ChatGPT Training NZ, home

9 min read. Updated 6 October 2026

A ChatGPT usage policy your New Zealand team can apply

A useful AI policy answers the questions staff face at the keyboard: which account to use, which information to include, who must check the result and what to do when something goes wrong. Build those answers around the work your business actually does.

Illustration generated with AI.

Define the work you are authorising

Begin with a task register. Ask each manager to describe a recurring job, its inputs, its output and the person who normally approves it. Include informal uses already happening on personal accounts. A policy that covers marketing drafts but ignores the office manager's uploaded customer spreadsheet leaves a large gap. Collect examples without collecting the sensitive documents themselves.

Separate permission to try ChatGPT from permission to use a particular dataset or release an answer. A staff member may have an approved account and still lack authority to upload a contract. Likewise, an approved upload does not make the resulting advice correct. MBIE's governance guidance recommends clear oversight and accountability for AI risk across the business.1

For a generic Hamilton accounting practice, the starting register might permit rewriting a public service description and organising an empty month-end checklist. Client accounts and staff performance records stay outside the initial scope. This is an illustrative decision, not a report about a client. Record why each task is allowed and what would trigger a fresh assessment.

  • Name the manager who approves new uses and the administrator who implements account controls.
  • Write the permitted outcome: for example, an internal draft for review, rather than a general licence to automate finance.
  • Give staff an escalation route when their task falls between the listed examples.
  • Add contractors and temporary workers to the scope if they handle your information.

Select the workspace and match the controls to it

Use the actual plan name in the policy: ChatGPT Business or ChatGPT Enterprise if that is what you have purchased. OpenAI states that content in these managed workspaces is excluded from model training by default. On personal accounts, the relevant control is Settings, then Data controls, then Improve the model for everyone. Turning it off does not delete chat history.2

Write a company rule that business work belongs in the approved workspace. Show staff how to recognise its name before they paste text. Specify who can invite users and remove leavers. Keep account sharing out of the process. A manager should be able to trace an approved workflow to an authorised person, rather than a shared login used by several teams.

Treat connected services as a separate approval. Current OpenAI guidance puts user app connections under Settings, then Plugins. Workspace administrators can review them in Admin Console by selecting the ChatGPT workspace and opening Plugins. Provider permissions and workspace controls still apply.3 Before enabling an app, document which account it connects, what information it can reach and whether it can change records.

  • Keep a dated record of the settings you checked, including any control unavailable on your plan.
  • Choose a backup administrator and test their access before the primary administrator is away.
  • Require approval for a new plugin, external action or shared resource that changes the information flow.
  • Use a safe practice chat to show staff the workspace selection and connection controls.

Write data boundaries people can recognise

The Privacy Act 2020 applies when your business uses AI with personal information. The Office of the Privacy Commissioner recommends a Privacy Impact Assessment before use and regular updates as risks change. Its guidance covers collection, security, use, accuracy and sharing.4 Start with a diagram of where an input goes, who can see the output and where the accepted result will be stored.

Use business examples to define your categories. Public information could include an already published brochure. Restricted business material could include a confidential supplier agreement. Personal information could include a customer complaint, employee contact details or an identifiable photo. Removing a name may leave enough clues to identify someone. MBIE warns that apparently anonymised inputs can be combined with other information to re-identify people.5

Make your initial rule conservative: no identifiable customer or employee material until the privacy review authorises the precise use. The Commissioner's generative AI guidance cautions against entering personal or confidential information without explicit confirmation about provider retention and disclosure.6 An account's training default answers only part of that question. Check retention, access, the contract and any downstream app before approving the workflow.

  • Approved practice material: public product copy, empty forms and fictional training records that cannot identify a person.
  • Approval required: non-public commercial documents, client material and data with contractual restrictions.
  • Excluded from ordinary prompting under this starter policy: payroll detail, medical information, bank details, passwords and access keys.
  • Check attachments, screenshots and document comments as carefully as the text entered into the chat.

Assess overseas processing and shared Projects

Avoid a blanket statement that every overseas cloud upload is an overseas disclosure. The Privacy Commissioner explains that a provider acting only as your processing agent can fall within section 11 of the Privacy Act 2020. A provider using information for its own purposes changes the analysis. Use the Commissioner's decision tree to assess whether the overseas-disclosure rules apply and what safeguards you need.7 Record your reasoning and obtain specialist help for uncertain arrangements.

ChatGPT Projects group files, instructions and chats. OpenAI's current sharing controls distinguish chat access from edit access. Chat access includes visibility of project chats, files and instructions; edit access adds powers such as changing instructions and adding material.8 Tell people what that means before they add a document to a shared project. A shared space should have a defined business purpose and an accountable owner.

For an illustrative Nelson accommodation business, a shared guest-information project could hold public directions and approved descriptions of facilities. Guest medical requests and reservation records belong in a different process. The project owner checks every source before sharing and removes superseded versions. The guest-services manager still checks drafts against the current booking terms.

  • Use named recipients for sensitive team resources and review their access when roles change.
  • Describe which source folders an app may search and who approves changes to that scope.
  • Store the signed policy and approval register in your normal controlled document system.
  • Keep an accepted business record outside a chat when colleagues need reliable access to it.

Assign review duties for decisions that affect people

Choose reviewers by subject knowledge and authority. For a supplier letter, that might be the purchasing manager. For a calculation, use someone who can reproduce it in the source workbook. Give reviewers the original inputs, the draft and the assumptions. Asking ChatGPT to critique its answer is a useful extra step, but the reviewer must compare the result with independent evidence.

