Using ChatGPT in your company, GDPR-compliant

ChatGPT is already in use in most companies, except that nobody decided it. Staff open it in the browser, sign in with a private address and paste in whatever they are working on: a customer email, a quote, a draft contract. Shadow IT is the name for that, and the data protection officer hears about it last. What follows sets out where the legal problem sits, what a commercial tier changes, which alternatives exist, and what you have to settle inside your own company.

Why private use is a GDPR problem

Five things are left open the moment somebody uses a private account for company data. They hang together, and none of them closes with an announcement at a team meeting.

  • No data processing agreement

    Article 28(3) GDPR requires processing by a processor to be governed by a contract that binds the processor to the controller. Someone signing up privately enters a contract on their own behalf. Your company is not in it, and your customer data is.

  • Inputs can go into training

    For the consumer version OpenAI states itself that ChatGPT improves by further training on the conversations people have with it, unless the user opts out. That switch sits inside the individual account. It is therefore out of your reach, and whether anyone has flipped it is something you cannot check.

  • No documented transfer route

    Where the data goes and on what basis is set out in a contract you do not have. The business data processing addendum names OpenAI Ireland Ltd as the contracting party for customers in the EEA and Switzerland, and names standard contractual clauses or an adequacy decision as the basis for transfers out of the EEA. Through a private account none of that applies to you.

  • No deletion concept

    What an employee types sits in their account, not in yours. You cannot export it, block it or delete it. If a data subject asks what you hold, you have no access to the place where their data lives. And when the employee leaves, the account leaves with them.

  • None of it appears in your record of processing

    Article 30(1) GDPR requires each controller to maintain a record of processing activities. Processing that management knows nothing about is not in it. Day to day this never shows. It shows at the first audit, or after the first incident.

What a business tier changes, and what it does not

A commercial tier clears away the points that hang on the contract. Whatever hangs on your own organisation stays where it is. Between those two groups runs the line that matters here.

What the tier provides

  • No training on your data

    For its business products, meaning ChatGPT Business, ChatGPT Enterprise and the API, OpenAI states that by default it trains on neither inputs nor outputs. Anyone who wants to release data for model improvement has to opt in explicitly. Without that opt-in the answer stays no.

  • A data processing agreement

    OpenAI provides a Data Processing Addendum that supplements the services agreement. It states that OpenAI processes customer data as a processor on your behalf, and that for customers in the EEA and Switzerland the contracting party is OpenAI Ireland Ltd. That gives you the paper Article 28 asks for.

  • Administration and retention

    ChatGPT Business comes with four built-in roles: Owners, Admins, Analytics Viewers and Members. SAML SSO comes with it too. Multi-factor sign-in does not belong on that list, because each person switches it on in their own OpenAI account, and it then applies across every OpenAI service. Automated provisioning and deprovisioning of accounts through SCIM, and custom roles you define yourself, start at Enterprise and Edu. Retention periods for business data can be configured, though only for qualifying organisations. OpenAI writes that limitation down explicitly, and it belongs in your review before anybody signs a contract.

  • Storage in Europe, but not everywhere

    For ChatGPT, storage at rest in Europe is aimed at new Enterprise and Edu workspaces. In-region processing needs data residency switched on for that same region as well. OpenAI does not list ChatGPT Business here. Through the API, Europe can be selected as a region. Two things are needed for that: approval for the abuse-monitoring controls, and a signed Modified Retention amendment to the contract.

What no tier takes away

  • You remain the controller

    Under Article 4(7) GDPR the controller is whoever determines the purposes and means of the processing. That is you, the moment you decide what an assistant is used for and which data it sees. The provider processes on your behalf and does not take that role over with the subscription.

  • Technical and organisational measures

    Article 32(1) GDPR requires appropriate technical and organisational measures, matched to the risk. Who gets which access, how they sign in, who takes accounts away again: those are your measures, not the provider’s.

  • The entry in the record of processing

    Processing does not walk into your record by itself just because a contract exists. Purpose, data categories, recipients and retention periods get written down by somebody at your end. Changing tier changes none of that work. It only changes what goes in the recipients column.

