ChatGPT and the GDPR
Why the question is framed the wrong way
GDPR · ChatGPT
Is ChatGPT GDPR compliant? The honest answer: the question is framed the wrong way. It is not the tool that is compliant or not, but the way your company uses it.
In many companies ChatGPT has long been part of everyday work: drafting emails, shortening texts, preparing quotes, summarising research. It often starts with individual employees' private accounts, without data protection or IT knowing about it. As soon as names, customer data or internal documents end up in the prompt, the GDPR applies.
Whether that use is lawful is decided in three places. None of them sits with OpenAI alone.
The contract
Which plan, and is there a data processing agreement? That determines whether OpenAI acts on your behalf or as a controller in its own right.
The settings
Training, memory, retention, connections to other systems. Much of it is configurable, but not all of it is set appropriately by default.
The inputs
What employees actually type or upload. This is where most breaches happen, and only a clear rule helps.
Which ChatGPT plan is suitable for companies
OpenAI distinguishes between personal plans and plans for organisations. From a data protection perspective the difference is fundamental, not a question of features.
For Business, Enterprise, Edu and the API, OpenAI commits not to use inputs and outputs for training by default, and points to SOC 2 Type 2 audits and ISO/IEC 27001, 27017, 27018 and 27701 certifications. Those are good foundations. They do not replace the obligations that rest with the company itself.
Common misconception
"We use Plus and switched training off, so we're fine." The switch keeps content out of training. It does not turn a personal plan into a business contract. On Free, Plus and Pro, OpenAI remains a controller in its own right, and there is no data processing agreement for those plans. Customer data in such an account is a disclosure to a third party, which as a rule has no legal basis.
The contract: data processing with OpenAI Ireland
Since February 2024, the contracting party for customers in the European Economic Area has been OpenAI Ireland Limited. For its business plans, OpenAI offers a data processing agreement, the Data Processing Addendum. The current version has applied since 1 January 2026.
Confirm and file it
Make sure the agreement applies to your account and file the current version with its date. A note on the vendor's website is not yet evidence.
Sub-processors
OpenAI uses further service providers and lists them publicly. That list belongs in your documentation, and changes to it should be tracked.
Transfers to the US
OpenAI bases transfers to third countries on the European Commission's Standard Contractual Clauses. That is permissible, but it obliges you to assess and document the transfer risk.
A data processing agreement governs how OpenAI handles your data. It does not settle whether you may process the data with ChatGPT in the first place. For that you still need your own legal basis, in day-to-day business usually legitimate interest under Art. 6(1)(f) GDPR. And your privacy notice has to name OpenAI as a recipient and mention the transfer to the US.
Storage in Europe: what data residency does and does not do
Since 2025, business customers can have OpenAI store their content in Europe. For new Enterprise and Edu workspaces this can be selected; for Business it is being rolled out gradually and is not yet available to every account. With the API, processing in Europe can also be selected for supported endpoints.
Data residency is real progress. It does not solve every question.
Common misconception
"With storage in Europe there is no third-country transfer any more." Data residency determines where content is stored at rest, not necessarily where it is processed. For Business workspaces with storage in Europe, OpenAI states that safety and abuse-monitoring data remains in the US, as do copies of prompts and responses for a limited time. And OpenAI remains a US company that may, in certain circumstances, have to give US authorities access to data held in Europe.
How much the plan matters became clear in 2025 in a US copyright dispute. In May 2025 a New York court ordered OpenAI to preserve even deleted conversations. Free, Plus, Pro, Team and API customers without a zero data retention arrangement were affected. Enterprise and Edu were excluded. The obligation ended on 26 September 2025, and according to OpenAI, conversations from the EEA are excluded from any further retention. The case shows that storage questions also depend on proceedings outside the EU, and that the plan helps decide them.
According to OpenAI, deleted conversations are removed within 30 days unless a legal obligation prevents it. For your deletion policy, that means setting and documenting retention periods in ChatGPT deliberately.
What employees may enter
The contract sets the framework. Whether day-to-day use is lawful is decided at the prompt. A simple traffic light helps more than a blanket ban.
Pseudonymising helps, but often is not enough: pseudonymised data is still personal data. A text is only anonymous once the person can no longer be identified from the context either. Replacing a customer's name with "Customer A" is not enough if sector, location and order volume are in the same paragraph.
Two features deserve particular attention: memory, which stores information beyond individual conversations, and connections to email, drives or calendars. Both expand the scope of data processed considerably and should only be enabled after review. And for every output: statements about people can be wrong. They have to be checked before use, because the GDPR requires personal data to be accurate.
Who supervises OpenAI, and who supervises you?
In March 2026, a court in Rome annulled the €15 million fine the Italian data protection authority had imposed on OpenAI at the end of 2024. The reason was not the substance but jurisdiction: since OpenAI Ireland became its main establishment in the EU in February 2024, the Irish Data Protection Commission has been the lead authority. The court did not rule on the substantive allegations.
