[nonimo]
EN
Download

Is putting client data in ChatGPT a data breach, and must you tell?

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Usually yes as a matter of fact, and sometimes yes as a matter of law. Putting client data into ChatGPT is a disclosure to a third party: the moment the text leaves the computer, an organisation outside yours holds data you were responsible for. The Australian regulator says so in as many words, and the definitions the others work from have the same shape.

Whether it is a reportable breach is a second question, decided by the risk to the people in the document, and the answer differs in London, Dublin, Melbourne and Chicago. This guide answers both and gives you the first hour.

Is putting client data in ChatGPT a data breach?

Three words do separate work here, and merging them is how firms talk themselves into the wrong decision.

QuestionWho decidesThe test
Did a disclosure happen?You, on the factsDid the text leave your control?
Is it a personal data breach?UK and EU GDPR, art. 4(1)(12)Unauthorised disclosure of, or access to, personal data
Tell the ICO or the DPC?The regulator’s thresholdRisk to people, within 72 hours of awareness, where feasible; high risk to tell them too
Australia: tell anyone?OAICSerious harm likely, after an assessment you must actually run
United StatesNo single answerContract, state statute, HIPAA if health data, professional rules

So: treat it as a breach until you have assessed it, and assess it properly, because in Australia failing to run that assessment is penalised on its own. Nothing in the next hour depends on our product, and what is built today is on the record either way.

You have already pasted it: what to do in the first hour

  1. Write down what was in it, now. Not the chat: the document. Names, how many people, whether any of it was health, financial, immigration or criminal information, and whose matter it was. Memory degrades within hours, and this list feeds every decision below.
  2. Export the conversation before you delete it. Use the account’s own export, not a screenshot: it carries the dates. Then delete, knowing what deleting does. OpenAI says a deleted chat “is removed from your account immediately and scheduled for permanent deletion from OpenAI systems within 30 days”, with two exceptions it names: material already separated from your account, and anything it must keep for security or legal reasons.
  3. Check which account it went into. A personal account, a work account on a business plan and an API call are three different legal positions.
  4. Start the clock deliberately. In the UK and Ireland the 72 hours run from awareness, not from the paste. Noting that time is the one part of the hour no product decides for you.
  5. Read the notification clause in your professional indemnity policy. Policies differ, and yours will say whether a circumstance like this has to be reported, and how fast. A single call to your broker answers it.
  6. Tell one named person, not the group chat. If an external IT provider runs your systems, they hold the tenant access and the records of who signed in. Ask for both today, in writing.

What you should not do is decide in that hour that it is fine. The next section is a firm that did.

UK and Ireland: the ICO, the 72 hours, and a fined law firm

On 14 April 2025 the Information Commissioner’s Office fined DPP Law Ltd, a firm in Bootle, Merseyside, £60,000 for infringing Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. Not a bank: a law firm. The firm said it would appeal; the penalty remains on the ICO’s register. What the tool itself does with a UK firm’s text is a separate question, answered in who your data controller is.

What matters most here is Article 33(1). DPP reported 43 days after its systems went offline, and the ICO treated the late notification as an infringement in its own right, listed alongside the security failures, not folded into them. Deciding for yourself that something has not crossed the reporting threshold does not stop the clock while you decide.

The 72 hours, and the second test for telling the client

Article 33(1) requires notice to the ICO without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to risk people’s rights and freedoms. Article 34 requires telling the affected people when the risk to them is high. The ICO puts the maximum for failing to notify at “up to £8.7 million or 2 per cent of your global turnover”.

72 hoursnotice to the ICO, from awareness, where feasible
43 daysthe delay at DPP Law, from systems offline to reporting
£60,000the penalty for four infringements, with the late report counted as one in its own right
UK GDPR Article 33(1); ICO, DPP Law Ltd penalty notice, 14 April 2025

What the SRA added in August 2026

For a solicitor, one more document changes the picture. On 17 August 2026 the Solicitors Regulation Authority published a warning notice, Misuse of AI, tying AI use to paragraph 6.3 of both SRA Codes of Conduct. Two of its lines close the arguments people actually make. The first: “Both free to use and paid for AI systems may pose risks to client confidentiality.” Paying does not settle it.

The second is the standard, and it is workable.

The SRA standard
"Client information should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality." SRA warning notice, Misuse of AI, 17 August 2026

A firm of twelve people can answer that honestly, and it is the question our organisations page is written against. The SRA covers England and Wales only.

