How can you use ChatGPT safely for work?
Start with a simple rule:
Give the AI only the information required to complete the task.
ChatGPT can help with drafting, restructuring, brainstorming, explaining concepts and creating templates, but workplace convenience should not override your employer's privacy, confidentiality, security or data-handling rules.
Before using any AI service with work information, check what your organisation allows.
Good work tasks for AI assistance
Many useful tasks do not require confidential information.
Examples include:
- improving the structure of an email
- turning rough notes into a checklist
- brainstorming headings
- creating a generic project template
- explaining an unfamiliar technical concept
- improving grammar
- generating interview questions
- converting instructions into steps
- identifying possible risks in a fictional scenario
or creating a reusable meeting agenda.
The safest starting point is often to ask:
Can I complete this task with invented or generalised information?
If yes, there may be no reason to paste the real data.
Information you should treat carefully
Workplaces use different classifications, but information that may require special handling includes:
- customer names
- personal email addresses
- phone numbers
- addresses
- identification numbers
- employee records
- passwords
- API keys
- access credentials
- internal financial data
- unreleased business plans
- confidential contracts
- medical information
- source code that your organisation considers confidential
- legal correspondence
- security configurations
- information covered by a nondisclosure agreement.
This list is not exhaustive.
Your employer's policy determines what you are authorised to share.
Use the minimum-information principle
Suppose you want help improving a customer-service email.
You may not need to provide:
Sarah Williams from Example Corporation, account 8763542, complained about invoice 55291 for $4,780.
Instead, use:
A customer says an invoice contains an incorrect charge. Rewrite my response so it is clear, professional and apologetic without admitting liability.
The second prompt can accomplish the writing task without exposing unnecessary identifying information.
Redact before you prompt
Redaction means removing or replacing information that is not needed.
Useful placeholders include:
- [CUSTOMER]
- [COMPANY]
- [EMPLOYEE]
- [PRODUCT]
- [ACCOUNT NUMBER]
- [DATE]
- [AMOUNT]
- [LOCATION]
- Before
Please summarise this complaint from Maria Gonzales at Brightway Ltd about invoice INV-93844 and her account 447291.
After
Summarise this customer complaint. Replace identifying details with neutral descriptions and separate the issue, requested outcome and next action.
The important skill is not merely deleting names. Ask whether the remaining details could still identify a person or reveal confidential business information.
Five safer prompt patterns
These patterns are deliberately generic so they can be adapted without real confidential data.
Rewrite without providing the real message
Create a professional response to a customer who reported a delayed delivery. Acknowledge the issue, explain that it is being investigated and provide a clear next step. Do not invent a delivery date.
Create a reusable template
Create a weekly project-status template with sections for completed work, current tasks, blockers, decisions required and next steps.
You can fill in approved information later.
Analyse a fictional example
A fictional project is two weeks behind because one supplier missed a delivery. List five questions a project manager should ask before changing the schedule.
Improve structure with placeholders
Improve the clarity of this internal announcement while keeping all placeholders unchanged: “[TEAM] will move from [SYSTEM A] to [SYSTEM B] on [DATE].”
Ask for a verification checklist
Create a checklist for reviewing a technical troubleshooting guide before it is sent to a customer. Include factual accuracy, safety, prerequisites, rollback steps and unclear assumptions.
None of these requires actual customer records.
Separate the task from the data
One of the most useful habits is to split your workflow into two stages.
Stage 1: Ask AI for structure
Generate:
- template
- checklist
- questions
- outline
decision criteria. Stage 2: Add approved information yourself
Insert the real names, numbers or internal details inside your authorised workplace systems rather than unnecessarily submitting them to an external AI service.
This approach can preserve much of the productivity benefit while reducing unnecessary disclosure.
Never paste passwords or secrets
Do not include:
- passwords
- one-time codes
- private cryptographic keys
- API secrets
- authentication tokens
- recovery codes
- or unrestricted access links
in a prompt.
If a secret has already been exposed accidentally, follow your organisation's incident process and rotate or revoke the credential where appropriate.
Do not assume deleting a chat alone is an adequate credential-response procedure.
Check AI-generated work before using it
AI output can be fluent and still contain mistakes.
Verify:
- names
- dates
- calculations
- citations
- technical commands
- legal wording
- policy statements
- product specifications
- claims about customers or colleagues.
For consequential work, use the original authoritative source rather than relying on an AI answer as the final authority.
Do not use AI to invent evidence
A professional document should not contain fictional facts merely because they make the writing sound stronger.
Do not ask AI to invent:
- customer testimonials
- financial figures
- research
- project results
- qualifications
- references
- audit findings
- quotations
or completed testing.
If information is unknown, mark it for confirmation.
Check your workplace policy first
Some organisations allow approved AI tools for particular tasks.
Others restrict:
- external AI platforms
- certain data categories
- customer information
- internal documents
- regulated data
or source code.
If your employer provides an approved enterprise tool or specific procedure, follow that policy rather than generic online advice.
What about ChatGPT privacy and data controls?
ChatGPT products and controls can change.
Before using ChatGPT at work, verify the current official documentation for your plan, its data controls and retention behaviour, and any workplace or enterprise features your organisation provides.
The article should not imply that all ChatGPT plans have identical privacy or data-handling behaviour.
Pre-prompt checklist
Before submitting work information, ask:
- Is this AI tool approved for this task?
- Does the prompt contain personal information?
- Does it contain customer data?
- Does it contain confidential company information?
- Can names and identifiers be removed?
- Can the task be completed with fictional data?
- Does the prompt contain credentials or secrets?
- Will a human verify the result?
- Is there an authoritative source for factual claims?
- Does my workplace policy permit this use?
If you are unsure about a sensitive-data question, do not submit the information until the appropriate policy or owner is consulted.
Bottom line
Using ChatGPT safely at work is largely about data minimisation and verification.
Use generic prompts where possible, redact unnecessary identifiers, never submit credentials, follow workplace rules and check AI-generated facts before they affect customers, colleagues or business decisions.
Source checks
Use the current guidance from OpenAI Help Center, OpenAI, OpenAI Help Center for the claims and procedures discussed above. Product interfaces, prices, rules and availability can change, so recheck time-sensitive details before acting.
