Gotchaa Lab
Back to Blog
AIpdpadata-privacymalaysiaSME

Customer Data and AI Tools in Malaysia: Where It Actually Goes

26 July 2026·7 min read·By Gotchaa Lab
Customer Data and AI Tools in Malaysia: Where It Actually Goes

TL;DR

  • The risk is not the brand, it is the tier. ChatGPT Free and ChatGPT Enterprise are the same product with two very different contracts underneath, and your staff signed up on the free one.
  • Deletion works forward, not backward. Google keeps human-reviewed Gemini chats up to 3 years even after you delete your activity, and Anthropic can hold de-identified copies for up to 5 years if model improvement was switched on.
  • Under Malaysia's PDPA you stay the responsible party. The 2024 Amendment raised penalties to RM1 million and 3 years' imprisonment, and replaced the old country whitelist with an adequacy test you have to justify yourself.
  • Do not write an AI policy this week. Delete three columns (name, phone, email or IC) from the file your team pastes most often. Ten minutes, most of the exposure gone.

Someone on your team has already pasted customer data into an AI tool. Not to be reckless. Just to clean up the formatting before a meeting.

Here is what happens to that list. The text leaves your office, lands on a vendor's servers overseas, and sits there under the vendor's terms rather than yours. On free and personal tiers it can be read by human reviewers and used to improve the model. On business tiers it usually is not. Under Malaysia's PDPA you stay responsible for it either way, because handing data to a vendor does not hand over the duty.

Most Malaysian SMEs have never checked which of those two situations their customer data is in. That is the exposure, and it costs nothing to close.

The tier is the whole decision, not the brand

Most owners ask which AI tool is safe. The answer barely depends on the brand. It depends on which tier of it you are logged into.

ChatGPT Free and ChatGPT Enterprise are the same product with two completely different contracts underneath. Claude Pro and Claude for Work, same story. One tier is built for a person trying things out. The other is for a company that answers to a regulator. Your staff are on the first, because it has the free button.

Which AI tools keep your customer data, and which don't

Terms as published July 2026. Vendors revise these, so check the policy page first.

Tool and tierUsed to train the model?Human reviewHow long it sticks around
ChatGPT Free, Plus, ProYes, unless you switch it off in data controlsPossibleChats stay in your account until you delete them
ChatGPT Business, Enterprise, Edu, APINo, off by defaultNot for trainingEnterprise and Edu admins set retention, 90-day minimum. API logs default to 30 days
Claude Free, Pro, MaxOnly if model improvement is switched onPossibleDeleted chats leave back-end storage within 30 days. If model improvement was on, de-identified copies can sit in training pipelines up to 5 years
Claude for Work, APINo by default. Feedback you submit is the exceptionFeedback onlySubmitted feedback kept up to 5 years
Gemini free appsYes, unless you turn off Keep ActivityYes, a subset of chatsActivity auto-deletes at 18 months. Reviewed chats kept up to 3 years, even after you delete your activity

Google says it plainly in its own help page: do not enter confidential information you would not want a reviewer to see. That is the vendor answering for you.

The Gemini Apps Privacy Hub table of contents, listing sections on how data is used, human review and retention periods Google publishes all of it: who reviews your chats, how long they are kept. Almost nobody opens the page. Source: Google Gemini Apps Privacy Hub

The table cannot show where the data physically sits. DeepSeek's privacy policy says it collects, processes and stores personal data in China. Not automatically a problem, but it is a cross-border transfer, and since 2025 you have to justify one.

Does PDPA cover customer data you put into AI tools in Malaysia?

Yes. You are the data controller. The AI vendor is a processor acting on your behalf, and picking that processor is a decision you have to defend.

The 2024 Amendment to the PDPA, phased in through 2025, changed three things that matter here:

  1. Processors now carry direct obligations under the Security Principle, with criminal exposure of their own. Your vendor is no longer invisible to the regulator.
  2. The old whitelist of approved destination countries is gone. Sending data overseas now rests on the destination offering protection at a level equivalent to the PDPA, supported by a transfer impact assessment that stays valid for three years.
  3. Penalties for breaching the data protection principles rose to RM1 million and up to three years' imprisonment, from RM300,000 and two years.

If you want the long checklist version of this, we wrote one: PDPA compliance checklist for Malaysian SaaS startups.

Can you delete customer data you already pasted in?

Partly, and slower than you would like.

Deleting a chat clears it from your screen. Anthropic says deleted consumer conversations leave its back-end storage within 30 days. But if model improvement was switched on when that chat happened, de-identified copies can stay in training pipelines for up to five years. Google keeps human-reviewed Gemini chats for up to three years, and those survive you deleting your activity, because they were disconnected from your account before any reviewer saw them.

So deletion works forward, not backward. Whatever is already in a review queue or a training set is out of your hands. Which is why the fix has to happen before the paste.

