CRYPTOITDATACRYPTOITDATA

Artificial intelligence

Your employees already put client data into ChatGPT

Shadow AI: employees paste client data into ChatGPT from personal accounts. What AI vendors keep, what GDPR actually says and why a simple ban does not hold.

11 min read

In early 2026, Gartner surveyed more than 12,000 employees and managers in 40 countries. Among those who already had access to an AI tool provided by their employer, 88% also used a personal one for work tasks. Verizon, which measures differently — from data loss prevention telemetry rather than surveys — found that 45% of employees regularly use AI on work devices, up from 15% a year earlier, and 67% of them sign in with accounts that are not the company’s. So the question is no longer whether your people put client data into ChatGPT. It is which account they use and under which contract.

In Romania, Eurostat shows a gap that says something about how AI enters companies. In 2025, only 5.2% of companies with at least 10 employees reported using AI, the lowest share in the EU, against an average of 20%. In the same year, 17.8% of Romanians aged 16 to 74 were already using generative AI. These are different populations and one cannot be subtracted from the other, but the direction is clear: in many Romanian companies, AI did not arrive through a management decision but through people.

How often client data ends up in ChatGPT

The figures below come from security vendors and surveys, mostly of large companies in the US and Western Europe. We cite them separately, each with its source, because they measure different things and cannot be added up into a single average.

  • Copy-paste: in browser telemetry from its customers, LayerX found that 77% of employees who use generative AI paste data into chatbots. 82% of those pastes come from personal, unmanaged accounts, and 22% contain personal or payment card data.
  • Files: across more than three million prompts and files, Harmonic Security measured in Q3 2025 that 26.38% of files uploaded to AI tools contained sensitive information. 21.81% of the sensitive data went to tools that train on what users enter.
  • Client data, self-reported: in a PagerDuty / Wakefield Research survey from June 2026 of 1,250 office workers at companies with revenue above $500 million, 88% said they had put work information into public AI, and 34% had entered customer data.
  • Volume: Netskope reports that data policy violations involving generative AI doubled in a year. The average organization in its telemetry sees around 223 incidents a month, and regulated data (personal, financial, health) accounts for 54% of violations.

One detail matters: both Harmonic and LayerX measure through browser extensions. Native phone apps and direct API calls do not show up in their numbers. We do not know how large the unseen part is. We only know that, for whatever happens on phones, these measurements underestimate rather than overestimate.

And the cost is not theoretical. In its Cost of a Data Breach 2025 report, IBM studied 600 organizations that had suffered a breach: one in five reported a breach caused by shadow AI. Where shadow AI was widespread, the breach cost on average $670,000 more than where it was rare or absent. Only 37% of organizations had policies to manage AI or detect shadow AI.

Same ChatGPT, two completely different regimes

This is the part most internal discussions miss. The same product, with the same logo, follows almost opposite rules depending on the account you sign in with. In short, based on the vendors’ public documentation:

  • ChatGPT Free, Plus and Pro: using conversations for training is on by default. The “Improve the model for everyone” setting can be switched off, but it only applies to new conversations. Temporary chats do not train the model, but are kept for up to 30 days.
  • ChatGPT Business, Enterprise and the API: data is not used for training by default. OpenAI offers a data processing addendum (DPA) and data residency in Europe. On the API, inputs may be retained for up to 30 days for abuse monitoring, except for customers with Zero Data Retention.
  • Gemini with a personal Google account: some conversations are read by human reviewers, and reviewed ones are kept for up to three years. With “Keep Activity” on, activity is also used for training; with it off, chats are kept for 72 hours. Google itself advises against entering confidential information.
  • Gemini in Google Workspace (eligible editions): content is not reviewed by humans and is not used for training outside the company’s domain without permission.
  • Microsoft Copilot with a work account: covered by the Microsoft DPA, with Microsoft as processor, and prompts do not train the foundation models. One exception worth knowing: web queries sent to Bing follow a different regime, Microsoft acts as an independent controller there, and the EU Data Boundary does not apply to them.
  • Claude Free, Pro and Max: since 28 August 2025, users choose whether their data is used for training. If they opt in, retention is five years; if not, 30 days. The rule does not apply to Claude for Work or the API.

