Guide

Is customer data safe in ChatGPT or Claude in Australia?

Personal ChatGPT and Claude plans can train on your chats unless you opt out. What never to paste into AI and which plans suit Australian client data.

Want this done for you? Book a free 30-minute AI audit

In short

It can be, if you pick the right plan and keep the riskiest data out. ChatGPT Free, Plus and Pro and Claude Free, Pro and Max can train on your chats unless you switch that off, while business plans and the APIs (which On Autopilot, a Melbourne AI consultancy, builds its agents on) do not by default. Either way the customer’s information stays your responsibility, so tax file numbers, card details, health records and privileged legal material never go into a chat app.

Do ChatGPT and Claude train on what you type?

Personal plans can; business plans and APIs do not by default. ChatGPT Free, Plus and Pro may use your chats to train OpenAI’s models unless you turn off “Improve the model for everyone”. Since 28/08/2025, Claude Free, Pro and Max users choose whether their chats train Claude through a model-improvement setting. ChatGPT Business, Claude Team, the Enterprise plans and both companies’ APIs are not used for training by default.

A paid personal plan is not a private one. Plus or Pro buys more usage, not a different data policy, so check the setting on every account your team uses.

Plan (as at October 2026)Used to train models?Where to check
ChatGPT Free, Plus, ProMay be, unless you turn it offSettings, Data controls
ChatGPT Business, Enterprise, EduNot by defaultWorkspace admin settings
OpenAI APINot by defaultAPI terms
Claude Free, Pro, MaxYour choice since 28/08/2025Settings, Privacy
Claude Team, EnterpriseNot by defaultOrganisation admin settings
Claude API, Amazon Bedrock, Google Vertex AINot by defaultCommercial terms

Sources: OpenAI’s data controls in ChatGPT, Anthropic’s consumer terms update and model training policy, checked October 2026.

Which AI plan is safe for client data?

Use a business plan or a tool built on an API for anything containing customer or client details: ChatGPT Business, Claude Team or Enterprise, or an AI system that calls the Claude or OpenAI API. These are not used for training by default, they come with business terms, and the account belongs to the business rather than to whoever signed up. A personal Plus or Pro account is the wrong home for customer data, even with training off.

Personal accounts are the quiet problem: you cannot see what staff paste, cannot enforce the training setting, and the history leaves with them. As at October 2026, ChatGPT Business and a Claude Team standard seat each cost US$25 per user a month, or US$20 billed annually.

What you are doingMinimum sensible setup
Marketing copy, brainstorming, your own contentAny plan, training switched off
Replies that include a customer’s name or detailsBusiness plan or API-based tool
Summarising client files, CRM exports or ordersBusiness plan or API-based tool, de-identified where possible
Health, legal or financial client recordsAPI-based system or business plan, checked against your professional rules
Data you have promised to keep in AustraliaClaude through Amazon Bedrock’s Australian profile

Our Claude vs ChatGPT comparison for Australian small business covers price and fit.

Does ChatGPT or Claude keep data in Australia?

Mostly not. Anthropic’s own API processes data outside Australia (globally by default, or US-only on request), with no Australian residency option, and you should assume the ChatGPT and Claude apps process data overseas too. Claude on Amazon Bedrock, using the Australian cross-region profile, keeps data in the Sydney and Melbourne regions for supported models. Azure OpenAI’s Australia East deployments cover only some older models; newer GPT models route through an Asia-Pacific data zone or globally.

Onshore data is not a Privacy Act requirement for most businesses; it matters when a contract or your own privacy policy promises it. Sources: Anthropic, AWS and Microsoft, checked October 2026.

Does the Privacy Act apply to my AI use?

If your business is covered by the Privacy Act, yes. The Australian Privacy Principles apply to personal information you put into an AI tool and to any personal information it produces, as they do with any other software. Most businesses with annual turnover of $3 million or less are exempt, but health service providers (including allied health practitioners, gyms and naturopaths) and businesses that trade in personal information are covered whatever their turnover.

The OAIC sets out the small business exemption and the rules for health service providers. Its guidance on privacy and commercially available AI products (21/10/2024, updated 17/01/2025) is direct:

“As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools”

It also asks businesses to be open about AI use in their privacy policies. If you are exempt, act as if you were covered anyway: customers expect it, larger customers may require it in contracts, and the exemption ends when turnover passes $3 million.

Can I send customer data to an overseas AI provider?

Yes, but Australian Privacy Principle 8 makes it your responsibility. Before a covered business discloses personal information to an overseas recipient, it must take reasonable steps to ensure that recipient does not breach the APPs, and it can be held accountable if the recipient does. Because most AI services process data in the United States or globally, this applies to almost every AI tool a small business uses.

Reasonable steps: a plan that does not train on your data, the provider’s data terms read, only the fields the task needs, and a privacy policy that says (as APP 1 already requires) whether information is likely to go overseas and, where practicable, to which countries. See the OAIC’s APP 8 guidelines.

What should a small business never paste into AI?

Never paste tax file numbers, government identifiers such as Medicare or passport numbers, card numbers, bank details with names, health information, privileged or confidential legal material, anything under a confidentiality agreement, or passwords and API keys into a chat app. Most other work can be done just as well with names and identifying details swapped for placeholders, which removes most of the privacy risk before it starts.

