Last updated: June 5, 2026
ChatGPT drafts the proposal, summarizes the meeting minutes, answers the support request. In most companies this has long been routine, often without approval, often with real customer data in the prompt field. This is exactly where a productivity tool turns into a data protection issue. Because as soon as personal data flows into an AI service, the General Data Protection Regulation applies. In full, immediately, and regardless of whether the tool was “only” meant for internal copy.
This article clarifies what really matters under data protection law when using AI: when the GDPR applies in the first place, which obligations follow from it, what the supervisory authorities have decided so far, which tool tier is fit for business use, and what an AI policy looks like that works in everyday operations. No call for bans, no all-clear either. Step by step, with the right terminology.
Two sets of rules that are often confused: GDPR and EU AI Act
In the debate about “AI and the law”, two different sets of rules get mixed up, and that confusion leads to wrong conclusions. It pays to keep them cleanly apart.
The EU AI Act (Regulation (EU) 2024/1689) regulates AI systems by risk class. It asks: how dangerous is this application to health, safety and fundamental rights? In May 2026, with the so-called Digital Omnibus, the EU agreed to push back the deadlines for high-risk systems, to December 2, 2027 for standalone systems and to August 2, 2028 for systems embedded in products (formal adoption was still pending in early June 2026). What tends to get overlooked: the AI literacy obligation (Article 4) has applied unchanged since February 2, 2025. The AI Act's fining framework has applied since August 2025, and the competent authorities' full enforcement powers take effect from August 2026. We have broken down the full timeline in our article on the EU AI Act for mid-sized businesses.
The GDPR, by contrast, has been in force since 2018 and knows no grace period. It does not ask how risky the AI is, but whether personal data is being processed. If it is, the GDPR applies immediately and in full. That is the decisive point for practice: even if your AI use is uncritical under the AI Act and none of the postponed deadlines affect you, the very same use can be delicate under data protection law. The two regulations apply side by side, not as alternatives. The rest of this article deals with the GDPR side, because it is the one that already applies today.
When AI use falls under the GDPR in the first place
The GDPR governs the processing of personal data, meaning any information relating to an identified or identifiable natural person. A name, an email address, a phone number, an employee ID, the content of a customer complaint referring to a specific person: all of it is personal data. As soon as such data ends up in the prompt field of an AI tool, that is processing within the meaning of the regulation.
This distinction matters more in practice than it sounds. Having an AI tool write a marketing headline, with no reference to any person, is unproblematic under data protection law. Having the same AI summarize an incoming job application or analyze a customer call is not. So it does not depend on the tool, but on what you put into it.
Then there is the question of roles, which the AI Act treats similarly but the GDPR regulates in its own right. The company that decides for what purposes and by what means data is processed is the controller (Art. 4(7) GDPR). The service provider that processes the data on its behalf and under its instructions is the processor. If you use ChatGPT in your company, you are the controller, and OpenAI is, under the right contract model, your processor. This setup is only clean if a data processing agreement is in place. That is exactly where the free version fails, more on that below.
Controllership is also the reason why this topic belongs at management level. GDPR infringements carry fines of up to 20 million euros or 4 percent of global annual turnover, whichever is higher. Unlike in the spectacular provider cases, in case of doubt this risk hits your own company, and responsibility for lawful processing lies with the management, not with the individual employee who opens a tool.
The five obligations you must meet when using AI
Whether an AI tool runs in compliance with data protection law does not hinge on a single checkbox, but on five requirements that must be met together. They are not optional extras, but a direct consequence of the GDPR.
First, a legal basis. Every processing of personal data needs a basis under Art. 6 GDPR, such as the performance of a contract, consent or a legitimate interest. For AI use this means: you must be able to justify why this data runs through this particular tool. Legitimate interest (Art. 6(1)(f)) is often the obvious basis, but it requires a documented balancing against the interests of the data subjects. How you can tell it is missing: if nobody in the company can say which basis the AI use rests on, there is none.
Second, a data processing agreement (DPA). As soon as an external service processes data on your behalf, Art. 28 GDPR requires a DPA. Without one, the processing is simply unlawful, no matter how well the service is secured technically. OpenAI provides such a contract (Data Processing Addendum), which you must actively conclude, but only for the business products, not for the free tiers.
