Why personal accounts are the main risk
When staff paste customer emails, contracts or spreadsheets into a personal AI account, the company loses control of that data: it may be retained, may be used to improve the provider's models depending on settings, and cannot be deleted or audited by the company. That can breach your PDPA obligations and client confidentiality agreements.
A safer setup
Choose one approved AI tool on a business or enterprise plan and give everyone access, so there is no reason to use personal accounts. Define which data types are never allowed, such as NRIC numbers, bank details and health information, and which are allowed with care. Teach staff to anonymise, for example replacing names with 'Client A'. Review the policy as tools change.