Is ChatGPT safe for company data in Canada? The account decides
Is ChatGPT safe for company data in Canada? Training, retention and admin visibility are set by your account tier, not the model. What PIPEDA and Law 25 add.
Angus McDonald · 25 Aug 2026 · 14 min read
written for Canada ● also for Australia, United States, United Kingdom, New Zealand

ChatGPT is safe for company data on the tier whose published terms say so, and unsafe on the tier most staff are actually using. The same model behaves differently depending on which account you reach it through: training, retention, human review, admin visibility and whether a processor agreement exists at all are set by the account, not the model. The Azgard AI Data Boundary matches four classes of company data to three account tiers.
In Canada the account is also where the law lands. PIPEDA, Alberta's PIPA and Quebec's Law 25 bind the business doing the pasting, not the vendor being pasted into.
Why "is ChatGPT safe for company data" is the wrong question
"Is ChatGPT safe for company data" names the model as the variable, and the model is not the variable. The same weights sit behind a free account, a Plus subscription, a ChatGPT Business workspace and a contracted API key, and those four accounts do four different things with the text you paste.
The Azgard AI Data Boundary starts from one rule. The model does not decide what happens to your data. The account does. Name the tier you are on, read three lines of that tier's published terms - training, retention, human review - and match them against the most sensitive class of data you intend to paste. If you cannot name the tier, you are on the consumer one.
The trap is the word consumer: ChatGPT Plus and Pro are paid consumer subscriptions, and OpenAI's no-training commitment starts at ChatGPT Business. The commonest shadow AI account in a Canadian small business is somebody's personal Plus subscription, expensed.
The three AI account tiers, and what each one's published terms say about your data
Three account tiers cover almost every way a Canadian business reaches a large language model, and each publishes different terms for the same model.
| What the terms say | Personal consumer (free, Plus, Pro) | Paid business subscription (ChatGPT Business) | Contracted workspace or API (Enterprise, Edu, ZDR API) |
|---|---|---|---|
| Training on your content | OpenAI "may use your content to train our models" unless you switch it off in Data Controls | Off by default and in the contract: OpenAI "will not use Customer Content to develop or improve the Services" | Off by default, under the same Services Agreement clause |
| Retention | On Free, Plus and Pro a deleted chat leaves your account immediately and OpenAI's systems within 30 days, unless it must be retained for legal or security reasons; Temporary Chats leave no history at all | Workspace admins control how long data is retained | Admin-controlled, and Customer Content deleted within 30 days of termination |
| Human review and admin visibility | No admin anywhere, and a conversation you submit feedback on may be used for training even after you opt out | Admins can "view, access, export, and delete" end user conversations | Conversation audit log through the Enterprise Compliance API |
| Processor agreement | None on offer | Data processing addendum incorporated into the business agreement | Addendum plus negotiated terms |
| Canadian data residency | No | No | At rest only, for eligible API customers and new Enterprise or Edu workspaces |
A settings toggle is a preference; a contract is a commitment. OpenAI said a US preservation order covered Free, Plus, Pro, Team and API accounts without a zero-data-retention agreement and not ChatGPT Enterprise or Edu. That list predates OpenAI's current tier names and does not mention ChatGPT Business at all, so a Business subscriber reading it cannot infer that they were excluded. In early January 2026 a federal judge affirmed an order to produce 20 million de-identified ChatGPT logs.
Other vendors sort the same way: Microsoft 365 Copilot prompts are not used for training but are stored for admins to retrieve, and Anthropic keeps Claude conversations de-identified for up to five years where you allow them to be used for model improvement. Each vendor's tiers set its own defaults, and a vendor that will not train on your prompts may still keep them.
The Azgard AI Data Boundary: which class of data may cross which tier
The Azgard AI Data Boundary is a boundary rather than a ladder. It names four classes of company data and says which account tier each class may cross.
| Class of company data (Azgard AI Data Boundary) | Personal consumer account | Paid business subscription | Contracted workspace or API |
|---|---|---|---|
| 1. Public or already published: website copy, a published price list, a brochure | Fine | Fine | Fine |
| 2. Internal operational: drafts, meeting notes, process documents with no names in them | No | Fine | Fine |
| 3. Personal information about customers or staff | No | Only once your customers have been told in plain language that their information may be processed abroad | Yes, under a written agreement, and in Quebec an assessment first |
| 4. Client-confidential or regulated: work under NDA, unreleased client material, health, legal and financial records | No | Contractual confidentiality only, and only where that contract allows a subcontracted processor | Yes for both kinds, under a signed agreement that names this use |
Two rules make the grid work. Classify by the most sensitive line in the paste rather than the average, because one customer's name inside a 400-word draft makes the whole paste class three. And if you cannot name the tier, you are on the consumer one.
