Can I paste this into ChatGPT? A practical guide for social service agencies

Before putting a case note, donor spreadsheet or grant draft into ChatGPT, use this guide to decide whether the material should leave your agency's systems.

In brief

If the material contains client, donor, volunteer or staff information, do not paste it into a public AI tool just because the task feels harmless. First check the purpose, the data, your agency's policy and the controls of the specific account.

On this page

Introduction

Before putting a case note, donor spreadsheet or grant draft into ChatGPT, use this guide to decide whether the material should leave your agency's systems.

Begin with what the document contains

The question “Can I paste this into ChatGPT?” sounds like a product question. Usually, it is a data-handling question.

When text or a file is submitted to an online generative AI service, the agency is sending information to an external system. The relevant considerations include what the information contains, why it was originally collected, what the provider may do with it, where it may be processed or stored, who can access it, and how long it is retained.

Singapore's Personal Data Protection Commission (PDPC) says social service agencies may hold personal data such as names, contact details, financial and family circumstances, and medical histories. The agency must consider applicable duties including purpose limitation, notification, consent or an available exception, protection, retention and overseas transfer.[1] This is not a blanket statutory ban on using generative AI. Nor does consent automatically make every use sensible. The facts, purpose, safeguards and agency arrangements matter.

Following a public consultation held from 2 June to 1 July 2026, PDPC issued its Advisory Guidelines on Use of Personal Data in Generative AI on 20 July 2026. The Guidelines apply the PDPA across the generative AI lifecycle, including to personal data in end-user prompts and inputs.[2] Treat a prompt as another place where agency information is processed.

A vendor's controls are relevant, but they do not settle the decision. OpenAI currently says content from individual ChatGPT services may be used to train models unless the user opts out. Temporary Chats are not used for training and are deleted from its systems after 30 days. OpenAI says inputs and outputs from ChatGPT Business, Enterprise and the API are not used for training by default.[6][7] But “not used for training” does not mean “not retained”, “approved by our agency” or “safe for any confidential record”. Check terms and settings.

Four useful information classes

Use your agency's existing labels if they work. The point is to help staff recognise risk quickly.

Public

Information intentionally released for anyone to see, such as a published annual report or programme description. This is normally the easiest material to use, subject to copyright, accuracy and communications rules.

“Available online” is not always approved for reuse. A client's public social media post can still be personal data. PDPC's generative AI guidelines discusses fact-specific limits around publicly available personal data and digital barriers.[2]

Internal

Routine working material not meant for public release but with limited harm if exposed: a blank facilitation template, generic staff instructions or an agenda with no sensitive discussion. An agency-approved business AI workspace may be suitable if policy allows it. A personal or free account may not be.

Confidential

Information whose disclosure could cause harm: an unannounced grant proposal, tender pricing, legal advice, passwords, security details or board deliberations. It may not be personal data, but it still needs protection under contracts, duties and agency policy.

Personal or sensitive in context

Information about an identifiable person, whether accurate or not. It includes obvious identifiers and combinations that identify someone. For SSAs, this often covers case histories, health and disability information, family conflict, financial hardship, addresses, photographs, voice recordings, donor details and staff performance matters.[1]

The PDPA does not create a separate statutory category called “sensitive personal data”. However, the likely harm and sensitivity affect what reasonable protection looks like. A generic attendance count is not equivalent to a case note about abuse, debt or mental health.

A document can occupy several classes. Use the strictest applicable treatment.

Before you begin

Before pasting or uploading, work through these questions in order.

Use this decision process

  1. Is this tool and account approved for agency work?

    If no, stop. Do not use a personal account as a workaround. If yes, confirm the approved use cases and prohibited data. “We pay for it” is not the same as “we assessed it”.

  2. What exactly am I sending?

    Include attachments, hidden spreadsheet columns, comments, tracked changes, file metadata and quoted email chains. Classify the highest-risk content, not just the visible paragraph you plan to edit.

  3. Can I complete the task without real information?

    Start with a blank template, invented example or high-level instruction. Instead of uploading last month's case notes, ask: “Create a structured case-summary template with sections for presenting issue, actions, risks and follow-up.” This often produces a useful first draft without exposing a person's story.

  4. If real information is needed, is the purpose permitted?

    Ask whether the use fits the purpose communicated when the information was collected, whether consent covers it, or whether another relevant PDPA basis applies. Follow an approved use case or ask the data protection officer (DPO) or designated reviewer. PDPC's social service guidelines say personal data should be relevant to a purpose that a reasonable person would consider appropriate.[1] Its generative AI guidelines say broad notices such as “product improvement” may be insufficient where consent is relied upon for model training; AI-specific notification may be needed.[2] Summarising a note is a different scenario, but the same practical principle helps: be specific about what happens to people's data.

