Subscribe
Learn Library

Don't Be So Quick to Feed Company Secrets to ChatGPT

A recap of a podcast with a marketer-turned-Data Protection Officer covering GDPR's global spread, the EU AI Act, shadow AI, and data enrichment risks. It offers practical advice on AI policies, staff training, DPIAs, data minimization, and keeping sensitive material out of public chatbot tools.

ai-marketingskillevidence
2026-08-16SupaMarketers13 min read

A few days ago, I listened to a podcast episode.

Honestly, on topics like GDPR and data protection, I usually zone out after ten minutes. Too much jargon, too many clauses.

But this one, I listened to from start to finish — all 52 minutes of it.

Because the guest is a "traitor." He spent more than twenty years in marketing, ran marketing across multiple countries, then deliberately went off and got certified as a Data Protection Officer (DPO) — a chartered director, too. A marketer who crossed over to the side that polices marketing.

On the show he described a scene that sent a little chill down my spine.

Picture this:

Friday, 4:30 in the afternoon. Your head is already on the weekend; one mass email left to send, to a thousand customers. Send it and you're out the door.

You hit Send.

Those thousand addresses went into the CC field, not BCC.

A thousand customers, all seeing one another's email addresses. Some with names and companies attached.

That is a data breach.

By his numbers, up to nine out of ten data breaches start with human error. Not hackers. Not system vulnerabilities.

It's people.

Scary thought. The most dangerous vulnerability turns out to be the most exhausted person in the office on a Friday afternoon.

Nine out of ten data breaches start with human error, not hackers — a Friday-afternoon mass email sent with CC instead of BCC exposes 1,000 customers to one another

So why would a marketer stop chasing perfectly good growth to go get certified as a data protection officer?

Because the rules of the game have changed over the past few years. Into what? He says: mainly two things.

1. GDPR Has Grown Into the World's Template

When GDPR took effect in 2018, everyone remembered exactly two numbers: 4% of global turnover, or €20 million. Plenty of companies trained staff overnight and inventoried their data, as if cramming for a make-or-break exam.

Eight years on, the big exam has become routine.

Regulators have written plenty of fines, and the heaviest hits have landed on Big Tech. Of the top ten fines by amount, eight or nine belong to the likes of Meta, Google, Amazon, TikTok, LinkedIn and Uber. Lay the list out and it's basically the first screen of apps on your phone.

The heaviest of all went to Meta: €1.2 billion, issued in 2023 by the Irish Data Protection Commission.

And ordinary companies? No exemption. Small and mid-sized businesses get fined just the same — the amounts simply scale to their size: a few thousand or a few tens of thousands of euros. They just never make headlines.

In these eight years, GDPR has pulled off one more thing: going global. California followed with CCPA; Singapore and South Africa each passed laws of their own. Look across the world's data protection laws and you'll find a bit of GDPR in every one of them.

The best report card a law can earn is having the whole world copy its homework.

2. AI Arrived — Carrying a Black Box

Since 2022, large language models (LLMs) like ChatGPT, Claude and Perplexity have become daily tools for many marketers. Writing copy, drafting proposals — genuinely handy.

But one line from the guest stuck with me: this is "black box" technology. How the algorithm computes, how a given result came to be — even the developers themselves may not be able to explain it.

And that is how personal data ends up flowing into a black box no one can explain.

Personal data items flowing into an AI black box — not even the developers can explain what happens inside

The EU's answer is the EU AI Act. It entered into force in August 2024, with its provisions applying in phases.

What does risk-based tiering mean? You regulate by how heavy the consequences are when things go wrong.

The top tier is banned outright. One tier down sits high risk — using AI to screen résumés, deciding who gets access to education: systems that genuinely shape a person's fate must keep a human in the loop. Below that, requirements ease off tier by tier.

Plenty of people assume the AI Act is the "new GDPR."

It isn't. The AI Act governs the safety of AI products themselves; the moment a system touches personal data, GDPR still comes calling. The two laws stack.

And then there's extraterritorial reach. Whether you're located in the EU doesn't matter. If your AI product enters the EU market, or you process EU residents' data, it can get you.

There's no hiding from it.

