What not to share with AI at work
Updated October 5, 2026 · 6 min read
In a consumer AI tool, do not enter personal data (names, contact details, health, salaries), confidential company information (contracts, accounts, projects), or passwords. The French data protection authority (CNIL) recommends it: submit only what you are authorized to share. Everything else goes through the tool your company has approved, or through a document from which you have removed the names and amounts.
The rule, and where it comes from
What you write in an assistant leaves your computer. Depending on the tool and the type of account, your text may be kept, reviewed by people, or used to improve the AI. In its questions and answers on generative AI, published on July 18, 2024, the CNIL, France’s data protection authority, sets out three markers.
- You give the tool only what you have the right to share.
- In a consumer service, nothing confidential: no personal data, no data belonging to the company or the public body, all the more so if it is covered by a duty of secrecy.
- The employer sets the framework in writing, in a policy that separates what is allowed from what is not.
This guide gives practical markers. It is not legal advice: ask your data protection officer, or failing that your management, for the rule that applies to you, and check it with the data protection authority in your country.
What should not go into a consumer tool
| Category | Examples | Instead |
|---|---|---|
| Personal data | Name, address, phone number, email, social security number, voice, photo | Write “a customer” or “an employee,” or replace with brackets |
| Sensitive data | Health, political opinions, religious beliefs, trade union membership, racial or ethnic origin, biometric or genetic data, sex life or sexual orientation | None of this in a consumer assistant |
| Personnel files | Salaries, performance reviews, sick leave, family situations | They stay in the company’s HR software |
| Confidential company information | Contracts, accounts, margins per customer, a planned sale of the business, ongoing litigation | The team workspace the company has approved, or a document with no names or amounts |
| What a customer has entrusted to you | Documents under a confidentiality clause, interview notes | Check what the contract allows; ask for the customer’s agreement if needed |
| Access credentials | Passwords, codes, card numbers, network diagrams | Never, in any tool |
Under GDPR, personal data is any information relating to an identified or identifiable person. A name is enough, but so is a phone number, an email address, or several details combined. If in doubt, treat it as personal data.
Personal account or company account: what changes
The same tool does not apply the same rule to every account. According to the vendors’ pages, checked on October 3, 2026:
| Tool | Personal account | Team or company account |
|---|---|---|
| ChatGPT | Your conversations can be used for training, unless you turn the setting off | Business, Enterprise, and Edu: no training on your data by default |
| Claude | They are used for training only if you agree | Team and Enterprise: no training on your content by default |
| Gemini | They can be used to improve the AI and be reviewed by people, unless you turn off “Keep Activity” | Google Workspace: content is not reviewed by people and not used for training without permission |
| Copilot | They can be used for training, unless you opt out in the settings | Work account: your prompts and your work data are not used for training |
| Mistral Vibe | Free plan: they can be used to improve the AI as long as you have not opted out | Paid plans (Pro, Team, Enterprise): no training by default, according to the documentation |
Two consequences. Paying for a personal plan does not always change the rule: the type of account is what counts. And at work, the account the company provides is almost always the right one: do not create a personal account on the side.
Using it anyway: six moves
- Ask for the list of approved tools. If there is none, ask the question: that is the job of the policy the CNIL recommends.
- Change the training setting on day one. In ChatGPT: “Settings,” “Data controls,” turn off “Improve the model for everyone.” In Claude: “Settings,” “Privacy.” In Gemini: turn off “Keep Activity.”
- Remove what identifies people. Replace names, contact details, and amounts with brackets before you paste a text. You will put them back by hand in the result.
- Give the structure rather than the data. To write a formula or a letter template, the column names or the outline are enough.
- Keep temporary mode for a one-off question. A temporary chat or an incognito chat is not used for training. That is not permission to put a confidential file in it.
- Check what comes out. The CNIL points out that the user keeps a critical eye and checks that the results are accurate.
One detail to know: in ChatGPT, a thumbs up or thumbs down sends the conversation to OpenAI to improve its AI, even if you have turned training off. Avoid it on a sensitive topic.
For the business owner: set the framework
A ban on its own does not say what to use: the risk then is the personal account, where the rule protects the least. The CNIL points out that the organization is liable when its staff misuse the tool. Here is what falls to the organization.
- Write a short policy: the approved tools, the type of account, the data that never goes into them.
- Provide a team workspace for company data, for example a team plan of Copilot, ChatGPT, Claude, or Mistral Vibe.
- Ask the vendor about its tool’s compliance with GDPR.
- Explain to the teams how these tools work and where they go wrong.
- Involve the data protection officer, whose role the CNIL considers useful on these topics.
What Nova brings
Nova is subscription software. Each tool page says what the vendor does with your data, where it hosts it, and the setting to change, with the check date. Each job page recalls the rules specific to the job. On a team plan, the owner keeps a catalog of approved tools; Nova never shows them one person’s activity. Try the interactive demo.
Frequently asked questions
Can you put personal data into ChatGPT?
Not in a personal account, according to the CNIL’s recommendation on consumer services. In a company workspace set up for that purpose, it is the employer’s decision, to be validated with the data protection officer. If in doubt, remove the names and contact details.
Is temporary or incognito mode enough to protect a document?
No. It keeps the conversation from being used for training and from staying in your history. The text is still sent to the vendor to be processed. A contract or an employee file has no place in a personal account, even in temporary mode.
Does a paid plan protect my data better?
Not necessarily. ChatGPT Plus is still a personal plan: you have to turn off the training setting yourself. Team and enterprise plans are the ones that exclude your data from training by default. Look at the type of account, not the price.
I pasted a confidential document by mistake: what should I do?
Delete the conversation, then tell your manager or your data protection officer right away. It is up to the company to judge whether to go further. Reporting it quickly is always better than keeping quiet.
Who should I ask if my company has no rule?
Your data protection officer if there is one, otherwise your management or your IT team. The data protection authority in your country may publish guidance: in France, the CNIL’s questions and answers on generative AI can serve as a basis for writing a policy.
Sources
- CNIL’s questions and answers on using a generative AI system (July 18, 2024, in French), CNIL, the French data protection authority
- Regulation (EU) 2016/679, the General Data Protection Regulation (Articles 4 and 9: personal data, special categories of data), EUR-Lex, European Union
- Personal data: definition (in French), CNIL, the French data protection authority
- Sensitive data: definition (in French), CNIL, the French data protection authority
- Data controls FAQ, OpenAI, help center
- Is my data used for model training?, Anthropic, privacy center
- Gemini Apps Privacy Hub, Google
- Enterprise data protection in Microsoft 365 Copilot, Microsoft
- Privacy policy, Mistral AI
Go further
- ChatGPT: privacy, setting by setting
- Claude: privacy, setting by setting
- Gemini: personal account or Google Workspace
- Microsoft Copilot: personal or work account
- Mistral Vibe, the French assistant
- AI meeting notes: the precautions
- Getting started with AI at work: the first five moves
- AI training for data protection officers
- AI training for HR managers
- AI training for in-house counsel
- AI training: all jobs
Create your workspace. Solo, or as a team.
Nova shows each person what AI can do in their job, guides them to the result, and keeps them up to date.
Interactive demo
€0
Free, no account needed. You try the real product yourself, as a preview: it is not a sales call.
Try the interactive demoTeams
from €129 per month
Team, Business, or Company, for up to 50 people. Beyond that, custom, quote on request.
See pricingNo commitment · Cancel anytime · Nova is subscription software, not an accredited training provider