Category: Data Privacy

  • Paying for ChatGPT or Claude Doesn’t Make Your Business Data Confidential

    Paying for ChatGPT or Claude Doesn’t Make Your Business Data Confidential

    A growing number of business owners run day-to-day work, drafting emails, summarizing contracts, brainstorming strategy, through a paid AI subscription, and assume that because they’re paying, their conversations are private. That assumption is often wrong. Consumer-paid plans like ChatGPT Plus or Pro, Claude Pro or Max, and Gemini Advanced buy you speed, higher limits, and better models than the free tiers, but they remain consumer products governed by individual terms of service and privacy policies, not the enterprise contracts that come with real confidentiality guarantees.

    This post covers general business confidentiality. It doesn’t address the separate, more demanding duty attorneys owe under the rules of professional conduct, that’s a different discussion for another day. If you’re a lawyer, the short version is: do not put client information into a free or consumer-tier AI tool. And to be clear, nothing here is a recommendation of one platform over another; each has its own strengths, and this is simply a look at what their policies actually say.

    Are Your Prompts and Responses Actually Confidential?

    Not completely. Your prompts and the model’s responses are processed and stored on the provider’s own systems, not end-to-end encrypted the way a secure messaging app is. Providers retain data for operational, safety, legal, and, depending on your settings, model-improvement purposes. Consumer paid plans don’t come with the contractual protections, a data processing agreement, zero-data-retention options, audit rights, that commercial and enterprise tiers typically include. Treating a paid consumer chat as a private notebook is a real risk for client data, employee or customer personal information, or anything covered by an NDA or a regulatory obligation.

    Will Your Conversations Be Used to Train the Model?

    This is where the platforms diverge most, and it’s worth checking your own account settings rather than assuming.

    • OpenAI (ChatGPT, including Plus): the default is on. Your conversations may be used to train future models unless you turn off “Improve the model for everyone” under Settings, Data Controls. Temporary Chats are never used for training and are deleted after 30 days regardless. Business, Enterprise, Team, and Edu plans include additional controls and generally exclude customer data from training by default.
    • Anthropic (Claude Free, Pro, Max): the default is off. Anthropic only uses your chats to improve Claude if you affirmatively turn that setting on in Privacy Settings, with one exception: conversations flagged by Anthropic’s safety systems can still be analyzed to improve abuse detection regardless of your setting. Incognito chats are excluded from training even when the general setting is on. Feedback submitted through the thumbs up or down button is retained for up to five years and may be used regardless of your training preference. Claude for Work and API accounts don’t train on customer content by default.
    • Google (Gemini, including Advanced): controlled by the “Keep Activity” setting. When it’s on, your chats, and Gemini Live audio, video, or screenshares, may be used to improve Google’s AI models, with your activity auto-deleted after 18 months by default (adjustable). When it’s off, chats aren’t used for training, but Google still retains them for 72 hours to operate the service and guard against abuse, and submitting feedback can bring part of that conversation back into scope for review.

    Across all three, an opt-out, or a decision not to opt in, is forward-looking only. Data already folded into a completed training run can’t be pulled back out after the fact.

    Can a Human Actually Read What You Typed?

    Yes, in a limited way, on every platform. A restricted set of employees or contractors can review flagged or sampled conversations to investigate abuse, respond to a support request you initiated, handle legal process, or check response quality when training and improvement settings are enabled. Google is explicit that a subset of chats go through human review to improve its models and keep the platform safe, and that reviewed conversations are retained separately for up to three years, even after you delete your own activity history. None of the major platforms promise that no human will ever see a given conversation; they promise that access is limited, logged, and tied to a specific business reason.

    What This Means for Your Business.

    A paid subscription buys you capability, faster responses, higher limits, stronger models, not enterprise-grade confidentiality. If your team is putting anything sensitive into an AI tool, contract terms, financial data, employee information, unreleased product details, the safer path is an approved commercial or enterprise account whose contract actually restricts training and human access, backed by an internal policy that keeps that kind of information off personal accounts.

    Even on a consumer plan, you can meaningfully cut your exposure:

    • Turn off the model-improvement or training setting, and use Temporary, Incognito, or “Keep Activity off” modes where available.
    • Keep confidential, personal, or regulated data out of the tool entirely.
    • Review and delete chat history on a regular schedule.
    • Check the current settings and policy language for the specific plan your team actually uses, these terms change, and the version that matters is the one attached to your account today.

