ChatGPT Team and confidential documents: what it solves and what it doesn't

The short answer. ChatGPT Team is a real improvement: OpenAI doesn't train on your data by default, you get admin controls and a proper business processing relationship. But it explicitly does not solve one thing: you still transmit the raw content of your documents to OpenAI's servers. Not training is different from not sending. For confidential client documents, a step belongs in front: make the document safe, then give ChatGPT Team the safe version.

Make your document safe for ChatGPT

What ChatGPT Team handles well

Credit where due, this is valuable:

  • No training on your data, by default, no opt-out hunting.
  • A business processing relationship with a DPA, instead of consumer terms.
  • Admin controls: workspaces, access management, shared GPTs.
  • Serious security certification of the infrastructure.

If your team works with AI daily, a business plan is the right foundation. This is not a "ChatGPT bad" story.

What it does not handle

Four things stay open, and they are exactly what your client will ask about:

  1. The data still leaves your control. Your client's question is not "was it trained on?" but "why were my name and figures on those servers at all?". No plan answers that.
  2. Minimisation remains your duty. GDPR requires processing no more than necessary. A summary does not need real names and amounts. A DPA with OpenAI does not release you from that.
  3. History is an archive. Every chat containing raw client data is a searchable file riding on every account in your workspace. One phished account, and everything ever pasted is exposed.
  4. You cannot verify it yourself. Retention, logging and abuse monitoring happen outside your sight. The policy may be sound; you cannot audit it.

The combination that works

Don't choose between ChatGPT Team and safe documents. Stack them:

LayerWhat it covers
ChatGPT TeamTraining, administration, contractual base
ShareSafe.ai in frontWhat gets sent in the first place
Identity Key with youTranslating back without the link ever leaving the building

The workflow: document through ShareSafe.ai first (EU processing, nothing stored, you hold the key), safe version into ChatGPT Team, answer translated back locally. How that works team-wide: [A GDPR-safe AI document workflow for consultants].

FAQ

Is ChatGPT Enterprise enough then?
Enterprise mainly adds scale, SSO and stronger guarantees. Stronger contract, same principle: the raw data is still sent. Minimisation remains your measure, on every plan.
Does this apply to Claude for Work and Copilot too?
Yes. The business plans from Anthropic, Microsoft and Google arrange similar things and leave the same question open. The step in front is identical for all of them.
Doesn't pseudonymisation ruin ChatGPT's quality?
Rarely. Consistent placeholders preserve structure: [NAME_01] stays the same person, ratios between amounts stay intact. For most advisory work the difference is not noticeable.
We already have a DPA with OpenAI. Why this extra step?
A DPA governs the relationship with the processor. Minimisation governs what you hand that processor. They are two separate obligations, and your client feels the second one most.

ShareSafe.ai is part of VaultLM. Raw files stay in the EU. Minimal retention. You hold the key. Try it with your own document →