AI privacy

Is ChatGPT safe for business? What Australian organisations should know

ChatGPT can be used safely at work, but the plan matters and so do your rules. Here's what OpenAI's own documentation says about training and data location, what the OAIC recommends, and the rules to give staff.

By the AusGPT team · Updated · 7 min read

General information only, not legal advice. Check the primary sources linked below, and get advice for your situation.

Is ChatGPT safe for business? It can be, but "ChatGPT" covers very different products. On OpenAI's individual plans (Free, Go, Plus and Pro), OpenAI may use your conversations to train its models unless you opt out. On ChatGPT Business, Enterprise and Edu and the API, OpenAI says it doesn't train on your inputs or outputs by default, and admins get controls over retention and access. What makes ChatGPT safe or unsafe for your organisation is mostly which plan staff use and what they put into it.

For Australian organisations there's a second question: where the data goes. As of October 2026, OpenAI offers storage at rest in Australia for eligible new ChatGPT Enterprise and Edu workspaces and eligible API customers. It doesn't offer Australian inference residency for ChatGPT, so prompts are processed outside Australia.

ChatGPT plans compared

Individual plans (Free, Go, Plus, Pro) ChatGPT Business ChatGPT Enterprise and Edu OpenAI API
Used for training by default? Yes, unless the user opts out No No No
Who controls retention The user Workspace admins Workspace admins Abuse monitoring logs kept up to 30 days by default; zero data retention needs approval
Australian storage at rest Not offered Not listed as eligible Eligible new workspaces Eligible customers, with approval
Australian inference (processing) No No No (offered for Europe, US, UAE) No

Based on OpenAI's help centre, enterprise privacy page and API documentation as of October 2026. Check OpenAI's current documentation before you decide.

Training: personal accounts vs business plans

OpenAI's help centre is clear about the split. For "services for individuals, such as ChatGPT and Codex", OpenAI says it "may use your content to train our models". Users can opt out by turning off Improve the model for everyone under Settings > Data controls, or through OpenAI's privacy portal. Two caveats apply even after opting out:

  • If a user gives feedback, such as a thumbs up or down, OpenAI says the entire conversation linked to that feedback may be used for training.
  • The setting belongs to the individual. Your organisation can't see or enforce it on personal accounts.

Temporary Chat isn't a fix either. OpenAI says temporary chats aren't used to improve its models "while they remain temporary". They are still sent to and processed by OpenAI, and saving one turns it into a regular chat.

For business products the default flips. OpenAI states that "by default, we don't use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, or our API" to improve its models. Its enterprise privacy page adds that customers own their inputs and outputs (where allowed by law). Business data is used for training only if the customer explicitly opts in.

That's a meaningful protection, and it's the main reason a business plan is safer than staff using personal accounts.

Who can see your conversations

Not training on data is different from nobody seeing it. OpenAI's enterprise privacy page says:

  • ChatGPT Business: workspace admins can view, export and delete members' conversations. OpenAI's access is limited to authorised employees for engineering support, investigating potential abuse and legal compliance, and to specialised third-party contractors bound by confidentiality who review for abuse and misuse. Deleted or unsaved conversations are removed within 30 days, unless longer retention is legally required or reasonably necessary to protect the service or others.
  • ChatGPT Enterprise and Edu: admins control retention, and authorised OpenAI employees access conversations only to resolve incidents, recover conversations with your permission, or where required by law.
  • All business data may be run through automated content classifiers and safety tools.

OpenAI also reports SOC 2 Type 2 audits for ChatGPT Business, Enterprise and the API platform, encrypts data at rest (AES-256) and in transit (TLS 1.2 or higher), and offers a Data Processing Addendum for ChatGPT Business, Enterprise and the API.

Where ChatGPT data is stored and processed

OpenAI's privacy policy for users outside Europe and the US says it processes and stores personal data on servers "in the United States, or in countries or territories where our affiliates and partners or our vendors and service providers are located".

