AI Recruiting Academy › Module 4: Risk, law and fairness
The short answer
Only what the task needs, and only in a version your company has approved. On a personal ChatGPT account, your chats can be used to train OpenAI’s models unless you switch that off. On ChatGPT Business or Enterprise they are not used for training by default. Either way, the candidate’s data is still personal data you are responsible for.
A safe habit: strip names and contact details before you paste, never paste sensitive details such as ID numbers, health, disability, age or background check results, and never let a chatbot make the decision.
Does ChatGPT keep what I paste into it?
It depends on the plan. OpenAI’s data controls page says personal accounts can choose whether conversations help train its models, through a setting called “Improve the model for everyone” under Settings, then Data controls. Business, Enterprise and Edu workspaces are not used for training by default.
| Version | Used to train models? | Fit for candidate data? |
|---|---|---|
| Free, Plus or Pro, default settings | Can be, unless you turn training off | No |
| Free, Plus or Pro, training turned off | New chats are not used for training | Only anonymized details, and only if your company allows it |
| Temporary chat | Not used for training; may be kept up to 30 days for safety | Only anonymized details |
| ChatGPT Business or Enterprise | Not by default | Yes, within your company’s rules and retention settings |
| AI built into your ATS or CRM | Depends on the vendor contract | Yes, if the contract covers training, storage and deletion |
One detail catches people out. According to OpenAI, if you give a thumbs up or thumbs down on a response, the whole conversation may be used for training even after you opted out. Claude, Gemini and Copilot have similar personal and business splits, so check the settings on whichever tool you use.
Why does it matter if the model trains on it?
Once data is in a training set, you cannot pull it back out, and you have shared a candidate’s information with a third party they never agreed to. In 2023, Samsung banned staff from using ChatGPT after engineers pasted internal source code into it. Resumes, interview notes and salary details are just as sensitive for the people they describe.
Data protection law also applies. In the UK and EU, candidate data can only be used for the purpose it was collected for, and only as much as needed. When the UK’s data regulator audited AI recruitment tools in 2024, it found some collected far more personal information than necessary and kept it indefinitely. In California, applicant data has been covered by the state’s privacy law since 2023.
What can I safely put in, and what should I keep out?
| Safe to use | Use only in an approved business tool | Keep out entirely |
|---|---|---|
| Job descriptions and intake notes | Resumes with names and contact details | Social Security, passport or other ID numbers |
| Interview questions and scorecard templates | Interview notes and transcripts | Health, disability, pregnancy or medical information |
| Anonymized resumes with names, contacts and dates removed | Candidate pipelines and shortlists | Date of birth, age, race, religion or other protected traits |
| Outreach templates without personal details | Offer letters and compensation plans | Background check, credit or criminal record results |
| Market research and general questions | Reference feedback | Bank details, passwords or login codes |
Your company’s policy comes first. If it bans a tool or a type of data, the table above does not override it.
How do you anonymize a resume before using AI?
Remove identity. Name, email, phone, street address, photo and social profile links.
Remove age signals. Graduation years and dates of early jobs. Keep the length of each role instead.
Remove protected traits. Nationality, religion, marital status, and clubs or groups that reveal them.
Replace, do not delete. Swap the name for “Candidate A” so you can match the output back to the right person in your ATS.
Tell the AI what not to consider. For example: “Assess this resume only against the listed requirements. Do not infer age, gender, ethnicity or health.” Module 1, Lesson 4 has more prompt patterns.
What are the other risks besides privacy?
Bias. Chatbots carry the same name and language bias covered in Lesson 1. Anonymizing helps here too.
Made up facts. A chatbot can invent a skill or misread a date. Check every summary against the original.
Legal notice. If ChatGPT ranks or filters candidates and you act on it, that is AI in a hiring decision, and the notice rules in Lesson 4 can apply.
Record keeping. Decisions made from chatbot output with no record are hard to defend. California’s rules require automated decision data to be kept for four years.
Quick answers
Is it OK to paste a resume into ChatGPT to write a summary for a client?
Only in an approved business account, with the candidate’s knowledge, or after removing identifying details. On a personal account with default settings, no.
Does turning off training make a personal account safe?
Safer, not safe. The data is still stored with OpenAI under consumer terms, and your company may not have a contract covering it. Use anonymized details only.
Can I ask ChatGPT which candidate to hire?
You can ask it to compare evidence against the requirements, but the decision must be yours. A chatbot should never be the one that rejects someone.
What if I already pasted something I should not have?
Delete the chat, tell whoever handles data protection at your company, and follow their steps. Do not try to fix it quietly.
This lesson explains the law in plain English. It is not legal advice; check your company’s AI policy and your own situation with a lawyer.
Explore in the directory
Module 4: Risk, law and fairness
- How does bias get into AI hiring tools?
- What is an AI bias audit?
- Which AI hiring laws apply to you?
- What should you tell candidates about AI?
- What candidate data can you put into ChatGPT?
You have finished Module 4. Next up is Module 5, Putting AI to work.