In this article11
- 1.Is ChatGPT GDPR compliant?
- 2.When does ChatGPT use become a data breach?
- 3.Business vs consumer accounts: who trains on your data?
- 4.Is ChatGPT data stored in the EU?
- 5.What can employees put into ChatGPT?
- 6.How to write an AI policy people actually follow
- 7.Customer-facing AI: additional rules
- 8.When a custom setup beats ChatGPT
- 9.Frequently asked questions
- 10.Next steps
- 11.Sources
ChatGPT GDPR compliance depends far more on how your company uses it than on the tool itself. On a business plan such as ChatGPT Business or Enterprise, OpenAI does not train on your data by default, but GDPR also cares about where data is processed, whether you have a data processing agreement, and what your employees are allowed to paste in. Get those right and ChatGPT, Claude or Gemini can be used responsibly for most business work. Get them wrong and a single prompt can become a reportable data breach.
The short version:
- European regulators treat employees entering personal data into AI chatbots against company rules as a data breach, often reportable.
- OpenAI, Anthropic and Google do not train on business-account data by default. Consumer accounts work differently.
- EU data residency varies: OpenAI offers it for Enterprise, Edu and API; Microsoft through the EU Data Boundary; Google for Gemini in Workspace. Anthropic's first-party Claude services offer no EU option.
- A business account without a clear AI policy solves only half the problem.
Is ChatGPT GDPR compliant?
There is no such thing as a GDPR-compliant tool in isolation. GDPR governs your processing of personal data. When you put customer records, HR files or health information into an AI tool, you are the controller and the AI vendor is your processor. So the real questions are: do you have a lawful basis, a data processing agreement (DPA) with the vendor, clarity on where data is stored and for how long, and rules your staff actually follow?
On free or personal accounts you usually can't answer those questions for business data. On a business plan with a DPA and a sensible policy, you can.
When does ChatGPT use become a data breach?
The Dutch data protection authority (AP) has been one of the most explicit regulators on this. In August 2024 it reported receiving multiple breach notifications caused by employees sharing personal data with AI chatbots. One involved a medical practice employee entering patient data; another a telecom employee uploading a file of customer addresses.
The AP's position is useful for any company operating in the EU:
- Entering personal data against internal agreements is a data breach. Notifying the regulator, and sometimes the individuals affected, is often mandatory.
- If chatbot use is part of company policy, it is not a breach, but it may still be unlawful if the GDPR fundamentals are not in place.
- The regulator recommends clear rules for employees and, where possible, agreements with the vendor that input data is not retained.
That creates a real dilemma. Ban AI outright and people use it anyway on personal accounts. Allow it without rules and you may be processing data unlawfully. The practical way out is a business account plus clear rules.
Business vs consumer accounts: who trains on your data?
The biggest difference between consumer and business accounts is model training and retention. Prices as of September 2026:
| Vendor | Consumer (Free, Plus, Pro) | Business plan | Training on business data |
|---|---|---|---|
| OpenAI | Used for training unless the user opts out | ChatGPT Business: $20 per user per month (annual) or $25 (monthly), minimum 2 seats. Enterprise via sales | Not by default |
| Anthropic | Used for training if the user allows it, with 5-year retention; otherwise 30 days | Claude Team: $20 per seat per month (annual) or $25 (monthly), 2 to 150 people. Enterprise: $20 per seat plus usage | Not by default |
| Depends on personal settings | Gemini included in Workspace (Business Starter $7, Standard $14, Plus $22 per user per month, US pricing) | Not outside your domain without permission | |
| Microsoft | Depends on personal account | Copilot Chat at no extra cost with an eligible Microsoft 365 plan; Microsoft 365 Copilot from $30 per user per month (enterprise, annual) | Covered by Microsoft 365 terms |
A detail worth flagging on Anthropic: since September 28, 2025, consumer accounts (Claude Free, Pro and Max) keep chats for five years if the user allows training. An employee summarizing client emails on a personal Pro account may be sharing more than you think.
For a comparison of the models themselves, see ChatGPT vs Claude vs Gemini for business.
Is ChatGPT data stored in the EU?
Not training on your data is different from keeping it in Europe. Under GDPR, transfers outside the EU need a valid mechanism such as an adequacy decision or standard contractual clauses. Here's how the major vendors compare:
- OpenAI offers data residency in Europe for ChatGPT Enterprise, ChatGPT Edu and the API platform, and in-region inference in Europe for eligible Enterprise, Edu and Healthcare customers. ChatGPT Business is not on that list.
- Microsoft completed its EU Data Boundary: European customers can store and process data for Microsoft 365 and most Azure services within the EU and EFTA. Microsoft 365 Copilot is covered, with in-country processing available in a number of countries.
- Google lets Workspace customers restrict Gemini processing to the US or the EU, and published a DPIA support guide.
- Anthropic offers only "global" (default) and "us" processing for claude.ai and its own API. There is no EU option. Claude is also available through AWS, Google Cloud and Microsoft Azure; whether you get EU processing there depends on the platform and your contract.
For typical office work without sensitive personal data, a business account with a DPA is usually enough. If you process health data, national ID numbers or large customer databases, EU processing and a data protection impact assessment (DPIA) become important.
