How to Protect Client Data When Using AI as a Filipino VA (2026)

Filipino virtual assistant guide on how to protect client data when using AI tools

You can protect client data when using AI as a virtual assistant by doing three things, in this order: turn off model training in every AI account you use for work, strip out anything that identifies a real person before you paste, and get your client’s AI rules in writing. Do those three and most of the risk is gone. The rest of this post is detail.

I started as a VA in 2020, before ChatGPT existed. Back then the worry was whether a client would trust you with their inbox at all. Now the worry is sharper: you have a tool that makes you three times faster, and the quickest way to use it is also the quickest way to hand a stranger’s company your client’s customer list. These days I build AI automations on the side while working full-time as a VA, so I look at this from both ends.

Below: what Philippine law actually says (and what it does not say about you personally), which mainstream AI tools train on your chats by default and where the off switch sits, how to strip client data in under a minute, whether AI note-takers are safe for client calls, and what to say when a client asks if you use AI. One thing first, I am not a lawyer and this is not legal advice.

Key takeaways

  • Personal AI accounts are where the risk lives. OpenAI says content from its services for individuals may be used to train its models unless you opt out. On ChatGPT Business, Enterprise, and the API, it does not train on your data by default.
  • Google says it plainly in the Gemini Apps Privacy Hub: do not enter confidential information you would not want a human reviewer to see. Human-reviewed chats are kept up to three years and survive deleting your activity.
  • Under the Data Privacy Act, your client is usually the personal information controller, not you. But the NPC’s December 2024 AI advisory keeps the controller accountable for who it outsources to, which is why clients get nervous.
  • Strip before you paste: names, emails, phone numbers, addresses, card and account numbers, anything health related. The AI almost never needs them to do the task.
  • Put it in writing. One paragraph in your contract naming which AI tools you use, for what, and with what data turns a scary question into a reason to hire you.

How do you protect client data when using AI as a virtual assistant?

Five habits, and you can set up four of them tonight. Turn off model training in every AI account you use for client work. Strip identifiers before you paste anything. Keep client work in a separate account from your personal chats, so that if a client ever asks what you have been doing in there, you have a clean and boring history to show. Ask which tools are approved and get the answer in writing. And upload a summary instead of the raw file whenever a summary will do the job, because a spreadsheet of 4,000 customers does not need to enter a chat window so you can get help writing one email.

The order matters more than it looks. Turning training off protects you from the tool vendor keeping your content. Stripping identifiers protects you from everything else: a bad prompt, a shared chat link, a screenshot in a Loom video, a teammate opening your account. Settings are one layer. Habits are the layer that still holds at 2am when you are tired and just want the task finished.

Here is the part that is not really about tools. The reason my longest client relationship lasted about five years is that I treated the business like it mattered to me, not like a task list, and this is the same instinct. A client’s customer list or supplier pricing is not just data to them, it is the thing that would end their business if it went public. Handling it carefully without being asked is not paranoia, it is what makes you the one they keep. If you are building toward that kind of work, my guide on executive VA roles in the Philippines covers why high-trust roles pay more in the first place.

What does Philippine law actually say about AI and client data?

The short version: the Data Privacy Act of 2012 (Republic Act No. 10173) already covers AI. The National Privacy Commission made that explicit in NPC Advisory No. 2024-04, dated 19 December 2024, which states that the DPA, its implementing rules, and NPC issuances apply whenever personal data is processed in the development or deployment of AI systems, including training and testing. There is no separate “AI law” to memorize. The existing rules simply follow the data into the chat window.

Now the part most VAs get wrong. Under Section 3 of the DPA, a personal information controller is the one who decides what data is collected and why, and the definition explicitly excludes “a person or organization who performs such functions as instructed by another person or organization.” If you are doing tasks the way your client told you to, you are usually not the controller. Your client is. That is genuinely good news, but do not read it as “so it is not my problem,” because Advisory 2024-04 says controllers stay accountable for the actions of the processors they outsource to. Your mistake lands on your client’s compliance record first, and on your contract right after.