While You're in the Meeting, AI Is Already Sitting Next to You

On the show, the host made an observation that, I suspect, most people haven't noticed.

Jump on a Zoom or Google Meet these days and there's often an AI assistant in the meeting, quietly transcribing. It "joins the meeting" on its own — nobody necessarily tells you. Every word you say is flowing to OpenAI's or Google's servers.

Then the guest told a story that stings even more.

At one school, a teacher managed student data in a single Excel spreadsheet. Excel now comes with Copilot — tidy up the sheet with one click. So handy.

One click.

And the whole sheet of student data is off to Microsoft's, OpenAI's or Anthropic's servers — processed, and quite possibly folded into a training set.

Is the teacher at fault? He just discovered a handy new feature. You can't expect every teacher to understand where an LLM sends its data.

When a tool gets so smart that no one can see how it's smart, risk stops being about "who meant harm" and becomes about "who had no idea."

"Shadow AI," and Dropbox 15 Years Ago

There's a new name for this: shadow AI — employees bringing their own tools to work.

Why? "The company's AI is clunky; my own ChatGPT remembers my preferences." And just like that, customer lists and internal decks get pasted into personal accounts.

Sound new? Not remotely. The same play ran 15 years ago: when the company said no, people dropped files into their own Dropbox or Google Drive; when the BlackBerry was too painful to use, they pulled company email onto their own iPhones. The company ran along behind, putting out fires — like herding cats.

The only difference is scale. What burned back then was a single file; today, one absent-minded paste can feed an entire customer database to somebody else's model.

So what do you do?

His advice is almost too plain to sound like advice: write down a policy first, even a rough one.

With a policy, at least everyone knows where the boundaries are. Without one, every department follows its own risk appetite: sales watches the growth numbers, legal watches for landmines, and the company lives in the Wild West.

Once it's written, take it around to the teams, win their buy-in, then revise it again and again. Technology keeps changing; the policy has to grow with it.

A few more moves to go with it.

Appoint a "data champion." It doesn't need to be a full-time role — just the person on the team who genuinely cares about this and is willing to track legislative changes. Have them meet regularly with legal and with outside experts.

Put it on the agenda. Weekly or monthly meetings, either works — just don't let it get bumped every time by something "more urgent."

Take stock of what you have. Audit which tools you're using and which ones touch personal data. And note: a list you finish once and lock in a drawer is dead — it has to stay alive. ChiefMartec's annually updated report puts the latest figure at fourteen thousand: more than 14,000 digital platforms are now within a marketer's reach. If you can't even list your tools, what chance do you have of getting your data under control?

And training. That one deserves its own section.

Nine Out of Ten Accidents Are Prevented in Training

How do you prevent the nine-in-ten human error from the opening? The answer is boring, but it works: training. Teach it at onboarding; run refreshers for the veterans.

Because your compliance is only as strong as the least-trained person on your team.

GDPR runs to 99 articles. Don't try to read them from the top. Grab two handles: does every act of data processing rest on a lawful basis? And are the seven core principles being upheld?

And then there's the thing that puts marketers to sleep at the mention and sinks them the moment something goes wrong: data retention periods.

Marketing teams used to compete over who had the biggest database. GDPR tore up that KPI: those tens of thousands of cold leads — did you ever get consent? The campaign ended three years ago — on what grounds are you still clutching people's names and phone numbers? If it leaks, the liability is all yours.

The old belief: the more data, the better. The new one: the less you hold, the better you sleep.

In plain terms, this is "data minimization": for a newsletter signup, an email address is enough. Don't ask for their birthday — and certainly not their mother's maiden name.

So Can You Paste Files into ChatGPT or Not?

Back to the question in the title.

The guest offered a rule of thumb, and I'll pass it along word for word: if your company wouldn't mail it to an outside party, don't paste it into the public version of ChatGPT.

Confidential documents, commercially sensitive data — if you want to play with those, play with a model deployed inside the company. The internal version may not be as sharp as the latest public one. Accept that loss. It's worth it.

The host added a jab of his own: offline models are getting seriously competitive. He uses a free, open-source tool called LM Studio to run models from Google, Meta, IBM and DeepSeek — fully offline. Pair it with RAG (retrieval-augmented generation — feeding your own documents to the local model as its reference library), and your sensitive data never steps out the door.

