Knowledge · Is this AI tool safe · 8 minutes
Is ChatGPT safe for business data? Facts and settings
What OpenAI does with what you type into ChatGPT: training, 30-day retention, Business and Enterprise plans, EU data, the Garante fine. As of October 2026.
Last updated: October 5, 2026
Is ChatGPT safe? What it depends on
The question "is ChatGPT safe" has two parts. One: what happens to what you type. Two: whether you can trust the answers. This article covers the first part, your data.
OpenAI runs two separate sets of rules. Personal plans are covered by the Europe privacy policy (version of August 2026). Business plans and the API are covered by the Enterprise privacy page (version of 8 January 2026) and the customer agreement. The privacy policy says plainly that it does not apply to content processed on behalf of business customers, such as the API.
So the same employee can paste the same document in two places and get two different sets of rules. A personal account opened with a work email is still a personal account. If everyone at your company uses their own account, that is shadow AI: the company does not know where its data goes.
What happens to data you type into ChatGPT: personal vs business plans
Personal plans (Free, Go, Plus, Pro). According to the OpenAI Help Center, content from these services may be used to train models. You can turn this off. Even after opting out, rating a response (thumbs up or down) can send the whole conversation into training. Deleted chats and temporary chats are removed from OpenAI systems within 30 days, unless they must be kept for legal or security reasons.
For Free and Go, the current privacy policy also covers ads. OpenAI collects information about the ads you see and, with your consent, may tailor them to past chats. Non-personalised ads may use the context of the current conversation.
Business plans (Business, Enterprise, Edu) and the API. According to the Enterprise privacy page, OpenAI does not train on business data by default and inputs and outputs belong to the customer. On Enterprise and Edu the admin sets the retention period. API data may be kept for up to 30 days to provide the service and detect abuse. Workspace admins can view, export and delete members' conversations.
Which data is fine to paste at all is covered in can you paste data into ChatGPT.
Where ChatGPT processes data and on what legal basis
For users in the EEA and Switzerland the controller is OpenAI Ireland Limited in Dublin. The lead supervisory authority is the Irish Data Protection Commission (DPC).
The privacy policy says data is processed on servers outside the EEA, including in the United States. As the transfer basis OpenAI cites European Commission adequacy decisions and standard contractual clauses (Article 46(2)(c) GDPR).
Companies get extra options. OpenAI signs a DPA for Business, Enterprise and the API. Since 5 February 2025 eligible API customers can process data in Europe, and new ChatGPT Enterprise and Edu customers can store content at rest in Europe. According to an update on 16 January 2026, eligible Enterprise and Edu customers can also choose inference in Europe. On the Business plan, according to the OpenAI Help Center, choosing a storage region is rolling out gradually. It covers storage, not processing, and with a region outside the US a copy of prompts and responses is kept in the US for a limited time for abuse monitoring.
How to stop ChatGPT training on your data, step by step
Personal account: 1. Open Settings, then Data controls. 2. Turn off "Improve the model for everyone". 3. Use a temporary chat for conversations you do not want kept in history. 4. Under Personalization, review what ChatGPT stored in Memory and delete what you do not need. 5. Do not rate responses in chats that contain confidential data.
Instead of step 2 you can select "Do not train on my content" in the OpenAI privacy portal (privacy.openai.com). OpenAI says either route is enough. Opting out applies to new conversations, not earlier ones.
Company: 1. Choose Business or Enterprise instead of personal accounts. 2. Sign the DPA. 3. Turn on SSO and decide who has access. 4. Set a retention period. 5. Write it down in your AI usage policy.
If someone pasted an API key or a .env file into a chat, deleting the chat is not enough. Rotate the key. You can identify what exactly was pasted with the Paste tool, which runs in your browser and sends nothing.
ChatGPT incidents and regulator decisions
March 2023, Italy. The Italian data protection authority (Garante) temporarily limited ChatGPT's processing of data. The service came back after OpenAI made changes.
20 December 2024, Italy. The Garante announced it had closed its investigation and fined OpenAI 15 million euros (decision of 2 November 2024). It cited training without a proper legal basis, transparency gaps, no age verification and failure to notify a data breach from March 2023. It also ordered a six-month information campaign and passed further matters to the Irish DPC.
