Skip to content
AZGARD
security

Is ChatGPT safe for company data in the UK? The account decides

Is ChatGPT safe for company data? In the UK the account tier, not the model, decides training, retention and whether you get a DPA at all.

Angus McDonald · 25 Aug 2026 · 12 min read

written for United Kingdom ● also for Australia, United States, Canada, New Zealand

Is ChatGPT safe for company data in the UK? The account decides

ChatGPT is safe for UK company data on some accounts and not on others. The Azgard AI Data Boundary maps four classes of data - public, internal operational, personal data about customers or staff, client-confidential or regulated - against three account tiers: personal consumer (free, Plus or Pro), paid business subscription, and contracted workspace or API. The model is identical across all three. Training, retention, human review and whether a DPA exists are not.

Why "is ChatGPT safe for company data" is the wrong question

"Is ChatGPT safe for company data" cannot be answered about ChatGPT: the same model reaches a UK business through three products with three sets of terms. The next question most UK SMEs type, "is it UK GDPR compliant?", has no answer either. Compliance is a property of your processing, and no product carries it for you.

The Azgard AI Data Boundary starts from one fact: the model does not decide what happens to your data. The account does. Name the tier you are on, read three lines of that tier's published terms - training, retention, human review - and match them against the most sensitive class of data you intend to paste. If you cannot name the tier, you are on the consumer one.

The commonest unsafe account in a UK small business is not the free one. It is somebody's personal Plus subscription, expensed on the card statement.

The three AI account tiers, and what each one's published terms say about your data

The three AI account tiers are personal consumer, paid business subscription, and contracted workspace or API. The row that decides most UK cases is the last one: whether a data processing addendum is on offer at all.

Account tierTrains on your content by defaultRetention controlAdmin visibilityDPA
Personal consumer: free, Plus or ProYes, for its services for individualsDeleted chats and Temporary Chats gone within 30 daysNoneNo
Paid business subscription: ChatGPT BusinessNo, by defaultAdmins control retentionAdmins can view, access, export, and delete end user conversationsYes
Contracted workspace or API: Enterprise, Edu, APINo, contractually rather than by settingContent deleted 30 days after terminationAudit log via the Enterprise Compliance APIYes, plus storage at rest in the UK

"Paid" is not the boundary; "business" is. Plus and Pro are paid consumer subscriptions sitting in row one. A free user can also switch training off in Data Controls, so the consumer tier is not unconditionally training on you. What the purchase buys is Services Agreement §4.2, a written commitment not to use Customer Content to improve the Services. A toggle is a preference. A contract is a commitment.

A tier sets the default and nothing more. OpenAI trains on a conversation you give feedback on even after you opt out, and Anthropic retains chats you allow to improve Claude de-identified for up to five years.

The Azgard AI Data Boundary: which class of data may cross which tier

The Azgard AI Data Boundary is a line, not a ladder. Four data classes run down the side and three account tiers across the top. Find the most sensitive thing you are about to paste, then read across.

Class of company data (Azgard AI Data Boundary)Personal consumer (free, Plus, Pro)Paid business subscriptionContracted workspace or API
Public or already publishedYesYesYes
Internal operational: process notes, templates, non-personal recordsNoYesYes
Personal data about customers or staffNoOnly once a lawful basis is documented and a DPA is heldYes, same condition
Client-confidential or regulated: NDA and other contractually confidential material, or anything under a professional or statutory dutyNoContractual confidentiality only, and only where your own contract permits disclosure to a processorYes, under an agreement your contract or your regulator's rules permit

The personal-data row carries a UK footnote. The ICO lists seven lawful bases under UK GDPR and says you must determine yours before you start using the personal information, and document it. Special category data needs an additional condition. The obligation attaches before the paste, so no account tier settles it for you.

The fourth row splits on where your duty comes from, which is the distinction most guidance skips. If the material is confidential by contract - an NDA, a client agreement with a confidentiality clause - no sector rules apply and the business tier's DPA is often the right answer, provided your own contract permits disclosure to a processor at all. If the duty is statutory or professional-conduct based, it waits for the signed agreement, because no setting and no subscription can consent on the regulator's behalf. A design studio holding an unreleased product and a solicitor holding a matter are not in the same position, and a grid that treats them alike is wrong about one of them. Read the NDA before you assume either answer.

What happens to a prompt you paste into a consumer AI account

A prompt pasted into a consumer AI account leaves your network and sits in an account nobody in your business administers, under whatever retention and training terms the vendor sets for consumers. It is also discoverable. In the New York Times copyright litigation, OpenAI's published answer says ChatGPT Free, Plus, Pro and Team data and non-ZDR API data were in scope for preservation while Enterprise and Edu were excluded. The ABA Journal then reported that a magistrate judge ordered production of 20 million de-identified chat logs, and that a district judge affirmed that order in early January 2026. The tier drew that line in a court docket rather than a marketing page.

A 30-day deletion promise and a preservation order can both be true at once, which is worth saying because the two look like they cancel. OpenAI's preservation obligation ended on 26 September 2025 and its standard retention practices resumed. The January 2026 production order concerns the April to September 2025 data already held, not anything pasted since.

Shadow AI: your staff are already pasting company data into personal accounts

Shadow AI is company data going into personal AI accounts without anyone deciding it should, and the UK's own statistics say most firms touching AI have no process to stop it. The Cyber Security Breaches Survey 2025/2026 found that of the roughly one third of businesses using, adopting or considering AI, only 24% had cyber security practices in place to manage the risks from it. Methodology: a random probability survey of 2,112 UK businesses, fieldwork August to December 2025, weighted, excluding sole traders. The ONS puts adoption higher, at 29% in June 2026 against the 21% who had adopted some AI tools in the Breaches Survey, on different definitions. That 21% sits in the survey's figure 3.15 adoption breakdown rather than its body text, so searching the page for the number will not find it.

