

ChatGPT promises to revolutionise the way we write and work. In late May, Thomson Reuters announced a partnership with Microsoft (which essentially controls ChatGPT) to create a contract drafting AI for Word. Meanwhile, Microsoft’s Co-Pilot promises ‘a whole new way to work’.
But ChatGPT and generative AI are also set to drastically change the face of privacy.
Concerns have already been raised around the potential privacy risks that come with ChatGPT, for example:
While we expect a position on how to handle privacy issues with generative to be developed, there any many questions currently to be addressed by organisations looking to take advantage of this exciting new technology.
In this post, we’ll outline some key privacy concerns you should consider before using (or continuing to use) ChatGPT.
ChatGPT uses and stores the information you (and your employees and other stakeholders) share when you engage with it to train its AI and improve its services. The only way around this is to use the paid version of ChatGPT and opt out of this collection.
The OpenAI Privacy Policy notes that it may share the information it collects with vendors and service providers, business transfers, and its affiliates. This is an incredibly broad (and vague) data sharing provision that offers limited protections for anyone who uses the platform.
In other words, ChatGPT collects, processes, and uses all the information you share. The platform’s FAQs outline that you should avoid sharing sensitive information with it and highlights that its team may read any prompts you input.
Since ChatGPT collects, stores, processes, and uses the information you feed it, there is a risk that your organisation may breach your privacy policy and/or privacy laws. And the risk isn’t insignificant. In fact, a report from Cyberhaven notes that 11% of employees have pasted confidential or sensitive information into ChatGPT.
The Cyberhaven article reporting on their findings cites the following example:
“A doctor inputs a patient’s name and details of their condition into ChatGPT to have it draft a letter to the patient’s insurance company justifying the need for a medical procedure. In the future, if a third party asks ChatGPT “what medical problem does [patient name] have?” ChatGPT could answer based what the doctor provided.”
This example shows how sensitive information can be shared with ChatGPT. It’s also very likely to breach the privacy policy of the doctor as well as a suite of medical confidentiality laws.
While Australia does not have ‘a right to erasure’ (unlike under the GDPR and CPRA), federal privacy laws require covered organisations to take reasonable steps to destroy data once it is no longer needed. Specifically, APP 11.3 states:
“An APP entity must take reasonable steps to destroy or de-identify the personal information it holds once the personal information is no longer needed for any purpose for which the personal information may be used or disclosed under the APPs.”
This would be complicated where data has been shared with ChatGPT. The platform’s FAQs state that it cannot delete individual prompts.
![]()
This would mean Australian organisations would need to request all their data to be deleted. And given the lack of local laws, it’s uncertain whether OpenAI would honour this request.
Finally, ChatGPT also raises the stakes for organisational cybersecurity. ChatGPT can write malicious code and it’s likely to increase the sophistication of phishing efforts. As a result, it’s a good time to consider additional training for your team.
If you haven’t banned the use of ChatGPT and other generative AI in your organisation, you should implement a policy and processes that address the privacy risks associated with it:
Privacy 108 provides tailored privacy and security solutions to organisations operating in Australia. We can work with you to provide tailored training, upskill your team, or help you mature your organisational privacy.
Contact us to find out more.
"*" indicates required fields
"*" indicates required fields
Privacy 108 collects your name and email to send you our newsletter. If you do not provide this information, we will be unable to send it to you. We may use third-party service providers (such as email marketing platforms) to distribute our communications. Some providers may store information overseas, including in the United States. For more information about how we handle your personal information, including how to access or correct it or make a complaint, please see our Privacy Policy or contact us at hello@privacy108.com.au. You can unsubscribe at any time using the link in our emails or by contacting hello@privacy108.com.au.