Skip to content
AZGARD
security

Is ChatGPT safe for company data in New Zealand? The account decides

Is ChatGPT safe for company data in New Zealand? The account tier decides, not the model, and what the vendor does with your data decides the legal answer.

Angus McDonald · 25 Aug 2026 · 13 min read

written for New Zealand ● also for Australia, United States, United Kingdom, Canada

Is ChatGPT safe for company data in New Zealand? The account decides

ChatGPT is as safe for company data as the account you reach it through. The same model trains on your content on a personal consumer account, including paid Plus and Pro, and does not train by default on ChatGPT Business, Enterprise or the API. The Azgard AI Data Boundary matches four classes of company data against those three account tiers, so you can answer the question one paste at a time.

Why "is ChatGPT safe for company data" is the wrong question

"Is ChatGPT safe for company data" is the wrong question because ChatGPT is not one product. It is one model you reach through three different accounts, and the account sets training, retention, human review, who inside your business can read a chat, and whether the vendor will sign a data processing agreement at all.

MBIE's Quickstart for businesses using AI tools puts the same choice to New Zealand owners: "you can procure a tool your business controls (enterprise) which is likely to be more secure or use a public tool which might be more accessible". MBIE names the choice. Azgard's rule for making it, and the rule the Azgard AI Data Boundary is built on, is this:

The Azgard AI Data Boundary rule. The model does not decide what happens to your data. The account does. Name the tier you are on, read three lines of that tier's published terms - training, retention, human review - and match them against the most sensitive class of data you intend to paste. If you cannot name the tier, you are on the consumer one.

The three AI account tiers, and what each one's published terms say about your data

Three AI account tiers cover almost every way a New Zealand business reaches a large language model, and each publishes different terms for the same data.

Account tierTrains on your contentRetentionAdmin visibilityProcessor agreement
Personal consumer: free, Plus or ProYes by default: OpenAI "may use your content to train our models" (source)Deleted chats and Temporary Chats deleted within 30 days (source); Temporary Chats also leave no history and are not used for training (source)None, not even whether training was switched offNone
Paid business: ChatGPT Business, the small-business tier older OpenAI material calls TeamNo, by default and contractuallyAdmins "control how long your data is retained" (source)Admins "can view, access, export, and delete end user conversations" (source)Attaches via the Services Agreement
Contracted workspace or API: Enterprise, Edu, APINo: "OpenAI will not use Customer Content to develop or improve the Services" (source)Deleted within 30 days of termination; zero-retention endpoints never log (source)Audit log through the Enterprise Compliance API (source)DPA plus the agreement; residency on Enterprise, Edu and the API only

Two vendor facts cut against that clean story. OpenAI says a conversation you give feedback on "may be used to train our models" even after you have opted out, and Anthropic says that where you allow chats to improve Claude it "may retain your data in a de-identified format for up to 5 years". Claude splits along the same line as ChatGPT, so the answer to "is Claude safe for business data" is also the account: Anthropic's zero data retention covers eligible APIs, commercial organisation API keys and Claude Code on Enterprise plans, and even then Anthropic keeps its User Safety classifier results. A tier sets the default; it does not cover every case. Admin visibility runs the other way: Microsoft says prompts "aren't used to train foundation LLMs", while the same page tells administrators to read them through Content search or Purview.

The Azgard AI Data Boundary: which class of data may cross which tier

The Azgard AI Data Boundary sorts company data into four classes and asks which of the three account tiers each class may cross. There is no score: an account's published terms either cover that class of data or they do not.

Class of company data (Azgard AI Data Boundary)Personal consumerPaid businessContracted workspace or API
Public or already published: website copy, listed prices, marketingCrossesCrossesCrosses
Internal operational: drafts, process notes, job data with names strippedOnly after someone reads that tier's termsCrossesCrosses
Personal information about customers or staffDoes not crossCrosses once the section 11 disclosure question is answeredCrosses
Client-confidential or regulated: health information, privileged material, anything under an NDADoes not crossContractual confidentiality only, and only where that contract allows a subcontracted processorStatutory, professional or regulated material, only where the signed agreement names that category

The boundary is about the data, not the person. A director pasting a customer list into a personal Plus account is doing the thing a junior would be told off for.