Data residency changes that only for some customers:

  • Storage at rest in Australia is available to eligible API customers and new ChatGPT Enterprise and Edu workspaces, at no extra cost for Enterprise and Education plans. It covers conversations, files, custom GPTs, memory and some other content. Workspace metadata, billing information, user logins, external integrations and some transient processing can still sit outside the region.
  • Inference residency, which keeps model processing in-region, is available for ChatGPT only in Europe, the United States and the UAE as of October 2026. OpenAI says that even with it on, CPU processing such as extracting text from uploaded PDF or Word files can still happen elsewhere.
  • The API lists Australia for regional storage but not regional processing. OpenAI's documentation notes that where a region doesn't support regional processing, it may process and temporarily store customer content outside the region.

Why it matters: under APP 1, your privacy policy must say whether personal information is likely to be disclosed to overseas recipients, and APP 8 sets rules for cross-border disclosures. The OAIC's AI guidance draws a useful distinction. If you use an AI system with protections so that information entered isn't disclosed outside your organisation, such as to the system developer, that is a "use" rather than a "disclosure" of personal information. Contract terms and settings matter as much as the brand name.

What the OAIC recommends

The OAIC's guidance on commercially available AI products (October 2024) is the closest thing to an official Australian position. Its key points:

  • Privacy obligations apply to any personal information entered into an AI system and to personal information it generates or infers.
  • As best practice, organisations should not enter personal information, and particularly sensitive information, into publicly available generative AI tools, "due to the significant and complex privacy risks involved".
  • Due diligence on AI products "should not amount to a 'set and forget' approach". Check the terms, whether the vendor can use your inputs, and whether risky features can be switched off.
  • Organisations remain responsible for accuracy under APP 10, so staff should check AI output before relying on it.

The OAIC's own example involves insurance staff who paste a customer's claim, including health information, into a public chatbot and ask it to assess the claim. That is exactly the use to rule out.

Is ChatGPT safe for confidential information?

Not on a personal account. On a business plan, the risk is lower but not zero. Business plans remove training by default and give you admin control, but your information is still processed by a US company, mostly outside Australia, under its terms.

Apply a simple test. Ask whether your client, patient or customer would be comfortable seeing their information pasted into a third-party service in another country. Then ask whether your contract with them, your professional rules or your privacy policy allow it. If the answer to either is no, keep that information out, or use a tool whose terms and data location match your obligations.

Rules to give staff

  1. Use only the approved workspace. No personal ChatGPT accounts for work, including on phones.
  2. Know what never goes in: health information, tax file numbers, bank details, passwords and access keys, information about children, and anything covered by legal privilege or a confidentiality agreement, unless your policy expressly allows it for an approved tool.
  3. Remove identifiers when you can. Replace names and other identifying details with roles or initials when they don't matter to the task.
  4. Check every output. AI can be confidently wrong. The person using it is responsible for what gets sent, filed or relied on.
  5. Don't let AI decide things about people. Using AI to score, rank or approve people can trigger new privacy policy obligations from 10 December 2026 and needs human review.
  6. Don't connect apps without approval. OpenAI notes that external integrations operate under the third party's own terms and may sit outside data residency.
  7. Report mistakes quickly. If someone pastes something they shouldn't have, they should tell the privacy officer the same day.

When an enterprise plan or an alternative makes sense

Your situation A reasonable approach
Occasional drafting and research, no personal or client information ChatGPT Business (or any business plan) with a written AI policy
Regular work with personal information, contracts that require Australian storage ChatGPT Enterprise with Australian data residency, or another tool that stores data in Australia, after a privacy assessment
Health, legal, financial or government work where you want prompts processed in Australia A tool that offers Australian processing, as ChatGPT doesn't currently offer it
Building your own app on AI models An API with the region controls and retention settings you need

ChatGPT Enterprise is a serious product with strong controls, and for many organisations it is a sound choice. Its Australian residency covers storage at rest, not processing. If you need both, look at providers that process in Australia. AusGPT is one option. It runs Anthropic's Claude through Amazon Bedrock's Australian cross-region inference, so requests are processed only in AWS Sydney and Melbourne. Conversations and documents are stored in Australia, and customer data isn't used to train AI models. Read how that works on our Claude in Australia page.

