Can You Use ChatGPT with Personal Data? A GDPR Compliance Guide For Businesses
Yes, you can use ChatGPT with personal data under GDPR. Businesses across the EU and UK do this legally every day. However, it depends on which version of ChatGPT is in use, what OpenAI’s agreement actually commits to once you read past the summary, and whether the specific piece of data involved falls into a category that stays restricted no matter how the account is set up.
This guide breaks down exactly when it’s safe to use ChatGPT with a business’s personal data, when it isn’t, and what you need to have in place so you’re not guessing every time you open a chat window.
Can You Use ChatGPT with Personal Data?
Yes — but only on a business account, and only once OpenAI has signed a Data Processing Addendum (DPA) with your organization.
Under the European Data Protection law, or GDPR, the moment you hand personal data to another company to process on your behalf, whether that’s a payroll provider, a CRM tool, or an AI system like ChatGPT, that company needs to be operating under a written contract that spells out what it can and can’t do with the data. That contract is what GDPR calls a processor agreement, and OpenAI’s version of it is the DPA.
The free version of ChatGPT and ChatGPT Plus don’t come with this. They’re consumer products, built for individuals, and OpenAI doesn’t offer a DPA for them. If your team is using either of these and pasting in personal data, there’s no contract governing that data, which means you have no legal basis for that processing under GDPR.
ChatGPT Business, ChatGPT Enterprise, and the OpenAI API are different. These are built for organizations, and OpenAI will sign a DPA with you for any of them. Once that’s in place, OpenAI is contractually bound to only use the data to deliver the service, not to train its models, unless you separately opt in to that. Also, you have the paper trail to show a regulator if you’re ever asked how that data is handled.
So, when it comes to using ChatGPT for business managers, the tool itself isn’t the risk. The account type is. Move your team to a business-tier plan, get the DPA signed, and the AI platform becomes a tool you can use lawfully. Leave them on personal accounts, and every prompt containing personal data is a compliance gap.
Why Does GDPR Apply to ChatGPT?
GDPR applies to ChatGPT for the same reason it applies to any tool you use to handle personal data: the moment personal data is typed in, collected, stored, or transmitted, that’s “processing” under GDPR — and the law governs processing, not specific tools or industries.
That’s a broader definition than most people expect. Under Article 4(2), processing isn’t just about storing data long-term or building a database. It covers collection, use, transmission, even a single act of typing something into a text box and hitting enter. So when an employee pastes a customer’s name, email, or case details into ChatGPT to get help drafting a response, that single action is processing, and GDPR’s rules kick in at that moment.
It doesn’t matter that OpenAI is a US company, and it doesn’t matter that ChatGPT isn’t a “data” product in the way a CRM is. GDPR’s territorial reach, under Article 3, extends to any organization handling the personal data of people in the EU — regardless of where that organization is based, and regardless of where the data physically ends up being processed. So if your business handles personal data belonging to EU customers, employees, or suppliers, GDPR applies to how you use ChatGPT with that data, even if your company itself isn’t based in Europe.
What Counts as Personal Data under GDPR?
Personal data is anything that points back to a specific, identifiable person — whether it names them directly or lets you figure out who they are through a combination of details.
That’s really the only test you need to run: does this information, on its own or combined with anything else you have access to, let you identify a real person? If yes, it’s personal data. If the answer is genuinely no — the information can’t be traced back to anyone, no matter how it’s combined or cross-referenced, then it falls outside GDPR entirely.
Most people picture personal data as the obvious details like names, email addresses, and phone numbers. Those absolutely count. But GDPR’s definition doesn’t stop at direct identifiers — it also covers indirect ones. A customer complaint that mentions no name but includes an order number, a delivery address, and a purchase date is still personal data, because that combination is enough to identify one specific customer. An internal note describing “the employee who raised the pay dispute last Tuesday” is personal data, even without a name attached, because anyone with access to the team roster could work out who that is.
So, before using ChatGPT, it’s important to determine whether someone could use the data, alone or combined with something else, to work out who this is about. If the honest answer is yes, treat it as personal data.
How to Use ChatGPT Lawfully Under GDPR
Compliant use of ChatGPT rests on five things being true at the same time:
- The right account,
- A signed DPA whose terms you’ve actually checked,
- A documented lawful basis,
- A DPIA where the processing is high-risk,
- And special category data is kept out of it entirely.