Class four splits on where the obligation comes from, and the split decides the tier. A statutory duty - health records, regulated financial files, a professional body's rule - waits for the contracted tier and an agreement that names the use, because no setting and no subscription can consent on the regulator's behalf. A contractual duty is a different question: an NDA over a client's unreleased product, or an agency holding an embargoed campaign, is governed by what that contract permits, and where it allows a subcontracted processor under confidentiality, the business tier's agreement can be the thing that satisfies it. Read the NDA before assuming either answer.
The grid covers attachments, not just typed text. Uploading a PDF, dragging in a spreadsheet and connecting a shared drive are the same act as pasting, and they are the route most class four data actually travels: nobody retypes a client file, they upload it. A connected drive is worse again, because it hands over material nobody chose file by file.
What happens to a prompt you paste into a consumer AI account
A prompt pasted into a consumer AI account is stored against an individual's personal login, may train the model unless that individual found the setting, can be read by a human if they submit feedback on the answer, is visible to no administrator at your company, and is reachable by legal process against the vendor. Deleting the conversation starts a 30-day clock that OpenAI's own terms let a legal or security obligation stop, and whatever a training run already absorbed stays absorbed.
Quebec's regulator says the default itself was wrong: in joint findings published on 6 May 2026 the Commission d'accès à l'information concluded that the privacy settings should have provided, by default, that user chats would not be used for model training. OpenAI committed to warn signed-out web users before their first prompt, though that is a promise on a timetable, and not something Azgard has verified in the product.
Shadow AI: your staff are already pasting company data into personal accounts
Shadow AI is company data moving into personal accounts nobody bought, and Canada's numbers on it are official rather than vendor-sponsored. 35.9 per cent of Canadian workers used generative AI at work in the 12 months to March 2026, and the heaviest users of any occupational group were legislative and senior management at 75.1 per cent: the people with the widest access to commercially sensitive material use these tools most. Among private-sector employees who did not use them, 4.2 per cent gave company or organizational policy as their main reason.
The popular prevalence figures, including the widely repeated claim that 77 per cent of employees paste company data into generative AI tools, trace to no published methodology, so Azgard does not cite them. The figure that does trace points the wrong way for small firms: 11.6 per cent of businesses with 1 to 4 employees named cybersecurity or privacy as a barrier to AI, against 30.0 per cent of those with 100 or more. Concern scales with headcount. Exposure does not.
Client-confidential and regulated data: what the law where you operate requires
Client-confidential and regulated data is where Canadian law stops being general advice, and the duty sits with your business rather than the vendor. PIPEDA has no controller and processor split, so there was never a role to hand off. The Office of the Privacy Commissioner treats sending personal information abroad for processing as a use rather than a disclosure, keeps the transferring organization accountable for the file, and says no contract can override the criminal, national security or any other laws of the country the information was transferred to. It also requires a plain-language notice to the individual: their information may be processed in a foreign country and may be accessible to that jurisdiction's law enforcement.
The provincial rules that follow are Alberta's, British Columbia's and Quebec's; a business anywhere else in Canada works from the federal duty above rather than from any of them.
Alberta and British Columbia turn that notice duty into opposite instructions. Alberta's PIPA section 6(2) requires written policies naming the countries where a service provider outside Canada handles the information and the purposes it is authorized for, and section 13.1 requires you to tell the individual, at or before transfer, how to get that document and the name or title of someone who can answer questions about it: a Calgary business on a US-hosted AI account owes both. British Columbia is the reverse. The residency rule owners quote came from FIPPA, the public-sector act, and 2021 amendments removed it; BC's PIPA has no data-residency rule at all, so a Vancouver owner told "our data has to stay in Canada" has inherited a public-sector rule that no longer says that. Professional duties run separately: the Law Society of BC tells lawyers to keep client-identifying information out of these tools, with fully informed written consent the alternative.
