Is putting client data in ChatGPT a data breach, and must you tell?
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Usually yes as a matter of fact, and sometimes yes as a matter of law. Putting client data into ChatGPT is a disclosure to a third party: the moment the text leaves the computer, an organisation outside yours holds data you were responsible for. The Australian regulator says so in as many words, and the definitions the others work from have the same shape.
Whether it is a reportable breach is a second question, decided by the risk to the people in the document, and the answer differs in London, Dublin, Melbourne and Chicago. This guide answers both and gives you the first hour.
Is putting client data in ChatGPT a data breach?
Three words do separate work here, and merging them is how firms talk themselves into the wrong decision.
- Disclosure. Nobody has to read the text for this one to be true. It is true the moment the text arrives somewhere you do not control.
- Personal data breach. Article 4(1)(12) of the UK GDPR defines it as “a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed”. The ICO’s own examples include “access by an unauthorised third party”.
- Reportable breach. The one that costs you a phone call to the client. Telling the regulator and telling the people are two tests with two thresholds, and firms that merge them get both wrong.
| Question | Who decides | The test |
|---|---|---|
| Did a disclosure happen? | You, on the facts | Did the text leave your control? |
| Is it a personal data breach? | UK and EU GDPR, art. 4(1)(12) | Unauthorised disclosure of, or access to, personal data |
| Tell the ICO or the DPC? | The regulator’s threshold | Risk to people, within 72 hours of awareness, where feasible; high risk to tell them too |
| Australia: tell anyone? | OAIC | Serious harm likely, after an assessment you must actually run |
| United States | No single answer | Contract, state statute, HIPAA if health data, professional rules |
So: treat it as a breach until you have assessed it, and assess it properly, because in Australia failing to run that assessment is penalised on its own. Nothing in the next hour depends on our product, and what is built today is on the record either way.
You have already pasted it: what to do in the first hour
- Write down what was in it, now. Not the chat: the document. Names, how many people, whether any of it was health, financial, immigration or criminal information, and whose matter it was. Memory degrades within hours, and this list feeds every decision below.
- Export the conversation before you delete it. Use the account’s own export, not a screenshot: it carries the dates. Then delete, knowing what deleting does. OpenAI says a deleted chat “is removed from your account immediately and scheduled for permanent deletion from OpenAI systems within 30 days”, with two exceptions it names: material already separated from your account, and anything it must keep for security or legal reasons.
- Check which account it went into. A personal account, a work account on a business plan and an API call are three different legal positions.
- Start the clock deliberately. In the UK and Ireland the 72 hours run from awareness, not from the paste. Noting that time is the one part of the hour no product decides for you.
- Read the notification clause in your professional indemnity policy. Policies differ, and yours will say whether a circumstance like this has to be reported, and how fast. A single call to your broker answers it.
- Tell one named person, not the group chat. If an external IT provider runs your systems, they hold the tenant access and the records of who signed in. Ask for both today, in writing.
What you should not do is decide in that hour that it is fine. The next section is a firm that did.
UK and Ireland: the ICO, the 72 hours, and a fined law firm
On 14 April 2025 the Information Commissioner’s Office fined DPP Law Ltd, a firm in Bootle, Merseyside, £60,000 for infringing Articles 5(1)(f), 32(1), 32(2) and 33(1) of the UK GDPR. Not a bank: a law firm. The firm said it would appeal; the penalty remains on the ICO’s register. What the tool itself does with a UK firm’s text is a separate question, answered in who your data controller is.
What matters most here is Article 33(1). DPP reported 43 days after its systems went offline, and the ICO treated the late notification as an infringement in its own right, listed alongside the security failures, not folded into them. Deciding for yourself that something has not crossed the reporting threshold does not stop the clock while you decide.
The 72 hours, and the second test for telling the client
Article 33(1) requires notice to the ICO without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to risk people’s rights and freedoms. Article 34 requires telling the affected people when the risk to them is high. The ICO puts the maximum for failing to notify at “up to £8.7 million or 2 per cent of your global turnover”.
What the SRA added in August 2026
For a solicitor, one more document changes the picture. On 17 August 2026 the Solicitors Regulation Authority published a warning notice, Misuse of AI, tying AI use to paragraph 6.3 of both SRA Codes of Conduct. Two of its lines close the arguments people actually make. The first: “Both free to use and paid for AI systems may pose risks to client confidentiality.” Paying does not settle it.
The second is the standard, and it is workable.
