Source-linked AI summary
Chat First, Worry Later: Understanding Individuals' Privacy Perceptions Using ChatGPT in a Work Context
Christoph Nirschl, Magdalena Glas, Gerhard Messmann, Günther Pernul
TL;DR
Commercial GenAI tools are entering work routines while raising questions about users’ understanding of privacy risks and organizational readiness. The study surveys 224 ChatGPT users across employment sectors to examine how proficiency, privacy concerns, and organizational policies relate to usage. Organizational policies are positively associated with privacy-related proficiency, while privacy concerns reduce usage frequency and diversity, especially without policies.
Problem
ChatGPT’s work use raises privacy risks, while evidence is limited on how organizational policies, privacy concerns, and knowledge of data practices jointly relate to usage behavior.
Method
An online survey of 224 ChatGPT users in different European industry sectors assessed organizational policies, integrated privacy concerns, privacy-related ChatGPT proficiency, and usage behavior.
Results
Organizational policies significantly enhance ChatGPT proficiency, while privacy concerns reduce usage frequency and application diversity, particularly without organizational policies.
Takeaways & Limitations
Organizational guidance is associated with greater privacy understanding and broader ChatGPT use, whereas users without policies rely more on personal privacy judgments and knowledge.
Takeaways & Limitations
The findings apply specifically to ChatGPT and cannot be generalized to other GenAI applications.
Abstract
from arXiv · showhide
Generative Artificial Intelligence (GenAI) tools like ChatGPT, which can generate human-like responses from vast amounts of textual data, are increasingly transforming work routines across various fields, including education, healthcare, and IT. This integration, however, raises privacy concerns and questions the readiness of both environments and individuals. To investigate this issue, we conducted a user study with $N=224$ participants from a range of different employment sectors that have integrated ChatGPT into their work routines. We examined how proficiency in the utilization of ChatGPT, general privacy concerns, and organizational policies for GenAI usage impact users' actual ChatGPT usage and how these factors interact. Our findings reveal organizational policies are significantly positively associated with privacy-related ChatGPT proficiency, however, the overall proficiency is low. Higher privacy concerns were found to negatively influence both the frequency of ChatGPT use and the diversity of its applications, especially among users in organizations without GenAI policies.
1 Introduction
The study examines how organizational policies, integrated privacy concerns, and ChatGPT proficiency relate to work-related ChatGPT usage. Using an online survey of 224 European workers, it finds that policies enhance proficiency and broader use, while privacy concerns reduce usage, especially without policies.
- The study examines how organizational policies, integrated privacy concerns, and ChatGPT proficiency affect ChatGPT usage behavior in work contexts.
- 224 participants from different European industry sectors who used ChatGPT at work completed an online survey.
- The study introduces constructs for integrated privacy concerns and privacy-related ChatGPT proficiency tailored to professional ChatGPT use.The proficiency construct is based on OpenAI’s explicit privacy policies rather than general technological adoption competence.
- Organizational policies significantly enhance ChatGPT proficiency and are associated with broader application use.The study links structured guidance with improved understanding of data storage and processing and more versatile ChatGPT use.
- Privacy concerns negatively affect both ChatGPT use frequency and application diversity, particularly in organizations without GenAI policies.
- No significant effects of ChatGPT proficiency on usage behavior were observed in organizations with established policies, and policy types did not differ in their effects.
2 Theoretical Background
The background describes how LLM-based GenAI tools generate content and have become relevant to work. It also outlines privacy risks from ChatGPT’s storage, processing, and potential exposure of sensitive inputs.
- 2.1 Large Language Models and GenAI: Language models predict sequences of words, while LLMs scale model size or training data to improve performance and capacity.Tokens may be characters, words, or sub-words serving as semantic processing units.
- 2.1 Large Language Models and GenAI: GenAI systems create new text, images, or audio from patterns learned from data and support natural-language generation and understanding.
- 2.1 Large Language Models and GenAI: ChatGPT is a widely used dialogue-oriented GenAI tool that generates human-like responses from input prompts using transformer-based GPT models.
- 2.3 Privacy Challenges of ChatGPT: ChatGPT’s work-related benefits coexist with privacy risks because it processes personal account data, stores conversations, and may use conversation data for model training.
- 2.3 Privacy Challenges of ChatGPT: Sensitive information entered into ChatGPT may be exposed through unauthorized access, internal processing, or disclosure of confidential third-party data.The paper illustrates this risk with patient data entered to create clinical reports without consent.
3 Related Work
Prior work examined privacy perceptions, risks, trust, and adoption of AI chatbots and LLM-based agents, but left limited evidence about privacy-driven ChatGPT behavior and competence in work settings.
- TAM-based studies addressed initial AI acceptance, but TAM is limited for post-adoption behavior shaped by privacy, trust, and risk considerations.
- Studies of ChatGPT and related agents examined privacy, cybersecurity risks, trust, and adoption, without addressing privacy effects on work-related usage behavior or competence.
- The authors position this study as the first quantitative examination of privacy-driven ChatGPT behavior among work-context users.
- Compared with qualitative work on custom GPTs, this study quantitatively measures privacy proficiency using questions derived from OpenAI policies in a work context.
