Skip to main content
Talk to a human
AI Assistant

What Employees Should Never Paste Into ChatGPT

Eight categories, why the PDPA treats a paste as a disclosure, and what to do when it has already happened.

Short answer

Anything that identifies a person, anything covered by a confidentiality obligation, and anything that would be a problem if it appeared in a competitor’s inbox. The practical test: if you would not email it to a stranger, do not paste it into a chatbot. Under the PDPA, pasting customer data into a public AI tool is a disclosure to a third party, and the obligations that apply to any other disclosure apply to that one.

The list, in order of how much trouble it causes

Do not pasteWhy
Customer names, NRIC numbers, addresses, phone numbersPersonal data under the PDPA. Pasting it into a public tool is a disclosure, and almost certainly one your customer never consented to.
Whole spreadsheets or CRM exportsThe most common serious incident we see. One paste can disclose thousands of records at once.
Employee records, salaries, performance notes, medical informationStaff data is personal data too, and this category is more sensitive than most customer data.
Client documents under an NDAA confidentiality obligation does not have an AI exception. Pasting is disclosure.
Unreleased commercial informationPricing models, tender responses, contract terms, roadmaps, board material.
Credentials, API keys, access tokensShould never be pasted anywhere. Anything pasted into a chat log should be treated as compromised and rotated.
Source code from a private repositoryDepends on your agreements and your employer’s policy, but assume no unless told otherwise.
Anything about an identifiable third partyIncluding screenshots. Redaction that leaves a name in a header is not redaction.

Why “it is just a chatbot” is the wrong mental model

The intuition that a chat window is private comes from it feeling like a search box. It is not. Depending on the product and the settings, what you type may be retained, may be reviewed by humans for quality or safety, and may be used to improve the service. Consumer tiers and enterprise tiers differ substantially here, and most staff have no idea which one they are using.

Under the PDPA the relevant question is not whether the tool is trustworthy. It is that you have disclosed personal data to a third party, so the Consent, Purpose Limitation and Transfer Limitation obligations apply, and you now have to be able to answer for that disclosure.

The scenario that actually happens

Nobody sets out to leak anything. Someone is busy, has a messy customer list, and pastes it in to ask for it to be tidied into a table. It works, it saves twenty minutes, and it never occurs to them that they have just disclosed several hundred people’s personal data to a third party. That is the entire incident, and no amount of security tooling prevents it. Training does.

What is fine to paste

  • Anything already public. Your published marketing copy, public documentation, public filings.
  • Genuinely anonymised data. Genuinely, meaning an individual cannot be re-identified by combining it with something else, which is harder than replacing names with initials.
  • Hypotheticals and structures. Describe the shape of the problem rather than supplying the real data. “I have a list with name, email and purchase date, write me a formula that…” works without pasting a single record.
  • Your own drafting. Text you wrote that contains nothing confidential and nobody else’s personal data.

That third habit is the one worth teaching, because it preserves almost all of the productivity benefit while removing almost all of the risk.

If someone has already pasted something

  1. Do not just delete the chat and move on. Deleting your view of it does not necessarily remove it everywhere.
  2. Establish what was pasted, and whose data it was. Categories and rough volume, not a vague description.
  3. Rotate anything credential-shaped immediately.
  4. Tell whoever holds your DPO role. They assess whether it is a notifiable data breach. That assessment is theirs to make, not the person who pasted it.
  5. Record the decision either way. If it is judged not notifiable, the reasoning is what you will need later.

The data breach response guide covers the assessment and notification steps, and DPO responsibilities covers who owns that call.

The fix is a rule people can actually remember

Long policies do not survive contact with a deadline. What works is one line staff can recall under pressure, plus a short list of what is approved. Ours is the one at the top of this page: if you would not email it to a stranger, do not paste it.

The AI use policy template is a starting point you can adapt. Using ChatGPT safely at work covers the wider operating model around it, and our AI training is where the habit actually gets built, because a policy nobody has practised is a document rather than a control.

Worried this is already happening?

It probably is. In most teams we work with, staff are already using AI tools that were never approved and nobody has counted. That is a governance question as much as a training one: our free AI governance guide covers the inventory and risk classification side.

Common questions

What should you never paste into ChatGPT?

Anything that identifies a person, anything under a confidentiality obligation, and anything commercially sensitive. That covers customer and employee personal data, spreadsheets and CRM exports, client documents under NDA, unreleased pricing or contract terms, credentials and API keys, and private source code. The practical test is whether you would email it to a stranger.

Is pasting customer data into ChatGPT a PDPA breach?

It is a disclosure of personal data to a third party, and the PDPA obligations that apply to any other disclosure apply to it, including consent and purpose limitation. Whether a particular incident amounts to a notifiable breach depends on the data and the circumstances, which is an assessment for whoever holds your DPO role.

Is it safe if I use the paid or enterprise version?

Safer, but it changes the risk rather than removing it. Enterprise tiers typically offer stronger commitments on retention and training use. The disclosure to a third party has still happened, so the obligations still apply, and most staff do not actually know which tier they are signed into.

What if I remove the names first?

Better, but be careful what counts as anonymised. Data is only anonymised if an individual cannot be re-identified by combining it with something else. Replacing names with initials while leaving postcodes, dates of birth or transaction histories usually is not enough.

What do I do if someone has already pasted confidential data?

Do not simply delete the chat. Establish what was pasted and whose data it was, rotate anything credential-shaped immediately, and tell whoever holds your DPO role so they can assess whether it is a notifiable breach. Record the decision either way, including the reasoning if it is judged not notifiable.

How do we stop this happening without banning AI tools?

Banning them mostly drives usage onto personal accounts where you have no visibility at all. What works is a short rule people can remember under pressure, a list of approved tools, and training that lets staff practise describing a problem instead of pasting the data behind it.

Disclaimer: This page is general information, not legal advice. The Personal Data Protection Act and the PDPC’s advisory guidelines are the authoritative sources, and requirements change. For your own obligations, seek qualified advice.

Want your team trained on this properly?

Our AI training builds the habit, not just the policy, using your team’s real workflows.

Schedule Consultation