An employee tells you they pasted a client's contract, a spreadsheet of customer accounts, or a patient note into a chatbot to get a summary. Or you find it in a shared browser history. Either way, most of what matters happens in the first two hours.
This is the plan. You can run the first three steps without a lawyer on the phone.
Step 1: Get the facts, not a confession
Ask four questions: which tool, which account, what exactly was pasted, and when. Have the employee open the conversation on screen if it still exists. You need the actual text, because the difference between "a client name" and "a client name with account numbers and a home address" changes everything that follows.
Do not discipline anyone at this stage. If admitting it costs people, the next incident goes unreported and you hear about it from the client instead. Write down the four answers with the time. That note is the start of your incident record.
Step 2: Delete the conversation and turn off training
What happens to the pasted text depends on the account type. Personal free accounts are the worst case.
- ChatGPT free or Plus: by default, conversations can be used to train future models. Open Settings, Data controls, and switch off the option to improve the model. Then delete the conversation. OpenAI states deleted chats leave its systems within about 30 days.
- Gemini: with activity saving on, conversations may be read by human reviewers and kept for up to three years. Delete the conversation under Gemini Apps Activity and turn saving off.
- Claude: personal accounts have a training setting under Privacy. Turn it off, then delete the chat.
- Copilot, ChatGPT Business, Claude Team, Gemini in Workspace: business accounts do not train on your data by default. Delete the conversation anyway and note which account it was on.
If the text was already used for training before you got to it, deletion does not pull it back out of a model. Say so in the record. It is one reason step 6 matters more than the cleanup.
Step 3: Rotate anything that was a secret
Passwords, API keys, bank logins, portal credentials, VPN details: if any of these were in the pasted text, change them within the hour. This is the one step that cannot wait for a meeting. If a client's login was in there, ask them to reset it today.
Step 4: Classify the data and decide who has to know
Sort what was pasted into one of three buckets.
- Internal only. Your own draft, your own numbers, nothing identifying a client or a person. Record it, fix the cause, move on.
- Client confidential. Covered by an NDA or a contract clause about third parties. Read the clause. Many require you to notify the client of unauthorized disclosure, sometimes within a fixed number of days. Even where the contract is silent, telling the client early, with what you did about it, usually costs less than them finding out later.
- Regulated personal data. Health information, financial account details, government ID numbers, anything about EU or UK residents. HIPAA has its own breach assessment, GDPR has a 72 hour clock from discovery, and most US states have a breach law with a notification threshold. This bucket is where you call a lawyer, today, with the record in hand.
Also check your cyber insurance policy. Many require notice of a suspected incident within a set window, and a late report can void coverage.
Step 5: Write the one page record
Date and time discovered. Who reported it. Tool and account type. Data involved, by category. Actions taken with timestamps: deletion, training opt out, credential changes, who was notified. What you changed to stop it recurring. Keep this even for internal only cases. When a client's security questionnaire asks whether you have had an AI related data incident and how you handled it, a clear record is the right answer.
Step 6: Fix the cause in the same week
Staff paste data into free chatbots because the free chatbot is the only one they have. The durable fix is a sanctioned tool plus a short rule.
- Buy business seats for the people who use AI daily. ChatGPT Business and Claude Team both run roughly 25 to 30 dollars per user per month. Most Microsoft 365 business plans already include a chat Copilot with commercial data protection, so check what you have before buying anything.
- Publish a one page AI use policy that names the approved tools and lists the four or five categories of data that never go into any chatbot.
- Ask your IT provider about blocking personal chatbot logins on company devices. On most Microsoft 365 or Google Workspace tenants it is about an hour of configuration.
- Run a 20 minute walkthrough with staff of what happened, without naming the person, and what to do next time.
For a 15 person firm that is a few hundred dollars a month in seats and one afternoon of setup. Compare that with the hours you just spent on steps 1 through 5.
If you would rather have help with the cleanup or the setup, the first call is free and takes about 30 minutes. We go through what was exposed, which tools your team actually uses, and what to put in place this week. Get in touch and pick a time.