Back to blog
Communications team using AI in an office – what happens to company data?Made with AI
AIsecurityGDPRChatGPTcommunicationscompany data

What happens to company data when your communications team uses ChatGPT?

Mikko Oksanen

Mikko Oksanen

CEO & Co-Founder

03.04.20267 min read

Summary

  • Communications teams feed data into ChatGPT every day. What actually happens to that data? Read what GDPR requires and what consumer AI tools don't tell you.

This article is not anti-ChatGPT. It's written for those who already use it or are considering it – and who should know what it means from a data privacy perspective.

01It happens every day

A communications manager opens a browser, pastes a draft press release into ChatGPT, and asks for a summary. Or a copywriter feeds in a client brief and asks for three headline options. Or the CEO speaks out loud the key points of the communications strategy and asks the AI to build a presentation outline from them.

Each of these is an ordinary, useful, efficient action. And each one transfers information outside the organization in a way that no one has explicitly approved.

02What actually happens when you type text into ChatGPT?

There's no conspiracy here. OpenAI discloses its practices in its terms of service. The problem is that few people read them – and even fewer think about what they mean for their organization's data privacy.

In the consumer version (free and Plus), OpenAI's terms allow input data to be used for model development, unless the user explicitly opts out in settings. In many organizations, no one has ever gone in to change that setting.

In practice, this can mean:

  • An unpublished press release may end up as part of the model's training data
  • Details from a client brief travel to third-party servers
  • An internal communications strategy is written out in a tool whose privacy practices have not been assessed
  • No one in the organization knows who used what and with which data

This doesn't mean ChatGPT is a dangerous tool. It means that the consumer version is not designed with organizational security requirements in mind.

03GDPR enters the picture sooner than you'd think

In many organizations, the communications team doesn't think of itself as a processor of personal data. But the moment a name, title, email address, or identifiable role appears in a message or draft, you're in the realm of personal data processing.

GDPR requires that you know: where personal data is being processed, who is processing it, on what legal basis, and how long the data is retained.

When a communications team uses consumer AI without organizational approval and assessment, the answers to those questions are: unknown, unknown, not assessed, unknown. That is not an acceptable situation – neither legally nor from the organization's own risk management perspective.

04Is ChatGPT Teams or Enterprise the solution?

Yes, partially. OpenAI offers enterprise versions with training use disabled by default and stricter data privacy terms. The same applies to Anthropic's and Google's enterprise offerings.

But an enterprise licence only solves part of the problem. It doesn't solve:

  • The fact that work still happens in individual chat windows with no version history, approval process, or audit trail
  • The fact that no one has an overview of what the team is doing, with what data, and to what ends
  • The fact that AI-assisted content doesn't stay in the organization's memory – it disappears when the browser window closes

An enterprise licence makes the tool more compliant. It doesn't make it a communications management system.

05What does a purpose-built tool do differently?

Lyyli was built from the ground up with organizational communications security and compliance requirements in mind.

Data stays with your organization

Lyyli routes language-model requests through Vercel AI Gateway to model providers (Claude, GPT, Gemini). Language models process requests under Zero Data Retention: the provider does not retain the prompt or response after the request. Lyyli stores conversations to deliver the service. Claude and Gemini inference is locked to the EU; GPT processing cannot currently be limited to the EU only. Customer content is not used to train models under applicable agreements — but processing involves subprocessors, not a closed loop. Route details: AI model register.

Access control is built in

Role-based access control, workspace sharing, and user roles are not add-on features – they are the core of the product. You know who has access to what.

Audit trail shows what happened

All content-related changes and approvals leave a trace. No more situations where no one knows who did what and when.

Approval process is part of the workflow

Content goes through a structured approval process before publishing. The right people approve the right content – not via a Slack message, not via an email chain.

GDPR practices are up to date

Our privacy practices, data processing agreements, and controller obligations are available at lyyli.ai/legal.

06Three questions worth pausing to consider

If your communications team uses or is starting to use AI, pause for a moment:

Do we know what data our team is feeding into AI tools? If the answer is "not exactly", that's the first thing worth finding out.

Has the tool we're using been assessed against our organization's data privacy requirements? IT or legal can assess this if asked. Often they're not asked.

Does AI-assisted work stay in the organization's memory? Results, versions, approvals, changes – or does everything disappear with the browser window?

These don't require alarm or urgency. But they're worth knowing.

07Finally

AI in communications is not a risk to be avoided. It's a tool that needs to be adopted in a controlled way.

The difference between consumer AI and a purpose-built organizational tool is not which one produces better texts. It's which one builds trust with customers, staff, and regulators while the work gets done.

08Further reading on security

Interested in ISO 27001 certification and what it means in practice for a B2B SaaS company? Read: ISO 27001 and B2B SaaS: Why security certification wins deals

A deeper look at Lyyli's security architecture for IT departments: Cybersecurity and Privacy in Lyyli.ai. All security and compliance solutions summarized on our Trust page.

Questions about our security practices?

We're ready to explain in more detail how Lyyli handles data and how it differs from consumer AI. Get in touch or try it yourself.

  • Vercel AI Gateway and language-model ZDR
  • Access control and audit trail
  • GDPR documentation
  • Approval process in practice
  • Comparison with consumer AI tools

About the author

Mikko Oksanen

Mikko Oksanen

CEO & Co-Founder

Mikko leads Lyyli.ai and writes about practical communication development for expert organizations.

Read also

A communications professional focused on work in a modern office in the age of AIMade with AItone of voice

Why tone of voice is AI's biggest challenge and opportunity

AI texts are starting to sound disturbingly alike. This article explains why brand voice is now the most critical competitive edge in communications, and offers five concrete ways to teach AI your company's unique way of speaking.

4 min read09.06.2026
Communications responsibility, trust and AI use in an expert organizationMade with AIAI

The ethical sustainability of communications in the age of AI – who is responsible when the machine writes?

AI makes communications faster, but without a managed process it also multiplies chaos. Ethically sustainable communications require traceability, expert review and human accountability.

7 min read08.05.2026
A professional working at an office desk with a bilingual content management screen showing Finnish and Swedish drafts side by sideMade with AIbilingual communications

Bilingual communications bottlenecks: Automatic translation in your brand voice — without sounding robotic

The biggest challenge in bilingual communications is slow translation and a brand voice that disappears along the way. Brand-guided AI translates and localises content in your organisation’s own tone.

7 min read10.08.2026
Modern office lobby with an abstract illuminated art installation representing AI transparency and structured governanceMade with AIEU AI Act

EU AI Act transparency requirements are now in force: What this means for communications and content production

Article 50 of the EU AI Act entered into force on 2 August 2026. The new transparency obligations reshape content production — but a managed human-in-the-loop workflow protects organisations without unnecessary bureaucracy.

7 min read04.08.2026
A communications professional using Lyyli to bring communications strategy into daily work in a modern officeMade with AIcommunications strategy

From the drawer to daily work

Implementing a communications strategy is one of the biggest challenges for communications leaders. The strategy is completed and filed away, but daily content production continues on its own logic.

8 min read26.06.2026
A communications professional managing content production on the Lyyli.ai platform in a modern officeMade with AIAI search optimization

AI search optimization is here: How to ensure your brand's visibility in answers from ChatGPT, Perplexity and similar tools

AI assistants like ChatGPT, Claude and Perplexity are changing how people search for information and make decisions. Traditional search engine visibility is no longer enough: your brand must also be found in AI-generated answers.

7 min read25.06.2026