A firm of twelve people can answer that honestly, and it is the question our organisations page is written against. The SRA covers England and Wales only.
Ireland: the same rulebook, a different postbox
The rules in Ireland are the same; the regulator you report to is different. The Data Protection Commission applies the EU GDPR, with the same obligation to report within 72 hours where the breach risks the people affected. Its contribution is a blog post of 18 July 2024, AI, Large Language Models and Data Protection: have the governance controls in place before the tool arrives, not after. Either side of the Irish Sea, the control is the one our guides describe.
Australia: APP 6, the OAIC guidance and the notifiable data breach clock
The Office of the Australian Information Commissioner published Guidance on privacy and the use of commercially available AI products on 21 October 2024 and updated it on 17 January 2025. Its famous sentence is the soft one, and it deserves quoting in full rather than being trimmed into something harder:
As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools, due to the significant and complex privacy risks involved.
That is a recommendation. The OAIC does not prohibit it, and a page telling you otherwise has put a word in the regulator’s mouth. What OpenAI itself will and will not do with an Australian file is a separate question, and storage in Australia is on one list and not the other.
The binding part: APP 6 and the insurance company
The same document has a passage that rests on binding law, and it is more useful. The guidance works through an example in which employees at an insurance company enter a customer’s claim details, including sensitive health information, into a public chatbot. Its conclusion is one sentence:
By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.
Disclosure is governed by Australian Privacy Principle 6, in Schedule 1 of the Privacy Act 1988: binding law, not best practice. An APP entity must not use or disclose information collected for one purpose for a secondary purpose unless consent or another exception applies. Which tools an Australian firm can put a client file into therefore turns on what that principle asks of each product rather than on the vendor’s own wording.
The guidance then closes the escape hatch most firms reach for, saying the reasonable expectations exception in APP 6.2(a) “may be difficult to establish … if customers were not specifically notified”. The regulator’s illustration is an ordinary office with ordinary staff, which is the situation we build for.
Failing to assess carries its own penalty
Australia also fines you for not assessing, and the trigger is reasonable grounds to suspect, not certainty. Under the Notifiable Data Breaches scheme, an entity aware of reasonable grounds to suspect an eligible breach must run “a reasonable and expeditious assessment” and take all reasonable steps to finish it within 30 days, under section 26WH(2). The threshold that follows is whether a reasonable person would conclude the disclosure is likely to result in serious harm.
On 8 October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over the 2022 Medlab Pathology breach. They were the first civil penalties ordered under the Privacy Act 1988.
The penalty splits three ways: $4.2 million for failing to protect personal information under APP 11.1, $800,000 for failing to assess whether there had been an eligible data breach, and $800,000 for not notifying the Commissioner promptly.
The $800,000 for failing to assess is the one that reaches an office of twelve people, or a council of two hundred: nobody is fined for the size of their firewall, and somebody can be fined for deciding in the corridor that it was nothing.
United States: HIPAA, state breach laws and the BAA list
In Europe the fear wears the face of a registered letter. In the United States it wears the face of a subpoena. Whether OpenAI hands a conversation over, and who else can read it first, is set out in who can read a conversation.
Enforcement is split, not centralised.
| Who | Over what | Under what |
|---|---|---|
| Federal Trade Commission | Almost any business | Section 5 of the FTC Act, “unfair or deceptive acts or practices” |
| HHS Office for Civil Rights | Health data, but only inside HIPAA | The HIPAA rules. Health data outside HIPAA answers to nobody federal |
| The states | Their own residents | State statutes. California created a regulator of its own |
The state clock can be shorter than Europe’s
One state has just shortened its own deadline. California Civil Code § 1798.82 requires anyone doing business in California who owns or licenses the data to notify any California resident whose unencrypted personal information was, or is reasonably believed to have been, acquired without authorisation.
Since SB 446 took effect on 1 January 2026 that notice is due within 30 calendar days of discovery, and above 500 California residents a sample copy goes to the Attorney General within 15 days of notifying them.
Health data: the burden runs the wrong way
With health data, the presumption works against you. Under the HIPAA Breach Notification Rule an impermissible disclosure of protected health information is presumed to be a breach unless the covered entity shows a low probability that it was compromised, on an assessment of four factors. The burden of proof sits with the entity, and notice to individuals is due within 60 calendar days of discovery.
