
ChatGPT Outlook Add-In Risks: What Every Business Needs to Know Before Installing It
Updated August 2026: Essential guidance for UK businesses using or considering the ChatGPT Outlook add-in
The ChatGPT Outlook add-in is one of the fastest-adopted AI tools in UK workplaces right now. It promises to help employees draft emails faster, summarise long threads, and manage their inboxes more efficiently. For busy teams handling high volumes of correspondence, the appeal is obvious.
But here is the problem: most businesses that have staff using it have no idea what data it is accessing, where that data goes, or whether it complies with UK GDPR. This guide sets out what every UK business owner and IT decision-maker needs to understand before this tool goes any further in your organisation.
What Does the ChatGPT Outlook Add-In Actually Do?
The ChatGPT Outlook add-in integrates OpenAI’s large language model directly into Microsoft Outlook. Once installed, it can read email content, suggest replies, summarise conversations, and assist with drafting. It operates within the Outlook interface, which means it runs with whatever permissions the user has granted.
Employees typically install it because it genuinely saves time. AI-assisted email is useful. The issue is not the functionality — it is the data implications of that functionality, and whether your business has properly assessed them before deployment.
What Data Can It Access?
⚠️ Important: The ChatGPT Outlook add-in can access substantially more than just the email you are currently drafting. When granted full permissions, it can read incoming and outgoing email content (including historical messages), attachments and files within those emails, calendar data and meeting details, contact information and distribution lists, and any documents uploaded or shared via connected Microsoft 365 services. In practice, this means a single staff member installing the add-in could expose client correspondence, internal financial discussions, HR communications, and strategic documents to an external AI service — without your knowledge or explicit sign-off.
This is not a hypothetical risk. The permissions are real, the data transfer happens in real time, and the implications for your business depend entirely on which account type your employees are using.
The Critical Distinction: Personal vs Business/Enterprise Accounts
This is the most important thing to understand, and it is the point that most IT teams miss. The data handling rules for ChatGPT differ significantly depending on whether your staff are using a personal OpenAI account or a Business/Enterprise subscription.
“By default, we may use content you provide us to train our models. You can opt out of model training at any time from your account settings. If you use the API or are on a ChatGPT Enterprise or Team plan, we do not train on your content by default.”
— OpenAI Privacy Policy (August 2026)
What this means in practice: if your employees install the ChatGPT Outlook add-in using their personal OpenAI accounts (which the majority do, because it is free and quick to set up), the email content they process through it may be used to train OpenAI’s AI models — unless they have manually opted out. Most users have not opted out, because they do not know the setting exists.
If your business has a ChatGPT Team or Enterprise subscription, training on your data is off by default. But if individual employees are using free personal accounts — as is extremely common — you have no such protection, and you almost certainly have no data processing agreement in place with OpenAI either.
Four Key Risks Every Business Must Address
1. Uncontrolled Personal Account Use by Employees
The most common scenario we see is employees installing the add-in on their own initiative using personal free accounts. They do this because it is useful, not because they intend to cause harm. But from a data governance perspective, this represents unmanaged data egress. Your business data is leaving your controlled environment and being processed by a third-party service under terms you have not reviewed and did not agree to on behalf of your organisation.
2. UK GDPR Data Processing Obligations
Under UK GDPR, your business is a data controller. When you use a third-party service to process personal data — including client emails, employee details, or any personally identifiable information — that third party becomes a data processor. You are legally required to have a Data Processing Agreement (DPA) in place with them, and you must ensure their security measures are adequate.
If employees are using personal ChatGPT accounts to process business data, you almost certainly have no DPA with OpenAI. If OpenAI processes or stores that data in the US (which it does), you need to ensure the transfer meets UK international data transfer requirements under the UK GDPR framework. Most businesses using the add-in informally have not addressed any of this.
3. AI Model Training Using Company Data
As OpenAI’s own policy confirms, personal account data may be used for training. This means confidential client correspondence, business strategy discussions, financial information, and sensitive HR communications could, in theory, become part of the data used to improve OpenAI’s models. Even if specific data is anonymised during training, the fact that it has been transmitted to and processed by an external service is itself a compliance issue under UK GDPR.