- Prior research linked privacy perceptions to GenAI adoption and usage behavior but less often examined users’ technological competence.
4 Constructs and Research Questions
The study examines how organizational policies, integrated privacy concerns, and ChatGPT proficiency relate to work-related ChatGPT usage, including frequency and application variety.
- Definition of Constructs: The study defines organizational policies as restrictions, task-specific permissions, or awareness initiatives concerning workplace GenAI use.
- Definition of Constructs: Integrated privacy concerns consolidate perceived privacy concerns and privacy risks associated with disclosing personal information to third parties online.
- Definition of Constructs: ChatGPT proficiency is a newly established construct assessing privacy-related competence in applying ChatGPT, derived from its privacy policies and technical functionalities.
- Definition of Constructs: ChatGPT usage behavior comprises frequency of work-related use and the number of different application purposes.
- Research Questions: RQ1–RQ2 test policy effects on proficiency and how policies, privacy concerns, and proficiency relate to usage behavior.
- Research Questions: RQ3 compares these relationships between organizations with and without GenAI policies, while RQ4 contrasts usage constraints with user constraints.
5 Method
The authors conducted a validated online survey of regular workplace ChatGPT users across diverse employment sectors and analyzed relationships among privacy, proficiency, policies, and usage.
- Sample and Data Collection Procedures: The online survey sampled regular workplace ChatGPT users across a wide range of employment sectors, with IT and technology most prevalent.
- Sample and Data Collection Procedures: A pilot study with N = 11 participants checked questionnaire comprehensibility, consistency, and language before recruitment through Prolific and email outreach.
- Measures: The questionnaire measured organizational policies, integrated privacy concerns, ChatGPT proficiency, frequency of use, and use cases.
- Measures: ChatGPT proficiency used eleven true/false knowledge items based on OpenAI privacy and security policies, with “unsure” treated as incorrect.
- Analysis: The analysis combined descriptive statistics, background-variable t-tests, correlations, and path models comparing policy conditions and policy types.
- Ethics: Participants provided consent, could withdraw, and could omit sensitive or uncomfortable responses under the institution’s ethics guidelines.
6 Results
Participants reported concerned privacy attitudes but low ChatGPT proficiency. Organizational policies were associated with higher proficiency and broader use, while privacy concerns predicted less frequent and less diverse use.
- Descriptives: 54% (n = 121) reported no organizational GenAI policies or no awareness of them; among policy organizations, 46% selected input-data de-identification or anonymization.
- Descriptives: M = 3.88 (SD = 0.81) indicated relatively strict privacy attitudes, while only 36% of statements were correctly answered (SD = 18%), indicating low proficiency.
- Descriptives: 90% incorrectly believed personal information would be anonymized, and 84% incorrectly assumed OpenAI secures online communication channels.
- Descriptives: M = 3.00 (SD = 1.41) use cases showed that participants generally applied ChatGPT across multiple applications; language translation and communication assistance was most common at 49.6%.
- Correlations: Integrated privacy concerns negatively correlated with frequency of use (r = −.14, p < .05) and use cases (r = −.16, p < .05), while frequency and use cases correlated positively (r = .42, p < .01).
- Path Models: Organizational policies positively affected ChatGPT proficiency (β = .15, p < .05) and broader use cases (β = .23, p < .001).
- Group Comparisons: Without organizational policies, privacy concerns predicted lower frequency (β = −.23, p < .01) and fewer use cases (β = −.26, p < .01).
7 Discussion
The study examined how organizational policies, privacy concerns, and ChatGPT proficiency shape work-related ChatGPT use. Policies were associated with broader usage and higher proficiency, while privacy concerns constrained use, particularly without organizational guidance.
- RQ1. Organizational policies and proficiency: Organizational policies were associated with higher ChatGPT proficiency, but participants answered fewer than 40% of privacy-related statements correctly on average.The authors report frequent misconceptions about anonymization, secure communication, data flows, and access to conversations.
- RQ2. Policies, privacy concerns, and proficiency on usage behavior: Employees in organizations with policies used ChatGPT for a wider range of work-related applications, suggesting that policies can support broader adoption rather than restrict it.The discussion frames policies as a structure for safer exploration of new applications.
- RQ2. Policies, privacy concerns, and proficiency on usage behavior: Higher integrated privacy concerns were associated with lower use frequency and fewer types of ChatGPT use cases.The authors note that prior findings on privacy concerns and AI adoption are mixed across contexts and user groups.
- RQ2. Policies, privacy concerns, and proficiency on usage behavior: ChatGPT proficiency showed no significant effect on usage behavior, whereas policies were described as more decisive in shaping actual use.This contrasts with the expectation that greater knowledge would facilitate more active adoption.
- RQ3. Moderation by presence or absence of policies: Without organizational policies, privacy concerns reduced both usage frequency and application range, while proficiency facilitated adoption; these effects disappeared when policies were present.The authors interpret available policies as providing structure and guidance that reduce the influence of individual factors.