Try AI that's stored and processed in Australia

AusGPT gives your team Claude AI with conversations and documents stored and processed in Australia. $29 per user per month, with a free trial.

The bottom line

ChatGPT isn't inherently unsafe, and personal accounts aren't a business tool. A business plan, a clear policy and a few firm rules on information handling make it reasonably safe for everyday work. For sensitive information, decide where it may be processed first, then choose the tool. For the wider legal picture, see our guide to the 2026 Privacy Act reforms.

Frequently asked questions

Does ChatGPT train on my data?
It depends on the plan. OpenAI says it may use content from its services for individuals (such as Free, Go, Plus and Pro) to train its models unless you opt out under Settings > Data controls. By default it does not use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu or the API for training.
Is ChatGPT safe for confidential information?
Not on a personal account. On ChatGPT Business or Enterprise your data isn't used for training by default and admins control retention, but it is still processed by a third party, mostly outside Australia. A sensible approach is to allow a business plan for internal material and keep client-identifying, health or legally privileged information out unless a privacy assessment supports it.
Where does ChatGPT store data for Australian users?
OpenAI's privacy policy says it processes and stores personal data in the United States and other countries where it or its service providers operate. Eligible new ChatGPT Enterprise and Edu workspaces, and eligible API customers, can choose to store customer content at rest in Australia. As of October 2026, ChatGPT inference residency is offered for Europe, the United States and the UAE, not Australia.
Is ChatGPT Team the same as ChatGPT Business?
Yes. OpenAI renamed ChatGPT Team to ChatGPT Business on 29 August 2025. Existing Team workspaces became Business workspaces, and OpenAI says the rename didn't change features, pricing or data protections.
Does Temporary Chat make ChatGPT safe for client information?
No. OpenAI says temporary chats aren't used to improve its models while they remain temporary, but they are still sent to and processed by OpenAI. Temporary Chat doesn't replace a business plan or a policy on what information staff can enter.
What does the Australian privacy regulator say about ChatGPT?
The OAIC's guidance on commercially available AI products recommends, as best practice, that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. It also says privacy obligations apply to personal information entered into any AI system and to personal information it generates.
Pages Claude in Australia AusGPT gives your team Anthropic's Claude models with every request processed in AWS Sydney and Melbourne, and your conversations and documents stored in Australia. Privacy law Privacy Act reforms 2026 Australia's privacy reforms are arriving in two stages. The 2024 amendments are law, with the last major change starting on 10 December 2026. The tranche 2 exposure draft is still a proposal. Here's how to tell them apart and what to do now if your organisation uses AI tools. Alternatives ChatGPT alternative A fair comparison of ChatGPT's plans and AusGPT for Australian teams: where your data is stored and processed, whether it trains AI models, admin controls and price. Competitor details are as of October 2026. Privacy Does AI train on your data? Business plans from the major AI vendors don't train on your content by default, but consumer plans differ and feedback buttons are a common exception. Here are the defaults and opt-out settings for each plan, as of October 2026. Pages Private ChatGPT for business Most teams asking for a private ChatGPT want an AI assistant that doesn't train on their data, that admins control, and that keeps data somewhere they can name. Here's how the main options compare for Australian organisations, and where AusGPT fits. AI governance AI policy generator Create an AI acceptable use policy for your staff in a few minutes. It follows the National AI Centre's AI policy template and six essential practices, with privacy rules based on OAIC guidance and extra clauses for your sector.

Secure AI for your team, processed in Australia

Claude AI, document chat and voice dictation, with your data stored and processed in Australia. $29 per user per month.