Miss any one of these, and the rest don’t save you.
1. Use a Business-Tier Account — Not a Personal One
As we’ve already mentioned, this is the most common failure point, and it’s rarely deliberate. In most organizations, someone signed the company up for ChatGPT Enterprise, everyone assumes that’s what staff are using — and meanwhile, half the team is still typing customer and employee data into ChatGPT Plus on personal accounts, because that’s the habit they built before the business plan existed. Personal accounts fall under OpenAI’s consumer terms, which have no DPA behind them. If your organization hasn’t actively blocked or migrated off personal accounts, assume this shadow use is happening right now, not that it might be.
You need to restrict ChatGPT Plus/free access on company devices and networks where you can, and make ChatGPT Business, Enterprise, or the API the only sanctioned option — with an actual announcement to staff explaining why, not just a policy buried in a handbook nobody reads.
2. Get the DPA Signed — Then Check What It Actually Covers
Signing the DPA is step one, not the finish line. OpenAI’s current DPA (updated in 2026) doesn’t mean your data disappears the moment you’re done with it. By default, API and business-tier content is still held for 30 days for abuse-monitoring purposes, even though it isn’t used for training. True zero data retention exists, but it isn’t automatic — it’s opt-in and requires approval through OpenAI’s sales team, and it can take time to get approved. If your compliance documentation assumes zero retention by default, that assumption is wrong until you’ve actually applied for and received it.
The same applies to data residency: it’s available for Enterprise and Edu workspaces, but not for the standard Business plan. If keeping data in the EU or UK specifically matters for your processing, that’s a plan-level decision you need to make beforehand.
3. Establish a Lawful Basis Before Anyone Starts Typing
A signed DPA governs OpenAI’s obligations to you, but it says nothing about whether you’re allowed to process the data in the first place. That’s a separate question under Article 6, and most organizations that rely on ChatGPT for this use “legitimate interest” as their basis. If that’s your route, you need a documented Legitimate Interest Assessment, done before you rely on it, weighing your business purpose against the impact on the data subjects. If a customer or employee would reasonably be surprised or uncomfortable to learn their data was pasted into ChatGPT, that’s a sign the legitimate interest test may not hold up, and consent or another basis may be needed instead.
4. Run a DPIA if the Processing Is High-Risk
If your use of ChatGPT involves large-scale personal data, systematic processing of customer or employee records, or anything resembling profiling or automated decisions with real consequences for people, GDPR requires a Data Protection Impact Assessment before that processing starts — not after. Most regular business use of ChatGPT with customer or HR data will trip at least two of the criteria that make a DPIA mandatory, so it’s safer to assume you need one than to argue you don’t. A DPIA doesn’t need to be elaborate: it needs to describe what you’re processing and why, assess whether it’s actually necessary, weigh the risk to the people involved, and document the safeguards you’ve put in place.
5. Keep Special Category Data Out of It
Health information, biometric data, information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, or sexual orientation are all subject to a separate, stricter prohibition under Article 9 — on top of, not instead of, the Article 6 basis above. Processing this kind of data through ChatGPT is not simply higher-risk; it’s flatly prohibited unless you meet one of a narrow list of exceptions, most commonly explicit consent or a specific employment-law obligation. The safest operational rule is the simplest one: treat special category data as off-limits for ChatGPT entirely, rather than trying to build a case for an exception every time it comes up. A sick note, a DEI survey response, or a note referencing someone’s religion should never make it into a prompt, however incidental it seems.
Is ChatGPT Enterprise Better for GDPR Compliance?
No — Enterprise isn’t required for GDPR compliance. ChatGPT Business, Enterprise, and the API can all be used compliantly, because all three come with a Data Processing Addendum and none of them trains on your data by default. What Enterprise buys you isn’t legality — it’s control, and the ability to prove that control if a regulator or a customer ever asks.
Here’s where the three actually differ.
ChatGPT Business is the entry point for organizations, and it’s enough for most small and mid-sized teams. You get the DPA, no training on your data, and the same 30-day default retention window as the other tiers. What it doesn’t include is data residency — there’s no option to keep data stored specifically in the EU or UK. If your organization has no particular requirement about where data physically sits, Business alone can be fully compliant.
