ChatGPT Training NZ, home

10 min read. Updated 6 October 2026

Is our data safe in ChatGPT? Plans, training opt-outs, data residency and admin controls

Whether ChatGPT is safe for your business data depends far more on the plan and settings you choose than on the product itself. This guide explains what OpenAI does with your content on each plan, where it is stored, and the admin settings worth changing on day one.

Illustration generated with AI.

The short answer depends on the plan

ChatGPT comes in two families, and they treat your content differently. Personal plans, which are Free, Go, Plus and Pro, are built for individuals. On those plans OpenAI may use what people type and upload to train its models, depending on each person's settings1. Business plans, which are ChatGPT Business, Enterprise, Edu and the API, are built for organisations. OpenAI says it does not use content from those workspaces to improve its models by default1.

That single difference explains most of the risk. The NCSC makes the same point in its AI guide for small businesses: whether a provider trains on submitted data can depend on configuration settings or the type of subscription13. Before you ask whether ChatGPT is safe, ask which ChatGPT your staff are actually using. In many small New Zealand firms the honest answer is a mix of personal free accounts and one paid Plus account on the owner's credit card.

  • Free, Go, Plus and Pro: content can be used for training unless each person opts out1.
  • Business: workspace content excluded from training by default, with admin controls5.
  • Enterprise and Edu: excluded from training, with added identity, retention and residency controls6,7.

Training opt-outs on personal accounts

If someone must use a personal account, turn training off. On the web, open the account menu, choose Settings, then Data controls, and turn off Improve the model for everyone2. On iOS and Android the same toggle sits under Settings, then Data controls2. Once switched off, new conversations are not used to train models, and the setting applies across the person's devices2. Chat history keeps working.

Temporary Chat is a second option for one-off sensitive questions. A temporary chat does not appear in history and is not used to improve models while it stays temporary. OpenAI may still keep a copy for up to 30 days for safety purposes3. Treat it as a privacy convenience, not a security control.

Neither setting fixes the governance problem. A personal account belongs to the person, not the business. When they leave, their chat history, uploaded files and anything they built in the account leave with them. Public service guidance from the Government Chief Digital Officer also tells staff not to put personal information into public generative AI systems14.

How long chats and files are kept

Deleting a chat removes it from the account straight away. OpenAI then schedules it for permanent deletion from its systems within 30 days, unless it has been de-identified or must be kept longer for security or legal reasons4. Deleted projects, and the files stored only in them, follow the same 30-day pattern4.

Enterprise customers get more control. OpenAI lists a custom data retention window among the Enterprise privacy controls, along with the Enterprise Compliance API for logging and audit6,12. If your industry has record-keeping rules, such as a law firm's file retention or a financial adviser's advice records, the Compliance API and eDiscovery integrations are a real reason to choose Enterprise over Business12.

Where your data lives, and what residency covers

Data residency is the question NZ boards ask most, and the answer needs care. OpenAI offers ChatGPT data residency in a set of regions that includes Australia, Japan, Singapore, the United Kingdom, Europe and the United States7. New Zealand is not on the list. Residency covers in-scope customer content stored at rest, and it is available to eligible new Enterprise and Edu customers, not to ChatGPT Business7.

Storage is only half of it. Inference residency, meaning the model runs on your content inside the region, is offered in fewer places: Europe, the United States and the United Arab Emirates, and only when data residency is also enabled there7. An Auckland firm that chooses Australian residency gets its stored content held in Australia, but the processing may still happen elsewhere. Read the exact scope before you promise a client anything.

For most private businesses, overseas storage is lawful under the Privacy Act 2020 when OpenAI acts only as your service provider, but you stay responsible for the information. Our guide on ChatGPT and the Privacy Act explains that test in more detail.

Security and certifications in plain terms

OpenAI says its Enterprise data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher6. It also says ChatGPT Enterprise is covered by its SOC 2 Type 2 report and is certified against ISO 27001, 27017, 27018 and 277016. Business plan data is also encrypted in transit and at rest, according to OpenAI5. You can request the audit reports through the OpenAI Trust Portal15.

Certificates show that a vendor runs a managed security programme. They do not show that your workspace is set up well. Plenty of incidents start on the customer side instead: a shared link sent to the wrong person, a former employee who still has access, or a connector that gives ChatGPT more reach than anyone intended.

Admin controls worth setting on day one

ChatGPT Business and Enterprise both have an admin console. The settings below close the common gaps. Work through them before you invite the wider team.

