We stand with Ukraine
Go Wombat logo

ChatGPT Data Security Concerns

Article by

Updated on March 29, 2024

Read — 7 minutes

This article looks at ChatGPT data security: how ChatGPT uses the data you give it, where the real risks are, and what users and companies can do to reduce them.

Understanding ChatGPT's Data Use

OpenAI trains ChatGPT's models on large datasets. That does not guarantee accurate answers: OpenAI's help centre warns that, like any language model, ChatGPT can produce incorrect or misleading outputs. ChatGPT also processes everything users type into it, and those inputs range from trivial to highly sensitive, so you need to know what is collected and how it is used.

There is also indirect collection. AI training data can include content scraped from social media and other public websites, so information you never typed into a chatbot can still end up in a training set.

Data Security Concerns

The main risks with ChatGPT and other LLM services are unauthorised access to data, leaks and misuse, and they are not hypothetical. OpenAI disclosed that on 20 March 2023 a bug in the open-source redis-py library let some ChatGPT users see the titles of other users' chats. For about 1.2% of active ChatGPT Plus subscribers, the same bug could expose their name, email address, payment address, card type and the last four digits of their card number to another user during a nine-hour window.

Scraping is a related risk. On 3 July 2024 Cloudflare released a one-click setting, available on all plans including the free one, that blocks AI bots and crawlers from scraping a website. Custom-built bots can still get through, so blocking reduces scraping rather than preventing it.

Addressing ChatGPT's Security Vulnerabilities

A ChatGPT integration handles user data, so start with a risk assessment that identifies vulnerabilities and how to mitigate them. Typical controls are encryption, access controls and regular security audits to ensure compliance with data protection regulations.

User Data Privacy

OpenAI publishes policies on how user data is handled, retained and deleted. Read them before you use ChatGPT for work.

Many users, especially non-technical ones, do not realise that AI platforms can collect their social media posts and interactions. As a result, personal information, business secrets or other sensitive data can spread further than intended.

OpenAI also has many competitors now, and there is no guarantee that all of them follow the same rules or ethical standards.

Impact of International Data Protection Laws

The data protection landscape is not the same globally - it varies significantly across jurisdictions. Laws such as the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) in the United States set precedents for the security and user consent levels needed before data processing. These international laws impact how AI platforms like ChatGPT collect, store, and utilise data. They also underscore global compliance's complexity, presenting challenges and opportunities for enhancing user trust and data security.

However, many companies and organisations are concerned that such limitations and regulations might impair competitiveness. They argue that stringent data protection laws can stifle innovation and put them at a disadvantage compared to competitors who may not be bound by similar rules, particularly in regions with less stringent data privacy requirements. This creates a complex dynamic where the drive for business excellence and market leadership must be balanced with legal compliance and ethical data management practices.

The international patchwork of data protection laws underscores global compliance's complexity, presenting challenges and opportunities for enhancing user trust and data security while maintaining competitive agility.

AI services like ChatGPT spread faster than regulation, but the rules are catching up. According to the European Commission, the EU AI Act entered into force on 1 August 2024. Bans on prohibited AI practices have applied since 2 February 2025, obligations for general-purpose AI models since 2 August 2025, and the rest of the Act, with some exceptions, since 2 August 2026.

Data Accuracy and AI Content Cycles

AI models are increasingly trained on text that other AI models generated. Without human review or fact-checking, errors and biases in that text get repeated and amplified. As AI-generated content becomes more common, it is also harder to tell apart from human writing, which helps misinformation travel. Data quality checks and moderation reduce these risks.

Best Security Practices for AI Users

Users are responsible for much of their own data security. The basics: do not share sensitive information in prompts, watch out for phishing, and understand the privacy settings of the tools you use.

Assume that anything you or your company posts online can be used by others, including to train AI models.

Practical steps:

  • Think about what you are sharing and who could see it before you press Send. Once information is online, it can be hard or impossible to take back.
  • Separate what is meant to be public from what should stay private, and set the privacy settings on your social media accounts to match.
  • Review what you have already shared on different platforms, so you know what data about you is available.
  • Stay informed about data privacy, what AI tools can do and what happens to data you share online. Pass this on to colleagues, employees and family.
  • Use the security features platforms provide: strong, unique passwords and two-factor authentication wherever it is available.
  • If you see suspicious activity or think your data is being misused, report it to the platform or the relevant authorities.

Conclusion

Before rolling out ChatGPT at work, stop company data from being used for model training. In individual accounts, turn off Settings → Data controls → "Improve the model for everyone". According to OpenAI, data from ChatGPT Business, ChatGPT Enterprise and the API is not used for training by default. Then write a short policy on what staff may paste into prompts.

Go Wombat builds security measures into its AI integration work to protect user data and privacy. Contact us to learn more about our ChatGPT integration solutions.

How can we help you ?

How can we help youHow can we help youHow can we help you