Quebec is the strictest and the most specific. Law 25 section 9.1 requires the privacy settings of a technological product offered to the public to "provide the highest level of confidentiality by default, without any intervention by the person concerned": training-off-by-default, written into statute. Section 17's third paragraph extends the cross-border duty to a business that "entrusts a person or body outside Québec with the task of collecting, using, communicating or keeping such information on his behalf", a precise description of an AI account. The privacy impact assessment comes first, the communication needs a written agreement, and the CAI publishes the guide and template for doing it; choosing a consultant in Canada covers the contract side. The penalties are Canadian dollars and each is written as the greater of two figures: administrative penalties to $10,000,000 or 2 per cent of worldwide turnover, whichever is greater, and penal fines to $25,000,000 or 4 per cent of worldwide turnover, whichever is greater.
Four regulators looked at the same facts and reached four different answers. On 6 May 2026 the federal, BC, Alberta and Quebec authorities published joint findings on OpenAI: well-founded and conditionally resolved federally, unresolved in BC and Alberta, and in Quebec split by how users reached the model, with account holders and mobile app users given compliant information and the signed-out free web version not. Read it for what it asks of you, not as a verdict on a product. The offices examined GPT-3.5 and GPT-4 only, both since retired, and found training on user interactions was not inappropriate in purpose. What failed was consent.
There is no Canadian AI Act governing business use of these tools. AIDA was part of Bill C-27, which never passed, and the government has archived its own companion document for it, while Bill C-36, which would amend PIPEDA, is at second reading. Waiting for AI law before fixing your accounts is waiting for the wrong statute. And where a vendor offers a special-category agreement for regulated data, you apply for it by email and wait on a review that can come back no.
Do you need a private LLM, or is a contracted tier enough?
A private LLM is usually the wrong answer to a Canadian residency question, because the residency you can buy is narrower than the one you are picturing. OpenAI offers Canadian storage at rest and no Canadian inference, so the conversation sits here while the model answering it runs elsewhere, and it goes to eligible API customers and new Enterprise and Edu workspaces: not ChatGPT Business, not any consumer account. Account data, billing, logs without content, workspace metadata and anything sent to an external integration stay outside the region regardless.
A Quebec business therefore gains less than it hopes, because Canadian storage does not stop information going outside Quebec and the section 17 assessment does not evaporate. Running your own model moves the problem rather than removing it: you take on hosting, access control and retention design, with no counterparty's terms to point at, and still owe the assessment. Where your company knowledge lives is a different question, and so is training AI on your company data.
How to move your team onto a safe tier in a week, without writing a policy first
Moving a team onto a safe AI tier takes about a week, and the order matters: the purchase protects data while the policy is being written, whereas drafting the policy first protects nothing for the six weeks it takes to agree one. Do both, in that order.
Day one, count the accounts: which tools, under which login, and expect personal Plus subscriptions. Day two, buy one business workspace and put everyone on it. Day three, set what you now control, the retention period and whether workspace content can be used for improvement, and record who the admin is. Day four, close the personal accounts doing company work. Day five, start the policy, borrowing from Canada's thirteen federal, provincial and territorial privacy authorities, who signed one set of principles for generative AI telling organizations to use anonymized or de-identified information in prompts where reasonable, to enter personal information only "where authorised", and that prompts "should not be retained, used for secondary purposes, or disclosed".
What the week does not buy is the top of the grid. A business workspace moves classes one to three; class four, the client files and regulated records, still waits for a signed agreement that names that use, and in Quebec for the assessment that has to come before it.
What Azgard does with a client's commercial data, and what it will not promise
Azgard is one engineer in Sydney delivering remotely, with no Canadian entity and nobody on the ground. Section 17 puts the entrusting at the account: a Quebec buyer's assessment has to cover the tier the work runs on and every supplier who touches it, and a one-person Australian firm working inside your accounts sits in that scope. Better raised in the first conversation than found at signing.
Every build runs inside accounts the client owns, on contracted tiers, so the agreement governing the data is the client's own with the vendor. The largest single body of client commercial data Azgard has handled is a supplier cost snapshot of 15,758 rows: class four on the Azgard AI Data Boundary, and it never went near a personal account. At Apex Signage quoting time went from about 3.5 hours to just over 2 hours per quote, in Apex's own tools, run by Apex staff.
What Azgard will not promise: that a vendor cannot be compelled by a foreign court, which the ChatGPT log order shows is nobody's to give; that signing an addendum settles your legal role, because under PIPEDA there was never a role to hand off; or that any of this is legal advice. For that, ask a lawyer in your own province.
FAQ
tags: security ● governance ● privacy ● adoption

Angus McDonald
Founder, Azgard
Builds and operates production AI systems for organisations that need results, not slide decks.