    Policies on all three platforms have shifted meaningfully over the past year, and they’ll shift again. The summary above reflects each provider’s stated policy as of this writing; the only reliable source going forward is the terms and privacy settings tied to your own account.

    This post is provided for general informational purposes only and does not constitute legal advice. It does not address the separate confidentiality obligations attorneys owe under the rules of professional conduct. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific circumstances.

  • Data Privacy Compliance for SaaS Companies Selling Across State Lines

    Data Privacy Compliance for SaaS Companies Selling Across State Lines

    If your SaaS company sells to customers in more than one state, and most do by design, you are likely already subject to more than one state’s privacy law, whether or not your company is headquartered in that state. What began with California’s Consumer Privacy Act (“CCPA”) has grown into a patchwork of approximately twenty (20) comprehensive state privacy laws, with more states adopting similar frameworks each year. This year alone Indiana, Kentucky, and Rhode Island joined the list. For SaaS companies, “we’re not based there” is no longer a reliable answer to “do we have to comply there.”

    Why Your Home State Doesn’t Determine Your Obligations

    Most state privacy laws apply based on where your customers or users are located, and how much of their personal data you process, not where your company is incorporated or headquartered. A SaaS company based in Oklahoma serving customers in California, Colorado, Virginia, Connecticut, and a dozen other states can find itself subject to all of those states’ requirements simultaneously. It’s a bit of a compliance nightmare right now with little hope for a unified federal data privacy law coming to tame the masses. As for current state laws, applicability thresholds vary (some laws apply based on revenue, others based on the number of residents’ records processed), so the analysis has to be done state by state.

    The Common Threads Across State Laws

    Despite the patchwork, most comprehensive state privacy laws share a core set of requirements: consumers get rights to access, correct, delete, and in some cases port their personal data; consumers can opt out of the sale of personal data and certain targeted advertising; companies must maintain reasonable data security safeguards; and companies must have data processing agreements in place with vendors and subprocessors who touch personal data on their behalf. If your SaaS product already has a privacy policy and a standard Data Processing Agreement (“DPA”) in its commercial contract stack, you have a foundation. The question is whether that foundation actually reflects the specific obligations that apply to your current customer footprint.

    Where SaaS Companies Typically Get Tripped Up

    Three recurring gaps show up again and again: DPAs that were drafted years ago and never updated to reflect current state law requirements or the company’s current subprocessor list; privacy policies that describe data practices in the abstract but don’t actually match what the product does today; and no internal process for tracking which states trigger new obligations as the customer base grows, so compliance becomes reactive instead of built in.

    A Practical Starting Point

    Before assuming you need a state-by-state legal opinion for every jurisdiction, most SaaS companies benefit from three concrete steps: mapping what personal data the product actually collects and where it flows, including subprocessors; reviewing the current DPA and privacy policy against that map; and building a lightweight internal process to flag new state obligations as the customer base expands. From there, targeted legal review can focus on the states and data types that create the most real exposure, rather than trying to solve every jurisdiction at once.
    Multi-state privacy compliance is manageable when it’s built into how a SaaS company already reviews and negotiates its commercial contracts, rather than treated as a separate project. If your DPA or privacy policy hasn’t been reviewed against your current customer footprint, that’s a good place to start the conversation.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific circumstances.

  • The Importance of Data Privacy to Businesses

    The Importance of Data Privacy to Businesses

    In today’s interconnected world, data privacy has emerged as a cornerstone of trust and responsibility. At its core, data privacy refers to the proper handling, processing, and protection of personal information, such as names, contact details, financial records, or behavioral data, ensuring it is collected, stored, and used in ways that respect individuals’ rights and expectations. For business executives, this concept is not just a technical concern but a strategic priority that can define a company’s reputation, compliance posture, and bottom line.

    Why should data privacy matter to leaders? First, customers and clients increasingly demand transparency and control over their information. A breach of trust, whether through a cyberattack or careless data practices, can erode loyalty and drive stakeholders away. In an era where consumer awareness is at an all-time high, businesses that prioritize privacy signal integrity and reliability, fostering stronger relationships.

    Second, the regulatory landscape continues to tighten. Governments worldwide are enforcing stringent laws, imposing hefty fines, and holding companies accountable for mishandling data. Executives who overlook these obligations risk not only financial penalties but also legal scrutiny that can disrupt operations and tarnish their brand.