  • Training your staff

    Article 4 of the AI Act has applied since 2 February 2025 and was rewritten on 27 July 2026. Providers and deployers now take measures that support the development of AI literacy among their staff, and nobody has to guarantee any particular level for any individual. So the rule will not carry a training programme on its own. Someone who does not know that a model can be convincingly wrong will not check the output, and that reason has not moved.

  • Retention periods

    How long a chat history stays and when it disappears is a question about your retention periods. The provider supplies the setting, you set the period. A default is not a decision, and defaults tend to run longer than your deletion policy allows.

The alternatives compared

Three routes turn up in practice. None of them is right for every company, and the difference rarely sits in the quality of the answers.

ChatGPT Business

The fastest way out of shadow IT. You get company accounts, the four roles Owners, Admins, Analytics Viewers and Members, the processing agreement and the commitment that your data is not trained on. What you do not get is storage in Europe. For ChatGPT that is aimed at Enterprise and Edu workspaces. If your data protection function insists on a European storage location, that single point decides against this tier.

Azure OpenAI in an EU region

The same models, run by Microsoft inside your own Azure tenant. Microsoft states that prompts, outputs, embeddings and training data are not available to the model providers and are not used to improve their models. Processing happens in the geography you choose, except for the Global and DataZone deployment types, and a DataZone deployment in an EU member state stays within the EU. For deployments in the EEA, the people who review content in an abuse case are located in the EEA too. You pay for this in effort: you need Azure, somebody to run it, and an interface in front of it, because this is not a finished chat window for your staff.

Open models on your own hardware

The questions about processors, third countries and training stop arising, because the data never leaves the server room. You pay in two places instead. Open models are generally weaker than the large commercial ones; on narrowly scoped tasks the gap barely shows, on open-ended reasoning across long documents it clearly does. Then there is the hardware, which is a capital expense, not a monthly invoice. With few users asking few questions, your cost per answer is higher than any subscription.

See the local AI suite

What you need organisationally

The contract is the smaller part of the work. Five things get made at your end, and they get made whichever of the three routes you pick.

  • A usage policy

    Two pages is enough: which tools are approved, which data may go in, which may not, and that only company accounts are used. A ban with no approved alternative gets worked around, which is why most of these policies achieve nothing. Where a works council exists, this is the point at which it belongs.

  • Training

    An hour per team, on real examples from their own work. What goes into a prompt and what does not, how to spot an invented answer, when an output has to be checked before it leaves the building. Article 4 of the AI Act wants the development of that kind of literacy supported. As evidence that the rule is satisfied, an attendance list still will not do.

  • An entry in the record of processing

    Purpose, categories of data subjects, data categories, recipients, retention periods. If the assistant is connected to your CRM, that connection belongs in the same entry, because it is where the data categories originate that never become visible in the chat window.

  • A check on whether a DPIA is required

    Article 35(1) GDPR requires a data protection impact assessment where processing is likely to result in a high risk to the rights and freedoms of natural persons. Drafts for marketing copy are a different case from pre-sorting job applications. The second case can also fall into the high-risk category under the AI Act, and after the omnibus package that entered into force on 27 July 2026, those obligations apply from 2 December 2027.

  • An approval path for new use cases

    Who decides that a new use is allowed, and within what deadline. Without a named person and a deadline, everyone answers the question for themselves again, and you are back where this page started.

In practice

We are building the local AI suite at a customer for the first time. Name, industry and size stay out of this while the project runs and the clearance for a reference is still pending. The decisions are worth describing anyway, because they carry over.

First came the list of data sources, ahead of any question about models. The CRM holds contact history, quotes and notes going back years, plus the files attached to each case. As soon as an assistant reaches into that, it processes personal data about customers and about staff. That is the core of what it does, not a side effect you configure away.

So the decision went to own hardware. The models run on GPUs in the building, the search index sits in a Qdrant instance on the company network, and no record leaves the premises to produce an answer. Processors, third countries and training are off the table before anyone raises them. A different question takes their place: who is allowed to see what.