4. Shadow AI and Unmanaged Usage
Perhaps the greatest long-term risk is not any single incident but the broader pattern of shadow AI adoption. When employees discover useful tools independently and use them without IT or compliance oversight, you lose visibility into where your data is going. Shadow AI is the AI equivalent of shadow IT — and it is growing rapidly in UK workplaces. Without a clear policy and technical controls, the ChatGPT Outlook add-in is just the start.
High-Risk Data Categories to Watch
🔴 Client & Customer Data
- Client email correspondence
- Case details and personal information
- Contract and agreement content
- Complaint and dispute records
🔵 Financial & Commercial Data
- Invoice and payment discussions
- Pricing and margin information
- Budget and forecast data
- Bank and account references
🟡 HR & People Data
- Employee personal details
- Salary and benefits correspondence
- Performance and disciplinary records
- Recruitment communications
🟢 Internal & Strategic Data
- Business strategy discussions
- Supplier and partner negotiations
- M&A and investment conversations
- Intellectual property and trade secrets
Any of these categories passing through a personal ChatGPT account represents a data breach risk, a UK GDPR compliance failure, or both.
Pre-Deployment Checklist: Before You Allow the Add-In
If you are considering officially deploying the ChatGPT Outlook add-in — or if you want to get control of employees who are already using it — work through the following checklist.
| Action Required | Details | Priority |
|---|---|---|
| Audit current usage | Identify which staff are already using the add-in and which account type (personal vs Enterprise) | Critical |
| Review OpenAI’s DPA | Obtain and review OpenAI’s Data Processing Agreement; ensure it covers your use case | Critical |
| Disable personal account use | Use Microsoft Intune or Group Policy to restrict add-in installation to approved accounts only | Critical |
| Upgrade to ChatGPT Team/Enterprise | Enterprise plan disables model training on your data by default and includes a DPA | High |
| Update privacy policy and ROPA | Add AI tool usage to your Record of Processing Activities; update client-facing privacy notices | High |
| Conduct a DPIA | Data Protection Impact Assessment required if processing special category or high-risk data with AI | High |
| Train staff on AI data risks | Ensure all employees understand what they can and cannot process through AI tools | Medium |
| Publish an AI usage policy | Document approved AI tools, permitted use cases, and prohibited data types | Medium |
How Pro Business Helps
The ChatGPT Outlook add-in is a genuine productivity tool — but only when deployed correctly, with the right controls in place. The problem is that most businesses do not have the internal expertise to assess the data protection implications, configure Microsoft 365 correctly to restrict personal account use, or draft the policies required to remain UK GDPR compliant.
Pro Business works with UK businesses to make AI adoption safe and compliant. Our security solutions include AI readiness assessments, Microsoft 365 configuration reviews, UK GDPR compliance support, and staff training on AI data risks. We help you get the productivity benefits of tools like ChatGPT without the legal and reputational exposure that comes from unmanaged adoption.
We can audit your current Microsoft 365 environment, identify whether the ChatGPT add-in is already in use across your organisation, assess your data protection obligations, and implement the technical controls needed to protect your business — all without disrupting the tools your staff are already using.
If you are not sure whether your business is exposed right now, that uncertainty is itself a risk. Get in touch for a straightforward conversation about where you stand.
Is Your Business Exposed Right Now?
If you have staff using the ChatGPT Outlook add-in — or any AI tool — without a formal policy or data processing agreement in place, you may already be in breach of UK GDPR. We can assess your risk and implement the controls needed to protect your business.
Call: 0161 519 0764 | Email: info@pro-business.co.uk
Related reading: If your business is using Microsoft Copilot, the data access and compliance questions are similar — and in some respects more significant given Copilot’s deeper Microsoft 365 integration. Read our guide: Microsoft Copilot: What Every UK Business Owner Needs to Know Before You Switch It On.