CyberCode.ph · Philippines

Customer Data Uploaded to ChatGPT: Philippine Privacy Rules and First Steps

Last updated October 5, 2026 · Practical privacy, cybersecurity and technology-law guidance

Last materially reviewed: October 5, 2026

Direct answer

Uploading identifiable customer information to ChatGPT or another generative-AI service is personal-data processing under the Data Privacy Act of 2012. It is not automatically unlawful, but the company must have a lawful purpose, transparency, proportionality, security controls and an appropriate vendor arrangement. If an employee uploaded data without authority, stop further use, preserve facts and assess whether the event is a reportable personal data breach.

First hour: contain the upload without destroying evidence

Treat an unauthorized AI upload as a security incident immediately. Deleting a chat may reduce continuing exposure, but first preserve enough facts to show what happened and support the breach assessment.

  1. Stop the source. Pause further prompts, file uploads, automated connectors and shared links tied to the incident.
  2. Preserve the minimum evidence. Record the account, workspace, model or feature, exact data categories, affected people, prompt or file, date and time, output, sharing settings and anyone who could access it. Store this record in the incident file—not in another AI prompt.
  3. Escalate internally. Notify the DPO, incident-response lead, security team and accountable business owner. An employee should report promptly and should not investigate by sending more customer data to the vendor.
  4. Contain through the real account. Remove public or team sharing, revoke exposed credentials, delete the conversation or file where available, and open a vendor support or privacy request. Preserve the ticket and response.
  5. Start the legal clock. Record when the company first knew or reasonably believed that a personal data breach had occurred. The NPC reporting window, when mandatory notification applies, is measured from that point—not from the end of a perfect forensic investigation.

Vendor retention changes the response

Service contextWhat to verify nowResponse consequence
Personal ChatGPT accountWhether model improvement was enabled, whether the chat was shared, and whether the conversation and uploaded files can be deleted.Do not assume a personal account has the company’s approved processor terms. Preserve the settings in force at the upload time and use the current privacy controls.
Temporary ChatConfirm that Temporary Chat was actually used. OpenAI says these chats are not used to improve models but may be retained for up to 30 days for safety.Temporary status can reduce persistence and training concerns, but it does not erase the incident or the controller’s Philippine-law duties.
ChatGPT Business or EnterpriseCheck the exact workspace, administrator controls, apps, sharing permissions, contract and data-processing terms. OpenAI says business data is not used for model training by default.Stronger controls may reduce risk; they do not by themselves authorize the upload or decide whether notification is required.
API or connected applicationIdentify the endpoint, store setting, abuse-monitoring terms, file or conversation objects, third-party tools and any approved retention control.Retention varies by endpoint and configuration. Obtain logs and delete stored objects where appropriate; do not quote a single retention period for every API use.
Another AI vendorReview the product tier, contract, privacy notice, training setting, support route, subprocessors, transfer locations and deletion limits in force on the incident date.Use the vendor’s current documents and the company’s agreement. A product label alone is not evidence of retention or deletion.

Does the upload require NPC notification?

Under NPC Circular No. 2016-03, mandatory notification requires the breach assessment to satisfy all of the core conditions: the data involves sensitive personal information or other information that may enable identity fraud; there is reason to believe an unauthorized person may have acquired it; and the breach is likely to create a real risk of serious harm. A vendor receiving an unauthorized prompt may be relevant to the acquisition question, but the result still depends on the actual account, safeguards, exposure and harm.

  • If all conditions are met: use the NPC’s Data Breach Notification Management System. The NPC states that the PDBNF must be submitted within 72 hours upon knowledge of, or reasonable belief that, a qualifying breach occurred. If the report is incomplete, submit the available facts and follow the current update procedure.
  • If the conditions are not met: document the facts, decision, containment and reasons. The NPC breach page says non-mandatory incidents should still be recorded and included in the Annual Security Incident Report.
  • If the facts are uncertain: do not wait passively. Continue containment and vendor inquiries, assess the likely harm and the value of warning affected people, and obtain Philippine legal or privacy advice before the deadline.

