By Jordi Daniels, founder of AI Board · ·
It depends on the plan and on what employees put into it. On ChatGPT Business and Enterprise, OpenAI does not train on your data by default. On Free, Go and Plus it may, unless you switch that off.
So the biggest risk is not a business plan. It is the employee who pastes customer data into a personal account.
This piece is part of the overview ChatGPT, Claude or a local model: which AI for business. Every claim about OpenAI links to one of OpenAI's own pages, checked on 25 September 2026.
Full disclosure: AI Board sells a different product. So do not take our summary on trust. Click through to the source.
What OpenAI commits to, plan by plan
OpenAI draws one hard line. On one side are services for individuals: Free, Go, Plus and Pro. On the other side are the business plans: Business and Enterprise.
| Free, Go and Plus | Business | Enterprise | |
|---|---|---|---|
| Training on your conversations | Allowed, unless you turn off "Improve the model for everyone" (OpenAI Help) | Not by default (OpenAI) | Not by default (OpenAI) |
| Retention | Chats stay in your history until you delete them; a temporary chat up to 30 days (OpenAI Help) | Admins set retention; deleted chats removed within 30 days, unless law or protection requires longer | Admins set retention; deleted chats removed within 30 days, unless the law requires longer |
| Administration | None: each user manages their own account | Admin console, SAML SSO and MFA; admins can view, export and delete conversations | On top of that, SCIM, key management and an audit log through the Compliance API |
| Data processing addendum | No; OpenAI processes under its own privacy policy | Available | Available |
| Storage in Europe | Not mentioned | Not mentioned | Possible for new workspaces (OpenAI) |
The Business and Enterprise columns come from Enterprise privacy at OpenAI, unless stated otherwise. The admin features are also listed on chatgpt.com/pricing.
Three details deserve attention, because most summaries leave them out.
The feedback button counts. If someone on a personal account gives a thumbs up or down, OpenAI may use the whole conversation for training. According to OpenAI, that applies even after an opt-out.
On business plans, systems look along. OpenAI runs business data through automated classifiers and safety tools. On Business, authorised employees and specialised third-party contractors have limited access, including for abuse investigations.
Encryption and audit. OpenAI encrypts data at rest with AES-256 and in transit with TLS 1.2 or higher. It reports that Business and Enterprise have completed a SOC 2 Type 2 audit.
Connected apps and your own GPTs fall under the business commitments too. If you connect a document store, for example, OpenAI does not train on what ChatGPT retrieves from it by default.
According to OpenAI, ChatGPT respects your existing permissions there, and each user signs in to the connected app separately. The admin decides which apps are switched on.
GPTs that employees build inside the workspace fall under the same commitments. If the admin enables public sharing, published GPTs may get additional review.
That is a seriously managed business product. Anyone who claims OpenAI trains on your Business conversations by default contradicts OpenAI's own documentation.
The real risk: personal accounts
The biggest chance of a leak is not in the business plan. It is in the employee who pastes a customer file into their own free account.
The Dutch Data Protection Authority received reports of exactly such data breaches. An employee at a GP practice entered patients' medical data. At a telecom company, a file with customer addresses went into a chatbot.
The regulator draws a sharp distinction. If employees use a chatbot on their own initiative, against company agreements, it is a data breach. If it is company policy, it is often not permitted by law.
Banning alone rarely works. The MIT research in the shadow AI economy found that at over 90% of companies, employees use their own AI tools for work.
Only around 40% of those companies had an official subscription, according to the same research. So the work is already happening, just out of sight.
A business plan brings that work back under control. One place, with commitments, a retention period and an admin. That is the real gain of Business over a personal Plus account.
What does work? Give people a better alternative than their personal account. Agree on what may go in. And make it easy to report a mistake.
A leak you never hear about is a leak you cannot fix. An employee who dares to say "I pasted something that should not be there" is your best security.
Data processing addendum and GDPR
This is not legal advice. It is the set of facts OpenAI publishes itself, so your lawyer or privacy adviser knows where to look.
OpenAI offers a data processing addendum (DPA) for ChatGPT Business, ChatGPT Enterprise and the API. You sign it through a form linked from the business privacy page.
If your business is in the European Economic Area, you sign the DPA with OpenAI Ireland Ltd. In it, OpenAI acts as a processor. Where appropriate, OpenAI helps with a data protection impact assessment (DPIA).
On Free, Go and Plus, your business has no DPA. According to the European privacy policy, OpenAI Ireland is the controller there itself. Your business then has no agreement with OpenAI about that data.
