Plainstart Back to the kit

Article

Someone Pasted Confidential Data into an AI Tool. What Now?

If this just happened, take a breath. A calm, ordered response is more useful than a fast, panicked one. This article walks through the practical steps. It is a general guidance checklist, not legal advice. If the data involved belongs to customers, employees, or any regulated category, speak to a qualified professional before deciding what to do next.

Step 1: Establish Exactly What Went In

Before you do anything else, write down what you know.

Answer these questions:

  • What data was pasted? Names, email addresses, financial figures, health information, contract terms, passwords, something else?
  • How much of it? One record or many?
  • Was it your data, your customers' data, your employees' data, or a third party's data?
  • Who pasted it, and when?
  • Was this a one-off or part of a regular workflow?

Write it down now, even in rough notes. You will need this record later, whether for your own review or for a conversation with a professional.


Step 2: Identify the Tool

The tool matters. Each platform handles your data differently.

Common tools where this happens:

  • ChatGPT (OpenAI), including free and Plus tiers
  • Claude (Anthropic)
  • Gemini (Google)
  • Microsoft Copilot
  • A browser-based AI tool of unknown origin

If you are not sure which tool was used, check with the person who pasted the data. The tool's URL or the browser history will usually confirm it.


Step 3: Check That Tool's Data Retention and Training Settings

Go to the tool's privacy or settings page. Look for two things specifically.

First, is conversation history turned on?

Most consumer AI tools store your conversations by default. Some use those conversations to improve their models unless you opt out.

What to check per tool:

  • ChatGPT (free or Plus): Go to Settings, then Data Controls. You can turn off "Improve the model for everyone." You can also turn off chat history entirely.
  • Claude (Anthropic): Anthropic's current policy states it does not train on conversations from users who opt out or who use the API. Check the current privacy settings in your account.
  • Gemini (Google): Go to myaccount.google.com, then Data and Privacy, then Web and App Activity. Gemini conversations may be stored there.
  • Microsoft Copilot: If used through a Microsoft 365 business account, the data handling follows your organisation's Microsoft tenant settings. If used through the consumer web interface, check Microsoft's privacy dashboard.

Second, are you on a consumer plan or a business plan?

Business and enterprise plans from most major providers include stronger data protection commitments, such as not using your inputs for training. Consumer plans often do not. This distinction matters.

Check the plan your organisation is actually paying for, not the plan you assumed you were on.


Step 4: Delete the Conversation and Any Saved History

Once you know what tool was used and what the settings are, delete the specific conversation.

How to delete:

  • ChatGPT: Open the conversation in the sidebar. Click the three dots next to it. Select Delete. Then go to Settings, Data Controls, and check whether any memory features are storing content separately.
  • Claude: Open the conversation. There is a delete option in the conversation menu.
  • Gemini: Go to myaccount.google.com, Manage your data and privacy, and delete the relevant activity from Gemini Apps activity.
  • Microsoft Copilot (consumer): Use the conversation history panel to delete the session. Check Microsoft's privacy dashboard for any stored activity.

Be aware that deletion removes the conversation from your visible history. Whether it removes it immediately from the provider's servers depends on that provider's data retention policies. Read the relevant policy or contact the provider's support directly if you need certainty.


Step 5: Work Out Who Else Is Affected

This step is where the seriousness of the incident becomes clearer.

Ask yourself:

  • Whose data was in the paste? Yours alone, or other people's?
  • If it was customer data: how many customers, and what type of data?
  • If it was employee data: payroll, performance, health, or something else?
  • Is any of this data covered by a regulation you are subject to, such as UK GDPR, the EU GDPR, HIPAA, or a sector-specific rule?

If the answer to any of those questions involves other people's personal data, this is no longer just an internal process issue. Stop here and get professional advice before deciding what to tell anyone or what to do next. This is general guidance and cannot substitute for a qualified legal or compliance professional when personal data is involved.


Step 6: Decide Whether Anyone Needs Telling

This decision depends on what went in and whose data it was.

If it was only your own internal business data with no personal data belonging to others: You may be able to handle this internally. Document it, fix the process, and move on.

If it involved other people's personal data: UK GDPR and many other frameworks have specific rules about when a breach must be reported to a regulator and when affected individuals must be notified. There are time limits. You need professional advice, not a checklist.

If it involved commercially sensitive third-party information: Check any NDAs or contracts that cover that information. You may have a contractual obligation to notify.

If you are in any doubt: Tell a qualified professional what happened before you tell anyone else. Getting the sequence wrong can make things worse.


Step 7: Write Down What Changed So It Does Not Recur

Once the immediate issue is handled, document what happened and what you are changing.

A short incident note should cover:

  • Date and time of the incident
  • What data went in and to which tool
  • What you did in response, and when
  • What process or setting change prevents this happening again

Then make the process change. Common changes after this type of incident:

  • Add a rule to your AI usage policy that lists categories of data that must never be pasted into an AI tool
  • Clarify which tools staff are approved to use and under what conditions
  • If you are using a consumer plan for business work, move to a business plan with appropriate data terms or stop using that tool for work
  • Brief anyone else who might be doing the same thing

A Short Note on This Article

Everything above is general practical guidance. It is not legal advice, compliance advice, or a substitute for professional counsel. If this incident involves personal data belonging to customers or employees, or if you operate in a regulated sector, speak to a qualified solicitor or data protection professional before making decisions about notification or reporting.


The Underlying Problem: No Policy

Most incidents like this happen because there was no clear rule about what staff could and could not do with AI tools. People defaulted to what was fast and convenient.

A written AI usage policy changes that. It gives staff a clear list of what is permitted, what is not, and what to do if something goes wrong. It does not need to be long. It needs to be specific and readable.


Get the Free AI Usage Policy

Plainstart provides a free, plain-language AI usage policy for small and medium businesses. It covers approved tools, data handling rules, prohibited inputs, and what to do when something goes wrong.

It is free. No account needed.

[Download the free AI Usage Policy at Plainstart]

If you want the full framework, the Plainstart AI Adoption Kit includes the policy, a data governance checklist, a 90-day adoption plan, a tool scorecard, prompt libraries, an ROI tracker, and a one-page staff briefing document. The full kit is $149.

AI adoption, done properly.

Free download

The AI Usage Policy your team can actually follow

One page, plain language, ready to put in front of staff today. No cost, no catch.

Get the free policy