Two episodes show how little control you have over a conversation held on a consumer account. In the New York Times lawsuit against OpenAI, the company was ordered to preserve even deleted chats, until 26 September 2025. The order covered Free, Plus, Pro, Team and the API without Zero Data Retention; ChatGPT Enterprise and Edu were not included. And in summer 2025, conversations shared through the “Make this chat discoverable” option showed up in Google results, until OpenAI withdrew the option on 31 July / 1 August. The option had to be switched on explicitly, so this was not a leak of “all” chats. It is an example of how easily a link shared in a hurry ends up where you would not expect it.

The problem is not AI, it is the account without a contract

GDPR draws a distinction that completely changes the picture: controller versus processor. When the company uses ChatGPT Business, Enterprise or the API, OpenAI’s DPA states that the company is the controller and OpenAI is the processor, acting on the company’s instructions. That is exactly what Article 28 GDPR requires: a contract with whoever processes data on your behalf. When an employee puts the same data into their personal account, that contract does not exist. For consumer users in the European Economic Area, the controller is OpenAI Ireland, under a contract between the provider and the employee. Your company is not a party to it.

We are not lawyers and this article is not a substitute for legal advice, but the reasoning is simple: your clients’ data reaches a third party that processes it on its own terms, with no contract with you and without your instructions. Transfer outside the EU is not the heart of the problem. On 3 September 2025 the EU General Court upheld the EU-US Data Privacy Framework, although an appeal before the CJEU is still pending. The heart of it is the missing contract and the missing control.

The useful question is not whether your employees use AI. It is on whose account, under which contract, and whether you would ever find out.

The Dutch data protection authority said it plainly as early as August 2024, after receiving notifications from a GP practice and a telecom company whose employees had entered patient data and customer addresses, respectively, into a chatbot. Its position: this can be a data breach, and notifying the authority and the affected individuals is often mandatory. At the end of 2025 it returned to the topic: dozens of such notifications in 2024 and 2025, more of them in 2025, many coming from free tools employees had used on their own initiative.

The best-documented case is the municipality of Eindhoven. An internal check covering 23 September – 23 October 2025 showed that employees had uploaded files containing personal data to public AI websites: child protection documents, CVs, internal reports. The breach was notified on 23 October. The municipality blocked the sites, moved staff to an AI tool inside its own secure environment and asked OpenAI to delete the files. The total volume could not be established. It is a Dutch public body, not a Romanian SMB, but the mechanism is the same everywhere.

For a company in Romania, the competent authority is ANSPDCP, the national data protection authority; elsewhere in the EU it is your national supervisory authority, and the regulation is the same. Article 33 requires notification within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals, and requires every breach to be documented internally, including the ones you do not notify. Article 32 requires appropriate technical and organizational measures; a written rule about what goes into AI is, in practice, one of them.

There is another layer beyond personal data: contracts. We have not found any ruling stating that entering a document into ChatGPT breaches a non-disclosure agreement. Practitioners say it depends on the wording: if the NDA prohibits disclosure to third parties or limits use to a specific purpose, a consumer AI service may fall under the prohibition. The same goes for trade secrets: Directive (EU) 2016/943, transposed in Romania by Government Emergency Ordinance 25/2019 and elsewhere by equivalent national laws, protects information only if its holder has taken “reasonable steps” to keep it secret. Some lawyers warn that prices or client lists put into a public AI may weaken exactly that argument. It is worth rereading the confidentiality clauses in your major contracts with this question in mind.

Why a ban does not hold

The natural reflex is to block ChatGPT at the firewall and send an email. Samsung went that way in May 2023, after engineers put internal source code into ChatGPT: it banned generative AI on company devices and networks. The relevant detail is what it had to do in parallel: ask employees not to share company information from personal devices either, and build its own internal tools. Blocking on the company network does not reach the phone in someone’s pocket.