ChatGPT Enterprise adds two things that matter specifically for larger or more exposed organizations: data residency, so you can commit to keeping data at rest in the EU, UK, or other specific regions, and centralized admin controls — audit logs, usage visibility, domain-level management. Neither of these is a legal requirement under GDPR itself. But if you’re handling personal data at real scale, or you need to demonstrate to a regulator, auditor, or enterprise customer exactly who accessed what and when, that visibility is the difference between claiming compliance and being able to show it.
The API sits apart from both — it’s not a chat interface at all, but the infrastructure you’d use to build ChatGPT into your own product or internal tool. The DPA and no-training default still apply, and zero data retention has historically been more readily available here than through the standard business plans, though it’s still opt-in and requires approval through OpenAI, not something you get by default. The API makes sense when you’re building something, not when your team just needs a place to chat.
So, if you don’t have a specific data residency requirement and don’t need audit-level visibility, Business with a signed DPA is a legitimate, fully compliant choice — you’re not cutting corners by not paying for Enterprise. Enterprise earns its cost when residency, scale, or provability actually matter to your organization.
Best Practices for Organizations When Using ChatGPT
1. Write an AI Acceptable Use Policy — and Make It Specific
A generic warning, like a “be careful with AI” memo, doesn’t hold up, and it doesn’t protect you either. Your policy needs to name the approved tools by name (which ChatGPT plan, specifically), state plainly what categories of data can and can’t be entered, and set out what happens when someone breaks it. Without a documented policy, you have no basis to act when it happens — and when a data protection authority asks how you’re managing this risk, you will have no justifiable answer that holds up.
2. Assume Shadow AI Is Already Happening
Don’t treat this as a hypothetical risk to plan for; treat it as something already underway. Employees paste company and customer data into consumer AI tools regularly, often without realizing there’s a difference between the version they use at home and the version their employer is meant to sanction. So, just make sure the approved tool is as easy to reach as the unapproved one. If ChatGPT Business requires three approval emails and the free version is one click away, people will take the click.
3. Put Technical Controls Behind the Policy
A policy that relies purely on people remembering it will fail. Where you can, block or restrict access to consumer ChatGPT on company networks and managed devices, and route staff toward the sanctioned business account instead. Larger organizations are increasingly layering AI-aware monitoring on top of this — tools that can flag when something resembling personal data is about to leave the organization through a prompt, not just when a file is emailed out. You don’t need enterprise-grade tooling on day one, but the policy and the technical enforcement need to be pointed in the same direction.
4. Train People on What Personal Data Actually Looks Like
Most accidental exposure doesn’t come from someone ignoring the rules — it comes from someone not recognizing that what they just pasted counted as personal data in the first place. Training that actually changes behavior is specific: real examples of what’s fine to paste into ChatGPT and what isn’t, not an abstract lecture on GDPR principles. This should happen before anyone gets access to the approved tool, not as an afterthought once it’s already in use.
5. Name an Owner
Someone in your organization needs to own this — not “IT” in the abstract, but a specific person or role responsible for keeping the AI usage policy current, reviewing new tools before they’re approved, and being the person staff actually ask when they’re unsure. Without a named owner, questions don’t get asked, and the DPA, the DPIA, and the policy all quietly go stale.
6. Revisit This Regularly — Not Once
OpenAI’s terms have changed more than once recently, and they’ll change again — retention defaults, DPA language, what’s included at each plan tier all shift. A compliance setup that was accurate six months ago may not be accurate now. Put a recurring review on the calendar — every six months is reasonable — to re-check the DPA terms, the retention settings, and whether your policy still reflects how the tool actually works today.
Frequently Asked Questions
Does ChatGPT store or save the data I type into it?
Yes, on every plan — the question is for how long, and for what purpose. On the free and Plus versions, your prompts may be stored and used to improve OpenAI’s models unless you turn that off. On business-tier plans, OpenAI doesn’t train on your data by default, but it still retains it for 30 days for abuse and safety monitoring, even with training off. True zero data retention exists, but it’s a separate, approval-gated request — not a setting that’s on by default.
Can I turn off ChatGPT from training on my data?
