Privacy and data hygiene when using AI at work
Beginner8 min readAI Safety & Data Privacy

Privacy and data hygiene when using AI at work

A practical guide to reducing privacy and confidentiality risk when using AI at work. Check the exact product, plan, configuration, data, and applicable rules before you paste.

What you should be able to do

Work AI hygiene starts with one rule: use the exact tool and configuration approved for the data. Add a sensitivity check, data minimization, and human review where the stakes require it.

Saved only in this browser.
In this article

Workplace AI creates a preventable risk pattern: an engineer pastes source code into a personal chatbot, a salesperson uploads a customer list to a meeting summariser, or an HR manager drafts a layoff letter in an account whose retention and access rules have not been checked. Any of these actions can expose confidential or regulated data even without a dramatic public breach.

What follows is a practical way to reduce privacy and confidentiality risk at work. It is not a substitute for your organization’s policy or an assurance that every mistake can be prevented.

A prohibition alone may not prevent unapproved use. Practical controls include approved tooling, explicit rules for each data class, access and retention settings, and workflows that make the compliant path clear.

Privacy boundary: Work content that includes personal data, customer data, source code, confidential documents, or regulated information does not belong in a personal AI account. Use the exact product, tenant, and configuration approved for that data, or do not paste it.

The fundamental issue

The technical behavior of an AI service depends on the exact product, plan, settings, contract, integrations, and provider. Jurisdiction and sector determine legal obligations, not the service’s technical defaults. Before using a tool, answer three questions:

  1. Which provider and subprocessors receive or process the content?
  2. How long can prompts, files, outputs, logs, and abuse-monitoring records be retained, and who can access them?
  3. Can any of the content be used for model improvement, including through feedback, and what settings or contract terms control that use?

The answer is product-specific. Customer data, internal financials, source code, contracts under NDA, employee details, and data covered by GDPR or sectoral rules may also require a lawful basis, minimization, access controls, a processing agreement, or a complete prohibition. Follow the applicable policy and qualified legal or security guidance.

The one rule

Start with this rule:

Use only the exact AI product, account or tenant, and configuration your company has approved for the relevant data class and task.

Approval is narrower than a brand name. Microsoft 365 Copilot, ChatGPT Enterprise, Claude for Work, Google Workspace with Gemini, Cursor, or another service may be approved for some users, connectors, and data classes but not others. Confirm the tenant, account, feature, and task.

Enterprise and business plans may provide stronger controls than consumer plans, but you must verify the current terms and configuration:

  • Model-training exclusions may apply by default to business data, with conditions or exceptions such as explicit feedback or third-party actions.
  • Data residency may be available only for eligible plans, regions, and features; it is not implied by a European customer address.
  • SOC 2, ISO 27001, and similar certifications provide assurance evidence, not automatic approval for every data class or regulated workflow.
  • Audit, retention, and administrative controls vary by product and plan and still need to be enabled and governed.
  • Access controls can be stronger when the workspace, connectors, permissions, and retention are configured correctly.

If your company has not approved a tool for the data and task, do not use AI on that work content. Request an approved workflow rather than treating a personal account or a different feature in an approved brand as a workaround.

For managers, that means the policy has to name the tool, not just the principle. “Use approved tools” is not enough if nobody knows which tool is approved.

The sensitivity check

Before pasting anything into any AI tool, run this check:

  1. Does it contain anyone’s personal data? Names, emails, addresses, ID numbers, phone numbers, health information, financial details. If yes → use only the approved workflow, minimize the data, and confirm whether AI processing is permitted.

  2. Does it contain proprietary company information? Source code, financial figures, customer lists, strategy documents, contracts under NDA. If yes → use only the approved product and configuration for that data class.

  3. Does it contain content you would not want screenshotted and shared? Internal discussions, candid commentary, anything that could cause harm if disclosed. If yes → verify approval and minimize it; Temporary or Incognito mode is not a substitute for policy.

  4. Is the data subject to a specific regulation? GDPR, HIPAA, financial regulation, export control. If yes → consult your data protection officer or compliance team before using AI on it.

  5. Could this be replaced with minimized or de-identified example data? Remove fields the task does not need and consider re-identification risk. Pseudonyms and rough numbers are not automatically anonymous and may change the analysis.

Take the time the data and task require. This check can catch obvious paste mistakes, but it does not establish legal compliance or turn an unapproved workflow into an approved one.

The three things never to paste into a personal AI account

A short list of things that, regardless of how convenient your personal ChatGPT is, do not belong there:

1. Real customer data. Even one customer’s name combined with other information can create privacy, contractual, or policy risk. Use only a specifically approved workflow, and minimize the data even there.

2. Source code from your employer’s repositories. Source code may be confidential or restricted by contract and policy. Use only the coding assistant, workspace, indexing settings, and repository scope your employer has approved.

3. Internal documents marked confidential. Strategy decks, financials, M&A discussions, legal communications. Sometimes there is no enterprise AI option at all for these — in which case do not use AI on them.

A practical data classification

Use four buckets:

BucketExamplesAI rule
PublicPublished website text, public docs, public job adsUse an authorized tool; still check copyright, terms, and task policy
InternalInternal process notes, de-identified examples, generic templatesUse the approved work tool and minimize inputs
ConfidentialCustomer data, source code, contracts, financials, strategyOnly a workflow approved for that exact data and need
RestrictedHealth data, HR investigations, legal privilege, regulated dataConfirm with legal/security before using AI

The companion checklist linked from this article is the operational version of this table.

