Your staff use ChatGPT, is that a data breach?
Three-quarters of employees use AI at work. Often with customer data, often without you knowing. The privacy regulator is already seeing the first breaches. Here is what is happening, and how to solve it without banning ChatGPT.
TerenceRight now, somewhere in your business, someone is pasting a customer email into ChatGPT to turn it into a polished reply. Or a quote. Or a list of names and phone numbers that needs ‘quickly sorting’. Handy, fast, and exactly the kind of action the Dutch Data Protection Authority is warning about. Because the moment personal data lands in an AI chatbot, that can be a data breach. One you have to report within 72 hours. Your staff have been using ChatGPT for ages, the question is whether you know what they put into it.
Shadow AI: your people use AI, you don't know what for
There is a name for it: shadow AI. Employees use AI tools, ChatGPT, Copilot, Gemini, free translation sites, with no agreements in place. Not out of bad intent. They just want to work faster. But because nobody has oversight, you don't know what company information is leaving the building.
of Dutch employees use AI at work, but only 14% received any training for it (TNO, 2025).
That gap between using it and knowing what you're doing is the problem. Three-quarters of your people work with AI. One in seven has learned how to do it safely. The rest are guessing, and, in the worst case, pasting sensitive customer data into a tool with no idea where that data ends up.
Why ‘just ChatGPT’ can be a data breach
The Dutch Data Protection Authority (AP), the national privacy regulator, has issued a clear warning about this. It received several reports of data breaches caused by the use of AI chatbots. The best-known example: an employee at a doctor's practice entered patients' medical data into a chatbot. The company behind the chatbot can store and reuse what is entered, and at that point you have lost control.
You don't have to be a doctor to run the same risk. A name, a phone number, a customer address, a personnel file, an email containing a complaint, these are all personal data. The moment they land in an AI chatbot without you knowing what happens to them, that may count as a data breach under the GDPR. And a breach involving personal data must be reported to the regulator within 72 hours. Fail to do so, and that alone can earn you a fine.
The regulator's warning boils down to this: the moment an employee types personal data into an AI chatbot, the provider can gain access to it. From that point on, you no longer control where that data ends up.
What your people are probably already entering
Don't ask your team directly, almost nobody says ‘yes, I paste customer data into ChatGPT’. But take an honest look at what happens every day:
- Customer emails being ‘quickly rewritten’, including the name, order number and sometimes a complaint about a person
- Quotes and invoices pasted in as an example to generate a new one
- Lists of names, email addresses or phone numbers that need ‘sorting or cleaning up’
- Job applications and CVs being summarised or assessed by AI
- Minutes and meeting notes with the names of customers, suppliers or staff
- Snippets from your bookkeeping or customer system handed over as context
Each one a logical, well-meant action. And each one a potential data breach if the tool isn't set up safely.
The double risk: not just the GDPR
Since 2 February 2025, there is something else. The European AI law (the AI Act) requires every company that uses AI to ensure its staff are ‘AI literate’, they need basic knowledge of what the tool can and cannot do safely. That is article 4. So one employee casually pasting customer data into a chatbot is two things at once: a possible GDPR breach and a sign that you don't meet that AI-literacy requirement.
of employees already use AI agents that carry out tasks on their own, without the employer knowing (NTX, 2026).
So this isn't shrinking. Where last year it was ‘someone asks ChatGPT a question’, there are now increasingly tools that independently send emails, book appointments or process files. If you have no view of that, the risk grows by the week.
Is ChatGPT even allowed under the GDPR?
Yes, ChatGPT isn't banned. It's not about the tool, but about what you put into it. Asking ChatGPT to write a blog or work out an idea without personal data? No problem. Pasting in a customer file or an email with names? That's where the risk starts. The line is simple: if information goes in that lets you identify a person, it doesn't belong in an open AI tool. That one rule prevents the vast majority of problems.
Banning it doesn't work, it makes things worse
Many owners' first reflex: ‘ChatGPT at work? Forbidden.’ Understandable, but it backfires. Your people use it because it makes their work easier. Ban it and they won't stop, they'll just do it in secret, on their own phone, out of all sight. That makes the problem invisible instead of smaller. The solution isn't less AI, but AI you can actually trust.
What does work, in 4 steps
- Make it discussable. Ask, without blame, which tools your team uses and what for. You'll be shocked how much is already running. This is also step one of the AI literacy the law requires.
- Agree what may never go into an open AI tool. One simple rule everyone gets: no names, no customer data, no personnel files in ChatGPT or a free translation site. Put it on a single page.
- Provide a safe alternative. This is the core: as long as there's no good, safe tool, people keep using the unsafe one. Make sure there's a version where company data doesn't leak out.
- Keep it alive. Make one person responsible, review it briefly once a quarter, and adjust your agreements as new tools appear.
The easiest mistake is thinking one email saying ‘stop doing this’ is enough. It isn't. As long as the safe alternative is missing, convenience always beats the rule.
The real solution: your own safe version
A list of rules won't stop anyone under time pressure. What does work is an AI tool that's just as easy as ChatGPT, but set up for your business, connected to your own systems so that customer data stays in-house. Your people get the speed they want, and you keep control over where the data goes.
That doesn't have to be a big, expensive project. It often starts with the two or three actions your team reaches for AI most, answering emails, drafting quotes, cleaning up lists, and you build a safe version for those. The rest follows naturally once people see it works and that it's allowed.
How Socialo approaches this
I start with a free introductory conversation. We discuss what takes time, which systems you use and where automation could help. You then receive a proposal with automation opportunities, integrations, a schedule and costs.
Ready to get started?
Request a free consultation. We look together at where you are losing time.
Schedule free callShadow AI isn't a future problem. Your staff use AI now, every day, often with data that should never leave the building. The good news: you don't have to ban it and you don't need a lawyer for it. You just have to make it visible and offer a safe alternative. Sort that out now and you'll be ahead, instead of playing catch-up with a breach report in hand.