Is customer data safe in ChatGPT or Claude in Australia?
Personal ChatGPT and Claude plans can train on your chats unless you opt out. What never to paste into AI and which plans suit Australian client data.
Want this done for you? Book a free 30-minute AI audit
It can be, if you pick the right plan and keep the riskiest data out. ChatGPT Free, Plus and Pro and Claude Free, Pro and Max can train on your chats unless you switch that off, while business plans and the APIs (which On Autopilot, a Melbourne AI consultancy, builds its agents on) do not by default. Either way the customer’s information stays your responsibility, so tax file numbers, card details, health records and privileged legal material never go into a chat app.
Do ChatGPT and Claude train on what you type?
Personal plans can; business plans and APIs do not by default. ChatGPT Free, Plus and Pro may use your chats to train OpenAI’s models unless you turn off “Improve the model for everyone”. Since 28/08/2025, Claude Free, Pro and Max users choose whether their chats train Claude through a model-improvement setting. ChatGPT Business, Claude Team, the Enterprise plans and both companies’ APIs are not used for training by default.
A paid personal plan is not a private one. Plus or Pro buys more usage, not a different data policy, so check the setting on every account your team uses.
| Plan (as at October 2026) | Used to train models? | Where to check |
|---|---|---|
| ChatGPT Free, Plus, Pro | May be, unless you turn it off | Settings, Data controls |
| ChatGPT Business, Enterprise, Edu | Not by default | Workspace admin settings |
| OpenAI API | Not by default | API terms |
| Claude Free, Pro, Max | Your choice since 28/08/2025 | Settings, Privacy |
| Claude Team, Enterprise | Not by default | Organisation admin settings |
| Claude API, Amazon Bedrock, Google Vertex AI | Not by default | Commercial terms |
Sources: OpenAI’s data controls in ChatGPT, Anthropic’s consumer terms update and model training policy, checked October 2026.
Which AI plan is safe for client data?
Use a business plan or a tool built on an API for anything containing customer or client details: ChatGPT Business, Claude Team or Enterprise, or an AI system that calls the Claude or OpenAI API. These are not used for training by default, they come with business terms, and the account belongs to the business rather than to whoever signed up. A personal Plus or Pro account is the wrong home for customer data, even with training off.
Personal accounts are the quiet problem: you cannot see what staff paste, cannot enforce the training setting, and the history leaves with them. As at October 2026, ChatGPT Business and a Claude Team standard seat each cost US$25 per user a month, or US$20 billed annually.
| What you are doing | Minimum sensible setup |
|---|---|
| Marketing copy, brainstorming, your own content | Any plan, training switched off |
| Replies that include a customer’s name or details | Business plan or API-based tool |
| Summarising client files, CRM exports or orders | Business plan or API-based tool, de-identified where possible |
| Health, legal or financial client records | API-based system or business plan, checked against your professional rules |
| Data you have promised to keep in Australia | Claude through Amazon Bedrock’s Australian profile |
Our Claude vs ChatGPT comparison for Australian small business covers price and fit.
Does ChatGPT or Claude keep data in Australia?
Mostly not. Anthropic’s own API processes data outside Australia (globally by default, or US-only on request), with no Australian residency option, and you should assume the ChatGPT and Claude apps process data overseas too. Claude on Amazon Bedrock, using the Australian cross-region profile, keeps data in the Sydney and Melbourne regions for supported models. Azure OpenAI’s Australia East deployments cover only some older models; newer GPT models route through an Asia-Pacific data zone or globally.
Onshore data is not a Privacy Act requirement for most businesses; it matters when a contract or your own privacy policy promises it. Sources: Anthropic, AWS and Microsoft, checked October 2026.
Does the Privacy Act apply to my AI use?
If your business is covered by the Privacy Act, yes. The Australian Privacy Principles apply to personal information you put into an AI tool and to any personal information it produces, as they do with any other software. Most businesses with annual turnover of $3 million or less are exempt, but health service providers (including allied health practitioners, gyms and naturopaths) and businesses that trade in personal information are covered whatever their turnover.