The bottom row splits by where the duty comes from, not by what the file is. A statutory or professional duty, health information or privileged material, waits for the signed agreement, because no setting and no subscription can consent on the regulator's behalf. A duty that is purely contractual is governed by what the contract permits, so an unreleased drawing held under an ordinary NDA may sit on a business tier where a client's medical file never can. Read the NDA before assuming either answer.

What happens to a prompt you paste into a consumer AI account

A prompt pasted into a consumer AI account, or a file uploaded to one, travels further than people picture. OpenAI may use it to train, unless the user turned off "Improve the model for everyone" in Data Controls, which even a free user can do. That is the honest crack in the tier story, and also why the tier still matters: a toggle is one person's preference, and nobody else in the company can see whether they flipped it. A contract is something the business can point to.

The prompt can also become evidence. In the New York Times copyright litigation, OpenAI's own page says the preservation obligation covered "ChatGPT Free, Plus, Pro, and Team" subscriptions and API use without a zero-data-retention agreement, and did not affect Enterprise or Edu. Legal press then reported that in early January 2026 a federal judge affirmed an order to produce 20 million de-identified ChatGPT logs. A foreign court tested the tier boundary and it held.

Shadow AI: your staff are already pasting company data into personal accounts

Shadow AI is company data going into personal AI accounts nobody approved, and in New Zealand that is the normal case. A July 2026 survey of more than 300 Employers and Manufacturers Association member businesses found 83% already using AI and 13% with an AI policy in place, and that 18% of the companies surveyed use AI with no clear owner. That membership is self-selected and sits mostly in Auckland and the upper North Island, so read it as a picture of those firms rather than a national count.

The figure to act on is the 18% with no clear owner, because an unowned tool is one nobody can move onto a safe tier. Naming a person is the cheapest control there is, which is why a company brain needs an owner and an expiry date. Auckland firms can start on the Auckland page.

Client-confidential and regulated data: what New Zealand law requires

New Zealand law does not start at "get a contract". It starts with a question most businesses skip: when you paste customer information into an AI tool, are you disclosing it at all? Section 11 of the Privacy Act 2020 splits that in two, and none of this is legal advice.

Branch A, the provider does not use your data for its own purposes. The Privacy Commissioner says a provider storing or processing solely on your behalf is not deemed to hold the information, "which means you do not need to worry about the Privacy Act's disclosure principle (IPP 11)", and that "your organisation remains fully responsible under the Privacy Act for what happens to that information". Section 11(4) says it makes no difference that the provider is offshore, and because IPP 12 only bites on a disclosure, on this branch it has nothing to attach to either.

Branch B, the provider does use it for its own purposes. Both of you are then deemed to hold it, the sharing can be a disclosure, IPP 11 applies, and IPP 12 becomes relevant because the provider is overseas. IPP 12 rests on your own reasonable belief, not an adequacy list to look up.

The account tier decides the branch. Section 11(3) of the Privacy Act 2020 makes the trigger conduct: information is held by the provider too "if A uses or discloses the information for its own purposes". What the vendor does with your data decides how the law treats it, so the same paste is legally two different acts on two different accounts. In practice a personal consumer account, free, Plus or Pro, sits on branch B, because OpenAI may use that content to train. ChatGPT Business, Enterprise and the API sit on branch A, because no training is the default there and it is written into the agreement. A consumer user who has switched training off has changed the facts and has nothing to show for it, which is why the Privacy Commissioner asks for explicit confirmation that inputs are not retained.

Two New Zealand sources look like they conflict. The Law Society tells lawyers that input data may go overseas and they "should have regard to Information Privacy Principle 12", and that client details and privileged material in a publicly accessible tool "may also give rise to a breach of privilege and confidentiality obligations". The OPC says that on branch A you are not disclosing at all. Both are right, on different branches of the same test.

