Yes, for most business work, if you choose the right plan and settings. ChatGPT Business doesn't use your data for training by default and adds admin controls, while Free, Go, Plus and Pro need "Improve the model for everyone" switched off. The bigger risks are people: client data in personal accounts, unchecked answers, and apps connected with too much access.
"Safe" covers four separate questions, and it helps to keep them apart. Data: who can see and use what you type? Accuracy: are the answers right? Access: what can ChatGPT read and do once it's connected to your email or files? Accounts: who uses it, on which account, and what happens when they leave? OpenAI's settings and plans answer the first question well. The other three are mostly in your hands.
The real risks, and the control for each
| Risk | How it shows up in a small business | The control |
|---|---|---|
| Chats used for model training | A client's details typed into a personal Plus account with the default settings | Switch training off, or use ChatGPT Business, which doesn't train on business data by default |
| Data kept longer than you think | A deleted chat whose uploaded file is still sitting in the Library | Delete files as well as chats; use Temporary Chat for one-offs |
| Wrong answers sent unchecked | A confident claim in a customer email that nobody verified | A human read of anything that leaves the business |
| Personal accounts and shared logins | A leaver who still has client chats in their own account | Company accounts in one workspace, with SSO and multi-factor sign-in |
| Connected apps with broad access | ChatGPT reading an entire shared drive to answer one question | Connect only what's needed; keep approval before important actions |
| Ads on the cheapest plans | Sponsored suggestions beside answers on Free and Go | Plus or a business plan if that matters to you |
On the ads point, OpenAI says ads may appear on Free and Go but not on Plus and above, and that advertisers don't get access to your conversations. It's a consumer-plan signal rather than a data leak, but it's one more reason customer work belongs on a business plan.
Settings that make a personal plan safer
If you or your staff use Free, Go, Plus or Pro for work, these settings matter. The labels below are the ones OpenAI's help pages use as of September 2026.
- Turn off training. Go to Settings, Data Controls, "Improve the model for everyone", and switch it off. On Free, Plus and Pro it's on by default. Once off, new conversations won't be used to train OpenAI's models, and the setting applies across all your devices.
- Know what feedback does. Even with training off, giving a thumbs up or down on an answer can send that whole conversation for training. If a chat contains anything sensitive, don't rate it.
- Use Temporary Chat for one-off sensitive questions. A temporary chat stays out of your history, isn't used to train models while it stays temporary, and doesn't create memories, though it can use memories you already have. OpenAI may keep a copy for up to 30 days for safety. When staff should use Temporary Chat covers the rules for a team.
- Decide about memory. ChatGPT's memory changed significantly in June 2026. Decide deliberately whether it should remember details across chats, and review what it has stored; how ChatGPT memory works for business explains the options.
- Review shared links. Under Settings, Data controls, Shared links, choose Manage and delete any link to a chat that contains client details.
- Delete files, not just chats. Deleting a chat removes it from your account and schedules it for deletion within 30 days, but a file saved to your Library stays until you delete it separately.
Those six steps take about ten minutes and remove most of the data risk from a personal plan. They don't add a data processing agreement, admin controls or a way to recover a leaver's work, which is where the business plan comes in.
What a Business plan changes for safety, and what it doesn't
ChatGPT Business (formerly Team) costs $25 a seat billed monthly or $20 billed annually, with a two-seat minimum, and Premium seats at $125 monthly or $100 annually for heavy users. What you get for the difference:
- No training on business data by default, without anyone needing to find a setting.
- A workspace you control, with admin controls, SAML single sign-on and multi-factor authentication. SCIM user provisioning isn't included on standalone Business.
- Separate histories. Each member has their own chat history; colleagues don't see each other's chats unless they're shared, and shared projects keep common files in one place.
- A data processing agreement. OpenAI offers one for Business, Enterprise and the API.
- A choice of storage region at checkout for your workspace content at rest. It doesn't control where requests are processed, and OpenAI keeps a copy of prompts and responses in its primary region for a limited time for abuse monitoring.
What it doesn't change: answers still need checking, staff can still paste things they shouldn't, and connected apps still need scoping. By default ChatGPT reads from connected apps freely but asks before important actions such as sending messages, deleting content, making purchases or moving files. Keep it that way. For the full comparison, see ChatGPT Plus vs ChatGPT Business.
Connected apps see what your account can see
Connecting ChatGPT to Google Drive, SharePoint or an inbox is where access risk becomes real. A connected app generally searches whatever the connected account is allowed to open, so the question isn't what ChatGPT is permitted to see, it's what you are. A pharmacy's office manager connected the shared drive to ask ChatGPT about a supplier's delivery terms. The answer was correct, but one of the cited sources was a disciplinary letter sitting in the same drive, which the manager had access to for HR reasons and had forgotten about. Nothing left the business, but a sensitive document had been pulled into an unrelated chat.
The fix is dull and effective: tidy permissions before connecting anything, keep HR and patient material in folders that ordinary admin accounts can't open, and connect the narrowest source that answers the question. On Business, admins can also control which apps are available and, where the app supports it, limit it to reading rather than acting.
