How to Use ChatGPT at Work in a Data-Protection-Compliant Way
How to use ChatGPT at work in line with the GDPR: policy, DPA, the right plan, anonymization and training. A practical checklist plus a do and don't table.
Yes, you can use ChatGPT at work in a data-protection-compliant way. But no switch does it for you. You need a written policy, a data processing agreement (DPA) with the vendor, a business plan with training turned off, and the rule to anonymize personal data first. This guide walks through the steps in the right order.
Is ChatGPT at work GDPR-compliant?
ChatGPT is a tool. Compliance is not about the tool. It is about how you use it. What matters is which data you enter, which plan you use and which contracts you have signed. A private account with no contract is unfit for customer data. A business plan with a DPA and clear rules can be compliant.
- A private ChatGPT account is not meant for work-related personal data.
- You need a legal basis under GDPR Art. 6 and a DPA under Art. 28.
- Personal data stays protected even when you hand it to an AI.
- The German Data Protection Conference (DSK) has published dedicated guidance on this.
The 7 steps to compliant use
Work through this list in order. Each step builds on the one before. That way you stop staff from typing customer data into a tool that was never approved for it.
- 1Write an AI policy. Define which tools are allowed, who may use them and which data is off limits.
- 2Sign a DPA with the vendor. The data processing agreement under GDPR Art. 28 governs how the vendor handles your data.
- 3Choose the right plan. Use a Business or Enterprise plan or the API, and turn off training on your data.
- 4Never paste personal data in plain text. Names, addresses, customer numbers or health data do not belong unprotected in a prompt field.
- 5Anonymize or pseudonymize sensitive fields first. Replace real values with placeholders before the text reaches the AI.
- 6Train your team. Show with real examples what is allowed and what is not.
- 7Log usage. Record which tools are in use, without storing the prompt content itself.
The right plan: Team, Enterprise or API
The plan decides what happens to your inputs. According to OpenAI documentation, business data from ChatGPT Team, Enterprise and the API is not used to train the models by default. These statements can change. So always check the current vendor documentation and the DPA before you buy.
- Business and Enterprise plans usually offer a DPA and admin controls.
- The API lets you control behavior technically and wire it into your own systems.
- Check the server location and the retention period per vendor documentation.
- A private free or Plus account is the wrong choice for customer data.
Do and don't: the decision table
This table sums up the key rules. Pin it next to your AI policy. Then every employee has clear guidance.
| Do (recommended) | Don't (avoid) |
|---|---|
| Use a Business, Enterprise plan or API with a DPA | Use private accounts for customer data |
| Pseudonymize names, customer numbers and addresses first | Paste real personal data in plain text |
| Turn off training on your data in the settings | Accept default settings without checking |
| Communicate a written AI policy to everyone | Let each person decide what is allowed |
| Involve the works council early (BetrVG Sec. 87) | Roll out monitoring features without co-determination |
| Log usage at the tool level | Store prompt content or outputs permanently |
Why anonymizing before sending helps
The safest way to handle sensitive data is not to expose it at all. That is where ONYRI Sanitize comes in. The tokenizer runs entirely in your browser. It detects sensitive fields and replaces them with reversible placeholders before the text reaches the AI. The mapping from placeholder to real value never leaves your browser. In the answer, the original values are restored locally.
- The AI sees only placeholders like [NAME_1] instead of real names.
- This lowers data exposure and supports data minimisation under GDPR Art. 5.
- For honesty: pseudonymized data is still personal data (GDPR Recital 26).
- Anonymizing does not remove any obligation. It reduces risk, but not your responsibility.
- With the built-in chat, only the already anonymized text is sent to the model.
Which data you should never paste in plain text
Some data types are especially protected or especially risky. For those bound by professional secrecy, such as doctors or lawyers, national criminal law adds extra duties. Avoid any unprotected entry of these fields.
- Names, addresses and contact details of customers or colleagues.
- Health data, biometric data and other special categories (GDPR Art. 9).
- Account numbers, IBANs, salary figures and tax numbers.
- Credentials, API keys and internal technical secrets.
- Confidential strategy or contract content.
Frequently asked questions
- Can I just use ChatGPT at work?
- Not without preparation. You need a written policy, a DPA with the vendor and a business plan with training turned off. Personal data should be anonymized first.
- Are my inputs used for training?
- According to OpenAI documentation, data from Team, Enterprise and API use is not used for training by default. These statements can change. Check the current vendor documentation and your settings.
- Does anonymizing make my use GDPR-compliant automatically?
- No. Anonymizing lowers data exposure and supports data minimisation. But pseudonymized data is still personal data. Your legal duties remain.
- Do I need to involve the works council?
- Often yes. If an AI tool can monitor employees' behavior or performance, co-determination under Sec. 87 BetrVG applies. Clarify this early.
Sources & references
- GDPR (Regulation 2016/679) – Art. 5, 9, 28 and Recital 26 — EUR-Lex
- DSK guidance on Artificial Intelligence and Data Protection — German Data Protection Conference (DSK)
- Enterprise privacy – handling of business data and training — OpenAI
- Federal Commissioner for Data Protection and Freedom of Information — BfDI
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.