or contracted account it does not. The Azgard AI Data Boundary sets four classes of company data against those three tiers, so you can tell before you paste.

Why "is ChatGPT safe for company data" is the wrong question

"Is ChatGPT safe for company data" asks about the model, and the model is identical in every account. What differs is the contract wrapped around it.

The rule behind the Azgard AI Data Boundary: the model does not decide what happens to your data. The account does. Name the tier you are on, read three lines of that tier's published terms - training, retention, human review - and match them against the most sensitive class of data you intend to paste. If you cannot name the tier, you are on the consumer one.

There is a real objection to that. A free ChatGPT user can turn training off in Settings under Data Controls, so the consumer account is not unconditionally training on your work. But that toggle is one person's preference. Nobody else in the business can see whether they flipped it, or prove to a client it stayed flipped.

The three AI account tiers, and what each one's published terms say about your data

Three AI account tiers exist across every major vendor, and the paywall is not the line between them. OpenAI's commitment that "by default, we do not train on any inputs or outputs from our products for business users" names ChatGPT Business, Enterprise and the API. Plus and Pro are consumer products.

Account tierTrains on your contentRetentionAdmin visibilityProcessor agreement
Personal consumer: free, Plus, ProYes, unless the user switches it offDeleted chats gone within 30 daysNone, and no audit trailNo
Paid business subscription: ChatGPT BusinessNo, by defaultAdmins control how long data is retainedAdmins read, export and delete staff chatsYes, the DPA applies
Contracted workspace or API: Enterprise, Edu, APINo, unless you agree in writingAdmin-set; deleted conversations gone within 30 days, API logs after 30 daysCompliance API audit logYes, plus confidentiality terms

At the contracted tier the promise becomes a clause. OpenAI's Services Agreement says it "will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees", treats that content as Confidential Information, and deletes all of it within thirty days of termination. Its data processing addendum is incorporated rather than sold separately.

Admin visibility is the variable owners miss. On ChatGPT Business, workspace admins can "view, access, export, and delete end user conversations", and Microsoft 365 Copilot works the same way: prompts and responses are stored and searchable through Purview while never training the models. The safe tier also buys a manager the ability to read what staff typed.

The Azgard AI Data Boundary: which class of company data may cross which account tier

The Azgard AI Data Boundary is a grid: four classes of company data down the side, three account tiers across the top. Every cell answers one question. May this class of data cross into this tier?

Class of company data (Azgard AI Data Boundary)Personal consumer accountPaid business subscriptionContracted workspace or API
Public or already publishedYesYesYes
Internal operational: your own pricing, process, draftsNoYesYes
Personal information about customers or staffNoOnly with the DPA signed and your APP 8 steps documentedYes, under the agreement
Client-confidential (NDA work, unreleased client material) or regulated by statute (health, legal, financial)NoContractual only, and only where the client contract allows a subcontracted processor under confidentiality. Statutory: noBoth: contractual under the agreement; statutory only where the vendor signs the instrument the obligation names

The fourth class covers two sources of obligation over the same data, and the source changes the answer. A statutory duty waits for the contracted tier, because no setting and no subscription can consent on a regulator's behalf: the vendor has to sign the specific instrument your obligation names. A contractual duty is governed by whatever that contract permits, and where it allows a subcontracted processor bound to confidentiality, the business tier's agreement can satisfy it. Read the NDA before assuming either answer.

The Azgard AI Data Boundary covers files, not only typing. OpenAI's training commitment runs over "content", and its residency scope names "Files (e.g., uploaded images, documents)" alongside conversations. Uploading a client contract is the same decision as pasting a paragraph out of it.

Two vendor exceptions keep the Azgard AI Data Boundary honest, because an account tier sets the default and defaults have exceptions. OpenAI says a conversation you give feedback on "may be used to train our models" even after you have opted out, so a thumbs-up counts as consent. And Anthropic's business associate agreement does not cover web search: a feature inside a covered product can sit outside the cover.

What actually happens to a prompt you paste into a consumer AI account

A prompt pasted into a consumer AI account does three things the person who pasted it cannot see. It becomes eligible for training, because OpenAI says that when you use its services for individuals "we may use your content to train our models". It persists: deleted conversations and Temporary Chats go within 30 days, and Anthropic may retain consumer chats de-identified for up to five years where it may use them for model improvement. And it can be produced to somebody else.

That third one is not hypothetical. In the New York Times copyright litigation, OpenAI's own account of who was affected named ChatGPT Free, Plus, Pro and Team plus API use without a zero-data-retention agreement, while stating Enterprise and Edu were not impacted. The American Bar Association Journal reported that in early January 2026 a federal judge affirmed an order to produce 20 million de-identified chat logs. Same model, one tier inside the order and one outside it.

Shadow AI: staff are already pasting company data into personal AI accounts

Shadow AI is the gap between the AI account a business bought and the AI accounts its staff actually use. Nobody can tell you your number, so count it yourself. List everyone on your workspace admin console, then list everyone who writes to customers. Anyone on the second list but not the first is on a personal account.

The exposure is easier to source than the prevalence. Only 12% of Australian businesses used AI in 2024-25, around 11% of small and micro businesses, on ABS fieldwork across nearly 7,000 businesses. Staff adoption ran well ahead of that, on accounts nobody procured. In the OAIC's 2026 attitudes survey of 1,504 adults on a probability panel, 93% said using personal information to train AI models or products is not fair and reasonable and trust in AI companies sat at 4%. The OAIC tells staff to refrain from entering personal information into publicly available tools.

