ChatGPT has long since made its way into many companies. It drafts emails, summarizes documents, assists with research, and helps create the first draft of a presentation. Sometimes this happens officially. Other times, the new digital colleague is running in a private browser window and has never been introduced to the IT department.
As soon as employees enter personal data into ChatGPT or reuse the resulting output, the General Data Protection Regulation applies. Companies must therefore not only determine whether ChatGPT may be used; they must also specify the purposes for which its use is permitted, as well as the account and data to be used.
Date of this post: August 31, 2026.
ChatGPT is neither universally GDPR-compliant nor fundamentally prohibited. Its legality depends on the specific use.
In particular, compliance with data protection regulations requires that the company:
A business plan can lay the groundwork for this. However, it does not grant a blanket exemption from data protection laws. The plan name appears on the bill, but the responsibility remains with the company.
Personal data refers to any information relating to an identified or identifiable individual. This includes not only names, addresses, and email addresses, but also customer numbers, specific contract details, job application documents, meeting notes, location data, or a combination of seemingly neutral pieces of information that can be used to identify an individual.
Personal data may appear in several places within ChatGPT:
Simply removing a name is not automatically sufficient to ensure anonymity. For example, if a prompt describes a person’s position, age, department, and an unusual incident, the person in question may still be identifiable even if their name is not mentioned. Personal identifiers may also be inferred from the context.
From a data protection perspective, the version of the product used makes a significant difference.
For personal Free, Plus, and Pro workspaces, OpenAI may use content to improve its models. This use can be disabled in the data controls. According to OpenAI, temporary chats are also not used for training and are generally deleted within 30 days. However, disabling training does not replace a legal basis or a data processing agreement.
For ChatGPT Business, ChatGPT Enterprise, and the API, OpenAI states that inputs and outputs are not used to train the models by default. In addition, a Data Processing Addendum is available for these enterprise offerings. However, the specific provisions regarding retention, administration, data residency, and access control vary depending on the plan. Therefore, the contract and product terms in effect at the time of implementation always take precedence.
For the regular processing of company data, a company should therefore provide centrally managed work accounts. Employees’ personal accounts are largely beyond the company’s control and generally do not serve as a suitable basis for regulated processing procedures.
To ensure that ChatGPT is used in compliance with data protection regulations, companies should review and document the following points before approving its use.
Before implementing ChatGPT, it must be clear what it will be used for. “To increase productivity” is too vague for this purpose.
A permissible use case might be: Employees are permitted to use ChatGPT to edit the wording of certain marketing texts intended for public consumption. Another use case would be summarizing customer inquiries. Because these contain personal data, this use case already requires a much more thorough review.
Authorization should therefore not be granted across the board for the entire tool, but rather for specific use cases.
Any processing of personal data requires a legal basis. Depending on the specific situation, this may include, for example, the performance of a contract, a legal obligation, or a legitimate interest. In the context of employment, the requirements of the Federal Data Protection Act must also be considered.
In the case of health data, biometric data, political opinions, or other special categories of personal data, Article 6 of the GDPR alone is not sufficient. In such cases, an exception under Article 9 of the GDPR must also apply.
Consent is not necessarily the most convenient solution. Particularly in the context of an employment relationship, there are doubts as to whether consent can truly be given voluntarily.
If OpenAI processes personal data on behalf of the company, a contract in accordance with Article 28 of the GDPR is generally required. The current OpenAI Data Processing Addendum describes, among other things, compliance with instructions, security measures, subcontractors, erasure, and support regarding data subjects’ rights.
Nevertheless, the company must verify whether the contract is appropriate for the product being used and the planned process. The allocation of roles should also be documented. Not every data processing activity related to a user account automatically constitutes data processing on behalf of a client.
Signing a contract is therefore an important step in the review process. It is not the end of the review.
According to the current Data Processing Addendum, data from the European Economic Area is processed through OpenAI Ireland. For transfers to affiliates or service providers outside the EEA, OpenAI refers to adequacy decisions or EU Standard Contractual Clauses.