The BAA list, and the one plan that is refused
Past that clock there is one more gate, and it is a published list rather than a negotiation. OpenAI names the products its business associate agreement covers, and keeps the page current: Every vendor publishes a list like it, and what those agreements cover and where they stop differs enough to decide which product a practice can use at all.
| Product | Covered by a BAA |
|---|---|
| ChatGPT for Healthcare | Yes |
| ChatGPT for Enterprise with Regulated Workspace | Yes |
| ChatGPT FedRAMP | Yes |
| ChatGPT for Clinicians | Yes |
| API with Modified Retention | Yes |
| API FedRAMP with Modified Retention | Yes |
| ChatGPT Business | No, and OpenAI says so in writing |
One plan carries an explicit refusal, in OpenAI’s own words: “we don’t offer a BAA for ChatGPT Business.” American lawyers have guidance of their own too: ABA Formal Opinion 512 of 29 July 2024 reads the Model Rules against generative AI, confidentiality under Rule 1.6 included. It is a committee’s reading of a model, not law until a state adopts it.
What a court did to everyone’s retention for five months
Then there is the retention order. On 13 May 2025, in the consolidated copyright litigation In re OpenAI, Inc., Copyright Infringement Litigation, a federal magistrate judge in the Southern District of New York directed OpenAI to “preserve and segregate all output log data that would otherwise be deleted on a going forward basis”, expressly including data that would have been deleted at a user’s request.
The blanket obligation no longer runs. On 9 October 2025 the court approved a stipulation ending it as of 26 September 2025, though forward preservation continues for accounts tied to a list of domains the plaintiffs named, and OpenAI still holds what it had already segregated, other than logs tied to requests from the European Economic Area, Switzerland or the United Kingdom.
The lesson survives the order. For five months a court in a case that had nothing to do with your client decided how long your text was kept, and your provider’s deletion policy did not get a vote. No product setting prevents that. It is the argument for keeping data out instead of deleting it later, which is why our answer is architectural, not contractual, and why the engine runs where the document already is.
What counts as client data, and why removing the names is not enough
Firms picture a leaked database. What gets pasted is a letter, and a letter is denser than it looks.
Re: 14 Bruce Street, complaint reference NR-2291
Client: Amara Nwachukwu, DOB 03/11/1974
NI number: QQ 12 34 56 C
Acting for: Mrs Nwachukwu and her daughter (minor, initials S.N.)
Previous solicitor: Harris & Poole, file ref HP/4471
Enclosed: bank statement, account ending 8812
Six lines: a name, a date of birth, a national identifier, a second person who is a child, an address, a prior adviser, a file reference at that adviser, and a partial account number.
The identifier changes shape by country, which is why a tool built for one market misses the others.
| Market | The number on the page |
|---|---|
| United Kingdom | National Insurance number |
| Ireland | PPS number |
| Australia | Tax file number |
| United States | Social Security number |
| Across Europe | IBAN |
Ours is built against real office paper from each market.
Now delete every name from that fragment. A specific street address, a child in the household and a file reference at a named previous adviser will still identify the matter to anyone who has seen the file, and often to anyone in the same small town. The German federal bar, the BRAK, states the rule: removing names and addresses does not as a rule suffice where the retainer can be inferred from the context.
Identifiability is a property of the whole document, not of the words you removed. That cuts against our own pitch, and we would rather say it than have a client discover it. It is why our guides describe a control, not a guarantee.
Anonymised or pseudonymised: the word you must not claim
Pseudonymisation has a definition. The UK GDPR gives it at Article 4, now paragraph 4(1)(5) after the Data (Use and Access) Act 2025 renumbered the article with effect from 5 February 2026: processing personal data so that it can no longer be attributed to a specific person “without the use of additional information”, kept separately and protected. Everything turns on the word additional: the link back to the person still exists somewhere.
Anonymisation is irreversible, and Recital 26 is why it matters: pseudonymised data that could be attributed to a person using additional information is still personal data, while truly anonymous data falls outside the regulation. A large legal difference rests on one question: can it be reversed. The same trap sits under the word deidentified, which sounds like a legal status everywhere but is a defined standard only in American law.
Almost every product here, ours included, performs pseudonymisation. It is not a route out of data protection law, and a firm that tells a regulator it “anonymised” a file it can still reverse has made a claim it cannot support. The European Data Protection Board is still working on both halves: its pseudonymisation guidelines remain a consultation version, and its anonymisation guidelines are open for feedback to 30 October 2026. The same vocabulary runs through our guides on AI and client data.
What you can do before the next paste, cheapest first
-
Free: decide which account people sign in with. It is the largest lever a small firm has, because it changes which contract governs the text. OpenAI states that for consumer services “we may use your content to train our models”, while “by default, we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API.”
