Next-Frame.Agency · Blog

What's Safe to Paste Into AI: A Data Privacy Guide for Philippine Businesses

By Leon Harris, Founder & AI Creative Director · Updated August 2026

A customer sends their ID over Messenger to confirm a booking, and the fastest way to pull the details out is to paste it into ChatGPT. A tenant's signed lease lands in your inbox and Gemini can summarise it in four seconds. Both habits quietly make you responsible for someone else's personal data under Philippine law — and most owners have never been told where the line is. This guide gives you that line: what never goes into an AI chat box, what to strip out first, and the settings to change today.

Yes, the Data Privacy Act covers your small business

The Data Privacy Act of 2012 (Republic Act 10173) is the country's main data protection law, enforced by the National Privacy Commission. Sec. 3(h) defines a "personal information controller" as any person or organization that controls the collection, holding, processing, or use of personal information — including one that instructs someone else to do the collecting. Sec. 4 says the Act applies to the processing of all types of personal information by any natural or juridical person involved in it. Neither section contains an exemption based on headcount or revenue. A three-person Shopee seller with a spreadsheet of buyer names and addresses is a controller in the same legal sense a bank is. The obligations scale with what you hold, not with how big you are. (Full text: lawphil.net; Official Gazette.)

What the law actually asks of you

Sec. 11 sets the governing principles: processing must adhere to transparency, legitimate purpose, and proportionality — collected for a declared purpose, not excessive relative to it, kept accurate, and retained only as long as needed. Sec. 20 adds a security duty: controllers must implement reasonable and appropriate organizational, physical, and technical measures against accidental or unlawful destruction, alteration, and disclosure. Pasting a customer list into a public AI chatbot sits badly against both. It's hard to argue proportionality when you only needed one field, and handing the file to a third party with no safeguard is the opposite of a security measure. That's the practical test to carry around: was this necessary, and did I protect it. This article is general information, not legal advice — for a real problem (a breach, an NPC inquiry, a specific processing question) go to privacy.gov.ph or a Philippine lawyer.

The RED / AMBER / GREEN list

RED — never paste into any consumer AI tool:

AMBER — only after stripping identifiers: an email thread you want summarised, a resume to reformat, a complaint you want a draft reply for. Remove the name, mobile number, address, and any ID numbers first — or handle it inside a business tier (below).

GREEN — fine as-is: your own captions and marketing copy, public business listings, generic templates, and genuinely aggregated numbers that can't be traced to one person.

The settings to change today

ChatGPT (free or Plus): Settings → Data Controls → Improve the model for everyone → off. New chats then stay out of training. Note what this does not do: it isn't auto-deletion. Chats you delete, and Temporary Chats, are removed within about 30 days; ordinary chats stay in your history until you delete them (OpenAI Help).

Gemini: the setting is now called Keep Activity — manage it at myactivity.google.com/product/gemini. Google's own wording: with it off, "Future chats are still saved for 72 hours" so Gemini can respond and protect users.

Microsoft Copilot: on a work or school account, Microsoft 365 Copilot states that prompts, responses, and Microsoft Graph data "aren't used to train foundation LLMs" — no toggle to find (Microsoft Learn). A personal Microsoft account has different defaults; check the Copilot privacy FAQ before assuming.

If your team uses AI daily, pay for the business tier

A toggle is something a new hire forgets. A business tier changes the default. Per each vendor's documentation, ChatGPT Business and Enterprise don't train on your conversations by default, Google Workspace's Gemini doesn't use your organisation's content to train models outside it, and Microsoft 365 Copilot on a work account carries the same commitment. None of this makes RED-list data safe to paste — it removes one risk (model training) for AMBER material, not the risk of sending data outside your business.

Make it a five-second habit

Before pasting anything with a person attached, blank out the name, mobile number, address, and any ID or account number, and use placeholders — "Customer A", "[PHONE]". Write the rule down in three lines: what's RED, what needs redaction, which tool the team may use. Put it where staff actually are — a pinned Viber message beats a policy document nobody opens.

If someone already pasted something sensitive, stop using that thread and delete it, then turn off training and history so it doesn't repeat. Work out exactly what went out — whose data, which fields. If it was sensitive information such as health, financial, or government ID data, consider telling the person affected and check the NPC's guidance or a lawyer on what else applies. Again: general information, not legal advice.

Frequently asked questions

Does the Data Privacy Act (RA 10173) apply to a small business, or only to large companies?

It applies regardless of size. Sec. 4 covers the processing of all types of personal information by any natural or juridical person involved in it, and Sec. 3(h) defines a 'personal information controller' functionally — anyone who controls the collection, holding, or use of personal information. Neither section contains an exemption based on headcount or revenue, so a small shop or online seller keeping customer or employee records is covered. This is general information; check privacy.gov.ph for your specific situation.

Is it illegal to paste a customer's name and phone number into ChatGPT or Gemini?

RA 10173 doesn't name specific tools. What matters is whether the processing meets Sec. 11's principles of transparency, legitimate purpose, and proportionality, and whether you took the reasonable security measures required by Sec. 20. Sending a named customer's details to a consumer AI service with no safeguards is hard to justify on either count and is usually avoidable — treat it as RED and redact first.

If I turn off training or chat history, is my data now private?

No. Turning off ChatGPT's 'Improve the model for everyone' stops new chats being used for training, but it is not automatic deletion — deleted chats and Temporary Chats are removed within about 30 days, while ordinary chats stay until you delete them. Google states that with Keep Activity off, Gemini chats are still saved for 72 hours. The setting reduces exposure; it does not eliminate it, so RED-list data still doesn't belong there.

Do I need to register my business with the National Privacy Commission?

Under NPC Circular 2022-04, registration of data processing systems is mandatory if you employ 250 or more people, process the sensitive personal information of 1,000 or more individuals, or process data likely to pose a risk to data subjects' rights and freedoms. Systems involving automated decision-making or profiling must be registered regardless of size. Below those thresholds registration is voluntary. Confirm the current rule on privacy.gov.ph before acting, as circulars are updated.

What's the privacy difference between the free and business versions of an AI tool?

Free consumer tiers generally allow the vendor to use your chats to improve their models unless you opt out manually. Business tiers change the default: per each vendor's own documentation, ChatGPT Business and Enterprise don't train on your conversations, Google Workspace's Gemini doesn't use your organisation's content to train models outside it, and Microsoft 365 Copilot on a work account states that prompts, responses, and Microsoft Graph data aren't used to train foundation models. Verify the current wording on the vendor's page, since these policies change.

Someone on my team already pasted sensitive customer data into a chatbot. What now?

Stop using that conversation, delete it, and turn off training and history for future chats — keeping in mind deletion isn't always instant. Then identify exactly what was exposed: whose data and which fields. If it was sensitive personal information such as health, financial, or government ID details, consider notifying the person affected and check the NPC's guidance or a Philippine lawyer on whether further steps apply. This article is general information, not legal advice.

Related guides

Sources: privacy.gov.ph · lawphil.net · officialgazette.gov.ph · privacy.gov.ph · privacy.gov.ph · help.openai.com · help.openai.com · openai.com

Want this done for you? We build the AI content system; you approve. Free audit + custom quote within 24 hours.

Get a free audit →