One Email Address for 20 Fields

Now, a category that's exploding across the marketing world: data enrichment.

The idea goes roughly like this: you hold one prospect's email address; AI crawls the whole web and stitches the fragments together — which company they're at, roughly what title, maybe even their phone number. One field goes in, 20 fields come out.

For a marketer, this is catnip. Profiling, targeting, personalization — upgraded across the board.

The guest, as usual, threw cold water on it. The core of the problem is a single question: does the person know? Is there transparent disclosure? Is there a lawful basis? Profiling people at scale, without their knowledge — that's a gray zone, and the most dangerous kind.

Drill down and it splits by scenario. In the UK and Ireland, B2B marketing — emailing a person's work address with content related to their work — runs on an opt-out norm as the accepted practice, which leaves a bit more room to maneuver; B2C plays by a completely different rulebook. But wind through it however you like, every path ends at the same question: what's your basis for obtaining data this way?

Will Anyone Come Knocking?

This is the question many bosses really want to ask: if I do nothing, who's going to come checking?

It depends on the industry. Finance and healthcare are watched closely. For small companies in ordinary sectors, the odds of an on-site inspection really are low.

But two things you should know.

First, there are penalties beyond fines. The Irish Data Protection Commission has a favorite move: banning you from processing a certain category of data for a period of time. For a company that lives off data, that can hurt more than a fine.

Second, by the time something actually goes wrong and they come asking, it's usually too late — and they pull the thread. Do you have records of processing activities? When was your last data audit? Are your staff trained? Were all data access requests answered within 30 days? One question follows the next, and the snowball keeps growing.

So his conclusion is plain as day: rather than praying no one knocks, start doing the right things one by one, and let the culture grow.

Compliance and Growth: Don't Pick a Side

There's a pair of concepts from the podcast I find especially useful: conformance (playing by the rules) and performance (delivering the numbers).

Management tends to err in two opposite directions. Bury yourself in compliance and let every growth opportunity pass by — that's one kind of risk. Charge ahead and step on every regulatory mine — that's another. The comfortable spot is in the middle.

In practice, that means spelling out the company's risk appetite and writing it down. For instance: sales and marketing can afford to be a little bolder with AI; hiring and HR must stay conservative with it. Put it in the policy, and everyone knows where the lines are.

So — will regulation loosen from here?

His judgment: no. Having heard him out, I agree.

The 2024 Draghi report was already warning that the compliance burden on EU companies may be dragging down innovation. And the EU itself did hit pause in 2025, shelving the update to the ePrivacy Regulation. The wind does seem to be shifting a little.

But look at it from another angle: personal data is the hard currency of the modern economy, and the legislation surrounding it will only multiply.

And on the consumer side, the wind is blowing toward tighter rules. Fifteen years ago nobody talked about privacy; then breach after breach woke everyone up. Now even VPNs run TV ads, and Apple flat-out sells privacy as a core feature. In early 2025, Ireland's regulator ran a public survey: 73% of respondents worried their data was being used in ways they never agreed to — and couldn't understand.

Over the next five to ten years, the real fight lies elsewhere: explaining the black box so people can actually understand it. If even the developers don't fully know what's happening inside the system, what grounds do we have for expecting the average person to make it through a privacy policy?

Three Pieces of Advice

At the end of the show, the guest left three pieces of advice, and I wrote every one of them down.

One: design privacy in from day one of the project. There's a ready-made tool for this, the Data Protection Impact Assessment (DPIA): answer 12 to 13 screening questions first; hit two or three high-risk flags and it escalates into a full assessment. Free templates are available online — the UK's Information Commissioner's Office (ICO) publishes a good one. One stroke of the pen at the blueprint stage beats tearing down a half-built building.

Two: make training a constant, not a one-time onboarding ritual.

Three: think through your company's risk appetite on data and AI — how big, exactly — write it down, attach guardrails, and then let it be revised, version after version.

Back to that Friday-afternoon email from the opening.

A tool can get smarter overnight. Habits form one day at a time.

May every mass email you send get BCC right.

And may your company never have to call a thousand customers, one by one, to apologize — after they've all seen each other's email addresses.