A DPA alone does not put your use in order. The Dutch regulator asks organisations for clear agreements with employees about what may and may not go into a chatbot.
A starting point for those agreements is our AI policy example. Adopt it, adapt it and have it checked by whoever handles privacy for you.
What may go in, and what may not
Use this list as a starting point for your own agreements. It assumes a business plan with a data processing addendum.
May go in:
- Public information, such as your website, press releases and published figures.
- Your own drafts without names: a proposal outline, an email draft, the structure of a presentation.
- Questions about method, such as how to build a business case or write a formula.
- Internal documents without personal data, if your policy allows it.
Only with agreements:
- Personal data of customers or employees. Only on a business account with a DPA, only if the purpose requires it, and only after review.
Keep out:
- Special category data, such as medical data. That is exactly the example from the report to the Dutch regulator.
- National ID numbers, passwords, API keys and other access codes.
- Information under confidentiality, such as an NDA, unless the contract allows it.
- Customer data in a personal account, not even "just quickly".
When in doubt, anonymise first. Replace names with roles and exact amounts with orders of magnitude. The question often stays just as answerable.
And for the admin
A business plan is only as safe as its settings. Five things to arrange at the start, all features OpenAI describes itself:
- Sign the data processing addendum before any personal data goes in.
- Turn on SSO sign-in, so access runs through your own account management.
- Choose a retention period that fits your own policy, not the default.
- Switch on only the apps you need, and add more later.
- Keep public sharing of GPTs off, unless there is a reason for it.
What ChatGPT Business costs
A business seat costs less than many people think. All prices are per user per month, checked on 25 September 2026.
| Plan | Billed annually | Billed monthly | Terms |
|---|---|---|---|
| Business, standard seat | $20 | $25 | 2 to 200 users |
| Business, premium seat | $100 | $125 | five times the usage of a standard seat |
| Enterprise | no public price | no public price | through sales |
| Plus, personal | not listed | $20 | one user, no admin |
Sources: the ChatGPT Business billing page and What is ChatGPT Plus? on the OpenAI Help Center. In the Netherlands, chatgpt.com/pricing shows €21 and €26 for the standard seat, €23 for Plus and €8 for Go.
Ten employees on a standard seat cost $200 a month billed annually. That is $2,400 a year, and $50 a month less than billed monthly.
If employees now pay for Plus themselves, you pay twice once Business is added. Cancel those personal plans.
Every business plan side by side, including Claude's, is in what does AI cost your business.
ChatGPT, Claude or an assistant on your own data
Security rarely decides this. On business plans, OpenAI and Anthropic both say they do not train on your data by default. What Anthropic commits to per plan is in Claude for business.
Which one fits better depends on your work. We work that out in ChatGPT, Claude or a local model.
If one decision-maker wants AI on the company's own data, there is a third form: an assistant on your own laptop.
For business owners in SMEs, we install it on a setup day. What that looks like for your company is something we discuss in a call.
Not everything stays local there either. In the Claude edition, your question and the retrieved context go to Anthropic. Only in the local edition does that stay on your laptop too. How we describe that is on our security page.
Frequently asked questions
Does OpenAI read my conversations?
Systems do, people only in limited cases. OpenAI runs business data through automated classifiers and safety tools. On Business, authorised employees have access for support, abuse investigations and legal compliance. Third-party contractors only for abuse review.
On Enterprise, OpenAI says its employees only access conversations for incidents, for recovery with your permission, or when the law requires it. Inside your own company, the Business admin can view conversations.
Is my data used to train ChatGPT?
On Business and Enterprise, not by default, unless you opt in yourself. On Free, Go and Plus, OpenAI may use your conversations.
You switch that off with "Improve the model for everyone" under Settings and Data controls. Temporary chats are not used for training and are kept for up to 30 days.
May I enter customer data into ChatGPT?
Not in a personal account. On a business plan with a data processing addendum it can work, if purpose and agreements support it. Have that checked by whoever handles privacy for you.
Keep special category data, such as medical data, out. The Dutch regulator names exactly that example in the reported breaches.
Is ChatGPT GDPR compliant?
"GDPR-proof" does not exist as a certification, for any product. Whether your use of ChatGPT complies with the GDPR depends on your own setup.
Think of which plan, which DPA, which data and which agreements with employees. In the Netherlands the regulator is the Autoriteit Persoonsgegevens. Its guidance is in Algorithms, AI and the GDPR.
What if we already work in Microsoft 365?
Then your licence often already includes a basic version of Microsoft Copilot. What Microsoft commits to on your data, and whether you need the paid add-on, is in our piece on Microsoft 365.