Back to Blog
    Security

    How to Stop Employees Pasting Client Data into ChatGPT

    You already know staff paste client data into ChatGPT. Blocking the website just moves them to Claude, Gemini, or their phone. Here is what actually stops the paste.

    Fendr Security28 August 20266 min read
    Employee pasting client data into ChatGPT, blocked at the browser

    It happens in every wealth manager, law firm, and finance team. Someone copies a client note from Outlook or the CRM, opens ChatGPT, and pastes it in with a quick "tidy this up". The domain is allowed because an outright ban killed productivity last quarter. Network DLP sees HTTPS traffic to OpenAI. It does not see the client name.

    Blocking chatgpt.com does not stop the paste. It stops you seeing it.

    You already know it is happening. The question is what actually stops it.

    Three things teams try that fail

    Ban chatgpt.com

    Staff switch to Claude, Gemini, Perplexity, or a phone hotspot. Usage becomes invisible rather than stopped. You lose the data and the visibility.

    An acceptable use policy

    A policy PDF is useful for setting expectations, but it has no enforcement, no log, and nothing to show the ICO or a client due-diligence questionnaire when someone asks "how do you know this did not happen?"

    Microsoft Purview prompt protection

    This is real, but it lives in Edge for Business on Entra-enrolled Windows, and it sits on E5 or E7. Chrome, Mac, contractors, and any firm without the right Microsoft licence are outside it. For a fuller comparison, see our guide to ChatGPT DLP without Purview.

    What each approach actually stops

    ApproachStops the paste?What it misses
    Domain blockNo, it blocks the toolPhones, other models, home Wi-Fi
    Policy PDFNoEverything
    Purview / Edge DLPYes, in Edge on enrolled WindowsChrome, Mac, BYOD, anyone without E5
    Browser extension DLPYes, in Chrome and EdgeNative desktop apps (Claude desktop, Copilot in Word)

    The last row is worth being honest about. A browser extension like Fendr sees what happens in the browser tab. It does not see Claude desktop or Copilot inside Word. If those are risks in your environment, you need endpoint coverage alongside the browser control.


    What to do this week

    A sensible rollout for a 50-500 person UK firm looks like this:

    Week 1: visibility only

    Deploy the extension via MDM to Chrome and Edge. Run in monitor mode. See which AI tools are in use and whether pastes include client identifiers, account numbers, or source code. Do not block yet. You are building evidence, not a wall.

    Week 2: block the data, not the tool

    Stop pastes that look like client data, account numbers, or proprietary code into unsanctioned AI. Allow general questions and approved tools. The aim is to prevent the specific leak, not to ban AI.

    Week 3: redirect to the approved tool

    When someone opens ChatGPT with client data, redirect the tab to ChatGPT Enterprise or Copilot with a short explanation. A dead tab teaches workarounds. A redirect teaches the right tool.

    Keep the audit log

    Every blocked paste, redirect, and policy trigger should be logged. That log is what turns your policy into evidence. Fendr's compliance product produces immutable, export-ready AI usage logs, and our guide to evidencing your AI policy explains how to present them.


    The GDPR piece is already covered

    If the legal risk is the question, read our piece on shadow AI and UK GDPR. This page is the control. The two belong together: one explains why the paste is a problem, the other explains how to stop it.


    Get started

    If you are an IT manager or CISO at a UK SME, the fastest way to close the gap is a short audit. Fendr maps active AI usage across your organisation in under five minutes, with no infrastructure change.

    Run a free AI audit to see which tools are in use and where client data is leaking, or book a demo to see the controls in action.

    Ready to see what your team is actually using?

    Ready to Take Control of AI in Your Organisation?

    Join security-conscious teams who are enabling safe AI adoption without becoming the "department of no."

    Watch Demo