02 / 15·PDPO, cross-border data, and private AI
Can staff use of ChatGPT breach the PDPO?
Green, amber, red
Green: public product copy and published market facts. Amber: internal drafts after names and phone numbers are removed. Red: ID numbers, bank details, unpublished contracts, staff discipline records, and raw client chats.
What the one-pager should say
Name the approved tools, banned fields, who may clear amber items, and what happens if someone breaks the rule. New joiners read it on day one. If you cite PCPD generative-AI staff guidance, verify the official title and date on the PCPD site first.
What managers should do
Sample a month of pastes. Move red-zone work to an enterprise account or private AI instead of relying on a verbal reminder.
Questions
- Is a company-email ChatGPT account safe?
- Not by itself. Who owns the login and what gets pasted are different questions. Consumer plans may still use chats under their terms.
- Is removing the name enough?
- Not if a phone number, contract ID, or address still identifies the person. Amber becomes green only when the person cannot be identified.
This article is general information, not legal advice. PCPD guidance changes — check the latest version before you rely on it.
Want a first look at whether one real workflow touches personal data? Book a 1-hour business diagnosis.
Book a 1-hour diagnosis