Three ideas from that advisory touch your daily work. Data minimization: controllers shall exclude, by default, any personal data unlikely to improve the AI output, which is “strip before you paste” written in legal language. Transparency: people whose data is processed should know it is happening, so quietly running client records through a tool nobody agreed to is the risky move, not the AI itself. Human intervention: the advisory asks for meaningful human review where decisions carry real risk, which for you means never sending an AI answer to a customer without reading it.

One more rule decides what you do on your worst day. NPC Circular 16-03 requires the Commission and affected individuals to be notified within seventy-two (72) hours of knowledge or reasonable belief that a notifiable breach has occurred, and it keeps that obligation on the controller even when processing is outsourced, with the controller expected to use contractual means so its processor reports breaches to it. In your job that means: if you think you leaked something, your clock is short and your only correct move is to tell your client immediately, in writing, with what happened and when. Hiding it for a day to “check muna” is what turns a mistake into a violation.

Which AI tools train on your chats, and where is the off switch?

It depends on whether you are on a personal plan or a business plan, and the gap between the two is wider than most VAs realize. Business and API tiers are generally not trained on by default. Free and personal tiers are where you have to go change something yourself. Here is where each mainstream tool stood in its own documentation when I checked in early August 2026.

ToolTrained on by default?Where the control isWorth knowing
ChatGPT Free, Plus, ProYes, unless you opt outSettings, then Data Controls, then turn off “Improve the model for everyone”Temporary Chat is not saved to history and is not used for training
ChatGPT Business, Enterprise, APINo, off by defaultNothing to changeBusiness is $25 per user per month billed monthly, or $20 billed annually, minimum 2 seats
Claude Free, Pro, MaxNo, only if you switch it onPrivacy Settings, the Model Improvement controlIncognito chats are never used to improve Claude, even with the setting on
Claude for Work, Anthropic APINo, off by defaultNothing to changeThumbs up or down feedback you submit can still be stored for up to 5 years
Google Gemini, personal accountYes, while Keep Activity is onGemini Apps Activity, turn Keep Activity off, or use a Temporary ChatHuman-reviewed chats are kept up to 3 years and survive deleting your activity
Otter.aiYes, on de-identified dataAccount settings, plus your own choice not to recordOtter requires users to get consent and indicate that they are recording

Fix ChatGPT first, since it is the one most of us use. OpenAI’s help documentation says that for its services for individuals it may use your content to train its models, and that you can opt out through Data Controls or the privacy portal, after which new conversations are not used for training. Two details are easy to miss: opting out does not delete what you already sent, and even after opting out, submitting thumbs up or thumbs down feedback can put that entire conversation back into training. So do not click the little thumbs on a chat full of client information. Claude runs the other way for consumer accounts. Anthropic’s privacy article, updated March 16, 2026, says it uses your chats to improve its models only if you allow it, if a conversation is flagged for safety review, or if you explicitly opt in, and Incognito chats are excluded either way.

Gemini deserves the bluntest reading, because Google itself is blunt. Its Gemini Apps Privacy Hub tells users not to enter confidential information they would not want a reviewer to see or Google to use to improve its services. Human reviewers, including trained service providers, read a subset of chats, and those reviewed conversations are retained for up to three years and are not deleted when you delete your Gemini activity. Turning Keep Activity off means future chats are stored for only 72 hours and are not used to train Google’s models unless you send feedback. If client data has to touch Gemini at all, Keep Activity goes off before you type the first word.

And if a client has real compliance worries, stop paying for the fix yourself. A ChatGPT Business workspace costs $25 per user per month billed monthly, or $20 billed annually, with a two-seat minimum, and OpenAI states it does not train on that workspace’s data. At roughly ₱1,200 to ₱1,500 a month per seat, that is a rounding error in most client budgets and an easy ask: “if you want AI-assisted work with no training on your data, put me on a Business seat.” You look like a professional for asking. For the free-tier stack I still lean on for everything else, see my roundup of free tools every Filipino VA needs.

One honest note

Every setting and price above is what each company’s own documentation said in early August 2026, and these policies change often, so verify in the app before you trust a table on the internet, including mine. One specific hedge: Otter’s public privacy page confirms it uses a proprietary method to de-identify user data before training its models, but I could not confirm a documented, user-facing training toggle on Otter’s own pages, so treat the decision to record at all as your real control there.