    Finally, data privacy is a competitive advantage. As organizations leverage advanced technologies like AI and big data analytics, those that embed privacy into their strategies can innovate responsibly, avoiding the pitfalls of overreach. With digital transformation accelerating, executives who champion privacy will position their companies as leaders in an ethical, customer-centric marketplace.

    In short, data privacy is no longer optional, it’s a business imperative. For executives, understanding and prioritizing it ensures resilience, trust, and long-term success in a data-driven world.

  • The Data Privacy Hodge-Podge

    The Data Privacy Hodge-Podge

    On February 12, 2025 the U.S. House of Representatives Committee on Energy and Commerce announced the formation of a working group to explore creation of a framework for a comprehensive national data privacy bill. It seems Congress is catching a little heat from some business industry groups growing evermore concerned about the proliferation of state-specific data privacy laws. Will Congress put on their big boy/girl shorts and work together to pass a federal data privacy law that will preempt state data privacy laws and unify data privacy law across the nation? Looking back at my magic 8-ball again…”all signs point to probably NOT.” Congress has tried repeatedly over the last few years to hold hands and agree on some sort of privacy legislation, but failed to even get a bill to a full vote of their respective chambers. Most recently, just last June, a data privacy bill in the House Energy and Commerce Committee was scheduled for a markup session but was cancelled due to disagreement over its provisions. I’ll also note this year’s would-be data privacy law is being assigned to a working group of nine Republicans and ZERO Democrats; not exactly a bipartisan hug-it-out to get this done for the people kind of a start.

    In the absence of any ability of the U.S. Congress to get their collective brains dreaming in the same direction to pass a cohesive national data privacy law that doesn’t leave companies pulling their hair out attempting to be aware of and comply with various state’s data privacy laws, the problem is growing more unmanageable. As of this post 19 states have passed some version of a comprehensive data privacy law in an effort to protect their citizens personal data (6 of the 19 states’ laws don’t go into effect until later this year or 2026). In addition, there are 12 more states that currently have data privacy laws either introduced or already in committee in this 2025 legislative session. So, by the beginning of 2026 businesses will be struggling to navigate 31 or more distinct state data privacy laws. How does that sound, business leaders?

    Setting aside the 19 remaining states that, for whatever reason, do not yet have data privacy laws currently in process, this state-by-state solution is becoming a very large administrative burden on business. Before long we’ll all be telling jokes about the company’s army of data privacy specialists instead of its heard of accountants. Speaking of data privacy jokes, a little something from the Dad-Files, “Why doesn’t Cookie Monster have good internet privacy? Because he always accepts the cookies!” All my IT nerds out there are spitting Mountain Dew all over their monitors.

    The take away? Although our federal legislators continue to talk about, getting around to, proposing, to do something about a nationwide data privacy law. I’m not holding my breath. And in the meantime the states are cranking out new state-specific data privacy laws by the bushel. So, if you are a business that deals with personal data for employees, contractors, customers, vendors, or any other human being who possesses personally identifiable information, you need to enlist the assistance of a data privacy attorney or other privacy professional to ensure your business is compliant with all data privacy laws applicable to it. Data privacy is not going away, and its only getting bigger and less likely to not apply to you.

    Don’t think data privacy applies to you? Here is a fun fact for you. All data privacy laws define the processing of personal data. They might use a different word for “processing,” but it’s the same concept. I’ve participated in countless meetings with executives who assure me, neh, outright lecture me that the business is not processing personal data. All I do in response is read aloud the General Data Protection Regulation (“GDPR”) (fyi, GDPR is the mother and 500 lb. gorilla in the room of data privacy laws) definition of “processing.”

    “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    ~GDPR, Art. 4(2).

    It is correct to say that there are many reasons why a particular data privacy law may not apply to your business. But one thing that almost all data privacy laws have in common is a very broad definition of what constitutes processing (or selling or sharing, or whatever a specific jurisdiction may call it). So, if you store, transmit, delete or view personal data, you likely qualify as having processed it.

    Do yourself a favor, work with a data privacy attorney or other privacy professional to understand how your company’s data handling practices fit in with any and all applicable data privacy laws. If the professional you counsel with tells you data privacy doesn’t apply to you, then you can keep all the cookies too.

    Conduct yourself accordingly!