ChatGPT can be used safely in a business setting, but the right setup matters. The privacy and data controls available to a personal ChatGPT account are different from those available through ChatGPT Business, ChatGPT Enterprise or the OpenAI API.
How OpenAI handles business data
| Option | How business data is handled |
|---|---|
| ChatGPT Business or Enterprise | OpenAI does not use business inputs or outputs to train its models by default. |
| OpenAI API | API data is not used for model training by default. Inputs and outputs may be retained for up to 30 days for abuse monitoring, with eligible organisations able to request stricter retention controls. |
| Personal ChatGPT accounts | These should not be treated as a business-approved system for sensitive client information without clear internal rules and appropriate privacy settings. |
OpenAI encrypts business data at rest using AES-256 and in transit using TLS 1.2 or higher. This is strong encryption, but it is not the same thing as end-to-end encryption. Businesses should still control who can access AI tools, what employees are permitted to upload and which connected apps or external services are enabled.
Australian data residency
Australian data residency is now available for eligible new ChatGPT Enterprise and Education customers. It allows in-scope customer content, such as conversations, files and custom GPT content, to be stored at rest in Australia.
However, data residency does not mean every part of the service stays in Australia. Account details, billing data, system metadata, external integrations and some processing may still occur outside the selected region. Businesses using web search, apps, connectors or third-party GPTs should assess those services separately.
Privacy obligations for Australian businesses
Businesses covered by the Privacy Act 1988 must comply with the Australian Privacy Principles when handling personal information. In practice, this means collecting only what is needed, being clear about how information is used, protecting it with reasonable technical and organisational safeguards, and considering overseas disclosures when using cloud-based AI services.
A Data Processing Addendum can be executed with OpenAI for ChatGPT Business, ChatGPT Enterprise and the API. This can help clarify each party’s data-protection responsibilities, but it does not replace a business’s own privacy policy, staff training or risk assessment.
Practical steps before using ChatGPT with business data
- Use a business-managed ChatGPT workspace or API account rather than personal staff accounts.
- Do not upload sensitive personal, financial, health or confidential client data unless the use case has been approved.
- Set clear staff rules on what can and cannot be entered into AI tools.
- Review retention, access controls, connected apps and data-residency requirements.
- Get legal or privacy advice where the use case involves sensitive information or regulated industries.
Used with the right controls, ChatGPT can save time without compromising sensible privacy practices. Contact ROI Growth Agency to discuss a practical and secure AI setup for your business.