Never pasteWhy
Tax file numbersExtra legal protection applies to every business holding them, whatever its size
Medicare, passport and driver licence numbersPrime material for identity fraud
Card numbers and security codesCard data belongs only in your payment system, under the card industry’s PCI DSS rules
Bank account and BSB with a nameA ready-made fraud kit if it leaks
Health informationSensitive information under the Privacy Act, with stricter rules
Privileged or confidential legal materialLegal regulators in NSW, WA and Victoria tell lawyers to keep it out of public AI tools
Anything under an NDAYou may breach the contract
Passwords, API keys and loginsAnything in a chat log can leak

Swap the details for placeholders before you paste, then put them back in the final version:

Sarah Nguyen                      ->  Customer A
0412 345 678                      ->  [phone]
14 Smith St, Ballarat             ->  [address], Ballarat
Invoice 4471, $3,180 overdue      ->  [invoice], $X overdue

Health practitioners are covered by the Privacy Act at any size, and AHPRA expects them to stay responsible for AI output, check AI-scribed notes, get informed patient consent for scribes and know whether patient data trains the vendor’s model. Lawyers have been told to keep confidential and privileged information out of public AI tools. Tax and financial professionals stay bound by their existing codes.

Our guide to whether it is legal to use AI in your Australian business maps every regulator and common use.

What privacy law changes should you plan for?

Three dates matter. Since 10/06/2025, individuals can sue for serious invasions of privacy under a new statutory tort. From 10/12/2026, privacy policies must disclose substantially automated decisions that significantly affect people. A second tranche of reform is still a draft: the exposure draft released on 31/08/2026 proposes a fair-and-reasonable test and 72-hour breach notification, keeps the small business exemption, and is not yet in Parliament.

  • Tiered penalties. The Privacy and Other Legislation Amendment Act 2024 added OAIC infringement notices and a mid-tier civil penalty below the top tier. It did not create a general right to erasure (bills digest; OAIC on the tort).
  • Automated decisions. If an AI system makes, or substantially makes, a significant decision about a customer, such as declining an application, your privacy policy must say so from 10/12/2026.
  • Data breaches. Under the Notifiable Data Breaches scheme, a covered business must notify affected people and the OAIC when personal information is accessed or disclosed without authorisation, or lost, in a way likely to cause serious harm. A customer list pasted into an unapproved AI tool is one to assess.

What should your privacy policy say about AI?

Say which AI tools you use and for what, whether your data trains models, that providers may process information overseas and where, what you never put into AI, and how people can contact you. From 10/12/2026, add any substantially automated decisions that significantly affect people. One paragraph covers most small businesses:

How we use AI tools. We use AI tools, including [name the tools, for example Claude by Anthropic], to help us [draft replies and manage bookings]. We use business plans or API services that are not used to train AI models by default, and a member of our team reviews [what a person checks] before it is sent or acted on. These providers may process your information outside Australia, including in [the United States]. We do not enter tax file numbers, payment card details or [health information] into AI tools. [Describe any decision that significantly affects you and is made by automated means.] For questions, or if you would prefer we did not use AI on your matter, contact us at [contact details].

How do you set up AI safely in a small business?

  1. List where AI touches personal information: each tool, its plan, what data goes in and who uses it.
  2. Move customer data onto a business plan or API-based system, and switch training off on any personal accounts.
  3. Write a one-page staff rule with the never-paste list and the approved tools.
  4. De-identify by default.
  5. Keep a person on decisions about refunds, complaints and anything clinical, legal or financial.
  6. Update your privacy policy and add AI to your breach plan.

How On Autopilot can help

On Autopilot builds AI agents for Australian small businesses on the Claude API, which is not used to train models by default, and designs each agent to collect only the data its job needs. Our AI Front Desk ($1,500 setup plus $199 a month) answers enquiries and books appointments without ever asking for payment details, and never asks for more health information than your own intake form already does. If you want someone accountable for every agent, managed AI starts at $1,500 a month, month to month, and you own the code, prompts and settings. Book a free 30-minute AI audit with Jenn Yang to check which workflows are safe to automate, and on which plan.

Common questions

Does turning off training make ChatGPT or Claude private?

No. Switching training off stops your chats being used to improve the models, but the provider still stores them for a period, a staff member's account can still be compromised, and the data has still left your business. With Claude, opting out cuts retention to 30 days instead of up to five years. Treat the training setting as one control, not as permission to paste customer records.

Can I upload customer spreadsheets or PDFs to ChatGPT or Claude?

The same rules apply to files as to typed text. An uploaded spreadsheet or PDF goes to the provider just like a pasted message, and one CRM export can hold thousands of people's details. Remove names, contact details and identifiers first, or aggregate the data (sales by month, top products) so no one is identifiable. If the job needs real customer records, use a business plan or an API-based system.

Do businesses under $3 million turnover need a privacy policy?

Usually not by law, unless an exception applies. Health service providers and businesses that trade in personal information, for example, are covered whatever their size. The privacy reform exposure draft released in August 2026 keeps the small business exemption. A short statement explaining how you use AI is still worth publishing, because customers increasingly ask and it costs nothing.

Is Claude safer than ChatGPT for privacy?

Neither is automatically safer. Both sell personal plans that can train on your chats unless you switch it off, and business plans and APIs that are not used for training by default. The bigger difference is where data can be processed: Claude is available in Australian regions through Amazon Bedrock, while Azure OpenAI's Australian deployments cover only some older models. Choose on plan and settings, not brand.

Do I have to tell customers I use AI?

There is no general law requiring a label on every AI-assisted email. But businesses covered by the Privacy Act must explain how they handle personal information, including overseas disclosure; the OAIC recommends being open about AI use; from 10/12/2026 privacy policies must disclose substantially automated decisions; and a chatbot that lets customers think it is a person risks misleading conduct under the Australian Consumer Law.

Want this built for your business?

Book a free 30-minute AI audit call with Jenn Yang. We map where your time goes, name the first systems worth building and give you fixed AUD prices. No obligation.

Book a free AI audit

Or have us run it for you, end to end: On Autopilot is Australia's outsourced AI department.