Securing ChatGPT in your SME: preventing confidential data leaks

Published on May 11, 20268 min read
Illustration: a chat window with an AI, confidential-stamped documents scrolling through it

Sophie B. pastes a client's balance sheet into a chat window with ChatGPT and asks for a "presentable" summary before a meeting. The text contains a name, some figures, a company number. In three seconds, that firm data has just left the building, heading for an online service she has no control over. In the moment, no one at the firm sees a problem: the tool did the job, the summary is excellent.

That is exactly what makes this tricky — and why to secure ChatGPT you do not have to ban it, only to know what you feed it. The assistant is useful, fast, and it never warns you when you hand it something you should have kept to yourself.

Why securing ChatGPT has become an SME question

ChatGPT belongs to what we call generative AI: tools that produce text from a written instruction, called a prompt (whatever you type into the input box). You describe what you want, the tool writes it. Simple, and that is the trap: people type without thinking about what actually leaves.

Because a prompt is not a search that evaporates. By default, on consumer versions, what you write can be kept and used to improve the service. In practice, your text leaves the company and lands on servers you do not control, often hosted abroad. There is nothing malicious about it: this is how the tool normally works, and most people have no idea.

A useful reflex is to think in terms of a perimeter. As long as a document stays inside the firm's accounting software or its professional mailbox, it is with you, governed by your rules. The moment it is pasted into a public chatbot, it crosses an invisible border: you are no longer the only one deciding what happens to it. And unlike an attachment you can "recall" or delete, text handed to an online service is very hard to get back once it is gone.

For an accounting firm, this is the heart of the matter. Sophie B. and her colleagues handle data covered by professional secrecy all day long: bookkeeping, salaries, tax situations, banking details for dozens of client SMEs. Pasting one of those documents into a public chatbot means entrusting highly sensitive information to a third party, with no contract, no idea where it ends up or how long it stays there.

The nFADP (Switzerland's data protection act, in force since 2023) expects an SME that holds personal data to take "appropriate" security measures and to keep control over what it entrusts to its subcontractors. Sending client data to an online service without having decided or framed that use is the very opposite of control. And if the firm handles files on people based in the European Union, the GDPR (the equivalent European regulation) is added to the equation.

There is a second, quieter angle. The same tools that help Sophie B. write also help fraudsters: a phishing email drafted with AI no longer has the spelling mistakes or clumsy phrasing that used to give the scam away. All the more reason to raise the whole team's vigilance, without demonising tools that have become, for many, a working reflex.

What to remember

  • The tool is useful; the risk comes from how it is used. The problem is not ChatGPT itself, but what you feed it without thinking. The right question is not "should we ban it?" but "what has no business being in a prompt?".
  • What you type can leave the company. On default versions, pasted text can be kept and reused. Treat every prompt as a message sent to the outside world.
  • The responsibility stays yours. Neither the tool nor your IT provider carries professional secrecy on your behalf. The firm answers for its data, to its clients and to the law.

Habits to put in place this week

1. Write a one-page rule

Not a twenty-clause policy: a single page, readable in two minutes, saying what is allowed, what is forbidden, and what calls for a second thought. The core is a list of things that never go into a chatbot: client names and contact details, figures and accounting documents, salaries, passwords, company numbers, ID documents.

Give the team one simple test that replaces everything else: "Would I email this to a stranger?" If the answer is no, it does not belong in a prompt either. Sophie B. can get this page adopted in a single meeting, pin it near the workstations, and add it to onboarding. A rule no one reads protects no one: it has to fit on a page and speak the way people speak at the office, not like a contract.

2. Adjust the tool and anonymise before pasting

Two habits that change everything. First, in ChatGPT's settings, turn off the use of your conversations for training (and history, if you do not need it); for regular use, a professional or "enterprise" version, which does not exploit your data, is preferable.

Then get into the habit of anonymising before you paste: remove names, replace real figures with rough orders of magnitude, drop the company number. AI helps you structure "a client's" balance sheet just as well as "Mr So-and-so's" — but without exposing anyone.

In plain terms: nine times out of ten, the AI does not need the real data to be useful. It needs the structure of your request, not the identity of your clients. Separating the two quickly becomes second nature, and it is the most effective protection because it depends on no tool: it lives in the way you phrase the question.

3. Talk to the team, openly

Most leaks come not from intent but from a habit picked up with no guidance. A quarter of an hour is enough: show a concrete case (the pasted balance sheet), explain why it is a problem, and name one person to turn to when in doubt. The Swiss National Cyber Security Centre (NCSC) recommends exactly this kind of short, regular awareness rather than long training quickly forgotten.

The goal is not to frighten or forbid: it is that everyone knows, the moment they paste something, whether the move is harmless or not. A team that has been told the why watches itself far better than a team that has simply been told "it is banned" — especially when the banned tool is one click away and useful every day.

Where do you really stand?

These three habits are about governance and awareness — two areas where firms often believe they are "roughly in order" without ever having checked. Securing ChatGPT is not ticking a box: it is knowing who uses what, with which data, and under what clear rules.

The Cyber Passport self-assessment helps you take that honest look. It certifies nothing and does not declare you "compliant": it shows you, question by question, where your organisation stands firm and where it rests only on everyone's goodwill. To go further and roll out a real generative-AI usage policy, our dedicated blueprint lays out the full plan, step by step.

Topics

  • generative AI
  • ChatGPT
  • data leak
  • SME
  • nFADP

Read next