-
Free: turn off training in consumer accounts, and know the limit. The setting is “Improve the model for everyone”, under Settings then Data Controls. OpenAI states the limit itself: chats you exclude “will still show up in your history, but they won’t be used to improve ChatGPT.” It removes a use. It does not undo a disclosure or end retention.
-
Free: write one page. Which documents may never be pasted, and who to call when someone does it anyway. Collect the acknowledgements: an unsigned rule is hard to enforce. The same signed page is what an insurer’s question about AI asks you to attach, so it earns its keep twice.
-
Already paid for, if you are on Microsoft 365: signing in with a Microsoft Entra work or school account brings what Microsoft calls enterprise data protection. Microsoft states that “prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation LLMs”, and that Copilot Chat prompts and responses stay within the Microsoft 365 service boundary, at no extra cost on licences most firms already hold.
There is one exception, and it matters. The web search queries Copilot generates leave that boundary: they go to Bing, which Microsoft says “operates separately from Microsoft 365” and where it acts as an independent data controller under the Microsoft Services Agreement rather than the data protection addendum, outside Microsoft’s HIPAA and FERPA commitments.
Those queries carry no user or tenant identifiers and do not train the models, but they sit outside the perimeter people believe they bought. It is the detail an IT provider should raise before you sign.
-
Costs money: a tool that masks identifiers before the text is sent. That is our category, and firms this size deploy through the provider who owns the rollout.
What a tool can do here, and what no tool can do, including ours
Here is what software of this kind can do, set against what it cannot.
| It can | It cannot |
|---|---|
| Catch identifiers where they sit in the structure of a document, because that is mechanical | Decide that a document is too sensitive to send at all |
| Verify identifiers carrying check digits arithmetically, which leaves no room for opinion | Notice that a paragraph identifies someone through facts rather than names |
| Show what it changed and why, so a human can overrule it | Guarantee nothing was missed |
| Leave a record that the control was on, which is what an auditor asks for | Make you compliant, because compliance is not a property software has |
Stated plainly, this is where we are. Nonimo’s Mac and Windows apps mask identifiers on the computer itself, before the text is sent. For a whole firm, the browser extension installed by policy, the compliance panel and the monthly report complete it, and we are not claiming more than that.
What the apps keep on your disk, encrypted, and the daily usage count they send, which never carries a word of your text, are on the security page, with what each piece does.
If you buy nothing at all, do these five things
- Decide which accounts your people sign in with, and verify it. It changes the legal position and costs nothing.
- Write the never list. Five lines naming the document types that may never be pasted. Yours will name things nobody else can guess, and a policy template whose first annex is that list gives you the headings to start from.
- Name the person to call. The first hour then starts with a decision, not a group chat.
- Log the moment you become aware. It defines your 72 hours and starts the Australian assessment.
- Run the assessment even when you are sure it is nothing. Australia has put $800,000 on skipping it, and the UK has made a late report a standalone infringement.
A firm that does all five is in better shape than one that bought software and did none of them. If a technical control later looks worth it, our guides on AI and client data help you judge one and the partners page explains how these deployments happen.
Two things you will read elsewhere that are wrong today
Every page named below was open in front of us on 14 September 2026, and the quotations are theirs.
- “The Italian regulator fined OpenAI 15 million euros.” Not any more. The Court of Rome upheld OpenAI’s appeal in judgment No. 4153/2026, published 18 March 2026, and the Garante has temporarily removed decision No. 755 of 2 November 2024 from its own site, leaving a note saying so. Pages still presenting the fine as standing include syrenis.com, updated a month after the annulment, and wald.ai, updated 6 August 2026.
- “ChatGPT uses end-to-end encryption.” OpenAI’s enterprise privacy page, updated 8 January 2026, claims something narrower and more accurate: “Data encryption at rest (AES-256) and in transit between our customers and us, and between us and our service providers (TLS 1.2+).” Encryption at rest is not end-to-end encryption, and the page never says it is. intuitionlabs.ai, on a page dated 18 April 2026, still lists “end-to-end encryption” among ChatGPT Enterprise’s features.
A third claim, that turning training off makes client data safe to paste, is answered above in OpenAI’s own words. Dates move as well, which is the point of our note on the EU AI Act: a control that was adequate one year has to be checked again the next.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT. No account, and your client’s details never leave your machine.
Sources
Checked 14 September 2026.