Recent data says the same thing. In the PagerDuty survey, 66% of employees had used AI at work even though they believed they were not allowed to. And Gartner shows that even having an official tool does not stop people using a personal one. What does help is the alternative: in Netskope telemetry from October 2024 to October 2025, the share of AI users on personal apps fell from 78% to 47%, while the share on company-managed accounts rose from 25% to 62%. A later report from the same company, covering a different period with a different breakdown, shows however that the decline stalled around March 2026: 30% use only personal apps, and another 14% use both.

The conclusion the data points to: an approved, convenient tool reduces the problem substantially, but does not close it on its own. You also need a clear rule about which data may go in, and some form of visibility into what is happening.

What works: a short policy, classification, an approved alternative

Order matters. If you start by blocking, people move the activity to their phones and you lose what little visibility you had. If you start with the alternative but no rules, you have just moved the problem into a paid account.

  1. 1Find out what is already in use. Ask the team directly, without an interrogation tone, and look in proxy or DNS logs for AI tool domains. The goal is a map: who, which tool, for which task. The tasks tell you what alternative you need to offer.
  2. 2Write the policy on a single page. Which tools are approved and with which account, which data never goes into AI, who answers questions, and what an employee who made a mistake should do: report it immediately, without being punished for reporting. You need to know within hours, not a month later, because the 72-hour clock runs from the moment you become aware.
  3. 3Classify data in three colors. Green: public information and general text, any approved tool. Yellow: internal documents without personal data, only on a company account with a DPA. Red: clients’ personal data, health or financial data, contracts under confidentiality clauses, prices and source code, only in the approved internal tool or not at all. An employee should be able to decide in three seconds.
  4. 4Give people an equally convenient alternative. If the company already works in Microsoft 365 or Google Workspace, start there: Copilot with a work account is covered by the Microsoft DPA, and Gemini in eligible Workspace editions does not train on company data outside the domain. Other options are ChatGPT Business and Claude for Work. Check three things before you sign: the DPA, that training is switched off, and where the data is hosted.
  5. 5For the red category, consider an internal assistant on company documents. It answers from your procedures, manuals and contracts, citing the source, on a business API account, under a DPA, with no training on data by default. Retention settings matter too: on the API, OpenAI may keep inputs for up to 30 days for abuse monitoring, except under Zero Data Retention.
  6. 6Run a short training session and keep a record of it. Since February 2025, the AI Act has also required companies that merely use AI to take care of their people’s AI literacy. The July 2026 Omnibus relaxed the wording: the company must take measures that support AI literacy, without guaranteeing a particular level, and an internal record of the training is enough. A short session built on the examples in your policy is a good start.
  7. 7Prepare the steps for the day it happens. Document the incident, even if you do not notify it. Assess the risk to the people affected and, if there is one, notify the data protection authority (ANSPDCP, in Romania) within 72 hours. Ask the provider to delete the data, as Eindhoven did, and change the settings of the account involved.

With us, the policy, data loss prevention and logging work is part of our AI agency service, and the company’s GDPR framework is covered under cybersecurity, alongside NIS2 and sector-specific requirements. The internal assistant is the AI Chatbot package in our packages: a chatbot on your documents (RAG), with OpenAI or Claude models. The MVP version, with one use case and one channel, is delivered in 2–3 weeks, at RON 8,500 for implementation and RON 350 a month for operation, which covers hosting with us and the OpenAI API. We say openly what that means: requests go to the model through the business API, under contract; they do not run on a server in your office. And if the conversation turns to where company data lives and how long you keep it, we have written separately about data retention under GDPR.

Once this is in order, the next question is where AI brings in money, not just risk. We covered that in our analysis of AI ROI for SMBs.

Conclusion

Your people already use AI, and the difference between a compliance problem and a productivity tool is not the model but the account: a personal one, with no contract with the company, or a company one, with a DPA, training switched off and clear rules about what goes into it. A ban moves the problem to the phone; a one-page policy, three data colors and a convenient alternative bring it back under control. If you want to see what that would look like for your team, from the policy to the internal assistant, let’s talk for 30 minutes.