  5. Have I reduced the information enough?

    Remove everything the task does not require. Use an extract rather than a full file. Replace real facts with invented ones where fidelity is unnecessary. If you need trends, use aggregated counts. If you need editing help, paste only the sentence structure with fictional details.

  6. Could someone still identify a person or expose a confidence?

    Look beyond names. Consider unusual age, rare condition, precise date, neighbourhood, school, family structure, occupation, sequence of events and quotations. Also ask whether colleagues, partners or community members possess extra knowledge that makes recognition easy.

  7. Are the provider controls and contract adequate for this use?

    Check training use, retention, deletion, access controls, overseas transfers, incident handling and whether connected apps receive the content. The Commissioner of Charities' guide recommends due diligence, awareness of cloud security and storage jurisdiction, and a written outsourcing agreement for outsourced electronic data storage.[5]

  8. Is human review built in?

    AI output can omit context, invent facts or flatten professional judgement. A qualified staff member should check it before it enters a case record, donor communication, board paper, grant submission or decision that affects someone. If any answer is unclear, pause and escalate. A short delay is cheaper than trying to retrieve sensitive text after it has been submitted.

Anonymisation is more than deleting a name

Deleting “Mdm Tan” from a case note does not necessarily anonymise it.

PDPC distinguishes de-identification, which removes direct identifiers such as name, address or NRIC number, from anonymisation, a risk-based process intended to prevent identification. De-identification is only a first step. A record can be re-identified by combining indirect clues with public information or knowledge held by the recipient.[3][4]

Consider this sentence:

A 71-year-old former school principal living in a named rental block sought help two days after a widely reported fire; her adult son is serving a sentence for a distinctive offence.

Why combinations matter

Removing the name leaves strong clues. Someone in the neighbourhood may recognise her, and a web search could narrow the field.

For case notes, safer preparation may require generalising locations, dates, ages, occupations, relationships, rare events and quotations, or suppressing an unusual case. If that makes the text useless, use a fictional scenario or keep the task inside an appropriately controlled system.

PDPC suggests considering whether a motivated, reasonably competent person using standard resources could re-identify someone. It also warns about spontaneous recognition by a recipient with special knowledge.[3] This matters greatly in small programmes and close communities.

Four realistic examples

The answer changes with the material, the account being used and the agency’s approval for that task.

What agency leaders should put in place

Give staff a one-page acceptable-use guide naming approved tools and accounts, allowed tasks, prohibited inputs, escalation routes and how to report a mistake. Connect it to existing data classification and incident-response processes.

Keep a register of approved uses: purpose, users, data classes, provider and plan, settings, retention, human checks, owner and review date. Recheck vendor terms and enabled features regularly.

Train with realistic examples from the agency's work, using fictional data. Include volunteers and temporary staff. The PDPC's SSA guidelines say agencies remain primarily responsible for employees' and volunteers' actions in the course of their work, and should communicate their policies and practices to them.[1]

Make accidental disclosure easy to report. Staff should stop, preserve the facts, notify the designated person promptly and follow the incident process. Do not assume deleting a chat has removed every copy.

This guide is general information, not legal advice. If a proposed use involves identifiable clients, high-impact decisions, large datasets or unclear consent and contractual issues, involve the DPO and obtain legal or technical advice where appropriate.

Sources

  1. Personal Data Protection Commission, Advisory Guidelines for the Social Service Sector (revised 18 January 2024)
  2. Personal Data Protection Commission, Advisory Guidelines on Use of Personal Data in Generative AI (issued 20 July 2026)
  3. Personal Data Protection Commission, Advisory Guidelines on the PDPA for Selected Topics (revised May 2024), Chapter 3 on anonymisation
  4. Personal Data Protection Commission, Guide to Basic Anonymisation (updated 24 July 2024)
  5. Commissioner of Charities, Data Protection Guide for Charities: Managing & Securing Electronic Personal Data
  6. OpenAI, How your data is used to improve model performance
  7. OpenAI, Data Controls FAQ

About the author

Darren writes for Social Tech Guild about practical, responsible uses of technology in Singapore's social service sector.

Build an AI use guide your staff can actually use

Social Tech Guild can help your agency turn its data classifications, approved tools and escalation routes into a short, practical guide for everyday work.

Collaborate with Social Tech Guild

About Darren

Darren explores practical technology with Singapore social-service teams as a volunteer. The work starts with the workflow, the people responsible for it, and the safeguards it needs.

How Social Tech Guild approaches the work

Could a small tool make your team’s work lighter?

Tell me about a task that keeps taking time. We can look at it together and see whether a small volunteer project could help.

Please do not include client-identifying information.

Discuss a project

I volunteer with Singapore social-service teams to explore small, practical ways to reduce repeated work.

This starts a conversation only. It does not confirm fit, a pilot, a project or a partnership.

PrivacyPlease do not include client-identifying information.