Evidence and action checklist

EvidenceAction it supportsPause condition
Prompt, attachment, output, timestamps and user accountScope the incident and identify the people and data involved.Do not circulate raw customer data beyond the response team.
Workspace, plan, sharing, training and retention settingsChoose deletion, access revocation and vendor escalation steps.Do not claim deletion or non-training without plan-specific proof.
Vendor terms, DPA, support ticket and deletion responseAssess processor controls, transfers, retention and continuing exposure.Escalate if the vendor cannot confirm containment or the contract does not cover the use.
Data sensitivity, number and vulnerability of affected people, authentication or financial valueApply the NPC reportability and serious-harm tests.Seek urgent specialist advice where identity fraud, health, financial, children’s or credential data is involved.
Decision log and remedial controlsShow accountability and feed the breach-notification and AI-use-policy processes.Do not close the incident until the control gap has an owner and deadline.

Authority-to-action bridge

QuestionCybercode answer
What the authority saysRA 10173, its Implementing Rules, and NPC AI guidance require accountable, transparent and secure processing throughout an AI system’s lifecycle.
What it meansA company remains responsible for customer data even when an employee places it into a third-party AI prompt.
What changes the answerRisk rises sharply for sensitive information, identity or authentication data, financial or health records, children’s data, or data processed outside the stated customer purpose.
What to do nextIdentify exactly what was uploaded, disable sharing or delete the conversation where possible, contact the provider under the applicable plan, and begin a documented incident assessment.

Key takeaways

  • Do not assume a consumer AI account is an approved processor merely because the tool is popular.
  • Removing names may not be enough if the remaining details can still identify a person.
  • Consent is not the only lawful basis, but the existing purpose and privacy notice must actually cover the processing.
  • A prompt leak can be a security incident even if no public disclosure has been confirmed.
  • Preserve the prompt, account type, time, recipients, provider settings and remediation steps.

How Philippine privacy law applies

The Data Privacy Act of 2012 applies when customer information can identify a natural person. The business that decides why and how the data is processed normally remains the personal information controller; using an AI vendor does not transfer accountability.

The NPC guidelines on artificial intelligence emphasize lawful basis, transparency, fairness, data minimization, security, data-subject rights and accountability. A controller should know whether prompts are retained, reviewed, used for model improvement, transferred abroad or exposed through integrations.

The result is fact-specific. A controlled enterprise service with contractual protections, disabled training and approved data categories presents a different risk from an employee pasting a customer spreadsheet into a free personal account. Confidentiality duties and contracts may apply even where the data is not personal information.

Evidence to preserve

A screenshot alone rarely answers whether information was retained, shared or used by the provider. Build an incident record that can be audited.

  • Exact prompt, attachment and AI output, preserved securely with timestamps.
  • User account, subscription tier, workspace, sharing settings and model settings.
  • Provider terms, privacy documentation and data-control settings in force on the upload date.
  • Categories and number of affected customers, including whether sensitive data was present.
  • Deletion requests, support tickets, access logs and written containment decisions.

What to do next

  1. Stop additional uploads and suspend the relevant integration if necessary.
  2. Notify the DPO, security lead and business owner; restrict access to the incident record.
  3. Classify the data, people affected, purpose, account type, transfers and realistic harm.
  4. Use provider controls to delete the chat or file and request confirmation where available.
  5. Decide whether the incident meets the NPC breach-notification standard; document the reasoning even if notification is not required.
  6. Close the control gap with an AI-use policy, approved tools, redaction rules, training and technical restrictions.

Common mistakes

  • Treating deletion from chat history as proof that every provider copy disappeared.
  • Calling data anonymous after removing only the customer’s name.
  • Sending more personal data to the provider while asking for support.
  • Waiting for public exposure before beginning a breach assessment.

Frequently asked questions

Must we notify the NPC every time an employee pastes customer data into AI?

No. Notification depends on the breach rules and the facts, including the type of information, unauthorized access or disclosure, and likely risk of harm. The assessment should still be recorded.

Can customer consent fix an unauthorized upload?

Not automatically. Consent must be informed, specific and valid, and the controller still owes security, proportionality and accountability duties.

What if the employee used a paid business account?

That can materially change retention, training and contractual controls, but it does not remove the company’s obligations. Verify the exact plan and settings rather than relying on the product name.

Related Cybercode guides

Official sources

Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology, or business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety, or legal exposure may be affected.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.