Is It Safe to Put Customer Data in ChatGPT? Privacy Rules for Support
11 min read
Putting customer data in ChatGPT or any AI tool is safe only when you send less than you think you need. This lesson covers what to strip, which settings to check, and when to tell customers AI is involved.
Support is where AI meets personal information. A customer email carries a name, an address, an order history, sometimes a health detail or a card dispute. Paste the whole thing into a free chatbot and that information now sits on someone else's servers under terms you probably haven't read.
You don't need a lawyer on retainer to do this properly. You need one habit, two settings and one sentence.
The habit: strip before you paste
The AI needs the situation. It almost never needs the identity. Compare:
- What you received: "Hi, it's Dana Okafor, order 48213, 1180 Ouellette Ave. My blender arrived cracked and I need it for my daughter's party Saturday."
- What the AI needs: "Customer's blender arrived cracked. She needs a working one by Saturday. Policy allows replacement or refund. We have stock."
The second version drafts the same reply. You add "Hi Dana" and the order number back in when you send. After a week this takes ten seconds per message and removes most of the risk.
Some things should stay out of general AI tools entirely: card numbers, government ID numbers, passwords, medical details, and anything about a minor. If your business handles health or legal files, treat the whole file as off limits unless you're on a plan with a signed data agreement.
The two settings
Turn off training on your chats. Consumer versions of the big assistants may use conversations to improve their models unless you opt out. In ChatGPT it lives under Settings, then Data Controls. Claude, Gemini and Copilot have an equivalent switch in their privacy settings. Find it on every account your staff use and turn it off. It takes two minutes.
Know which tier you're on. Business and team plans from OpenAI, Anthropic, Google and Microsoft commit in writing to not training on your data, and they give you admin control over staff accounts. If your team pastes real customer details daily, the business tier is the honest answer, and it's the one place this course tells you to consider paying. The full reasoning is in How to Protect Customer Data When Using AI.
The Canadian basics
In Canada, PIPEDA covers how private businesses handle personal information in commercial activity. Alberta, British Columbia and Quebec have their own similar laws, and Quebec's Law 25 is the strictest of them. Three principles matter for AI support work:
- You stay accountable. Handing data to a third-party processor, which is what an AI tool is, doesn't hand off your responsibility for it.
- Use matches purpose. Information a customer gave you to fix their order is for fixing their order.
- Safeguards fit the sensitivity. A shipping question needs little protection. A health detail needs a lot.
Stripping identifiers before you paste satisfies most of this in practice, because what leaves your business is no longer about an identifiable person. If you're in the US, state laws vary and the same habit serves you well. This is orientation, not legal advice. If you handle sensitive files, spend an hour with a privacy professional.
The sentence: tell people when a bot is talking
Two different situations get confused here.
When AI drafts and you review, edit and send, you're the author. You don't announce your spellchecker and you don't need to announce this.
When AI replies on its own, in a website chat or an automated message, tell the customer up front. One sentence does it: "I'm an automated assistant. I can answer common questions, and I'll pass you to a person for anything else." Several jurisdictions now require this kind of disclosure, the rules are spreading, and customers who discover it on their own trust you less than customers who were told.
You're responsible for what your bot says
In 2024 a British Columbia tribunal decided Moffatt v. Air Canada. The airline's website chatbot told a grieving customer he could claim a bereavement fare after travelling. The real policy said otherwise. Air Canada argued the chatbot was responsible for its own words. The tribunal disagreed and ordered the airline to pay roughly $800 in damages and fees.
The amount is small. The principle isn't: whatever your automated assistant tells a customer, you said. That's why this course keeps AI on known answers, puts a human on anything involving money or policy exceptions, and repeats one guard line in every prompt.
A one-page rule your team will follow
AI and customer information: our rules
1. Remove names, emails, phone numbers, addresses and order
numbers before pasting anything into an AI tool.
2. Do not paste: card numbers, ID numbers, passwords, health
details, anything about a child.
3. Use only the company AI account. Training on our chats is
switched off there.
4. AI drafts. A person reads every word before it is sent.
5. Anything involving refunds over $[AMOUNT], legal threats,
injuries or the media goes to [NAME] and is not drafted
with AI.
6. If an automated reply is used, it says it is automated.Print it. Tape it next to the screen where support happens. A rule people can see beats a policy PDF that lives in a folder.
Try it now
Open the privacy settings on the AI account you use most and check the training toggle. Then fill in the two blanks in the one-page rule and send it to anyone who answers customers for you. Ten minutes, and the riskiest part of AI support is handled.