- RQ4. Types of organizational policies: Usage constraints had a marginally positive effect on the number of use cases, but there was little evidence that policy types differed strongly in their effects.The discussion concludes that policy existence may matter more than specific content and calls for further research on policy interventions.
- Overall discussion: Overall, policies were presented as helping employees navigate privacy risks while supporting more versatile ChatGPT use, despite persistent gaps in knowledge.Privacy concerns remained a source of self-restriction, especially where organizational guidance was absent.
- Practical Recommendations: The authors recommend awareness-based, practical privacy education combined with tailored usage restrictions rather than relying on bans or education alone.They caution that bans may drive employees toward less-vetted tools, local models may be infeasible for smaller organizations, and awareness alone may not prevent disclosure.
8 Limitations and Future Work
The study’s findings are constrained by its ChatGPT-only scope, European and demographically uneven sample, possible policy-awareness confounding, and design choices concerning enterprise use and questionnaire coverage.
- Study scope: The findings apply only to ChatGPT and cannot be generalized to other GenAI applications.The broader concern about insufficient awareness of data practices may still extend across commercial GenAI tools.
- Sample composition: The European-only sample, few participants aged 45 and older, and uneven industry representation limit generalizability across contexts and groups.Future research should use more geographically, demographically, and industrially diverse samples.
- Sample composition: Observed policy effects may partly reflect greater privacy-risk awareness in organizations that adopted policies, rather than policies alone.The analyses nevertheless show a clear positive impact of policies, requiring caution when interpreting causality.
- Study design: The study did not account for ChatGPT Enterprise, whose data storage and processing may differ from the free version.Future studies should consider enterprise deployment as adoption increases.
- Study design: The questionnaire lacked a comprehensive validated set of use cases, and occupation categories may have been interpreted inconsistently.These choices may limit insight into usage and the applicability of results across occupational groups.
- Future work: The positive role of both awareness programs and restrictive policies was unexpected and warrants further investigation.The study found no noteworthy differences between policy types.
9 Conclusion
The study identifies a privacy-awareness gap among ChatGPT users and examines how organizational policies, privacy concerns, and proficiency relate to workplace use. It finds that policies are associated with greater privacy knowledge and broader, more frequent use, while many organizations lack such guidance.
- Conclusion: The study finds a significant gap in users’ understanding of privacy risks associated with workplace ChatGPT use.Only half of participants reported knowing of organizational policies governing GenAI use.
- Conclusion: Organizational policies can positively affect privacy-risk knowledge and encourage more frequent ChatGPT use across varied work purposes.The authors recommend sensible policies extending beyond simple restrictions.
Disclosure of AI Usage
The authors disclose that DeepL Write, Grammarly, and ChatGPT 4o were used to enhance the paper’s language and readability, while retaining responsibility for its final content.
- Disclosure of AI Usage: DeepL Write, Grammarly, and ChatGPT 4o were used to enhance the paper’s language and readability.The authors state that they take full responsibility for the final content.
A Correlations
The appendix reports Pearson correlations for the entire cohort and for groups with and without organizational GenAI policies. The supplied passages identify the table populations but do not provide their row or column encodings.
- Entire cohort: Table 5 reports Pearson correlations for the entire cohort of 224 participants.The supplied caption identifies the population but does not state the table’s row or column layout.
- Organizations with policies: Table 6 reports Pearson correlations for the 103 participants whose organizations had GenAI usage policies.The supplied caption identifies the subgroup but does not state the table’s row or column layout.
- Organizations without policies: Table 7 reports Pearson correlations for the 121 participants whose organizations lacked GenAI usage policies.The supplied caption identifies the subgroup but does not state the table’s row or column layout.
C Questionnaire
The questionnaire examines ChatGPT use at work alongside organizational policies, privacy concerns, privacy-related proficiency, demographics, and use cases. It also compares path models for participants in organizations with and without policies.
- Questionnaire scope: The questionnaire frames ChatGPT as an illustrative GenAI technology for assessing workplace usage behavior.
- C Questionnaire: Figure 4 compares path models for organizations without policies (N = 121) and with policies (N = 103); the saturated models reproduce observed covariances exactly.
- C.1 Organizational Policies: Organizational-policy items cover access restrictions, required training, confidentiality limits, anonymization, personal-information prohibitions, sharing restrictions, and other controls.
- C.2 Integrated Privacy Concerns: Privacy concerns are measured with a five-point Likert-type scale covering information collection, unclear practices, secondary use, sharing, and possible misuse.
- C.3 ChatGPT Proficiency: Privacy-related ChatGPT proficiency is assessed through true, wrong, or unsure judgments about privacy-policy claims, data collection, tracking, sharing, storage, training, and opt-out settings.
- C.4 Frequency of Use and C.5 Use Cases: Usage measures ask how frequently participants use ChatGPT professionally and which applications they select, including coding, email, meetings, support, brainstorming, editing, marketing, analysis, decisions, and translation.
- C.5 Use Cases: The use-case list includes customer-support analysis, meeting summarization, idea generation, content polishing, marketing generation, data-analysis support, decision support, and language communication.
- C.6 Demographics: Demographic questions collect age, gender identity, education, and occupational sector, with education grouped into foundational, advanced, and academic levels.