Connected apps deserve the most attention. In ChatGPT Business, apps are on by default, and an admin can change which ones the workspace may use from the Plugins area of the Admin Console8. Enterprise and Edu admins can also use role-based access control to decide which groups can use each app8. Company knowledge, which lets ChatGPT search connected tools like SharePoint and Google Drive, respects each user's existing permissions9. That is only as safe as those permissions. If your shared drive lets everyone open the payroll folder, ChatGPT will too.

  • Verify your company email domain so only your staff can join11.
  • Turn on single sign-on with your identity provider where your plan supports it16.
  • On Enterprise, connect SCIM so leavers lose access when their directory account is disabled10.
  • Review the apps list and switch off every connector you do not need yet8.
  • Fix shared-drive permissions before enabling company knowledge9.
  • Decide who can create, share and publish skills and plugins. List any custom GPTs the team relies on and plan their move to plugins, because OpenAI is retiring custom GPTs17. The current retirement date is 11 December 2026, and custom actions must be rebuilt18.
  • Check usage analytics monthly to spot unexpected connector use10.

A worked example: a Christchurch engineering consultancy

Consider a generic forty-person engineering consultancy in Christchurch. Staff use a mix of free ChatGPT and Plus accounts. A director asks whether drawings and client reports are safe. The honest answer is no, not in the current setup, because several accounts still have training switched on and nobody can see what has been uploaded1.

The firm moves to ChatGPT Business, verifies its domain and asks staff to migrate their useful chats into the new workspace. The admin leaves the SharePoint connector off for the first month while the IT provider tidies folder permissions. The firm writes a one-page rule that bans uploading client contracts marked confidential until the director approves a project. Six months later, a large client asks for New Zealand or Australian data storage. The consultancy now has a clear decision: Enterprise with Australian residency, or keep that client's work out of ChatGPT7.

A data safety checklist for owners

Use this list as the minimum standard before your team puts client or staff information into ChatGPT. The NCSC recommends a similar mix: review vendor data handling, set an internal policy on what data cannot go into AI tools, and train staff and remove personal details before upload13.

  • Move all work use to a Business or Enterprise workspace1.
  • Ask staff to turn off model training on any personal account they still use2.
  • Write down which data types are banned from ChatGPT, such as IRD numbers, health details and passwords.
  • Sign OpenAI's data processing addendum6.
  • Set domain verification, SSO and a connector allow-list8,11,16.
  • Check whether any client contract or sector rule requires local storage, and confirm residency scope in writing7.
  • Remove access the same day a staff member leaves.
  • Review the setup every six months, because plan features change often.

Related

  1. 1Organisation

    ChatGPT Business and Enterprise rollout

    Set up a ChatGPT workspace properly: plan choice, admin settings, an AI use policy, shared skills and Projects, and support that keeps people using it.

  2. 2Advanced

    Skills, plugins, workspace agents and connected apps

    For power users and technical leads: skills, plugins, Projects, ChatGPT Work, connected apps, data analysis and workspace agents.

Industries

Regions

More on privacy and security

See all guides.

Questions

Can OpenAI staff read our chats?

OpenAI says a limited number of authorised personnel and trusted service providers may access content to investigate abuse or security incidents, provide support or handle legal matters1. On business plans that access is governed by your agreement and the data processing addendum6.

Is ChatGPT Business safe enough for client files?

For most small professional firms, yes, once it is set up properly. Business content is not used for training by default and is encrypted5. Lock down connectors, verify your domain and keep a rule about which client files need approval first8,11.

Can we keep our ChatGPT data in New Zealand?

Not at present. The nearest listed residency region is Australia, and it is offered to eligible Enterprise and Edu customers7. If you need New Zealand storage by contract, keep that work out of ChatGPT or ask OpenAI for a written position.

Does Temporary Chat make a conversation private?

It keeps the chat out of history and out of model training while it stays temporary, but OpenAI may keep a copy for up to 30 days for safety3. It does not replace a business plan.

Train your team

  1. Send us a few linesHow many people, where you are, and the jobs that eat your week.
  2. We reply with a planA suggested session and format, plus what to bring: real quotes, emails and questions.
  3. Your team does the workAt your place or over video. They finish with ChatGPT doing real tasks, not demos.
  • In person
  • Remote
  • Half-day workshop
  • Full-day workshop
  • Team rollout

Independent training by TheColab. Not affiliated with OpenAI.

Enquire

Tell us about your team. We reply by email with a suggested course and format.

We use these details only to reply to you, and store them securely with TheColab. Privacy

Sources