How to strip client data before you paste it into AI

Replace the identifiers with placeholders and leave the structure alone. The AI needs the shape of the problem, not the identity of the people in it. “Write a follow-up to [CLIENT_A] about invoice [INV_1] that is [N] days overdue” produces the same email as the version with a real name, a real invoice number, and a real amount, and you paste the real details back in yourself in thirty seconds.

What to strip, every time: full names, email addresses, phone numbers, home and business addresses, birthdays, card and bank account numbers, government IDs (TIN, SSS, PhilHealth), login credentials, order numbers that map to one person, pricing that is not public, and anything about a person’s health, finances, or legal situation. That last group matters most, because the DPA treats health, financial, and similar categories as sensitive personal information with stricter handling. If you work in medical VA support or bookkeeping, assume almost everything you touch sits in that stricter bucket.

A worked example, because this is easier to see than to describe. Raw version you were about to paste: “Maria Santos, maria.santos@gmail.com, 0917 555 1234, ordered August 2, package is 11 days late, order PH-88213, she paid ₱4,800.” The version you should paste: “A customer ordered on [DATE], the package is 11 days late, order [ORDER_ID], amount [AMOUNT]. Write a warm apology with a delivery update and a goodwill offer.” Same email comes back, and nothing about Maria left your laptop. One trap while you are at it: screenshots. Pasting an image of an inbox feels different from pasting text, pero it is the same disclosure, and the image usually carries more than you meant, like other names in the sidebar or a phone number in a notification. Crop hard, or better, retype the two lines you actually need.

Are AI note-takers safe for client calls?

They are safe when everyone on the call knows they are being recorded and has agreed, and they are a problem the moment they are not. This is less about the software than about consent. Otter’s own privacy page states that users are required to comply with local laws and regulations and must always ask for consent and indicate when they are recording and transcribing conversations with others. That is the vendor telling you the obligation is yours, not theirs.

I use an AI note-taker on my own client calls, and I will not pretend it is optional for me. I am an introvert, I still get nervous before clicking Join in Google Meet even after five years of this, and my whole approach to calls is preparation: a physical notebook, an iPad mini with an Apple Pencil as backup, and a note-taker to summarize afterwards so I am listening instead of frantically typing. What makes that safe is not the app, it is that the recording is expected. Nobody is surprised by it.

So the rule is simple. Announce it in the invite or in the first thirty seconds, and give people a way to say no. Do not send a bot into a call you were not invited to record, especially one with your client’s customers, patients, or job candidates on it. Delete transcripts on a schedule instead of letting years of client conversations pile up in a third-party account. And if a client’s rules say no recording, take the loss and go back to manual notes. If a client gets weirdly evasive when you ask whether recording is okay, read that alongside my post on red flags in a client.

What about AI for lead lists and scraping?

This is the fastest-growing gray area in VA work, and the NPC addressed it recently. NPC Advisory No. 2026-01, dated 13 April 2026, covers data scraping of publicly available personal data, and its core message is one line long: public availability of personal data does not amount to consent to use it for whatever you like, and it does not remove anyone’s obligations under the DPA.

The advisory also defines when scraping becomes unauthorized, and that definition is broader than most of us assume. Scraping is unauthorized when it violates applicable laws, the DPA, NPC issuances, or the terms of service of the site you are pulling from, and it specifically includes circumventing or bypassing technical measures a site put in place to stop scraping. So a tool that gets around a rate limit or a CAPTCHA is not a clever tool, it is the exact behavior named in the advisory, which says unauthorized scraping may give rise to criminal, civil, and administrative liability. Scraping sensitive personal information is prohibited outright unless the controller can show a lawful basis, strict necessity, and enhanced safeguards.

What that means on a Tuesday afternoon when a client says “just scrape 5,000 leads from LinkedIn”: you are allowed to ask what the purpose is and what lawful basis they are relying on, and you should, because that answer is supposed to exist before the work starts. Get the instruction in writing, avoid tools that advertise bypassing site protections, and do not touch health, financial, or similar sensitive categories on a scraping task at all. If the client cannot or will not tell you why they need it, that is the whole answer. Turning down one uncomfortable task is cheaper than being the name attached to a data problem you did not understand.

What do you tell a client who asks if you use AI?