The OAIC sets out the small business exemption and the rules for health service providers. Its guidance on privacy and commercially available AI products (21/10/2024, updated 17/01/2025) is direct:
“As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools”
It also asks businesses to be open about AI use in their privacy policies. If you are exempt, act as if you were covered anyway: customers expect it, larger customers may require it in contracts, and the exemption ends when turnover passes $3 million.
Can I send customer data to an overseas AI provider?
Yes, but Australian Privacy Principle 8 makes it your responsibility. Before a covered business discloses personal information to an overseas recipient, it must take reasonable steps to ensure that recipient does not breach the APPs, and it can be held accountable if the recipient does. Because most AI services process data in the United States or globally, this applies to almost every AI tool a small business uses.
Reasonable steps: a plan that does not train on your data, the provider’s data terms read, only the fields the task needs, and a privacy policy that says (as APP 1 already requires) whether information is likely to go overseas and, where practicable, to which countries. See the OAIC’s APP 8 guidelines.
What should a small business never paste into AI?
Never paste tax file numbers, government identifiers such as Medicare or passport numbers, card numbers, bank details with names, health information, privileged or confidential legal material, anything under a confidentiality agreement, or passwords and API keys into a chat app. Most other work can be done just as well with names and identifying details swapped for placeholders, which removes most of the privacy risk before it starts.
| Never paste | Why |
|---|---|
| Tax file numbers | Extra legal protection applies to every business holding them, whatever its size |
| Medicare, passport and driver licence numbers | Prime material for identity fraud |
| Card numbers and security codes | Card data belongs only in your payment system, under the card industry’s PCI DSS rules |
| Bank account and BSB with a name | A ready-made fraud kit if it leaks |
| Health information | Sensitive information under the Privacy Act, with stricter rules |
| Privileged or confidential legal material | Legal regulators in NSW, WA and Victoria tell lawyers to keep it out of public AI tools |
| Anything under an NDA | You may breach the contract |
| Passwords, API keys and logins | Anything in a chat log can leak |
Swap the details for placeholders before you paste, then put them back in the final version:
Sarah Nguyen -> Customer A
0412 345 678 -> [phone]
14 Smith St, Ballarat -> [address], Ballarat
Invoice 4471, $3,180 overdue -> [invoice], $X overdue
What extra rules apply in health, legal and financial businesses?
Health practitioners are covered by the Privacy Act at any size, and AHPRA expects them to stay responsible for AI output, check AI-scribed notes, get informed patient consent for scribes and know whether patient data trains the vendor’s model. Lawyers have been told to keep confidential and privileged information out of public AI tools. Tax and financial professionals stay bound by their existing codes.
- Health. AHPRA’s guidance on AI in healthcare (22/08/2024) sets those expectations. Under the TGA’s digital scribe rules, a scribe that suggests diagnoses or treatment the clinician did not state must be in the ARTG. See AI for Australian allied health practices.
- Legal. The joint statement on AI in legal practice (06/12/2024) from legal bodies in NSW, WA and Victoria also requires lawyers to verify every output personally. See AI for Australian law firms.
- Tax and financial services. The Tax Practitioners Board’s Code of Professional Conduct still applies and the registered agent stays responsible. ASIC’s REP 798 (29/10/2024) found AI adoption outpacing governance among licensees.
Our guide to whether it is legal to use AI in your Australian business maps every regulator and common use.
What privacy law changes should you plan for?
Three dates matter. Since 10/06/2025, individuals can sue for serious invasions of privacy under a new statutory tort. From 10/12/2026, privacy policies must disclose substantially automated decisions that significantly affect people. A second tranche of reform is still a draft: the exposure draft released on 31/08/2026 proposes a fair-and-reasonable test and 72-hour breach notification, keeps the small business exemption, and is not yet in Parliament.
- Tiered penalties. The Privacy and Other Legislation Amendment Act 2024 added OAIC infringement notices and a mid-tier civil penalty below the top tier. It did not create a general right to erasure (bills digest; OAIC on the tort).
- Automated decisions. If an AI system makes, or substantially makes, a significant decision about a customer, such as declining an application, your privacy policy must say so from 10/12/2026.