Ireland: the same rulebook, a different postbox

The rules in Ireland are the same; the regulator you report to is different. The Data Protection Commission applies the EU GDPR, with the same obligation to report within 72 hours where the breach risks the people affected. Its contribution is a blog post of 18 July 2024, AI, Large Language Models and Data Protection: have the governance controls in place before the tool arrives, not after. Either side of the Irish Sea, the control is the one our guides describe.

Australia: APP 6, the OAIC guidance and the notifiable data breach clock

The Office of the Australian Information Commissioner published Guidance on privacy and the use of commercially available AI products on 21 October 2024 and updated it on 17 January 2025. Its famous sentence is the soft one, and it deserves quoting in full rather than being trimmed into something harder:

As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools, due to the significant and complex privacy risks involved.

That is a recommendation. The OAIC does not prohibit it, and a page telling you otherwise has put a word in the regulator’s mouth. What OpenAI itself will and will not do with an Australian file is a separate question, and storage in Australia is on one list and not the other.

The binding part: APP 6 and the insurance company

The same document has a passage that rests on binding law, and it is more useful. The guidance works through an example in which employees at an insurance company enter a customer’s claim details, including sensitive health information, into a public chatbot. Its conclusion is one sentence:

By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.

Disclosure is governed by Australian Privacy Principle 6, in Schedule 1 of the Privacy Act 1988: binding law, not best practice. An APP entity must not use or disclose information collected for one purpose for a secondary purpose unless consent or another exception applies. Which tools an Australian firm can put a client file into therefore turns on what that principle asks of each product rather than on the vendor’s own wording.

The guidance then closes the escape hatch most firms reach for, saying the reasonable expectations exception in APP 6.2(a) “may be difficult to establish … if customers were not specifically notified”. The regulator’s illustration is an ordinary office with ordinary staff, which is the situation we build for.

Failing to assess carries its own penalty

Australia also fines you for not assessing, and the trigger is reasonable grounds to suspect, not certainty. Under the Notifiable Data Breaches scheme, an entity aware of reasonable grounds to suspect an eligible breach must run “a reasonable and expeditious assessment” and take all reasonable steps to finish it within 30 days, under section 26WH(2). The threshold that follows is whether a reasonable person would conclude the disclosure is likely to result in serious harm.

On 8 October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over the 2022 Medlab Pathology breach. They were the first civil penalties ordered under the Privacy Act 1988.

$5.8mordered by the Federal Court
223,000people exposed
Firstcivil penalties under the Privacy Act 1988
OAIC, Australian Clinical Labs penalties, 9 October 2025

The penalty splits three ways: $4.2 million for failing to protect personal information under APP 11.1, $800,000 for failing to assess whether there had been an eligible data breach, and $800,000 for not notifying the Commissioner promptly.

Failing to protect data$4.2 million
Failing to assess$800,000
Late notification$800,000
Failing to protect personal information under APP 11.1; to assess whether there had been an eligible data breach; and to notify the Commissioner promptly. OAIC media release, 9 October 2025

The $800,000 for failing to assess is the one that reaches an office of twelve people, or a council of two hundred: nobody is fined for the size of their firewall, and somebody can be fined for deciding in the corridor that it was nothing.

United States: HIPAA, state breach laws and the BAA list

In Europe the fear wears the face of a registered letter. In the United States it wears the face of a subpoena. Whether OpenAI hands a conversation over, and who else can read it first, is set out in who can read a conversation.

Enforcement is split, not centralised.

WhoOver whatUnder what
Federal Trade CommissionAlmost any businessSection 5 of the FTC Act, “unfair or deceptive acts or practices”
HHS Office for Civil RightsHealth data, but only inside HIPAAThe HIPAA rules. Health data outside HIPAA answers to nobody federal
The statesTheir own residentsState statutes. California created a regulator of its own

The state clock can be shorter than Europe’s

One state has just shortened its own deadline. California Civil Code § 1798.82 requires anyone doing business in California who owns or licenses the data to notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired without authorisation.

Since SB 446 took effect on 1 January 2026 that notice is due within 30 calendar days of discovery, and above 500 California residents a sample copy goes to the Attorney General within 15 days of notifying them.

Health data: the burden runs the wrong way

With health data, the presumption works against you. Under the HIPAA Breach Notification Rule an impermissible disclosure of protected health information is presumed to be a breach unless the covered entity shows a low probability that it was compromised, on an assessment of four factors. The burden of proof sits with the entity, and notice to individuals is due within 60 calendar days of discovery.

