Is ChatGPT GDPR-compliant for your organisation?
Short answer
ChatGPT is not GDPR-compliant by default, nor forbidden by default. With an employee’s free or Plus account you have no data processing agreement and no view of what happens to the data; entering personal data then quickly becomes a data breach. A business version lets you make agreements, but processing stays at OpenAI. For special-category and confidential data, your own AI environment is the safer choice.
What it comes down to
The GDPR does not ban AI. It requires you to know which personal data you process, why, with whom, and that you can demonstrate it. The question “is ChatGPT GDPR-compliant?” is therefore really a different one: can you show that processing personal data through ChatGPT is lawful, secure and limited?
For most organisations the answer depends on which version is used and by whom: the organisation, with agreements in place, or an employee, on their own initiative.
Free, Plus or business: the difference under the GDPR
| Free or Plus (personal account) | Business version (Team, Enterprise, API) | |
|---|---|---|
| Data processing agreement | No, you are not the customer | Yes, can be concluded with OpenAI |
| Use for training | Possible, unless the user switches it off | Not by default |
| Visibility for the organisation | None: the account belongs to the employee | Administration, users and (limited) logging |
| Where processing takes place | At OpenAI | At OpenAI, partly with a choice of storage in Europe |
A business version solves a lot: you have a contract, a data processing agreement and administration. What it does not solve is that an outside party processes your data, with a parent company in the United States. For transfers to the US, many organisations rely on the EU-US Data Privacy Framework. The EU General Court upheld that framework in September 2025, but the case is on appeal at the Court of Justice. If you build your AI use on it, you build on a framework whose future is not yet settled.
When is using ChatGPT a data breach?
The Dutch Data Protection Authority (AP) has been clear about this. In 2024 it reported several data breaches in which employees had entered personal data into an AI chatbot. An employee of a GP practice had entered patients’ medical data; at a telecoms company it concerned a file containing, among other things, customer addresses.
The AP’s reasoning: when an employee, on their own initiative and against company agreements, puts personal data into a chatbot, the chatbot provider gains unauthorised access to that data. That is a personal data breach. The notification duty then applies: within 72 hours to the supervisory authority if there is a risk to the people concerned, and to those people themselves if the risk is high.
In practice this means: every pasted customer file, every excerpt from a case file and every email with names in it can be a notifiable data breach. And you usually do not know, because it happens in personal accounts you cannot see. How to deal with that is covered in Shadow AI: what to do when staff use ChatGPT on their own.
What do you need to arrange if you allow ChatGPT?
If you decide to use ChatGPT for business, at least arrange:
- A business contract and a data processing agreement (Article 28 GDPR). Without that agreement you may not have personal data processed.
- A DPIA if the processing is likely to result in a high risk, for example with special-category data, large-scale processing or new technology (Article 35 GDPR). With generative AI that is often the case.
- An AI policy that says which data may and may not go into the tool, with concrete examples per department.
- Agreements on transfers outside the EU, and an assessment of their risks.
- Blocking personal accounts on the network, otherwise the old use simply continues.
- AI literacy: staff need to understand what they should and should not put into a model. The AI Act asks you to support that. See The EU AI Act in 2026.
The alternative: AI that does not leave your organisation
For part of your work, a business AI subscription with good agreements is enough. For data you do not want at an outside party (patient data, client files, HR data, customer records) the defensible route is for the AI to come to the data, rather than the other way round.
With private AI the language model runs on a node of your own in your server room. There is no outside AI vendor in the processing, so no transfer and no processor with access to the content. In werqly AI Control your IT department sets which data is blocked, who uses which model and what is logged. Staff get what they were looking for in ChatGPT, and you keep the visibility you need.
Frequently asked questions
Questions on this topic
May employees use ChatGPT for their work?
That is up to the organisation. Without a policy and without a business contract, you risk personal data ending up in personal accounts, which according to the Dutch Data Protection Authority can be a data breach. Set out which tool is allowed and which data may go into it.
Is ChatGPT Enterprise GDPR-compliant?
It makes GDPR-compliant use possible: you sign a data processing agreement and your data is not used for training by default. You remain responsible for a DPIA, purpose limitation, transfer arrangements and a policy on which data may go in. Processing takes place at OpenAI.
Do I have to report a breach if an employee put personal data into ChatGPT?
If it happened against company agreements and there is a risk to the people concerned, usually yes: within 72 hours to your supervisory authority. Record it in your breach register in any case and consult your data protection officer.
Is a European AI model automatically GDPR-compliant?
No. A European vendor removes the transfer risk to the US, but you still need a data processing agreement, a DPIA and a policy. Only when the model runs on your own infrastructure is there no outside processor of the content.
Sources
- Dutch Data Protection Authority — Caution: use of AI chatbot may lead to data breaches (2024)
- GDPR (Regulation (EU) 2016/679), Articles 28, 33 and 35
- EU General Court, Latombe v Commission (T-553/23), 3 September 2025
- OpenAI — Enterprise privacy
This article is general information, not legal advice. Rules and guidance change; check the sources listed or ask your lawyer or DPO if in doubt.