Twelve years in AI and automation · Auckland, New Zealand 021 365 082 Taking new projects Book a free call
Home What I build Case studies FAQ Newsletter Contact Book a free call

Guide · Staff and personal AI accounts

Is It Safe for Staff to Use Their Own ChatGPT Accounts for Work?

A plain-English guide for New Zealand businesses: what actually happens to the data, what the Privacy Act expects, and what a proper company setup costs.

Updated28 September 2026
Reading time7 minutes
BasedAuckland, working NZ-wide

How common is it?

In the New Zealand businesses I talk to, staff using their own ChatGPT or Claude accounts for work is extremely common, and it is admitted to far less often than it actually happens. Owners tend to find out when someone mentions it in passing, or when a document turns up that plainly wasn't written the usual way.

That is not a reason to be angry with anyone. Staff reach for these tools because they help, and usually because the business hasn't given them an approved alternative. The problem is not that people are using AI. It is that the business has no say in how.

The four risks

These are the four things I walk every client through before we talk about which tool to use.

  • 1. Customer data. A customer's name, email, account details or complaint pasted into a personal account is personal information leaving your control. Under the Privacy Act 2020 the business is still responsible for it, and the Office of the Privacy Commissioner expects senior leadership to have approved AI use and thought through the risks first.
  • 2. Sensitive company data. Pricing, margins, contracts, staff matters, tender responses and anything under a confidentiality agreement. Once it is in someone's personal account, it sits there for as long as they keep the account.
  • 3. Inconsistency. Five people using five different tools, plans and prompts produce five different standards of work. Nothing learned is shared, customers get answers in different voices, and nobody can check how a piece of work was produced.
  • 4. It walks out the door. A personal account belongs to the person. When they leave, the chat history, the useful prompts and any client material in it go with them, and the business cannot get it back or delete it.

What the privacy settings actually do

The settings on personal plans are real, but they are controlled by the individual, not the business. Here is how the two most common tools handle it on personal plans, as at September 2026:

  • ChatGPT Free, Plus and Pro. The "Improve the model for everyone" setting is on by default, which lets OpenAI use conversations to train its models. Each person can switch it off under Settings, Data controls (OpenAI data controls).
  • Claude Free, Pro and Max. Each person chooses whether their chats are used for training. If they allow it, Anthropic may keep that data for up to five years; if not, the standard retention is 30 days (Anthropic privacy centre).
  • Business plans. ChatGPT Business, Claude Team and Enterprise, Microsoft 365 Copilot and Gemini in Google Workspace do not train on your content by default, and they give the business an admin console, central billing and control over who has access.

So asking staff to "turn training off" helps with one risk out of four. It does nothing for inconsistency, and nothing for what happens when someone leaves.

Ban it, pay for it, or set rules?

Banning AI rarely works. Given how much of it already happens quietly, a ban mostly pushes it further out of sight. What works is giving people an approved tool that is at least as good as the one they were using, and a short set of rules for it.

Which tool is right is horses for courses, and it starts with asking your people what they actually want it for. Someone who wants help writing formulas in Excel is best served by Copilot, inside Excel. Someone who wants code reviewed will get more from ChatGPT or Claude. Someone living in Gmail and Google Docs already has Gemini on most Google Workspace plans. I cover that choice in detail in ChatGPT, Claude, Copilot or Gemini: which should a NZ business use?

"A company subscription costs about a couple of hours' wages a month, and that is very easy to win back." Skene Bennellick, founder, ez-ai.nz

What a company subscription costs

Business plans for the main AI assistants cost roughly NZ$30 to $45 per person per month, or less where an assistant is already bundled into software you pay for. Prices as at 28 September 2026, excluding GST. Plans billed in US dollars are converted at about US$1 = NZ$1.75.

PlanPrice per person per monthNotes
ChatGPT BusinessUS$20 annual / US$25 monthly (about NZ$35 / $44)Standard seat. Premium seats with 5x usage are US$100 annual.
Claude TeamUS$20 annual / US$25 monthly (about NZ$35 / $44)Standard seat, 2 to 150 users, includes Claude Code. Premium seats US$100 annual.
Microsoft 365 Copilot BusinessNZ$29.14 annual (promotional) / NZ$40.80 monthlyAdd-on to an existing Microsoft 365 plan. Normal annual price NZ$34; the discount runs to 31 December 2026. Copilot Chat is included free with most Microsoft 365 business plans.
Gemini in Google WorkspaceIncluded from NZ$21 (Business Standard)Gemini in Gmail, Docs, Meet and more is bundled into Workspace Standard and Plus. Starter (NZ$10.50) includes Gemini in Gmail only.

For comparison, the personal plans staff are often paying for themselves cost about the same: ChatGPT Plus and Claude Pro are both US$20 a month. The difference with a business plan is who controls it.

A one-page AI rule for staff

You don't need a long policy. One page that answers five questions covers most small and medium businesses.

  • Which tools are approved? Name them, and say that work goes in the company account, not a personal one.
  • What never goes in? Passwords and access keys, payment details, health information, and anything covered by a confidentiality agreement unless the approved tool has been cleared for it.
  • Who checks the output? A person reads and owns anything that goes to a customer. The AI drafts; it does not send.
  • When do we tell customers? If AI is used in a way that affects customers or their information, the Privacy Commissioner expects them to be told how and why, in plain language.
  • Who do I ask? One named person for questions, and a simple way to suggest new uses.

Review it every six months. The tools change fast enough that a rule written today will need adjusting.

Frequently asked questions

Is it illegal for staff to use ChatGPT for work in New Zealand?

No. Using AI tools at work is legal. The Privacy Act 2020 still applies, though: if personal information about customers or staff goes into an AI tool, the business is responsible for how it is handled, whichever account it went into.

If staff turn off training in their personal account, is that enough?

It deals with one risk: the provider training on the conversations. The business still has no visibility of what is being used, no consistency across the team, and no access to the history when the person leaves. A company plan fixes all three.

Do business plans train on our data?

Not by default. ChatGPT Business, Claude Team and Enterprise, Microsoft 365 Copilot and Gemini in Google Workspace all exclude business content from model training by default. Check the settings when you set the plan up, and keep an eye on the terms, because they do change.

What is the cheapest way to give staff an approved AI tool?

Use what you already pay for. Copilot Chat comes free with most Microsoft 365 business plans, and Gemini is included in Google Workspace Business Standard and above. For many teams that covers everyday drafting and summarising, and you only pay for more where someone needs it.

Want a hand setting it up?

A free 30-minute call is enough to work out which tool suits how your people actually work, and what your one-page rule should say. Discovery is always free.

Book a free call