30 calendar daysfrom discovery, to notify affected California residents
15 daysfrom notifying the residents, to send the Attorney General a sample, above 500 California residents
60 calendar daysfrom discovery, to notify individuals under HIPAA
California Civil Code § 1798.82 as amended by SB 446; HIPAA Breach Notification Rule, 45 CFR part 164 subpart D

The BAA list, and the one plan that is refused

Past that clock there is one more gate, and it is a published list rather than a negotiation. OpenAI names the products its business associate agreement covers, and keeps the page current: Every vendor publishes a list like it, and what those agreements cover and where they stop differs enough to decide which product a practice can use at all.

ProductCovered by a BAA
ChatGPT for HealthcareYes
ChatGPT for Enterprise with Regulated WorkspaceYes
ChatGPT FedRAMPYes
ChatGPT for CliniciansYes
API with Modified RetentionYes
API FedRAMP with Modified RetentionYes
ChatGPT BusinessNo, and OpenAI says so in writing

One plan carries an explicit refusal, in OpenAI’s own words: “we don’t offer a BAA for ChatGPT Business.” American lawyers have guidance of their own too: ABA Formal Opinion 512 of 29 July 2024 reads the Model Rules against generative AI, confidentiality under Rule 1.6 included. It is a committee’s reading of a model, not law until a state adopts it.

What a court did to everyone’s retention for five months

Then there is the retention order. On 13 May 2025, in the consolidated copyright litigation In re OpenAI, Inc., Copyright Infringement Litigation, a federal magistrate judge in the Southern District of New York directed OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis”, expressly including data that would have been deleted at a user’s request.

The blanket obligation no longer runs. On 9 October 2025 the court approved a stipulation ending it as of 26 September 2025, though forward preservation continues for accounts tied to a list of domains the plaintiffs named, and OpenAI still holds what it had already segregated, other than logs tied to requests from the European Economic Area, Switzerland or the United Kingdom.

Five months
of blanket preservation ordered by the court, reaching output logs that would otherwise have been deleted at a user's request. In re OpenAI, Inc., Copyright Infringement Litigation

The lesson survives the order. For five months a court in a case that had nothing to do with your client decided how long your text was kept, and your provider’s deletion policy did not get a vote. No product setting prevents that. It is the argument for keeping data out instead of deleting it later, which is why our answer is architectural, not contractual, and why the engine runs where the document already is.

What counts as client data, and why removing the names is not enough

Firms picture a leaked database. What gets pasted is a letter, and a letter is denser than it looks.

Re: 14 Bruce Street, complaint reference NR-2291
Client: Amara Nwachukwu, DOB 03/11/1974
NI number: QQ 12 34 56 C
Acting for: Mrs Nwachukwu and her daughter (minor, initials S.N.)
Previous solicitor: Harris & Poole, file ref HP/4471
Enclosed: bank statement, account ending 8812

Six lines: a name, a date of birth, a national identifier, a second person who is a child, an address, a prior adviser, a file reference at that adviser, and a partial account number.

The identifier changes shape by country, which is why a tool built for one market misses the others.

MarketThe number on the page
United KingdomNational Insurance number
IrelandPPS number
AustraliaTax file number
United StatesSocial Security number
Across EuropeIBAN

Ours is built against real office paper from each market.

Now delete every name from that fragment. A specific street address, a child in the household and a file reference at a named previous adviser will still identify the matter to anyone who has seen the file, and often to anyone in the same small town. The German federal bar, the BRAK, states the rule: removing names and addresses does not as a rule suffice where the retainer can be inferred from the context.

Identifiability is a property of the whole document, not of the words you removed. That cuts against our own pitch, and we would rather say it than have a client discover it. It is why our guides describe a control, not a guarantee.

Anonymised or pseudonymised: the word you must not claim

Pseudonymisation has a definition. The UK GDPR gives it at Article 4, now paragraph 4(1)(5) after the Data (Use and Access) Act 2025 renumbered the article with effect from 5 February 2026: processing personal data so that it can no longer be attributed to a specific person “without the use of additional information”, kept separately and protected. Everything turns on the word additional: the link back to the person still exists somewhere.

Anonymisation is irreversible, and Recital 26 is why it matters: pseudonymised data that could be attributed to a person using additional information is still personal data, while truly anonymous data falls outside the regulation. A large legal difference rests on one question: can it be reversed. The same trap sits under the word deidentified, which sounds like a legal status everywhere but is a defined standard only in American law.