Which plan fits five kinds of small business
| Business | Data involved | Sensible plan | Why |
|---|---|---|---|
| Sole-trader electrician | Quotes, marketing, very little client data | Plus at $20 a month, training off | Business would mean paying for two seats, about $40-$50 a month |
| Four-person plumbing firm | Customer names, addresses, job notes | Business, 4 seats | Company accounts, no training by default, leavers removed centrally |
| Osteopathy clinic, three practitioners | Patient health information | Business at minimum, and advice before any clinical use | Health data needs a contract, strict rules and often a formal risk assessment |
| Independent pharmacy | Patient and prescription data, supplier data | Business for admin; no patient data in ChatGPT without advice | Keep clinical records in clinical systems |
| Hearing-aid shop, two branches | Customer and audiology records | Business, with rules on what may be uploaded | Audiology records are health data |
Two edge cases come up often. A heavy individual user may be tempted by Pro at $100 a month (the $200 tier has been closed to new sign-ups since 10 September 2026); it buys more usage, not more privacy, because Pro is still a personal plan with training on until you switch it off. In a team, the better answer for one or two heavy users is usually a Business Premium seat ($125 monthly or $100 annually), which has no five-hour usage limit and can sit alongside Standard seats in any mix.
The sole-trader row is the one place a personal plan is reasonable, because the two-seat minimum makes Business expensive for one person and there's little client data involved. Once a second person works in the business, or health information is involved, a personal plan becomes hard to justify.
Moving a four-person plumbing firm onto Business
Consider how this plays out in a plumbing firm (an illustrative case), where the office manager and three engineers use ChatGPT: two on Plus ($40 a month between them) and two on Free. Nobody has switched off training. The trigger for change comes when an engineer leaves: he'd used his personal Plus account to draft dozens of customer emails, with names and addresses, and the firm has no way to see or delete those chats.
The move to Business takes an afternoon. Four seats cost $100 a month billed monthly, or $80 on annual billing, so $40-$60 more than before. What the firm gets for it: every account belongs to the business, the leaver problem can't recur, a shared project holds the price list and standard wording, and nobody has to remember a training setting. The manager also connects only the job-management spreadsheet and the office inbox, leaving the engineers' personal email and the accounts software out.
The firm also asks each engineer to delete work chats from their personal accounts and switch training off there too. It can't enforce that, which is exactly the argument for company accounts from the start. Setting up company AI accounts instead of personal logins walks through the switch.
Accuracy is a safety issue too
A safe account doesn't make a safe answer. An osteopathy clinic asked ChatGPT to draft a reply to a patient's question about insurance:
Draft a short, warm reply to a patient asking whether their health
insurance will cover their osteopathy sessions. 100 words.
The draft (illustrative) included: "Most health insurers cover osteopathy, so you should be able to claim for your sessions." It's fluent, reassuring and not something the clinic can promise, because cover depends entirely on the patient's own policy. The corrected version said the clinic could provide receipts with the practitioner's registration details and that the patient should check their policy's terms before booking further sessions.
The pattern is common: ChatGPT fills gaps with plausible generalisations. The fix is a rule, not a better model. Anything that goes to a customer gets read by a person who knows the facts, and anything that sounds like advice about the customer's own situation (legal, financial, medical, insurance) gets checked or removed. OpenAI's own usage policies rule out tailored advice that requires a licence without a licensed professional involved. For the task-by-task picture, see how accurate ChatGPT is for business tasks.
A one-page ChatGPT rule sheet for staff
- Use only your company ChatGPT account for work. Never a personal one.
- Don't paste in patient health details, full card numbers, passwords or ID documents.
- Remove names and addresses when the task doesn't need them. "Customer A, three-bed house, combi boiler" works as well as the real details.
- Read every draft before it goes to a customer. You're responsible for what's sent, not ChatGPT.
- Check facts, prices and dates against our own records, never ChatGPT's answer.
- Don't connect new apps or change app permissions without asking [name].
- Delete shared links you no longer need, and don't share chats that contain customer details.
- If you've pasted something you shouldn't have, tell [name] the same day. It's fixable when we know.
Rule eight matters more than it looks. People hide mistakes they expect to be punished for, and a chat that's reported the same day can be deleted before it becomes a problem. If you're unsure where the line sits for customer data in particular, whether it's safe to put customer data into ChatGPT goes into that question alone.
Pasting a customer complaint safely: before and after
Most day-to-day risk comes from what people paste. Here's the same job done two ways at a hearing-aid shop.
Before: the whole email goes in, including "Mrs [surname], [full address], customer since 2019, bought [model] on 3 March, hearing test showed moderate loss in the left ear, and I'm furious that the repair has taken three weeks".
After:
A long-standing customer is upset that a hearing-aid repair has taken
three weeks. The manufacturer has confirmed it will be back in 5 working
days. Draft a calm, apologetic reply: acknowledge the delay, give the new
date, offer a loan aid in the meantime. 120 words, sign off
"Kind regards, [first name]".
The reply ChatGPT drafts is just as good, because none of the removed details changed what the customer needed to hear. The name, address and audiology result never left the shop. Once staff see that the "after" version takes ten seconds longer and produces the same draft, the habit sticks.