Yes, but it doesn’t solve everything. On a personal account, you can disable “Improve the model for everyone” in settings, or use temporary chat. Both stop your conversations from being used for training. Neither one removes the 30-day retention OpenAI keeps for safety purposes, and neither one gives you a DPA — so turning off training makes your account more private, not GDPR compliant.
Is it illegal to put customer information into ChatGPT?
It depends entirely on which version and how. Pasting customer data into the free or Plus version, without a lawful basis and without a DPA in place, is very likely a GDPR violation. The same data, entered through a business-tier account with a signed DPA and a documented lawful basis, isn’t illegal at all. The tool isn’t the problem — the setup around it is.
Has OpenAI been fined for GDPR violations?
It has, but the outcome has changed. Italy’s data protection authority fined OpenAI €15 million in December 2024 over how ChatGPT was trained, citing a lack of legal basis and inadequate transparency. OpenAI appealed, and in March 2026 the Court of Rome annulled the fine entirely. It’s a useful case to know about, but not one to cite as a standing penalty — the legal outcome ultimately went the other way.
Can ChatGPT get someone’s personal information wrong, and is that a GDPR problem?
Yes, and this is an active, unresolved issue. GDPR’s accuracy principle requires that personal data be correct, and ChatGPT can fabricate false claims about real, identifiable people — a well-documented case involves a Norwegian man whom ChatGPT falsely described as having been convicted of a serious crime. The privacy group noyb filed a formal complaint over it, arguing it breached GDPR’s accuracy requirement. The complaint is still pending, not yet decided, but it points to a real limitation: ChatGPT currently has no reliable way to correct false things it’s generated about a specific person, only to block them from being shown again.
Do I need to tell customers or employees if I use ChatGPT with their data?
Yes. Having a lawful basis to process someone’s data isn’t the same as being transparent about it, and GDPR requires both. Articles 13 and 14 require that people be told who’s processing their data and why — so if you’re feeding a customer’s details into ChatGPT to help draft a response or summarize a case, that use should be reflected in your privacy notice, not left unmentioned.
Can HR use ChatGPT for employee data?
Yes, under the same conditions as any other personal data — business account, DPA signed, lawful basis documented — with one added layer of caution. Employee data often sits closer to sensitive territory than customer data (performance issues, medical notes, disciplinary matters), so it’s worth being stricter here than the minimum: keep anything touching health, disciplinary detail, or protected characteristics out of ChatGPT entirely, even on a compliant setup.
Is ChatGPT safe to use for legal or medical work?
Only with extra caution beyond standard GDPR compliance. For legal work, client confidentiality and privilege obligations sit on top of GDPR and aren’t satisfied just by having a DPA — many firms restrict what case details can go in at all. For medical or health-adjacent work, you’re almost certainly dealing with special category data, which is restricted by default under Article 9, not just Article 6. In both fields, the safer default is treating ChatGPT as unsuitable for anything containing real client or patient specifics.
Does using the paid ChatGPT Plus plan make it GDPR compliant?
No — this is one of the most common misunderstandings. Plus is still a consumer product. Paying for it doesn’t come with a DPA, doesn’t change OpenAI’s role from “no contract in place” to “processor under Article 28,” and doesn’t alter the default training and retention behavior in any way that matters for compliance. Compliance comes from the business-tier plans (Business, Enterprise, API), not from the price of the subscription.
Can I delete data I already sent to ChatGPT?
Yes. You can request deletion through OpenAI’s privacy portal, and EU users specifically have the right to request that their data not be used for training and to have personal data deleted under GDPR’s erasure right. It’s worth knowing this doesn’t undo anything that may have already influenced a model that’s already been trained — deletion going forward is reliable; retroactively removing influence from a model already trained on that data is a much harder technical problem, and not one OpenAI can fully guarantee.
Conclusion
At the end of the day, the setup you build matters more than the tool itself. A signed DPA, a clear lawful basis, and staff who know what personal data actually looks like will do more for your compliance than any plan you choose. What’s worth carrying forward is the habit behind any checklist that you might have, which is to treat this as something you check on regularly, not something you solve once and forget. OpenAI’s terms have already shifted more than once this year, and they’ll shift again — so the organizations that stay compliant won’t be the ones who got it right on day one, but the ones who kept checking.