Third, the training question. Are your inputs used to further train the model? In OpenAI's business products this is contractually excluded; in the free version it is allowed by default and must be actively switched off. Data that has once flowed into training is practically impossible to retrieve, and that is precisely the problem under data protection law.
Fourth, transparency and data subject rights. The people whose data you process must know that, and for what purpose, an AI is involved (Art. 13/14), and they have rights to access, rectification and erasure. With generative AI, erasure is technically demanding, which makes tool selection and data minimization all the more important. In practice this means: better not to enter any data in the first place that you cannot get back out later.
Fifth, third-country transfers. OpenAI is a US provider, so by default the data leaves the EU, and that requires a suitable transfer mechanism (usually the standard contractual clauses, supplemented by the EU-US Data Privacy Framework). This can be defused through EU data residency, which OpenAI has offered to Enterprise customers since February 2025, and since January 2026 additionally as EU inference residency, where the actual processing also takes place on European servers. For many mid-sized companies this is precisely the argument for paying attention to server location when choosing a tool.
Anyone venturing into areas of likely high risk, such as AI-supported applicant screening, must additionally check whether a data protection impact assessment (DPIA) under Art. 35 GDPR is required. It is an upfront risk analysis of the processing, and the German supervisory authorities assume it will frequently be necessary for AI use.
What the supervisory authorities have decided so far
Data protection in AI is no longer a lawless space where everyone decides by gut feeling. Three sources now provide solid orientation.
On December 17, 2024, the European Data Protection Board (EDPB) published Opinion 28/2024 on AI models. Three statements from it are central for practice. An AI model trained on personal data is not automatically anonymous; supervisory authorities must assess this case by case. Legitimate interest can be a viable legal basis for developing and deploying such models, but only after a careful three-step test. And if a model was trained on unlawfully processed data, that can carry through to its later use. The EDPB thus classifies the use of AI as permissible in principle, provided the data protection principles are observed.
At national level, the Datenschutzkonferenz (DSK), the body of the German supervisory authorities, already presented its guidance on artificial intelligence and data protection on May 6, 2024. Across around 15 pages it provides concrete criteria for selecting, introducing and using AI applications, with a focus on large language models, and includes a practical checklist. Anyone who wants to know what a German supervisory authority measures an AI deployment against will find the yardsticks here.
How serious the authorities are is shown by the OpenAI case in Italy. At the end of 2024, the Italian supervisory authority Garante imposed a fine of 15 million euros on OpenAI. The reasoning: no legal basis for training on user data, a data breach from March 2023 that was not properly reported, and transparency shortcomings. The proceedings concerned OpenAI as a provider, not individual business customers, but they send a clear signal: legal basis and transparency are not formalities, they are obligations backed by fines. So what does that mean for the choice of tool in your own company?
Which ChatGPT tier is fit for business use?
The most common misconception in mid-sized companies goes: “We use ChatGPT, that is GDPR-compliant.” But ChatGPT is not simply ChatGPT. Its data protection suitability depends entirely on which tier is in use.
| Tier | DPA / data processing | Training on your inputs | Suitable for business personal data |
|---|---|---|---|
| Free | no | on by default (opt-out available) | no |
| Plus / Pro | no | on by default (opt-out available) | no, consumer product |
| Team | yes | off by default | yes, with DPA and configuration |
| Enterprise | yes | off by default | yes, incl. EU data residency |
| API | yes | off by default | yes, with DPA |
So the line does not run between free and paid, but between consumer and business products. Free, Plus and Pro are unsuitable for processing other people's personal data because no DPA is available. Even if you activate the training opt-out in the free version (found under Settings, Data controls, “Improve the model for everyone”), that solves only one of five points. The missing DPA remains.
Team, Enterprise and the API are fit for business use. Here OpenAI provides a DPA, does not train on your inputs by default and acts as a processor. Enterprise adds EU data residency on top. For a mid-sized company that seriously wants to use ChatGPT in its operations, the business version is therefore not a nice-to-have but the entry requirement. The same logic applies to the competitors: Microsoft Copilot, Google Gemini and Anthropic Claude likewise distinguish between consumer and business tiers with different data protection commitments. Which platform fits in the end is exactly the question we clarify with companies in our AI consulting before any rollout.
Shadow AI: the real risk is unregulated use
In most companies the biggest weakness is not the tool but the missing rule. “Shadow AI” refers to the use of AI services bypassing IT and clear guidelines: the employee who quickly opens the free ChatGPT version and pastes in a confidential contract for review rarely acts in bad faith. They simply have no guideline telling them what is allowed.