- OAIC, Guidance on privacy and the use of commercially available AI products, 21 October 2024, updated 17 January 2025. The wording on best practice, the insurance example, the APP 6.2(a) difficulty.
- OAIC, APP Guidelines chapter 6. APP 6 as binding law.
- Privacy Act 1988 (Cth), ss. 26WE, 26WH, 26WK. The assessment within 30 days and the serious harm threshold.
- OAIC, Australian Clinical Labs penalties, 9 October 2025. The $5.8 million and its split.
- ICO, DPP Law Ltd penalty notice (PDF), 14 April 2025, with its register entry. The £60,000, the 43 days, Article 33(1) as a separate infringement.
- ICO, personal data breaches: a guide. The definition, the 72 hours, the penalty cap.
- SRA, warning notice Misuse of AI, 17 August 2026. Both quoted lines, and paragraph 6.3.
- DPC, AI, Large Language Models and Data Protection, 18 July 2024. The governance point, filed as a blog post.
- UK GDPR Article 4. Both definitions, and the 2026 renumbering.
- EDPB, Guidelines 01/2025 on Pseudonymisation (PDF), 16 January 2025. Its header: “Adopted - version for public consultation”.
- EDPB, Guidelines 02/2026 on Anonymisation, 7 July 2026, feedback to 30 October 2026.
- California Civil Code § 1798.82. The two clocks, as amended by SB 446.
- 45 CFR part 164, subpart D. The presumption of breach, the 60 days, the burden of proof.
- FTC, privacy and security enforcement. Section 5 as its main instrument.
- OpenAI, chat and file retention. The 30 days and its exceptions.
- OpenAI, data controls FAQ. The setting name, and its limits.
- OpenAI, how your data is used to improve model performance. The consumer and business defaults.
- OpenAI, HIPAA eligible products. The six eligible products.
- OpenAI, how to get a BAA for the API Services. The refusal, verbatim: “we don’t offer a BAA for ChatGPT Business”.
- OpenAI, enterprise privacy, 8 January 2026. The encryption wording.
- Microsoft, enterprise data protection. The service boundary and the Bing exception.
- Microsoft, data, privacy and security for Microsoft 365 Copilot. Not training foundation models.
- ABA Formal Opinion 512 (PDF), 29 July 2024. Model Rule 1.6. The Bar’s own copy blocks automated requests; this is the same file, from the National Conference of Bar Presidents.
- New York Times v. Microsoft docket. The preservation order and its termination.
- Garante, notice on decision No. 755. Its removal after judgment No. 4153/2026.
- BRAK, guidance on the use of AI (PDF), December 2024. Names removed does not as a rule suffice.
This page is for information and is not legal advice. For your own matter, ask your regulator or a qualified adviser.
Common questions
Is putting client data in ChatGPT a data breach?
Putting client data into an account your organisation does not control is a disclosure to a third party. Whether it is a reportable breach is a second question, decided by the risk to the people in the document, and the UK, Ireland, Australia and the US answer it differently.
Do I have to tell the client if a staff member pasted their file into ChatGPT?
Sometimes, and it is not the same test as telling the regulator. In the UK and Ireland you tell the affected people when the risk to them is high. In Australia you tell them when serious harm is likely. A contract or a professional duty can require it anyway.
Does turning off training make client data safe to paste?
It removes one use and leaves the rest. OpenAI's own answer is that chats you exclude from training still appear in your history. The text was still sent to a third party, still retained for a period, and still reachable under legal process.
Is ChatGPT covered by a HIPAA business associate agreement?
Only for a named list of products that OpenAI publishes and keeps current. One plan carries an explicit refusal: OpenAI states it does not offer a business associate agreement for ChatGPT Business. Patient data in an uncovered plan sits outside the BAA, and a processing addendum is not one.
Is Microsoft 365 Copilot safer than ChatGPT for client data?
For the same document, usually, because a work account brings enterprise data protection and Microsoft states that prompts and responses are not used to train its foundation models. One exception matters: the web search queries Copilot generates leave that boundary.
Does anonymising a document before pasting solve the problem?
It lowers the risk and rarely removes it. Most tools in this category replace identifiers reversibly, which is pseudonymisation, and pseudonymised data is still personal data for whoever holds the key. A document can also identify someone through context alone, with every name gone.
Do we have to buy a tool to be compliant?
No. No regulator names a product, and no product makes an organisation compliant on its own. Software is one control among several, and a small firm gets most of the way there with account settings, a short written rule and the habit of recording what happened.