Say yes in one sentence, then say what you do to keep their data out of it. The VA who says “no, everything is manual” in 2026 either sounds slow or sounds like she is hiding something, and clients can tell. The VA who says yes with specifics sounds like someone who thought about this before today, which is the actual thing being tested.

“Yes, I use AI for drafting and research to work faster. Model training is turned off on my accounts, I remove names, contact details, and account numbers before anything goes into a tool, and I review every output before it reaches you or your customers. If you have tools you prefer or data you never want touched, tell me and I will follow that.”

Then put a version of it in your contract or onboarding document, because a verbal answer disappears the moment the person who heard it leaves the company. Three lines is enough: which AI tools you use, what you use them for, and what data never goes in. Add one line saying you will tell them within 24 hours if you ever suspect a data problem. That last line looks like extra exposure but does the opposite, it tells a client you already know what a breach response looks like.

I occasionally handle hiring and interview candidates myself, so here is what this reads like from the other side of the table. Almost nobody volunteers their AI practices. When someone does, unprompted and in plain language, they stop being one of the many and start being the person you want on the sensitive account. That is an edge you can build in one afternoon, and it costs nothing. If you have not built your AI stack yet, start with my guide to the AI tools every Filipino VA should learn in 2026, then come back and lock down the settings.

Frequently asked questions

Is it illegal for a Filipino VA to use ChatGPT for client work?

No. There is no Philippine law banning AI tools for VA work. The Data Privacy Act of 2012 governs how personal data is handled, and NPC Advisory No. 2024-04 (19 December 2024) confirms those rules apply when AI systems process personal data. The problem is feeding someone’s personal data into a tool without a lawful basis, without your client’s agreement, or without basic safeguards. The tool is not the issue, the data you feed it is. General information, not legal advice.

Does turning off training make ChatGPT safe for client data?

It removes one risk, not all of them. Opting out means new conversations are not used to train OpenAI’s models, but your content is still sent to and stored by a third party, and submitting thumbs up or thumbs down feedback can put that whole conversation back into training. Treat the training setting as your floor, then still strip names, contact details, and account numbers before you paste.

Do I have to tell my client I use AI?

Legally it depends on your contract, so read it. Practically, yes. Many client agreements now carry confidentiality or third-party tool clauses that cover AI whether or not the letters “AI” appear. Disclosing it in one sentence and explaining your controls is a much better position than being asked about it later, and it reads as competence rather than a confession.

Can I use an AI note-taker on client calls without asking?

No, ask first. Otter.ai’s own privacy page states that users must comply with local laws and must always ask for consent and indicate when they are recording and transcribing conversations with others. Announce it in the invite or at the start of the call, give people a way to decline, and never send a bot into a call involving your client’s customers, patients, or candidates without clearance.

What client data should never go into an AI tool?

Health records, financial account and card numbers, government IDs such as TIN, SSS, or PhilHealth numbers, login credentials, contracts under NDA, and anything about a person’s legal situation. The DPA treats health, financial, and similar categories as sensitive personal information with stricter handling. If you cannot strip it out and still finish the task, that task needs a business-tier tool your client provides, not your personal account.

The VA who does not leak is the VA who gets kept

None of this is complicated. Turn training off in every AI account you use for work. Strip the identifiers before you paste. Ask your client what is allowed and save the answer. Announce your note-taker. Do not scrape what you cannot explain. If something goes wrong, say so the same day.

The bigger point is that data care has quietly become a skill clients pay for. Everyone can prompt now. Fewer people can be trusted with the account that would hurt if it leaked, and that is where the better-paying work sits. Protecting a client’s data when nobody is checking is not a rule I follow, it is part of why I still have the same client after five years.

So do the boring version tonight: open your AI settings, flip the training switches off, and send your client one message asking which tools are approved. Kaya mo ‘yan, fifteen minutes lang. Then start telling clients what you do, because right now almost nobody is saying it out loud, and that silence is your opening.

Sources

Jean Aguilar

Jean Aguilar

I’m a Filipina VA based in Cavite. I started in 2020 as a data-entry VA and worked my way up to Shopify manager and operations roles. I started PinoyRemote to share what actually worked, so you can skip the guesswork na pinagdaanan ko the hard way. Connect on LinkedIn →

Keep reading