Someone on your team has already pasted customer data into an AI tool. Not to be reckless. Just to clean up the formatting before a meeting.
Here is what happens to that list. The text leaves your office, lands on a vendor's servers overseas, and sits there under the vendor's terms rather than yours. On free and personal tiers it can be read by human reviewers and used to improve the model. On business tiers it usually is not. Under Malaysia's PDPA you stay responsible for it either way, because handing data to a vendor does not hand over the duty.
Most Malaysian SMEs have never checked which of those two situations their customer data is in. That is the exposure, and it costs nothing to close.
The tier is the whole decision, not the brand
Most owners ask which AI tool is safe. The answer barely depends on the brand. It depends on which tier of it you are logged into.
ChatGPT Free and ChatGPT Enterprise are the same product with two completely different contracts underneath. Claude Pro and Claude for Work, same story. One tier is built for a person trying things out. The other is for a company that answers to a regulator. Your staff are on the first, because it has the free button.
Which AI tools keep your customer data, and which don't
Terms as published July 2026. Vendors revise these, so check the policy page first.
| Tool and tier | Used to train the model? | Human review | How long it sticks around |
|---|---|---|---|
| ChatGPT Free, Plus, Pro | Yes, unless you switch it off in data controls | Possible | Chats stay in your account until you delete them |
| ChatGPT Business, Enterprise, Edu, API | No, off by default | Not for training | Enterprise and Edu admins set retention, 90-day minimum. API logs default to 30 days |
| Claude Free, Pro, Max | Only if model improvement is switched on | Possible | Deleted chats leave back-end storage within 30 days. If model improvement was on, de-identified copies can sit in training pipelines up to 5 years |
| Claude for Work, API | No by default. Feedback you submit is the exception | Feedback only | Submitted feedback kept up to 5 years |
| Gemini free apps | Yes, unless you turn off Keep Activity | Yes, a subset of chats | Activity auto-deletes at 18 months. Reviewed chats kept up to 3 years, even after you delete your activity |
Google says it plainly in its own help page: do not enter confidential information you would not want a reviewer to see. That is the vendor answering for you.
Google publishes all of it: who reviews your chats, how long they are kept. Almost nobody opens the page. Source: Google Gemini Apps Privacy Hub
The table cannot show where the data physically sits. DeepSeek's privacy policy says it collects, processes and stores personal data in China. Not automatically a problem, but it is a cross-border transfer, and since 2025 you have to justify one.
Does PDPA cover customer data you put into AI tools in Malaysia?
Yes. You are the data controller. The AI vendor is a processor acting on your behalf, and picking that processor is a decision you have to defend.
The 2024 Amendment to the PDPA, phased in through 2025, changed three things that matter here:
- Processors now carry direct obligations under the Security Principle, with criminal exposure of their own. Your vendor is no longer invisible to the regulator.
- The old whitelist of approved destination countries is gone. Sending data overseas now rests on the destination offering protection at a level equivalent to the PDPA, supported by a transfer impact assessment that stays valid for three years.
- Penalties for breaching the data protection principles rose to RM1 million and up to three years' imprisonment, from RM300,000 and two years.
If you want the long checklist version of this, we wrote one: PDPA compliance checklist for Malaysian SaaS startups.
Can you delete customer data you already pasted in?
Partly, and slower than you would like.
Deleting a chat clears it from your screen. Anthropic says deleted consumer conversations leave its back-end storage within 30 days. But if model improvement was switched on when that chat happened, de-identified copies can stay in training pipelines for up to five years. Google keeps human-reviewed Gemini chats for up to three years, and those survive you deleting your activity, because they were disconnected from your account before any reviewer saw them.
So deletion works forward, not backward. Whatever is already in a review queue or a training set is out of your hands. Which is why the fix has to happen before the paste.
Our take: banning AI tools in Malaysia will not hold
We use AI tools every day at Gotchaa Lab, so this is not a warning from the sidelines. It is the thing we keep walking into.
The instinct after reading the above is to ban AI tools at work. Bans do not hold, and the numbers are not close. In PagerDuty's June 2026 survey of 1,250 office professionals at large companies in the US, UK, Australia and Japan, 66% used AI tools despite believing company policy prohibited it, and 34% shared customer data or information with public tools. Malaysia has the same problem from the other side: in Xero's survey of Malaysian MSMEs, 59% named data privacy and security as their main AI concern, while 30% of those already using AI had no policy governing it.
A ban does not remove the habit. It creates shadow AI, the same habit somewhere you cannot see. Redaction is the better trade, because your team keeps the speed and you lose the exposure. And when the work genuinely cannot leave the country, run the model somewhere you control: we host systems in Malaysia, and AI solutions can run on-premise or in a Malaysian data centre. Then there is the question of which department should get AI first.
Do this before your next AI task
Do not write an AI policy. Nobody will read it and you will not finish it this week anyway.
Open the one file your team pastes into an AI tool most often. It is usually an order export, an enquiry list, or a dump from the support inbox. Delete three columns before it goes anywhere: name, phone number, and email or IC. Leave the order ID, the item, the amount, the date. The AI can still sort it, summarise it, find the pattern and draft the reply. It simply cannot identify anybody.
That takes ten minutes and removes most of your exposure, without asking anyone to change how they work. Save the stripped version as the file people reach for. Then, on a quieter afternoon, check which tier your team is logged into.
Not sure where your customer data lands in the tools your team uses? WhatsApp us and tell us which tools you are on. We will give you a straight read, no sales pitch.
This article is general information, not legal advice. PDPA obligations depend on your specific circumstances, and vendor terms change. Verify current policies with the vendor and your own adviser before acting.
References
- Google: Gemini Apps Privacy Hub, human review and retention
- OpenAI Academy: Data governance and compliance
- Anthropic: Is my data used for model training?
- Anthropic: How long do you store my data?
- DeepSeek Privacy Policy
- Mayer Brown: Key amendments to Malaysia's PDPA and the cross-border transfer guidelines
- Personal Data Protection Department (JPDP), Malaysia
- PagerDuty: Shadow AI workplace survey, June 2026
- Xero survey: Malaysian MSMEs are rapidly adopting AI



