ChatGPT DLP
ChatGPT
ChatGPT DLP starts before the send.
Protect sensitive employee prompts and files on a supported, managed ChatGPT path. Account restrictions, provider data settings and content inspection are different controls.
A support prompt with a customer identifier
ChatGPT browser prompt · synthetic customer data
Summarise the escalation for Northstar, account NS-48217. Keep the requested next steps.
Illustrated rule: redact customer and account identifiers before a supported submission.
An illustration, not an installed-product test or a coverage guarantee.Account. Surface. Action.
- 01Account
- Personal, Business or Enterprise: record the signed-in account.
- 02Employee surface
- Browser and native desktop are separate client paths.
- 03Data action
- Test typed prompts, pasted text and file uploads separately.
Provider and existing-stack controls
Start with the controls you already have.
Purview's ChatGPT Enterprise connector supports audit and compliance features; its capability table marks DLP as unsupported for that connector. Separate Purview browser and endpoint paths offer DLP for supported AI sites. Check the route and prerequisites, not just the licence name.
Provider documentation checked 20 September 2026. Availability and entitlement still need confirmation.
Make the outcome reviewable.
Get the acceptance checklist- 01
Record the ChatGPT account, browser or app and installed client version.
- 02
Test the prompt and file action independently with synthetic information.
- 03
Review the employee response, returned content and available policy event.
The details that change the decision.
Can we block personal ChatGPT accounts while allowing a business workspace?
Account access and content inspection are separate requirements. Confirm your identity, browser and workspace controls first. This page does not claim a verified Aona restriction that distinguishes every personal and business account.
Does a ChatGPT Business or Enterprise account remove the need for DLP?
Review the provider's agreement and workspace settings, then decide which information employees may submit. Provider data handling does not by itself establish the pre-submission content control your organisation requires.
What should we test for a file upload?
Name the upload route, file format and expected response. For a supported DOCX, XLSX or PDF redaction path, inspect the returned file, layout and any unsupported content separately from the prompt test.
How should we compare Aona with existing Purview or network controls?
Start with your licensed product, managed browser or endpoint and routed traffic. Compare the same synthetic action and required evidence. A network or provider control is not absent simply because the application is ChatGPT.
What must be installed before an Aona evaluation?
The Aona browser plugin supports Chrome, Edge, Firefox and Safari. Confirm the intended browser, application and input path; browser support does not establish feature parity. IT teams can deploy the Aona endpoint app on Windows and macOS with their preferred software deployment tools. Intune is one option; direct installation is also available on both platforms.
Review your ChatGPT data-protection path.
Bring the account type, employee surface and one sensitive-data action. We will focus on the control your team needs.
- Account and managed client
- Prompt or file policy response
- Existing controls, evidence and rollout