What to do the day someone pastes something they shouldn't
- Delete the chat, and any file it saved to the Library. That removes it from the account at once and starts OpenAI's deletion process, normally within 30 days.
- Check for shared links to that chat and delete them.
- Note what happened: what was pasted, into which account and plan, when, and whether training was switched on at the time.
- Decide whether it's a personal-data incident. If you're under data-protection rules like the GDPR and the chat held someone's personal data on a personal account with training on, record it. Serious breaches may need reporting to your data-protection authority within 72 hours, so ask your adviser promptly if you're unsure.
- Fix the cause, which is usually a missing company account, a missing rule or a rule nobody was shown.
Most of these incidents are small, and the ones that go wrong are the ones nobody mentions for a month.
A quarterly check that your set-up is still safe
Settings drift. New staff join, apps get connected, a leaver's seat stays active. Every three months, spend 20 minutes on this list:
| Check | What good looks like |
|---|---|
| Who has a seat | Every seat belongs to a current member of staff |
| Personal accounts in use | None for work; ask, don't assume |
| Connected apps | Only the ones on your approved list, with the default approvals intact |
| Shared links | No live links to chats with customer details |
| Projects and files | Old client files removed from projects and the Library |
| Staff rules | Everyone can say where a customer's letter may and may not be pasted |
The last row is the real test. Ask two members of staff, casually, "if a customer emailed you a complaint with their address and order history, where would you paste it to draft a reply?" If both answers match your rule sheet, ChatGPT is being used safely in your business. If they don't, the gap is training, not technology.
ChatGPT safety: follow-up questions
Is ChatGPT Go safe to use for business?
For non-sensitive work, yes, with care. Go costs $8 a month, is a personal plan, and is one of the two plans where OpenAI says ads may appear. Switch off the model-training setting and keep client, patient and staff details out of it. For anything involving personal data, a business plan with a data processing agreement is the safer home.
Do I have to tell customers I use ChatGPT?
If ChatGPT processes customers' personal data, your privacy notice should mention AI providers among the organisations handling it. Beyond that, neither data-protection law nor the EU AI Act generally requires you to label each email drafted with AI help and checked by a person. The firm rule applies to chatbots: customers in the EU must be told when they're talking to an AI system.
When does a small business need ChatGPT Enterprise?
Rarely at first. Look at Enterprise when you need admin-set retention periods, processing kept within a chosen region, user provisioning through SCIM, a compliance API for audit, or more seats than Business allows, which has been capped at 200 paid seats since August 2026. Enterprise is sold by custom quote rather than a list price.
Further reads
- Does ChatGPT Train on Client Data? Business vs Free Plans — The training rules for free and business plans, in detail.
- How to Set Up Single Sign-On for Your Team's AI Tools — Setting up single sign-on so staff log in with work accounts.
- How to Turn On Two-Factor Authentication for Every AI Account — Turning on two-factor authentication for every AI account.
- ChatGPT Connectors: What They Can See in Your Drive and Inbox — What ChatGPT can see once it's connected to your drive and inbox.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How ChatGPT compares with Claude, Gemini and Copilot on data protection.
- When Does a Shared ChatGPT Plan Stop Being Enough for Your Team? — Signs a shared plan has stopped working for your team.
- How to Use ChatGPT as a Business Adviser Without Being Misled — Prompts and checks that turn ChatGPT into a useful sparring partner for business decisions, and stop it flattering a bad idea into a plan.
- What Are the Risks of Using AI in My Small Business? — Eight risks of using AI in a small business, a four-factor score for your own exposure, three example risk profiles, and the cheapest control for each risk.
- Can Therapists Use ChatGPT for Session Notes? — Personal plan, de-identified shorthand, business plan or a therapy note tool: where each lands, and why removing a name rarely removes the client.
- Are Custom GPTs Private? What Happens to the Files You Upload — Who can see a custom GPT's chats and knowledge files, how consumer and business plans differ, and what the December 2026 retirement means for your uploads.
- Can ChatGPT Agent Handle Business Admin Tasks Unsupervised? — ChatGPT agent became ChatGPT Work in July 2026. A task-by-task guide to what it can run alone and what must wait for your approval.
- GDPR and AI Tools: What a Small Business Must Do — Eight practical GDPR steps for using ChatGPT, Claude, Gemini or Copilot in a small business, worked through for a podiatry clinic.
- Zero Data Retention: What It Means When You Choose an AI Tool — What a zero data retention promise really deletes, the exceptions OpenAI, Anthropic and Google keep, and the vendor questions that expose weak claims.
- ChatGPT Prompts for Small Business Owners: 50 Tested Examples — Fifty copy-ready ChatGPT prompts grouped by job, each with what it returns and how to adapt it, plus sample outputs showing the edits they need.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: OpenAI help centre pages on data controls, Temporary Chat, chat and file retention, ads, ChatGPT Business data and storage, and app permissions; OpenAI's enterprise privacy page; OpenAI's ChatGPT Learn pricing page; OpenAI usage policies (checked September 2026).