Subscribe free
Sample edition.These stories, sponsors and partners are placeholders for design and testing, not news. Live editions come from the curation pipeline and are signed off by an editor.
UK3 min readUpdated 07:02

Pasting work into a chatbot? Check these three things first

Before you paste something into an AI chatbot, ask yourself one question: would I be happy if a stranger read this?

UK data rules still apply when you paste text into a chatbot. Check the data, the account and the settings, and you can use AI at work with confidence.

Treat a chatbot like any other data processor: lawful basis, minimisation, a contract, sensible retention and, for risky uses, an impact assessment.

Same story, three depths. Switch at any time.

AI chatbots are brilliant at tidying up emails and summarising documents. But if what you paste is about a customer, a patient or a colleague, it is probably , and UK law says you have to look after it.

Three quick checks. Is anyone named or identifiable? Take the names out first. Is this my work account or my personal one? Use the tool your employer has approved. Is history switched on? Many apps keep your chats unless you change a setting.

None of this means you shouldn’t use AI at work. It means you use it the way you’d use email: carefully, with the right account.

Under , anything about an identifiable person is . Pasting a customer email or a staff review into a chatbot is processing that data, so the usual rules apply: have a reason, use no more than you need, and keep it secure.

The data. Remove names and details the task doesn’t need. Often you can swap them for placeholders and get the same result. The account. Consumer accounts and business plans differ. Business plans usually offer a and keep your conversations out of model training by default; check what your employer has approved. The settings. Look at chat history, training and memory settings, and how long recordings or files are kept.

If you’re unsure, ask whoever looks after data protection in your organisation. In a small business that may be you, and the regulator’s website has guidance written for small firms.

Prompting an external model with is processing under , and the provider is usually your processor. That brings the familiar obligations: a lawful basis, purpose limitation, data minimisation, security, and a that rules out training on your data unless you have agreed to it.

Practical controls: pseudonymise before prompting where the task allows, route sensitive workloads to business or API tiers with clear retention terms, log what is sent for audit, and check where data is processed if international transfers matter to you. For new high-risk uses, such as profiling customers or monitoring staff, run a data protection impact assessment before you go live.

The regulator’s AI guidance covers fairness and transparency too. If a model helps make decisions about people, tell them, and keep a human able to review the outcome.

Try it yourself 2 minutes

  1. Open your AI app’s settings and find the privacy or data section.
  2. Check whether your chats are used to improve the service, and switch it off if you prefer.
  3. Next time, replace names with ‘Customer A’ before you paste.

Try it yourself 2 minutes

  1. Take a recent work email you’d like help with.
  2. Replace each name and contact detail with a placeholder.
  3. Ask: Rewrite this reply to be friendlier and shorter.

Try it yourself 2 minutes

  1. List the AI tools your team uses this week.
  2. Mark which run on consumer accounts and which have a processing agreement.
  3. Move one sensitive workflow to the approved tier.

Spotted a mistake? Tell us and an editor will check it.

More from Unjargoned