The Employment Relations Act 2000 includes good faith duties. Employment New Zealand explains that parties must communicate, respond and avoid misleading conduct.9 Set a policy rule that ChatGPT cannot make final hiring, performance or dismissal decisions. Require the responsible manager to seek advice on the applicable employment process before using an AI-assisted document in an employment matter.

The Health and Safety at Work Act 2015 places a primary duty of care on businesses. WorkSafe describes the duty to protect workers and others so far as is reasonably practicable.10 Allow ChatGPT to organise approved safety notes only within a defined review process. The competent safety lead must verify controls against the real job, site conditions and existing procedures before anyone follows the document.

The GCDO's guidance, published through DIA, is written for the Public Service. It addresses governance, security, skills and accountability.11 Private firms can use those headings as a review aid. They should not label that guidance a compulsory private-sector policy or claim that copying it establishes compliance.

  • Identify the reviewer in the task register before the workflow starts.
  • Check names, facts, calculations, source versions and promises made to the recipient.
  • Return incomplete work to the author with a specific issue to resolve.
  • Record approval before publishing, sending or acting on the result.

Adapt this policy outline to your business

Use the clauses below as an outline. Replace role labels with real responsibilities and add your own permitted tasks. These are recommended operating rules. They do not approve personal-information processing or decide how a law applies to a particular case. Attach the task register and privacy assessment so staff can see how the rules work in practice.

Keep the main document readable. Put technical settings and supplier terms in a controlled appendix. If a rule says manager approval is required, explain where to request it and how staff will know it has been granted. Test the draft by asking someone outside the pilot to decide whether an ordinary work task is allowed.

  • Purpose and scope: We use ChatGPT for the tasks listed in our approved-use register. This policy covers staff and contractors doing company work.
  • Account access: Use your own authorised login in the company workspace. The workspace administrator manages access and removes it when it is no longer required.
  • Inputs: Check the data category before entering text or attaching a file. Restricted material requires a recorded workflow approval from the designated manager and privacy lead.
  • Tools and sharing: Obtain approval before connecting an app or sharing a Project, GPT or plugin. State the recipients, source material and permitted actions in the request.
  • Outputs: Treat generated material as a draft. The task owner checks the sources and assigns a suitable reviewer before external release or a consequential decision.
  • People and safety: Managers remain responsible for employment and safety processes. AI output cannot authorise an employment action or a change to a safety control.
  • Records: Save the accepted output, review evidence and approval in the business system named in the task register. Apply the relevant retention schedule.
  • Incidents: Stop the affected workflow and contact the incident lead immediately. Preserve the details through the approved incident channel.
  • Exceptions and review: The policy owner records exceptions, trains affected staff and updates the document when the approved workflow or provider controls change.

Practise the policy and the incident response

Run a tabletop exercise with a generic scenario: someone has uploaded the wrong workbook. Ask staff to name the contact, explain what details to preserve and identify who can restrict access. Capture the account, workspace, time, information type and sharing status. Avoid copying the affected information into an ordinary team chat while reporting the mistake.

Your incident lead should assess containment and potential harm. Under the Privacy Act 2020, a breach that has caused or is likely to cause serious harm requires notification to the Privacy Commissioner and affected people as soon as practically able.12 Keep that legal assessment with the responsible person. Do not tell staff that deleting a chat automatically resolves a breach.

Introduce the policy with worked examples from each team and a short practice task. Invite people to report confusing rules without blame. Review exceptions after the first pilot and whenever a new feature changes access or actions. TheColab's ChatGPT Business and Enterprise rollout course can help your managers turn the outline into workspace controls and a team process.

  • Confirm staff can find the current policy and identify the person who handles privacy questions.
  • Ask each department to test an allowed task and an excluded task.
  • Check that managers can explain the approval route without referring staff elsewhere.
  • Keep a change log so training and settings remain aligned with the policy.

Related

  1. 1Organisation

    ChatGPT Business and Enterprise rollout

    Set up a ChatGPT workspace properly: plan choice, admin settings, an AI use policy, shared skills and Projects, and support that keeps people using it.

  2. 2Role-based

    ChatGPT for HR and people leaders

    Job ads, policies, onboarding and staff communication drafted with ChatGPT, with firm rules on employee personal information and human decisions.

Industries

Regions

More on rollout and governance

See all guides.

Questions

Does ChatGPT Business make our use automatically compliant?

No. Its training default is a provider control. Your business must still assess its collection, use, security and sharing of personal information under the Privacy Act 2020.2,4

Can an owner approve an exception verbally?

Use a written exception record. State the task, input restrictions, reviewer and expiry condition. That gives the administrator clear instructions and helps staff distinguish a specific approval from a permanent change to the rules.

How detailed should the first policy be?

Detailed enough to decide your initial tasks without guesswork. Begin with a short policy and a task register. Add a technical appendix when a workflow needs controls that ordinary staff do not administer.

Train your team

  1. Send us a few linesHow many people, where you are, and the jobs that eat your week.
  2. We reply with a planA suggested session and format, plus what to bring: real quotes, emails and questions.
  3. Your team does the workAt your place or over video. They finish with ChatGPT doing real tasks, not demos.
  • In person
  • Remote
  • Half-day workshop
  • Full-day workshop
  • Team rollout

Independent training by TheColab. Not affiliated with OpenAI.

Enquire

Tell us about your team. We reply by email with a suggested course and format.

We use these details only to reply to you, and store them securely with TheColab. Privacy

Sources