Our take: banning AI tools in Malaysia will not hold

We use AI tools every day at Gotchaa Lab, so this is not a warning from the sidelines. It is the thing we keep walking into.

The instinct after reading the above is to ban AI tools at work. Bans do not hold, and the numbers are not close. In PagerDuty's June 2026 survey of 1,250 office professionals at large companies in the US, UK, Australia and Japan, 66% used AI tools despite believing company policy prohibited it, and 34% shared customer data or information with public tools. Malaysia has the same problem from the other side: in Xero's survey of Malaysian MSMEs, 59% named data privacy and security as their main AI concern, while 30% of those already using AI had no policy governing it.

A ban does not remove the habit. It creates shadow AI, the same habit somewhere you cannot see. Redaction is the better trade, because your team keeps the speed and you lose the exposure. And when the work genuinely cannot leave the country, run the model somewhere you control: we host systems in Malaysia, and AI solutions can run on-premise or in a Malaysian data centre. Then there is the question of which department should get AI first.

Do this before your next AI task

Do not write an AI policy. Nobody will read it and you will not finish it this week anyway.

Open the one file your team pastes into an AI tool most often. It is usually an order export, an enquiry list, or a dump from the support inbox. Delete three columns before it goes anywhere: name, phone number, and email or IC. Leave the order ID, the item, the amount, the date. The AI can still sort it, summarise it, find the pattern and draft the reply. It simply cannot identify anybody.

That takes ten minutes and removes most of your exposure, without asking anyone to change how they work. Save the stripped version as the file people reach for. Then, on a quieter afternoon, check which tier your team is logged into.

Not sure where your customer data lands in the tools your team uses? WhatsApp us and tell us which tools you are on. We will give you a straight read, no sales pitch.

This article is general information, not legal advice. PDPA obligations depend on your specific circumstances, and vendor terms change. Verify current policies with the vendor and your own adviser before acting.

References

  1. Google: Gemini Apps Privacy Hub, human review and retention
  2. OpenAI Academy: Data governance and compliance
  3. Anthropic: Is my data used for model training?
  4. Anthropic: How long do you store my data?
  5. DeepSeek Privacy Policy
  6. Mayer Brown: Key amendments to Malaysia's PDPA and the cross-border transfer guidelines
  7. Personal Data Protection Department (JPDP), Malaysia
  8. PagerDuty: Shadow AI workplace survey, June 2026
  9. Xero survey: Malaysian MSMEs are rapidly adopting AI

Share this article

Frequently Asked Questions

Is it safe to put customer data into ChatGPT?
It depends entirely on which tier you are on. On personal plans (Free, Plus, Pro) your chats can be used to improve OpenAI's models unless you switch that off in data controls, and conversations stay in the account until you delete them. On ChatGPT Business, Enterprise, Edu and the API, OpenAI states it does not use business customer content to train its models by default. Enterprise and Edu admins can also set a workspace retention policy with a 90-day minimum, while the API keeps abuse-monitoring logs for up to 30 days by default, or none at all for approved customers. If customer data has to go in at all, it belongs on a business tier with a signed data processing agreement, not on a free login.
Does PDPA apply when my staff use an AI tool?
Yes. Putting personal data into an AI tool does not move it out of the Personal Data Protection Act. You remain the data controller and the AI vendor is a processor acting on your behalf, so choosing that vendor and documenting the arrangement is your responsibility. The 2024 Amendment, phased in through 2025, also placed direct obligations on processors under the Security Principle and raised penalties for breaching the data protection principles to RM1 million and up to three years' imprisonment.
Can I delete customer data I already pasted into an AI tool?
Only partly. Deleting the chat removes it from your history immediately, and Anthropic says deleted consumer conversations leave its back-end storage within 30 days. But if the model improvement setting was on, de-identified copies can remain in training pipelines for up to five years. Google retains Gemini chats that went to human reviewers for up to three years, and those are not deleted when you delete your Gemini Apps activity. Assume anything already reviewed or used for training is out of your control.
Which AI tools do not train on your data?
As published in July 2026: ChatGPT Business, Enterprise, Edu and the API are not used for training by default. Claude for Work and the Anthropic API are not used for training by default either, with one exception, feedback and bug reports you deliberately submit, which are kept up to five years. Consumer tiers of both products are governed by different settings. Vendors revise these terms regularly, so check the current policy page before you rely on any of it.
Do I need a data processing agreement with an AI vendor in Malaysia?
If the vendor handles personal data on your behalf, you should have a written agreement covering it, and you should keep the record. Most large AI vendors publish a standard data processing agreement you accept once on a business plan. Consumer sign-ups generally do not come with one, which is a large part of why a free login is a poor place for customer records. This is general information, not legal advice, so confirm your specific position with a qualified adviser.

Need help building this for your business?

We help Malaysian companies turn ideas like these into working software. Free consultation, no obligation.