Client-confidential and regulated data: what Australian privacy law actually requires

Australian privacy law handles client-confidential and regulated data through APP 8 and section 16C of the Privacy Act 1988. Before disclosing personal information to an overseas recipient, APP 8.1 requires you to take such steps as are reasonable in the circumstances to ensure that recipient does not breach the APPs, and section 16C keeps you liable if it breaches anyway, even after you took those steps. You cannot outsource the exposure. This is general information, not legal advice.

Australian privacy law splits two events that look identical from the keyboard, and APP 8 only bites on one of them. The OAIC's APP 8 guidance treats giving personal information to an overseas provider as a use rather than a disclosure where a binding contract limits that provider to storing and enabling access, binds its subcontractors identically, and gives the entity effective control of how the personal information is handled. Same model, same servers, different legal event, and the contract is what changes it.

The account tier's power stops there. A tier settles the facts, but what those facts make you legally is a separate assessment your contract does not decide.

Three Australian specifics change who is covered.

  • The small business exemption is A$3 million and still in force. The OAIC's small business page states the threshold with no repeal notice attached. Removing it is a government commitment under review, not enacted law, so treat any blog handing you a repeal date as wrong until the regulator's page changes.
  • From 1 July 2026, tranche 2 brought whole professions inside. Lawyers, accountants, conveyancers, real estate professionals, trust and company service providers and dealers in precious stones and metals became reporting entities under the AML/CTF Act, and the OAIC states such small businesses must comply with the Privacy Act for their AML/CTF activities while staying outside it for the rest of the business. The accountant pasting client onboarding files into free ChatGPT was outside the Act in June and inside it now.
  • Automated decision transparency commences 10 December 2026. New APP 1.7 to 1.9 require a privacy policy to disclose automated decisions that could reasonably be expected to significantly affect an individual's rights or interests. That covers decisions about people, not AI use generally: screening job applicants is caught, drafting an email is not.

AI data residency in Australia: do you need a private LLM, or is a contracted tier enough?

AI data residency in Australia is the feature buyers reach for first and should ask about second. Australian law does not require it: the OAIC states that the APPs do not prevent an organisation or agency from sending personal information overseas. APP 8 governs how you do it, not whether you may.

The feature also does less than its name suggests. Australia is on OpenAI's data-residency list for storage at rest and is not on the inference-residency list, which covers the United States, Europe and the UAE. Conversations, files and memory sit in Australia while the GPUs answering them run offshore. Residency is also offered to eligible API customers and new ChatGPT Enterprise and Edu workspaces only, never to free, Plus or ChatGPT Business, and cannot be retrofitted to a workspace you already have. Account data, billing, workspace metadata and anything sent to an external integration sit outside the region regardless.

"Private AI versus public AI" is how the residency choice usually gets framed, and it is the wrong axis. The same public model on a contracted account gives you the written terms APP 8 asks you to rely on, while a private deployment gives you control over a question Australian law is not asking. So a contracted tier with an enforceable contract covers what Australian law asks for, and a private LLM buys you something the law does not require. The honest counterpoint: an APRA-regulated entity carries CPS 234 obligations to oversee third parties handling its information security, subcontractors included, and that assessment lands somewhere different.

How to move your team onto a safe AI tier in a week, while the policy gets written

Moving a team onto a safe AI tier takes about a week, and it goes first because it protects data while you are still writing the policy. It does not replace the policy. The OAIC advises organisations to write generative AI policies, communicate them and run refresher training, and the Australian Government publishes a free AI policy guide and template alongside the National AI Centre's six essential practices.

  1. Name the tier on every account. Anyone who cannot name theirs is on the consumer tier.
  2. Buy the business tier for everyone who touches customer information, on the company domain, with single sign-on.
  3. Set the two settings that matter. Training off at the workspace level, retention set to a period you can defend.
  4. Sign the addendum. At the business and contracted tiers the DPA is part of the agreement, so this is a signature rather than a negotiation.
  5. Publish the boundary. One page, four data classes, three tiers. Then write the policy.

One qualifier, because it is where this advice breaks. A purchase plus two settings covers training and retention. It does not cover the contract-level instruments regulated work needs: a healthcare addendum with OpenAI is an email and a case-by-case review that can be declined, and Google states its business associate agreement "is not subject to modification". Those are requests, not toggles, and they take longer than a week.

What Azgard does with a client's commercial data, and what it will not promise

Azgard is one engineer in Sydney, on-site around Sydney and remote elsewhere, so the data answer is short: builds land in the client's own accounts and tenancy, documented in plain files the client's team can read and change. The Azgard AI Data Boundary gets written down for the specific business before anything is built, because deciding which documents may go into a system is the same decision as how to train AI on your company data.

In practice: Apex Signage's quoting runs through a system Azgard built and Apex's own staff operate, with quoting time down from about three and a half hours to just over two hours per quote. Underneath it sits a supplier cost snapshot of 15,758 rows, built from the client's own files and held in the client's own storage. Home Grown Electrical and Inner Game Basketball are the other two named Australian customers.

Now the part most consultancies leave out. Azgard holds no security certification, publishes no audit report and has no penetration test to hand you. It is one person, so there is no separate security team and no bench to absorb a bad month. That is a genuine ceiling on what Azgard can take on. Azgard does not publish which vendor tiers it holds either, so apply the Azgard AI Data Boundary's own rule to Azgard: ask which account tier your work will sit on, before you sign. Costs are in what an AI consultant costs in Australia.

FAQ

tags: securityprivacygovernancetooling

Angus McDonald

Angus McDonald

Founder, Azgard

Builds and operates production AI systems for organisations that need results, not slide decks.