For companies in Germany, a different distinction matters more. The Irish authority supervises OpenAI. Your use of ChatGPT is supervised by the data protection authority of your federal state. Whether OpenAI itself gets everything right does not release you from your own obligations.
The German supervisory authorities summarised what they expect in their guidance on AI and data protection from May 2024, complemented by a checklist from the Hamburg data protection commissioner for chatbots based on large language models:
Company accounts only
Prohibit private accounts and devices for work purposes, use business licences with secure authentication.
Clear rules
Define purposes of use, name responsible people, raise awareness among staff.
Avoid personal data
Do not enter or generate personal data where it can be avoided.
Check results
Review outputs for accuracy and discrimination, no automated decisions about people.
Involve others
Involve the data protection officer and the works council, and check whether a data protection impact assessment is needed.
On impact assessments: the authorities' list of processing operations requiring a data protection impact assessment expressly includes the use of AI to steer interaction with data subjects or to evaluate personal aspects. A chatbot in customer contact or AI-assisted pre-selection of applicants typically falls under it. Rewording internal texts does not.
The GDPR changes planned in the Digital Omnibus do not change this for now. They are still being negotiated, and until they are concluded the GDPR applies unchanged.
What the EU AI Act adds
Alongside the GDPR, the AI Act applies. A company using ChatGPT is the deployer of an AI system. Most obligations fall on OpenAI as the provider, but some fall on you.
ART. 4
AI literacy
Anyone using ChatGPT at work needs to know risks such as invented facts. The duty has applied since February 2025, and market surveillance has been enforcing it since August 2026.
ART. 50
Transparency
Published AI-generated text on matters of public interest must be disclosed, unless a human reviews it editorially and holds responsibility for it.
ART. 53
OpenAI's obligations
As the provider of a general-purpose AI model, OpenAI carries its own documentation and transparency obligations and has signed the European Commission's code of practice.
ART. 25
High-risk through purpose
Using ChatGPT to rank applicants, for example, changes its purpose and can make you the provider of a high-risk system yourself.
ChatGPT therefore belongs in two registers: the AI inventory under the EU AI Act and, as soon as personal data is processed, the record of processing activities under Art. 30 GDPR.
Company accounts and the works council: the overlooked link
The supervisory authorities recommend prohibiting private accounts and providing company licences. Under German employment law, that step has a consequence many people have not considered.
In January 2024, the Hamburg Labour Court ruled that the works council has no co-determination right when employees use ChatGPT voluntarily through private accounts (case no. 24 BVGa 1/24). The key reason: the usage data is generated at the provider, the employer has no access to it and therefore cannot monitor behaviour.
With company accounts the picture changes. Business plans come with an admin console through which the employer can manage accounts and usage and, depending on the plan, evaluate further log data. Under established case law, co-determination under section 87(1) no. 6 of the German Works Constitution Act applies as soon as software is objectively capable of monitoring. That strongly suggests it applies to company accounts. The Hamburg ruling was also issued in summary proceedings and at first instance.
Practical consequence: anyone switching from private to company accounts should involve the works council early and prepare a works agreement. The step that is right under data protection law and the involvement required under employment law belong together.
Five steps to GDPR-compliant use
Take stock
Who already uses ChatGPT, with which accounts and for what? Private accounts used for work are the most common starting point, and without that overview nothing can be regulated.
Choose the plan and secure the contract
Business, Enterprise or the API, depending on use. Check and file the data processing agreement with OpenAI Ireland, and set the storage location where selectable.
Configure the settings
Keep training excluded, enable memory and connectors deliberately, set retention periods, and sign in through the company login with two-factor authentication.
Set rules and train people
A one-page AI policy with the traffic light from this article, private accounts prohibited for work purposes, staff trained. That also covers the AI literacy duty under Art. 4 of the EU AI Act.
Document and involve
Record of processing activities, AI inventory, transfer assessment for the US, privacy notice. Check whether a data protection impact assessment is needed and involve the works council.
The point that matters
ChatGPT can be used in a GDPR-compliant way. But not with the account someone set up privately two years ago, and not without a rule on what may go into the prompt.
The GDPR question is only part of the answer. The same tool is an AI system under the EU AI Act, a processing operation under the GDPR and a matter for the works council. Handling these three perspectives separately means doing the work three times. Bringing them together in one place means doing it once.
With SimpleAct
Record ChatGPT once, for the GDPR and the AI Act.
EU AI Act and GDPR in one platform: register AI systems centrally, classify them rule-based, assign responsibilities and export audit-ready evidence at any time. Made in Germany, hosted in Germany.
Start your AI inventory →This article is for general information only and does not constitute legal advice. Information on OpenAI's plans and features is based on the provider's own publications and may change. Last updated: 5 October 2026.
Tags
Ready to put EU AI Act compliance on autopilot?
SimpleAct helps you inventory AI systems, classify risk, and generate the required documentation automatically.
Yannick | SimpleAct Team
Author · SimpleAct Team