A few practical tools and patterns

Check the temporary mode, not just its name. ChatGPT’s default non-personalized Temporary Chat excludes personalization memory, custom instructions and plugins. Optional personalized mode can use those sources but adds no memories while temporary. Unsaved temporary chats stay out of history and training. Saving either mode creates a regular chat governed by the account’s personalization and training settings. OpenAI’s dedicated FAQ also describes safety-related context, a safety copy for up to 30 days, Enterprise Compliance API access and different third-party retention. These modes do not authorize restricted data or guarantee zero retention.

Do not assume Claude Incognito works the same way. Its guide describes no history, memory use or training, but profile preferences can still apply. Retention defaults to 30 days and can be longer under organizational policy. On Team and Enterprise, organization owners can export these chats; Enterprise Compliance API access also applies. They cannot be converted into regular chats or saved to history. Check the actual product, settings and integrations within the approved workflow.

Treat training controls as one control, not a privacy guarantee. In consumer ChatGPT, turning off “Improve the model for everyone” opts new conversations out of training while keeping them in history (Data Controls FAQ). Voluntary feedback can still make the associated entire conversation available for training (model-improvement policy). Business terms and other products must be checked separately. This setting does not approve workplace use or define retention, access, subprocessors, connected actions or legal obligations.

Minimize and de-identify before pasting. Remove unnecessary fields and replace direct identifiers where the approved task permits it. “[Company A]” is pseudonymized, not necessarily anonymous; combinations of details can re-identify a person or company, and rough numbers may materially change an analysis. The European Commission explains why re-identifiable data remains personal data.

Treat “local AI” as a property to verify. A downloaded model keeps data on the device only if the full workflow is local. Check network calls, telemetry, logs, embeddings and indexes, plugins, backups, and operating-system access. A product name or local interface does not prove isolation, and local processing does not waive workplace policy or legal duties.

Be careful with file uploads. A spreadsheet with customer data, a slide deck with financial figures, a PDF of an internal report — these are higher-risk uploads than a chat message because they often contain more than you remember. Open the file, look at what is in it, decide.

A specific note on coding

The coding case is special because the stakes are real and the temptation is high. You hit a bug, you want to paste the relevant code into ChatGPT and ask what is wrong. The code is your employer’s IP.

The safer path is product- and configuration-specific:

  • Use only the employer-approved coding assistant, account, repository scope, and configuration. Verify whether the tool indexes the repository, which subprocessors receive code, what is retained, and whether feedback or settings affect training.
  • A local runtime may reduce provider exposure only after its network, telemetry, logs, indexes, plugins, and backups have been verified and approved.
  • Do not use a personal AI account on employer source code. If no approved workflow exists, ask IT or debug without disclosing proprietary code.
A developer working on abstract code beside a closed document folder
AI-generated illustration of separating a minimal coding example from sensitive workplace material.

A specific note on customer-facing AI

If you are using AI in customer-facing work — drafting customer emails, replying in customer support, generating proposals — the considerations are different. Some specific issues:

  • Disclosure. Requirements differ by jurisdiction, sector, and whether the customer interacts with AI directly or receives AI-assisted content. Check the specific law and company policy for the channel.
  • Customer data in your draft. Use only a workflow approved for that exact data and minimize what the model receives; an enterprise label alone is insufficient.
  • The downstream effects. A customer email drafted by AI and sent under your name may create commitments or contain errors. Read every word before sending unless an approved automated workflow defines other controls.

One managed pattern is to connect an approved AI service to customer context instead of manually pasting details. That architecture still needs least-privilege connector scopes, access controls, retention rules, audit logs, data-loss prevention where appropriate, output review, and approval for the relevant data and task.

Customer-facing AI output is still your output. A drafted email, proposal, or support answer can create commitments, disclose wrong information, or damage trust. Review before sending unless the workflow has been explicitly approved for automation.

When in doubt, ask

If a use case feels borderline — you are not sure if it is sensitive enough to need the enterprise tool, you are not sure if a regulator would object, you are not sure if your manager would approve — ask. The cost of asking is small; the cost of being the example in a “do not do this” training is large.

Specifically, the people in your company who can answer:

  • Your data protection officer for GDPR, customer data, employee data questions.
  • Your IT or security team for tool approval questions.
  • Your legal team for contracts, NDA, and IP questions.
  • Your manager for “is this kind of thing OK to use AI for?” judgement calls.

A short Slack message to the right person is much cheaper than the incident.

What this is not

The message is not “do not use AI at work.” An approved tool can be useful when its controls match the data and task.

It is also not “use AI for everything without thinking.” That gets people in trouble.

The practical position is to use AI where it is approved and useful, with the sensitivity check, the right configuration for the data, minimization, and proportionate human review.

Official sources checked on 11 August 2026

Keep the baseline

One rule (the exact approved workflow for the data), one habit (the sensitivity check), and three categories never to paste into a personal account (customer data, employer source code, confidential documents). This is a workable baseline, not a compliance determination; restricted and regulated data still require the designated legal, privacy, or security review.

The check is small and can prevent avoidable mistakes. When policy, contract, or law is unclear, stop before pasting and ask the responsible team.