Four more things bind a New Zealand business:

The Privacy Act governs personal information, and that is a limit worth naming, because the material a professional firm most wants to protect often contains none. An engineering drawing under NDA, a commercial contract, a pricing schedule, a client's board papers: for those the operative rules are confidentiality, privilege and whatever the retainer with your client says, not the information privacy principles. Firms rarely paste that material anyway. They upload the file, which puts a whole document in front of the tool rather than a paragraph. An upload and a paste are the same act for every purpose the Azgard AI Data Boundary cares about.

Section 11's branch test never engages for a document with no personal information in it, so the Azgard AI Data Boundary's bottom row decides that material instead, splitting by the source of the duty rather than the file type. The distinction matters most where the duty is statutory or professional, because a general no-training commitment is not an agreement that says health information, or privileged material, or this client's file.

Do you need a private LLM, or is a contracted tier enough?

A private LLM is the answer New Zealand businesses reach for and few of them need. New Zealand has no OpenAI data-residency region: OpenAI's announcement lists ten, Australia among them, and says it plans to expand. Since that list grows, check the list rather than any date attached to it.

Then read section 11(4) again: it makes no difference whether the provider is outside New Zealand or holds the information there. Worrying about residency spends effort on a problem the statute has already settled. Where the data sits matters less than what the vendor does with it.

Where residency exists it is on ChatGPT Enterprise, Edu and the API, never on ChatGPT Business and never on a consumer account, and account data, billing, logs and external integrations sit outside the region anyway. For most New Zealand SMEs a contracted tier is enough. A self-hosted model buys a hosting bill, a patching schedule and somebody to own both.

How to move your team onto a safe tier in a week, without writing a policy first

Moving a team onto a safe AI account tier takes about a week, and it comes before the policy rather than instead of it. The OPC's published expectations for agencies using generative AI, still the standing guidance on its site, ask for leadership approval, a Privacy Impact Assessment and transparency with customers. The policy is still required. Moving the accounts is just faster than writing one.

  1. Days one and two, name the tiers. Ask everyone using AI which account they are on and who pays for it. If they cannot name the tier, they are on the consumer one.
  2. Day three, buy the business subscription and invite everyone onto it. Turn off "Improve the model for everyone" in Data Controls on any consumer account still in use.
  3. Day four, write the boundary on one page. Four data classes, three tiers, which crosses which.
  4. Day five, start the policy on the free tooling: the OPC's IPP 12 decision tree, its model-contract-clauses builder drafted by Chapman Tripp and aimed, in the OPC's words, at "small to medium enterprises in New Zealand", and NotifyUs.

The order matters because of the last of the OPC's eight expectations: do not input personal or confidential information "unless it has been explicitly confirmed that inputted information is not retained or disclosed by the tool provider". Explicitly confirmed means a document you can produce. After that, you can get on with teaching the tool your own material.

What Azgard does with a client's commercial data, and what it will not promise

Azgard builds on contracted tiers, in accounts the client owns. For Apex Signage, an Australian signage manufacturer and Azgard's first client, the estimating work cut quoting from around three and a half hours to just over two hours per quote, and the supplier cost snapshot underneath it holds 15,758 rows in Apex's own storage rather than Azgard's. Home Grown Electrical and Inner Game Basketball are the other two named clients.

What Azgard will not promise is the part a vendor page leaves out. Azgard is one engineer in Sydney, with no SOC 2 report, no ISO 27001 certificate and no security team. Nor is there a New Zealand company: no office here, nobody on the ground, so a New Zealand client contracts with an Australian supplier. Model accounts, the workspace and the vendor agreement go in the client's name, which makes the client the vendor's customer and Azgard a person the client can cut off. More on that on the New Zealand page.

FAQ

tags: securityprivacygovernancetooling

Angus McDonald

Angus McDonald

Founder, Azgard

Builds and operates production AI systems for organisations that need results, not slide decks.