Almost every product here, ours included, performs pseudonymisation. It is not a route out of data protection law, and a firm that tells a regulator it “anonymised” a file it can still reverse has made a claim it cannot support. The European Data Protection Board is still working on both halves: its pseudonymisation guidelines remain a consultation version, and its anonymisation guidelines are open for feedback to 30 October 2026. The same vocabulary runs through our guides on AI and client data.

What you can do before the next paste, cheapest first

What a tool can do here, and what no tool can do, including ours

Here is what software of this kind can do, set against what it cannot.

It canIt cannot
Catch identifiers where they sit in the structure of a document, because that is mechanicalDecide that a document is too sensitive to send at all
Verify identifiers carrying check digits arithmetically, which leaves no room for opinionNotice that a paragraph identifies someone through facts rather than names
Show what it changed and why, so a human can overrule itGuarantee nothing was missed
Leave a record that the control was on, which is what an auditor asks forMake you compliant, because compliance is not a property software has

Stated plainly, this is where we are. Nonimo’s Mac and Windows apps mask identifiers on the computer itself, before the text is sent. For a whole firm, the browser extension installed by policy, the compliance panel and the monthly report complete it, and we are not claiming more than that.

What the apps keep on your disk, encrypted, and the daily usage count they send, which never carries a word of your text, are on the security page, with what each piece does.

If you buy nothing at all, do these five things

  1. Decide which accounts your people sign in with, and verify it. It changes the legal position and costs nothing.
  2. Write the never list. Five lines naming the document types that may never be pasted. Yours will name things nobody else can guess, and a policy template whose first annex is that list gives you the headings to start from.
  3. Name the person to call. The first hour then starts with a decision, not a group chat.
  4. Log the moment you become aware. It defines your 72 hours and starts the Australian assessment.
  5. Run the assessment even when you are sure it is nothing. Australia has put $800,000 on skipping it, and the UK has made a late report a standalone infringement.

A firm that does all five is in better shape than one that bought software and did none of them. If a technical control later looks worth it, our guides on AI and client data help you judge one and the partners page explains how these deployments happen.

Two things you will read elsewhere that are wrong today

Every page named below was open in front of us on 14 September 2026, and the quotations are theirs.

A third claim, that turning training off makes client data safe to paste, is answered above in OpenAI’s own words. Dates move as well, which is the point of our note on the EU AI Act: a control that was adequate one year has to be checked again the next.


Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account, and your client’s details never leave your machine.

Sources

Checked 14 September 2026.


This page is for information and is not legal advice. For your own matter, ask your regulator or a qualified adviser.

Common questions

Is putting client data in ChatGPT a data breach?

Putting client data into an account your organisation does not control is a disclosure to a third party. Whether it is a reportable breach is a second question, decided by the risk to the people in the document, and the UK, Ireland, Australia and the US answer it differently.

Do I have to tell the client if a staff member pasted their file into ChatGPT?

Sometimes, and it is not the same test as telling the regulator. In the UK and Ireland you tell the affected people when the risk to them is high. In Australia you tell them when serious harm is likely. A contract or a professional duty can require it anyway.

Does turning off training make client data safe to paste?

It removes one use and leaves the rest. OpenAI's own answer is that chats you exclude from training still appear in your history. The text was still sent to a third party, still retained for a period, and still reachable under legal process.

Is ChatGPT covered by a HIPAA business associate agreement?

Only for a named list of products that OpenAI publishes and keeps current. One plan carries an explicit refusal: OpenAI states it does not offer a business associate agreement for ChatGPT Business. Patient data in an uncovered plan sits outside the BAA, and a processing addendum is not one.

Is Microsoft 365 Copilot safer than ChatGPT for client data?

For the same document, usually, because a work account brings enterprise data protection and Microsoft states that prompts and responses are not used to train its foundation models. One exception matters: the web search queries Copilot generates leave that boundary.

Does anonymising a document before pasting solve the problem?

It lowers the risk and rarely removes it. Most tools in this category replace identifiers reversibly, which is pseudonymisation, and pseudonymised data is still personal data for whoever holds the key. A document can also identify someone through context alone, with every name gone.

Do we have to buy a tool to be compliant?

No. No regulator names a product, and no product makes an organisation compliant on its own. Software is one control among several, and a small firm gets most of the way there with account settings, a short written rule and the habit of recording what happened.