Assume it is happening, because it is #
Nobody asked permission, because at the time there was nothing to ask permission for. The tools were free, the sign up took a minute, and the alternative was another hour reformatting something. A person doing that is behaving sensibly inside the information they had.
What follows from it is less sensible, and it is the part worth understanding before deciding what to do. The exposure is not that a chatbot is dangerous. It is that a supplier relationship exists which your business never entered into, never documented and cannot describe.
The four things that are actually wrong #
-
You have a processor with no contract
UK GDPR requires a written contract whenever somebody processes personal data on your behalf, and the ICO sets out the minimum terms it must contain. Consumer terms accepted by an individual member of staff are not written to be that contract. The detail is in what a data processing agreement is for.
-
You cannot say where the data is
Which accounts, whose email addresses, what was pasted, how long it is kept, whether it may be used to improve a model. Those questions have answers, and the answers depend on plans and settings you have never seen.
-
You cannot answer a subject access request honestly
If a client or a member of staff asks for a copy of what you hold about them, an unknown number of conversations in accounts you do not control is a gap you cannot close by looking harder.
-
Leavers keep their accounts
An account created with a personal email address does not belong to you and cannot be disabled by you. Whatever went into it walks out with the person.
None of those requires anything bad to have happened. They are true on a quiet Tuesday with no incident at all.
When it becomes a breach #
A personal data breach is not limited to a hack. It includes personal data being disclosed to somebody who should not have it or accessed without authorisation. Client records pasted into a consumer account, with terms that permit the content to be used for purposes you never agreed to, is capable of being exactly that.
If it is, the ICO's requirements are specific. You assess the likely risk to people's rights and freedoms. Where that risk is likely, you notify the ICO as soon as possible and where feasible within 72 hours. Where the risk to people is high, you tell the individuals affected without undue delay. The ICO explicitly advises reporting early and updating later rather than waiting for a complete picture.
What not to do about it #
- Do not open with a ban. Banning the tools without giving people a sanctioned route does not stop the behaviour, it stops the reporting of the behaviour. You keep every bit of the exposure and lose the only source of information about it.
- Do not go looking through people's accounts. Beyond being slower and less complete than asking, monitoring workers brings duties of its own. The ICO requires a lawful basis, transparency about what is being collected, and a check that the monitoring is necessary with no less intrusive way of achieving the purpose.
- Do not make an example of anyone. The first person who tells you what they have been doing is doing you a favour. How that is received determines whether anyone else does.
- Do not moralise about it. Nobody set out to create a compliance problem. They were trying to get home.
A week that fixes most of it #
-
Call an amnesty and mean it
Say plainly that you want to know what is being used, that nobody is in trouble, and that the point is to make it safe rather than to stop it. Ask for the tool, the account, the email address it uses, and what sort of information has gone into it.
-
Write the list down
That list is the first time the business has known what it is exposed to, and it is usually shorter and more mundane than feared.
-
Draw the line in plain words
The one that works for most businesses is that client and staff personal data does not go into any tool the business has not approved. Drafting, rewording, summarising your own notes and working through a problem are fine, and that covers a surprisingly large share of what people were doing anyway.
-
Give them somewhere to go
A sanctioned route, on terms somebody has read, with accounts in the business’s name so leavers can be removed. What differs between plans is covered in is ChatGPT GDPR compliant.
-
Deal with the historic accounts
Ask people to delete what they can and to stop using personal accounts for work. Record what you asked and when.
-
Write down what you decided, and date it
That record is the difference between a business that took a decision and one that drifted into a position.
The part that is genuinely good news #
The amnesty tends to hand you something valuable by accident. The tasks people quietly automated for themselves are, almost by definition, the repeated ones that were slowing them down, and they are a free map of where the hours go.
That list is worth keeping next to the numbers from the cost of admin time calculator, and it is often a better starting point than anything a manager would have guessed.
Saying all of this to the team without it landing as an accusation is covered in what to tell your team, and the wider duties that come with any of these tools are in what UK GDPR asks of a business using AI.