The most prominent example is the Samsung case from April 2023: within around three weeks, employees repeatedly entered confidential company data into ChatGPT, including internal source code. In May, the group responded with an internal ban. The lesson from this is not “ban AI” but “govern AI”. A ban only drives usage deeper into the shadows; a clear policy brings it into the light and makes it manageable.
That is exactly why the organizational side of data protection matters as much here as the contractual one. A perfectly configured Enterprise account is of little use if half the workforce uses the private free version for work content in parallel. Data protection compliant AI is to a large extent a question of internal organization, and that starts with an understandable policy.
An AI policy that works in everyday operations
An AI policy does not have to be a 30-page document that nobody reads. It has to be short, clear and applicable in day-to-day work. Three things are decisive: which tools are approved, which data may go in, and who is the point of contact. The following template can be adapted to your own business.
AI usage policy (template, short version)
- Approved tools. For work involving company or customer data, only [approved tool, e.g. ChatGPT Enterprise] may be used. Private or free AI accounts are not permitted for work content.
- Permitted inputs. General, non-personal content may be entered. Personal data (names, contact details, job applications, customer records) only if processing in the approved tool is expressly permitted.
- Prohibited inputs. Never to be entered: special categories of personal data (health, religion, trade union membership, among others), login credentials, third-party trade secrets, complete contracts containing personal data.
- Output review. AI outputs must be checked for accuracy before use. Responsibility for the result stays with the human.
- Point of contact. Questions and cases of doubt go to [data protection officer or designated contact] before any data is entered.
These five points cover the majority of everyday cases. What matters is less completeness than binding force: the policy should be embedded in employment terms, actively communicated once, and updated whenever new tools are introduced. A policy gathering dust in a folder changes no behavior.
Checklist: before an AI tool enters the company
The policy governs ongoing use, the following checklist governs procurement: it is the structured walkthrough before a new AI tool is introduced at all. The checkpoints summarize this article and follow the criteria that the DSK guidance also names.
- Personal data clarified? Is it defined whether and which personal data will enter the tool?
- Legal basis named? Is it established which basis under Art. 6 GDPR the processing relies on, including the balancing test for legitimate interest?
- DPA concluded? Is a data processing agreement with the provider in place (only available for the business products)?
- Training excluded? Is it ensured, by contract or by setting, that inputs are not used for model training?
- Third-country transfer covered? Is there a suitable mechanism, ideally EU data residency?
- Transparency established? Are data subjects informed about the AI use, and can their rights be fulfilled?
- Policy in place? Is there a communicated AI usage policy with named points of contact?
- Training completed? Are employees trained in AI literacy (mandatory under Art. 4 AI Act)?
- DPIA checked? In cases of likely high risk: has a data protection impact assessment under Art. 35 GDPR been carried out?
Working through these points before the rollout avoids the typical gaps. In sensitive deployment scenarios, for instance in HR, the DPIA question is not a formality but often the first step of the assessment.
AI literacy is mandatory, not optional
One point that often gets lost in the data protection debate comes from the AI Act but is closely interlocked with the GDPR in practice: the AI literacy obligation under Article 4. It has applied since February 2, 2025 and requires that people who operate or use AI systems have a sufficient level of AI literacy. Translated into everyday work this means: anyone using ChatGPT on the job should understand what they are doing, what the tool can do and where its limits lie.
This obligation is no bureaucratic end in itself. It is the human precondition for the data protection requirements being met at all. A workforce that knows why application documents do not belong in the free AI version needs less oversight and produces less shadow AI. This is exactly where structured enablement comes in, from tool selection through the policy to training teams in AI literacy, which makes the obligation from Article 4 achievable. In the end, data protection compliant AI is not a state you establish once, but a combination of the right contract, the right tool and people who know what they may enter.
AI in the company and data protection are not mutually exclusive. They only demand that the order is right: clarify the foundations first, then roll out the tools. If you use ChatGPT and its peers in the business tier, conclude a DPA, exclude training, put a clear policy in place and train your people, you are using AI not in spite of the GDPR but in line with it.
If you would like guidance along the way – from tool selection and the DPA check to the AI policy –, we support you as an AI agency with data protection compliant setups.
This article is a general overview and does not replace legal advice on the individual case.