What can employees put into ChatGPT?
A simple classification that works for most small and mid-sized businesses:
| Category | Examples | Guidance |
|---|---|---|
| Public or non-personal | Marketing copy, general questions, code without secrets, public documents | Fine on a business account |
| Confidential business data | Quotes, pricing agreements, strategy | Business account only, never personal accounts |
| Ordinary personal data | Customer names, emails, addresses | Only if your policy allows it, on a business account with a DPA, and only what's necessary |
| Special category data | Health data, national IDs, criminal records | Not in general chat tools. Use a purpose-built setup with a DPIA |
A good habit to teach: strip names and identifying details before pasting. "Client A in Denver wants a 10% discount" usually works as well as the real name.
How to write an AI policy people actually follow
A policy nobody reads doesn't help. Keep it short and specific:
- Name the approved tools. For example: only ChatGPT Business or Copilot through the company account, no personal accounts for work.
- Define data that never goes into AI tools. Use the table above as a starting point.
- Sign DPAs with every approved vendor and add them to your record of processing activities.
- Assign an owner who answers questions and updates the policy when new tools appear.
- Train your team. One hour with examples from your own work. This also covers the AI literacy requirement under the EU AI Act.
- Plan for mistakes. Who reports, to whom, and how you decide within the 72-hour GDPR window whether a breach must be notified.
Customer-facing AI: additional rules
When AI talks to customers, for example a website chatbot or an agent answering emails, more rules apply. Since August 2, 2026, the EU AI Act requires chatbots to be recognizable as AI at the latest at the first interaction. Dutch regulators have also stated that a chatbot may not fully replace humans in customer service: customers must always be able to reach a person, and the bot must not give incorrect or misleading information. For the full picture, see our guide to EU AI Act compliance.
When a custom setup beats ChatGPT
For ad-hoc office work, a business subscription is fine. Once AI becomes part of a business process, such as triaging customer emails, extracting contract data or answering questions from your own documents, you want more control. A custom solution built on model APIs lets you choose the model, the processing region, what gets logged, how long data is kept, and which fields are anonymized before anything reaches the model. OpenAI's API does not train on your data by default, and cloud platforms often let you pick a region.
That's the kind of system Airflows builds: AI agents and document processing connected to your own systems, where you own the code and the data. To see how AI can work safely with your internal knowledge, read our explainer on retrieval-augmented generation.
Frequently asked questions
Is ChatGPT safe for business data?
On a business plan such as ChatGPT Business or Enterprise, OpenAI does not train on your data by default, which makes it suitable for most business content. On free or personal accounts that is not guaranteed and you have no data processing agreement. Special category data such as health information does not belong in a general chat tool.
Is entering personal data into ChatGPT a GDPR breach?
According to the Dutch data protection authority, it is a data breach when an employee does so against internal rules, and notification is often mandatory. If the use is covered by company policy it is not a breach, but the processing still needs a lawful basis, a DPA and appropriate safeguards.
Does ChatGPT train on my data?
On consumer accounts, OpenAI uses conversations for training unless you opt out. On ChatGPT Business, Enterprise, Edu and the API platform, OpenAI does not train on your data by default. Anthropic and Google apply the same default to their business products.
Where does ChatGPT store data?
By default OpenAI processes data globally, largely in the US. For ChatGPT Enterprise, Edu and the API platform, OpenAI offers data residency in Europe, and eligible Enterprise customers can also get in-region inference. ChatGPT Business does not include EU residency by default.
Is Claude GDPR compliant?
Claude Team and Enterprise do not train on your content by default. However, Anthropic's own services (claude.ai and the first-party API) currently offer no EU processing option, only "global" or "us". For sensitive personal data, factor that in or use Claude through a cloud platform with a suitable region.
Next steps
Pick a business account, write a two-page policy and give your team an hour of practical training. That handles most of the privacy risk of AI in everyday office work. If you want to use AI in processes that touch customer or employee data and decide yourself where that data lives, take our free AI scan or see our services.
Sources
- Use of AI chatbots can lead to data breaches (Dutch Data Protection Authority, August 6, 2024)
- AP and ACM: chatbot may not fully replace humans in customer service (October 2, 2025)
- Business data privacy, security, and compliance (OpenAI, accessed September 26, 2026)
- Enterprise privacy at OpenAI (OpenAI, accessed September 26, 2026)
- ChatGPT Business, Overview (OpenAI Help Center, accessed September 26, 2026)
- Plans & Pricing (Claude by Anthropic, accessed September 26, 2026)
- Updates to Consumer Terms and Privacy Policy (Anthropic, August 28, 2025)
- Data residency (Claude Platform Docs, accessed September 26, 2026)
- Microsoft completes landmark EU Data Boundary (Microsoft, February 26, 2025)
- AI for Enterprise Productivity, Microsoft 365 Copilot pricing (Microsoft, accessed September 26, 2026)
- Generative AI Security, Compliance and Privacy (Google Workspace, accessed September 26, 2026)
- Compare Flexible Pricing Plan Options (Google Workspace, accessed September 26, 2026)

Builds AI agents, automations and custom software for businesses at Airflows.



