ChatGPT Privacy & Security Checklist Print

  • 0

 

Safe: Drafting emails, summarising public information, creating meeting agendas.

Use Caution: Internal business information, project documentation, customer communications.

Do Not Upload: Credentials, personal information, financial records, health information, confidential contracts, or regulated data.

Account Integration Warning: Do not connect Microsoft 365, Microsoft Outlook, Google Workspace, Gmail, Google Drive, OneDrive, SharePoint, Teams, or other business systems to third-party AI services unless the service has been formally approved by your organisation and reviewed by IT, Security, or Compliance teams.

 

1. Use the Right ChatGPT Subscription

Recommended order of preference:

✅ ChatGPT Enterprise

✅ ChatGPT Team

✅ Microsoft 365 Copilot

⚠️ ChatGPT Plus (personal use only)

❌ ChatGPT Free for business data

 

Business Use Warning: Consumer AI accounts are designed primarily for individual use. Before processing company information, use an organisation-approved AI platform and ensure the data can be shared in accordance with your organisation's security, privacy, and compliance requirements.

 


2. Disable Model Training

Settings → Data Controls → Improve the model for everyone → OFF

This prevents future conversations from being used to improve OpenAI's models.


3. Use Temporary Chat for Sensitive Work

For:

  • Customer information
  • Financial information
  • Security investigations
  • Contract reviews
  • Internal business discussions

Use Temporary Chat.

Temporary chats are not saved in history, do not create memories, and are not used for model training.


4. Disable Memory

Settings → Personalization → Memory → OFF

Memory can retain details across conversations, which is generally undesirable for business use.


5. Delete Existing Memories

Review and remove any existing memories that may contain:

  • Customer details
  • Project information
  • Internal business discussions

6. Enable Multi-Factor Authentication (MFA)

Settings → Security → Multi-Factor Authentication

Protects access to:

  • Chat history
  • Uploaded files
  • Saved memories
  • Connected apps

7. Review Connected Applications

Check any connected:

  • OneDrive accounts
  • Google Drive accounts
  • Calendars
  • Third-party integrations

Remove anything not required.

Account Integration Warning: Do not connect Microsoft 365, Microsoft Outlook, Google Workspace, Gmail, Google Drive, OneDrive, SharePoint, Teams, or other business systems to third-party AI services unless the service has been formally approved by your organisation and reviewed by IT, Security, or Compliance teams.

 


8. Remove Old Shared Conversation Links

Settings → Data Controls → Manage Shared Links

Delete links that no longer need to be accessible.


9. Regularly Delete Old Chats

At least quarterly:

  • Delete customer-related discussions
  • Delete old project discussions
  • Delete sensitive business conversations


10. Never Enter Restricted Information

Even with all privacy settings configured correctly:

Do Not Enter:

  • Passwords
  • MFA codes
  • API keys
  • Encryption keys
  • Bank account details
  • Credit card numbers
  • Medical records
  • Passport details
  • Customer databases
  • Legal privileged information

Use placeholders and redacted data instead.


 

 


Was this answer helpful?

« Back