18 March 2026, Italy. In a judgment of that date the Court of Rome annulled the fine (reported by the ANSA news agency on 20 March 2026). According to the reasoning published later, the court held that from 15 February 2024, when OpenAI's Irish company became its main EU establishment, the Irish authority was competent. The court did not assess the Garante's findings on the merits. As of 5 October 2026 we found no information on whether the Garante appealed.
2025, USA. In the New York Times lawsuit a court ordered OpenAI to preserve conversation data, including deleted chats. According to OpenAI the obligation ended on 26 September 2025. The company still holds a limited set of data from April to September 2025. It excludes conversations from the EEA, Switzerland and the UK.
Is ChatGPT safe for kids, and on WhatsApp
Kids. According to the privacy policy the services are not meant for children under 13, and users under 18 need permission from a parent or guardian. A parent can link their account to a teen's, manage some settings including training on conversations, and get alerts when OpenAI detects a serious risk.
WhatsApp. The 1-800-ChatGPT number on WhatsApp stopped working on 15 January 2026. OpenAI said the reason was a change in WhatsApp's terms. If something claims to be "ChatGPT on WhatsApp" today, it is not an official OpenAI channel. Check that number or link first.
ChatGPT at work: when it makes sense and when it does not
It makes sense when the company buys a business plan, signs a DPA, manages accounts centrally and has written rules. Then you know who is responsible for the data, where it is and for how long.
It does not make sense when staff paste client data, personal data or trade secrets into personal accounts. Be careful with data that by contract or law must not leave the EEA. First check in the contract where data is stored and where it is processed, because storage in Europe does not always mean processing in Europe.
Ask the same questions about other tools. Compare with our articles on Copilot, Gemini and DeepSeek.
What we do not know
We do not know exactly how OpenAI reduces personal data in training sets. The Help Center only says the company takes steps to reduce it.
We do not know how many users are in the data set retained because of the New York Times case, or when it will be deleted. Nor do we know security details beyond what OpenAI describes publicly and in the SOC 2 audit it refers to.
In short
- The plan sets the rules: personal accounts may be used for training, business ones are not by default.
- On a personal account, turn off "Improve the model for everyone" and do not rate confidential chats.
- At work: Business or Enterprise, a DPA, SSO and a written policy instead of personal accounts.
- EU data may go to the US; European residency covers Enterprise, Edu and the API, and is rolling out gradually on Business.
- The 2024 Garante fine was annulled by the Court of Rome on 18 March 2026 because the authority lacked competence.
Have a website, app or email address that looks suspicious?
Frequently asked questions
Is it safe to use ChatGPT?
It depends on what you type and on which account. On a personal account conversations may be used for training until you turn it off. Do not paste client data or trade secrets into personal accounts.
Does ChatGPT save my conversations?
Yes, they stay in your history until you delete them. Deleted chats and temporary chats are removed within 30 days, unless law or security requires keeping them longer.
Is ChatGPT safe for kids?
According to OpenAI the service is not for children under 13, and teens need a parent's permission. A parent can link their account to a teen's and manage some settings.
Is ChatGPT on WhatsApp safe?
The official ChatGPT on WhatsApp has not worked since 15 January 2026. A number or bot that presents itself that way today is not an OpenAI channel.
Does ChatGPT Business train on company data?
According to OpenAI, no: by default data from Business, Enterprise, Edu and the API is not used for training. The exception is when the customer chooses to share it, for example by sending feedback.
Sources
- OpenAI: Europe privacy policy (updated August 2026)
- OpenAI Help Center: How your data is used to improve model performance
- OpenAI: Enterprise privacy (updated 08.01.2026)
- OpenAI: Introducing data residency in Europe (05.02.2025, updated 16.01.2026)
- Italian data protection authority (Garante): press release of 20.12.2024 (15 million euro fine)
- ANSA: Court of Rome annuls the Garante fine against OpenAI (20.03.2026)
- Diritto.it: reasoning of Court of Rome judgment no. 4785 of 18.03.2026 (03.06.2026)
- OpenAI Help Center: Where your ChatGPT Business content is stored
- OpenAI: How we're responding to The New York Times' data demands (updated 22.10.2025)
- OpenAI: Continuing your ChatGPT experience beyond WhatsApp (21.10.2025)
Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.