Where it got uncomfortable is the email module. Draft replies come out of it, and the writing style behind them is learned from the sent mail of the same person, which means it processes staff data that has nothing to do with customer communication. In the plan the module sits behind the base and the chatbot, so that employee representatives can form a view against a running system and not against a slide.

What stays open is everything technology does not decide: access rights per role, retention periods for drafts and logs, and the list of cases an assistant should never see at all. Those points live in the design document, not in the code.

In six steps

The order matters more than the pace. Start at step three and you buy a tier for use cases nobody has written down yet.

  1. Take stock

    Ask who uses which tool today, and for what. Anonymously and without consequences, otherwise you get a survey full of zeroes and end up looking for the truth in server logs later.

  2. Sort use cases by data type

    Public text, internal text with no personal data, personal data, specially protected information such as health data. The last group decides the architecture. All the others decide the benefit.

  3. Choose a tier or an architecture

    Business tier, Azure in an EU region, or your own hardware, picked against the list from step two. A company can reasonably run two routes in parallel. Three is an administrative job nobody wants.

  4. Contracts and the record

    Sign the processing agreement, create the entry in the record of processing, run the DPIA check and write down its result. Document that check even when it ends in no.

  5. Policy, training, approval path

    Only now does the policy go out, together with the company accounts. You switch off private use on the day the company access works, and not a day earlier.

  6. Look again after three months

    Which use cases are actually running, which have quietly died, and which appeared without anyone asking. A record of processing that nobody touches after the rollout is wrong within a year.

Last updated: August 2026. The statements about tiers, contract terms and data residency come from each provider’s own documentation and were checked on 9 August 2026. Terms like these change, so check them again before you decide.

You remain the controller under the GDPR. We provide the technical implementation and the documentation for it, and this does not replace legal advice.

Common questions about ChatGPT and the GDPR

Is ChatGPT GDPR-compliant?

The question cannot be answered about a tool, only about a specific processing operation. With private accounts holding customer data the answer is no, because the contract, the deletion concept and the entry in the record of processing are all missing. With a business tier, a processing agreement, defined retention periods and a policy your staff actually follow, the same use can be lawful. That assessment, and the responsibility for it, stay with you.

May we enter customer data into ChatGPT?

If the processing has a legal basis, a data processing agreement is in place and the operation appears in your record of processing, then yes. Through private accounts none of those three apply. In practice the shortest route runs through two rules: company accounts for everyone, and a short list of data types that stay out even there. Health data and other specially protected information belong on that list.

Do we need a data protection impact assessment?

Article 35(1) GDPR requires one where processing is likely to result in a high risk to the rights and freedoms of natural persons. Whether your case qualifies depends on the data going in and on what happens to the output. Drafts for marketing copy are a different case from pre-sorting job applications. Record the check even when it ends in no, otherwise the reasoning cannot be found again later.

What does the EU AI Act change for us?

For use as a writing and research assistant, three points are in scope. Article 4 has applied since 2 February 2025 and was rewritten on 27 July 2026: providers and deployers take measures that support the development of AI literacy among their staff, without having to guarantee any particular level for any individual. Article 50 has applied since 2 August 2026; for deployers it bites where generated text is published to inform the public on matters of public interest. Where such text went through human review or editorial control and a person or entity holds editorial responsibility for it, the disclosure duty in Article 50(4) falls away. Superficial or purely formal checks such as a spellcheck do not count as either. The machine-readable marking of generated content in Article 50(2) falls on the providers of the systems instead, and for systems already on the market before 2 August 2026 it applies only from 2 December 2026. Obligations for high-risk systems, a category that can cover certain applications in the employment context, apply from 2 December 2027 following the omnibus package of July 2026.

What does a company rollout cost?

A provider subscription is only part of it. Effort sits in recording the use cases, connecting your systems, the policy and the training, and running the thing afterwards. Consulting is billed by time, while the local AI suite is a licensed product with an introduction priced by company size and an annual licence. Those figures are on the cost page.

What does custom software cost?

Let's talk about your use case.

Tell us briefly what you are working on. You get an honest assessment of whether AI is the right fit, and what a sensible first step looks like.