In short
Treat a paste into ChatGPT as a transfer of personal data to a third party, because that is what GDPR calls it. A ban moves the work onto personal phones. Choose one AI tool, pay for the business tier so the data processing agreement and the training opt-out apply, write one page on what may be pasted, and switch on the Microsoft 365 data loss prevention you already own.
Someone on your team has pasted client information into ChatGPT to get a piece of work done faster. Nobody told them not to, and nothing stopped them. It comes up in onboardings, and it is one of the easier problems to close.
The instinct is to ban it. That is the response we see most often, and it pushes the same activity onto personal phones where you have no sight of it. There is a better sequence, and it takes about a fortnight.
Pasting into a chat window is a data transfer
When your bookkeeper pastes a client's management accounts into a chat window, that information leaves your network and lands on a server run by another company. In data protection terms you have transferred personal data to a third party. The law treats that the same way whether the recipient is a payroll bureau or a chat interface.
Three things follow, and none of them are obvious to the person doing the pasting.
- On free and personal accounts, providers may use what you type to improve their models. Business and enterprise tiers turn that off by contract. The account tier decides this, so the same tool behaves differently depending on who signed up.
- The conversation is stored. It sits in that person's chat history, which is often a personal account tied to a personal email address, outside anything your organisation controls.
- Most of these providers process data outside the EEA. That needs a lawful transfer route, which for the main vendors means standard contractual clauses inside a business agreement you have signed.
None of this makes AI tools unusable. It makes the account and the contract behind it the thing that matters.
You are already under rules that cover this
You do not need a new AI policy to be in scope. GDPR applies today, because client information is personal data and you are the controller of it.
Article 28 says a processor handling personal data on your behalf needs a written contract with you. A free account signed up with a work email address is not that contract. Article 32 asks you to put appropriate security measures in place, and Article 30 asks you to keep a record of your processing activities, which should name the AI tool once staff are using one.
Regulated trades sit higher again. Dental and veterinary practices handle health data, a special category under Article 9. Accountancy and legal firms carry client confidentiality duties that predate GDPR and are enforced by their own professional bodies.
There is also the EU AI Act. Its Article 4 duty on AI literacy applied from 2 February 2025, and it asks organisations using AI systems to make sure the staff operating them understand what they are doing. A short training session you can evidence is the practical answer to that.
A ban pushes the work onto personal phones
Blanket bans fail for a plain reason. The person pasting the text is trying to do their job, and the tool makes them faster at it. Block it on the office network and the work continues on a phone, on a home laptop, on an account you have never seen.
That is a worse position than the one you started in. The same data reaches the same vendor, with none of the logging, no contract, and no way to answer a client who asks what happened to their file.
Decide what people may use, then make the approved route the easiest one to take.
Six controls that hold
- Pick one tool and pay for the business tier. Microsoft 365 Copilot, ChatGPT Business or Claude Team. The paid tier is where the data processing agreement and the training opt-out live.
- Check the training setting in writing. Read what the vendor commits to on the use of your inputs, and keep a copy. Vendors and account admins can both change that setting, so check it again at renewal.
- Write one page on what may be pasted. Two lists, in the language your team uses. Client names, PPS numbers, patient records, payroll files and contracts under NDA on one side. Anonymised drafts, published documents and your own marketing copy on the other.
- Turn on the controls you already own. Microsoft 365 Business Premium includes sensitivity labels and data loss prevention (DLP, rules that stop defined content leaving your organisation). A DLP policy can stop card numbers or PPS numbers leaving in email and shared files. Blocking a paste into a browser needs endpoint DLP, so check your licence covers it before you promise it.
- Train once, with real examples. Fifteen minutes, built around two jobs your team does every week. Abstract policy training changes nothing at the keyboard.
- Add the tool to your processing record and review it quarterly. New features arrive in this category every month, and the answer you gave in March may not hold in September.
Where to start this week
Ask the question before you write the policy. Send one message to the team saying you are choosing an AI tool, and asking which ones they use now and for what. You will get an honest answer if it is clear that nobody is in trouble, and that list is your real starting position.
Then pick the tool, buy the right tier, and write the page. Our managed IT team configures the Microsoft 365 side of this, and the Technology Success Program is where the quarterly review sits that keeps it current. If you want your identity and sharing settings checked first, our note on a Microsoft 365 cloud security review covers what that looks at.
If you would rather talk it through, get in touch and we will go through what your team is using today.
Is it a GDPR breach if an employee pastes client data into ChatGPT?
It can be. You are the controller of that client data, and sending it to a provider you have no written contract with sits outside Article 28. Whether it counts as a reportable breach depends on what was sent and what the provider does with it. Record the incident, work out what left, and take advice before you decide on notifying the DPC.
Does ChatGPT train on what I type?
It depends on the account. On free and personal plans, providers generally reserve the right to use your inputs to improve their models, with an opt-out buried in settings. Business and enterprise plans turn training off contractually. Check the terms for the plan you pay for, keep a copy, and check again at renewal, because these terms change.
Should I block ChatGPT on the company network?
Blocking alone rarely works. Staff switch to a personal phone or a home laptop, and you lose all sight of what is being shared. A better order is to approve one paid tool, say in writing what may go into it, then block the rest at the firewall. The block is the last step, not the whole plan.
What should an AI acceptable use policy for a small business say?
One page is enough. Name the approved tool and account type. List what must never be pasted, using your own examples: client names, PPS numbers, patient records, payroll files, anything under NDA. Say who to ask when someone is unsure. Say that AI output is checked by a human before it reaches a client. Date it, and review it quarterly.
Do we have to tell clients we use AI tools?
If personal data about them goes into the tool, your privacy notice should say so and name the category of recipient. Some professional bodies and client contracts go further and require prior consent or a specific disclosure. Read your engagement letters before you assume the privacy notice covers it. Being upfront early costs far less than explaining it after the fact.