Sources

  • Gartner — Global Labor Market Survey 1Q26, press release of 13 May 2026 (gartner.com)
  • Verizon — 2026 Data Breach Investigations Report (verizon.com/business/resources/reports/dbir)
  • Netskope — Cloud and Threat Report 2026, January 2026, and the 2026 AI report, via IT Brief, July 2026 (netskope.com; itbrief.co.uk)
  • PagerDuty / Wakefield Research — shadow AI survey, 11 June 2026 (pagerduty.com)
  • IBM — Cost of a Data Breach Report 2025, 30 July 2025 (newsroom.ibm.com)
  • Harmonic Security — report on sensitive data in GenAI tools, 18 November 2025 (harmonic.security)
  • LayerX — Enterprise AI and SaaS Data Security Report 2025, via The Register, 7 October 2025 (theregister.com)
  • Eurostat — AI use in enterprises (11 December 2025) and generative AI use by individuals (16 December 2025) (ec.europa.eu/eurostat)
  • OpenAI — Enterprise Privacy, Data controls in ChatGPT, Data Processing Addendum (openai.com; help.openai.com)
  • Google — Gemini Apps Privacy Hub and Generative AI in Google Workspace Privacy Hub (support.google.com; knowledge.workspace.google.com)
  • Microsoft Learn — Enterprise data protection in Microsoft Copilot (learn.microsoft.com)
  • Anthropic — “Updates to our consumer terms”, 28 August 2025 (anthropic.com)
  • Duane Morris, Engadget — the preservation order in NYT v. OpenAI; Malwarebytes, Fortune — withdrawal of the “Make this chat discoverable” option, August 2025
  • Autoriteit Persoonsgegevens — warning on AI chatbots and data breaches, 6 August 2024 (autoriteitpersoonsgegevens.nl); Accountant.nl, 30 December 2025
  • Binnenlands Bestuur and Omroep Brabant — the Eindhoven municipality data breach, 19 December 2025
  • Bloomberg — Samsung bans generative AI after code leak, 2 May 2023 (bloomberg.com)
  • Regulation (EU) 2016/679 (GDPR); Directive (EU) 2016/943 and Romanian GEO 25/2019 (trade secrets); AI Act, Art. 4, as amended by Regulation (EU) 2026/1744 (Omnibus) (eur-lex.europa.eu)
  • IAPP, Hunton — EU General Court upholds the EU-US Data Privacy Framework (Latombe, T-553/23), 3 September 2025 (iapp.org)

Frequently asked questions

Is it legal for employees to put client data into ChatGPT?+

On a personal account, the risk is high: the company has no data processing agreement (DPA) with the provider, even though Article 28 GDPR requires one for anyone processing data on its behalf. The Dutch data protection authority considers that entering personal data into a chatbot can be a data breach. On a company account, with a DPA, training switched off and clear internal rules, the situation is different. For your company’s specific case, the final call belongs to a lawyer.

What is the difference between free ChatGPT and ChatGPT Business for company data?+

On Free, Plus and Pro, using conversations for training is on by default, and switching it off only applies to new conversations. On Business, Enterprise and the API, data is not used for training by default, and OpenAI offers a DPA and data residency in Europe. The legal role matters too: on a consumer account, OpenAI is an independent controller; on a business account, the company is the controller and OpenAI is the processor.

If an employee put a client’s personal data into ChatGPT, do I have to notify the data protection authority?+

It depends on the risk. GDPR requires notification within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals. Whatever you decide, the incident must be documented internally. The Dutch authority has said explicitly that in such cases notification is often mandatory, so the assessment needs to be done quickly and in writing. In Romania, the competent authority is ANSPDCP.

Does it help to ban ChatGPT in the company?+

On its own, a ban moves the problem to personal phones. Samsung banned generative AI on company devices in 2023 and had to ask employees, in parallel, not to share information from personal devices either. In a 2026 PagerDuty survey, 66% of employees had used AI even though they believed they were not allowed to. A short policy, data classification and an equally convenient approved alternative work better.

Have a concrete question?

30 minutes, free. We discuss exactly your situation.

Book a consultation