- Data breaches. Under the Notifiable Data Breaches scheme, a covered business must notify affected people and the OAIC when personal information is accessed or disclosed without authorisation, or lost, in a way likely to cause serious harm. A customer list pasted into an unapproved AI tool is one to assess.
What should your privacy policy say about AI?
Say which AI tools you use and for what, whether your data trains models, that providers may process information overseas and where, what you never put into AI, and how people can contact you. From 10/12/2026, add any substantially automated decisions that significantly affect people. One paragraph covers most small businesses:
How we use AI tools. We use AI tools, including [name the tools, for example Claude by Anthropic], to help us [draft replies and manage bookings]. We use business plans or API services that are not used to train AI models by default, and a member of our team reviews [what a person checks] before it is sent or acted on. These providers may process your information outside Australia, including in [the United States]. We do not enter tax file numbers, payment card details or [health information] into AI tools. [Describe any decision that significantly affects you and is made by automated means.] For questions, or if you would prefer we did not use AI on your matter, contact us at [contact details].
How do you set up AI safely in a small business?
- List where AI touches personal information: each tool, its plan, what data goes in and who uses it.
- Move customer data onto a business plan or API-based system, and switch training off on any personal accounts.
- Write a one-page staff rule with the never-paste list and the approved tools.
- De-identify by default.
- Keep a person on decisions about refunds, complaints and anything clinical, legal or financial.
- Update your privacy policy and add AI to your breach plan.
How On Autopilot can help
On Autopilot builds AI agents for Australian small businesses on the Claude API, which is not used to train models by default, and designs each agent to collect only the data its job needs. Our AI Front Desk ($1,500 setup plus $199 a month) answers enquiries and books appointments without ever asking for payment details, and never asks for more health information than your own intake form already does. If you want someone accountable for every agent, managed AI starts at $1,500 a month, month to month, and you own the code, prompts and settings. Book a free 30-minute AI audit with Jenn Yang to check which workflows are safe to automate, and on which plan.
Common questions
Does turning off training make ChatGPT or Claude private?
No. Switching training off stops your chats being used to improve the models, but the provider still stores them for a period, a staff member's account can still be compromised, and the data has still left your business. With Claude, opting out cuts retention to 30 days instead of up to five years. Treat the training setting as one control, not as permission to paste customer records.
Can I upload customer spreadsheets or PDFs to ChatGPT or Claude?
The same rules apply to files as to typed text. An uploaded spreadsheet or PDF goes to the provider just like a pasted message, and one CRM export can hold thousands of people's details. Remove names, contact details and identifiers first, or aggregate the data (sales by month, top products) so no one is identifiable. If the job needs real customer records, use a business plan or an API-based system.
Do businesses under $3 million turnover need a privacy policy?
Usually not by law, unless an exception applies. Health service providers and businesses that trade in personal information, for example, are covered whatever their size. The privacy reform exposure draft released in August 2026 keeps the small business exemption. A short statement explaining how you use AI is still worth publishing, because customers increasingly ask and it costs nothing.
Is Claude safer than ChatGPT for privacy?
Neither is automatically safer. Both sell personal plans that can train on your chats unless you switch it off, and business plans and APIs that are not used for training by default. The bigger difference is where data can be processed: Claude is available in Australian regions through Amazon Bedrock, while Azure OpenAI's Australian deployments cover only some older models. Choose on plan and settings, not brand.
Do I have to tell customers I use AI?
There is no general law requiring a label on every AI-assisted email. But businesses covered by the Privacy Act must explain how they handle personal information, including overseas disclosure; the OAIC recommends being open about AI use; from 10/12/2026 privacy policies must disclose substantially automated decisions; and a chatbot that lets customers think it is a person risks misleading conduct under the Australian Consumer Law.
Want this built for your business?
Book a free 30-minute AI audit call with Jenn Yang. We map where your time goes, name the first systems worth building and give you fixed AUD prices. No obligation.
Book a free AI auditOr have us run it for you, end to end: On Autopilot is Australia's outsourced AI department.