Companies should review and document the actual data flow, subcontractors, and any additional safeguards. A European data residency can reduce risk, but it does not automatically mean that all processing takes place exclusively within the EU. Functions, security protocols, and connected services may follow their own rules.
The server location is important. However, it is not the only item in the privacy policy.
Employees should enter only the information necessary for the authorized purpose. Where possible, data should be anonymized or effectively pseudonymized.
In addition, technical and organizational measures must be established, such as:
New features should not be rolled out to everyone without being tested first. From a data protection perspective, connecting to the CRM system is quite different from a polite request for three alternative headlines.
If personal data of customers, job applicants, or employees is processed using ChatGPT, the privacy policy must be updated. Data subjects must be able to understand what data is being processed, for what purpose, and by whom.
Access, correction, and deletion must also remain practically feasible. This can be difficult if no one has documented which data was used in which chat or connected source.
A risk assessment is also required prior to use. If the processing is likely to result in a high risk to the rights and freedoms of natural persons, a data protection impact assessment must be conducted in accordance with Article 35 of the GDPR. In the case of AI applications, this is often a consideration depending on the area of application and the type of data being processed.
ChatGPT can express itself convincingly and still be wrong. If personal statements are adopted without verification, inaccurate or discriminatory information may end up in personnel files, customer communications, or decisions.
Particular caution is required in the selection of applicants, performance evaluations, credit decisions, and similar processes. Article 22 of the GDPR restricts decisions that are made exclusively by automated means and have legal or similarly significant effects. Human involvement must provide genuine discretion in the decision-making process. A quick glance at the result just before submission is not sufficient.
A simple traffic-light system can make the internal policy easier to understand.
Green – consistently uncritical:
Yellow – only after approval and with safety measures in place:
Red – not without a separate review:
The traffic-light system does not replace a case-by-case review. However, it prevents employees from having to write a mini-dissertation on the law every time a prompt appears.
Using AI in compliance with data protection regulations requires clear rules. An AI policy should specify approved tools, permitted use cases, excluded data, oversight responsibilities, and points of contact.
Employees must also understand why these rules exist. Role-based AI training can cover data protection, information security, copyright, and the requirements of the AI Act all at once.
An internal or external AI Officer may be useful for ongoing coordination. While this role is not generally required by law, it can serve to centralize approvals, inventory management, training, and audits. The Data Protection Officer must still be consulted when conducting a data protection assessment.
K11 helps companies conduct data protection reviews and implement new applications, develop internal policies, and establish robust AI governance.
Is ChatGPT Business automatically GDPR-compliant?
No. The business offering establishes important technical and contractual requirements. However, the company using it must still verify the purpose, legal basis, data categories, transfers to third countries, settings, and internal processes.
Can names be entered into ChatGPT?
Only if the specific process has been legally reviewed and approved. A name is personal data. In most cases, you should first check whether the task can be completed without mentioning names or by using effective pseudonymization.
Is it enough to disable model training?
No. Doing so simply prevents new conversations from being used for model training. Other issues—such as order processing, legal basis, storage, transfers to third countries, and data subject rights—remain.
Does every company need a data protection impact assessment?
Not automatically. A DPIA is required if the planned processing is likely to result in a high risk to data subjects. This must be assessed and documented before processing begins.
Does the Data Protection Officer Have to Approve ChatGPT?
The decision rests with the company. However, the Data Protection Officer should be consulted at an early stage, especially when personal data, employees, or high-risk decisions are involved.
ChatGPT can be used in a business setting in compliance with data protection regulations. Neither a "No Use" sign nor purchasing a business plan is sufficient to ensure this.
What is needed are specific use cases, appropriate contracts and policies, a sound legal basis, and clear rules for employees. Those who establish these foundations will not have to pit data protection against productivity.
After all, the prompt isn't a legal vacuum. It just looks neater.