No verified UK survey counts how many staff paste client material into a personal account, so count it yourself: check the card statement for personal AI subscriptions, then ask the three people who write the most documents which account they use.

Client-confidential and regulated data: what the law where you operate requires

Client-confidential and regulated data in the UK sits under two tests, and passing one does not pass the other. The SRA's warning notice of 17 August 2026 sets the first: "Both paid for and free-to-use AI tools may not provide the contractual, and technical safeguards needed to maintain client confidentiality." Rule 6.3 of the Code of Conduct covers all client affairs, not only personal data, so a solicitor pasting a matter into a consumer account is in breach whether or not a data subject is involved. That is a stricter test than UK GDPR, and it reaches accountants and brokers too.

If your confidentiality duty is contractual rather than professional, an NDA or a client agreement rather than a code of conduct, the SRA notice does not bind you and its test is still the one worth borrowing: ask whether the account you are using provides the contractual and technical safeguards your own agreement obliges you to maintain. Read the confidentiality clause before you read the vendor's terms, because some agreements forbid disclosure to any third party at all, and no account tier can fix that.

An Article 28 contract is the second test client data has to pass. The ICO's contracts guidance lists nine terms such a contract must contain, among them documented instructions only, a duty of confidence, and deletion or return at the end. Article 28(1) puts the duty on you: use only a processor providing "sufficient guarantees". Hold your vendor's standard DPA against those nine clauses yourself.

Signing a DPA does not settle your legal role under UK GDPR. The ICO's position is that "a contract does not necessarily determine whether an organisation is a controller, joint controller or processor. Instead, this is determined by the practical realities of the processing", and for closed-access models it considers joint controllership likely. The tier determines the facts; what those facts make you, legally, is a separate assessment.

Sending personal data to a US AI vendor is a restricted transfer under UK GDPR and needs a basis of its own. The UK Extension to the EU-US Data Privacy Framework is a separate arrangement from the EU's, and four things all have to be true before you can rely on it. The entity named on your contract appears on the DPF list, not a parent company or a trading name. Its status reads Active. Its certification covers the UK Extension specifically, not the EU framework alone. And the data you are sending falls inside its registered scope. Fail any one of the four and you are on the IDTA or the Addendum plus a transfer risk assessment, now a "data protection test" in UK legislation. Record the date you checked and check again at renewal, because certifications lapse. The higher maximum fine is £17.5 million or 4% of turnover, not the €20 million figure UK articles still quote. None of this is legal advice.

Do you need a private LLM, or is a contracted tier enough?

A private LLM is the right answer for a UK SME far less often than the people selling private LLMs suggest. A contracted workspace already gives you a no-training default in writing, plus admin visibility, retention control and a DPA.

Residency is where the honest answer gets uncomfortable. OpenAI lists the United Kingdom for data residency at rest but not inference residency, which covers only Europe, the United States and the UAE. You can keep your data stored here; the model that reads it still runs elsewhere. Residency reaches eligible API customers and new ChatGPT Enterprise and Edu workspaces, not ChatGPT Business. Account data, billing, logs and anything passed to an external integration sit outside the region regardless. Where a rule forbids the transfer outright, private deployment is the only thing that answers it.

How to move your team onto a safe tier in a week, without writing a policy first

Moving a UK team onto a safe AI tier in a week is a sequencing decision. The policy still has to be written, and it needs a lawful basis assessment, probably a DPIA, and sign-off from busy people. Your exposure does not pause while you wait for all that, so do the tier first and write the policy over data that is already protected.

Five days, in order. Buy the business subscription for everyone touching customer information. Turn training off and set retention at the workspace, then screenshot both. Cancel the personal Plus subscriptions on the card statement. Send one paragraph naming the tier and the class of data that never goes into it. Then write the policy, using the ICO's free AI and data protection risk toolkit and its advice for small organisations.

Client-confidential and regulated material is not covered by that week's work. Material under a professional or statutory duty stays out of every AI account until a signed agreement your own rules permit is in place. Material that is confidential by contract needs the contract read first, for whether it permits disclosure to a processor at all.

One thing plenty of vendors leave vague: the UK has brought in no new AI rules you are behind on, and there is no AI-specific statute. The FCA has said in writing it would avoid additional regulations for AI by relying on existing frameworks, and the ICO's core AI guidance still carries a March 2023 update date. The rules are settled; the guidance is mid-refresh.

What Azgard does with a client's commercial data, and what it will not promise

Azgard builds inside a client's own accounts and tenancy, on a contracted tier, and the first version of a regulated engagement often deliberately carries no client data at all: internal process, templates, precedent, research. That is the answer the Edinburgh page already gives financial services firms. Where your rules do not permit something, the answer is that they do not permit it, not a workaround, and the method is in how to train AI on your company data.

The first-party evidence is narrow and Australian. At Apex Signage, quoting time fell from around three and a half hours to just over two per quote, and a supplier cost snapshot built for the same client runs to 15,758 rows. Home Grown Electrical and Inner Game Basketball are the other two named clients. Three, not thirty.

The unflattering half: Azgard is Sydney-based and delivers remotely, with no UK entity, office or staff, and invoices from an Australian business, as the UK page says. There is no Companies House record, no ICO fee-payer entry and no Cyber Essentials certificate to check, because none exists. Azgard will not tell you a purchase makes you compliant. If that is not enough assurance for procurement, the honest recommendation is a consultant who can meet it.

FAQ

tags: securitygovernancedata-protectionuk-gdprchatgpt

Angus McDonald

Angus McDonald

Founder, Azgard

Builds and operates production AI systems for organisations that need results, not slide decks.