Is ChatGPT UK GDPR Compliant?
Consumer ChatGPT isn't UK GDPR compliant on its own. The moment you enter personal data, you become the data controller under the UK GDPR and DPA 2018.
No — consumer ChatGPT is not inherently “UK GDPR compliant” as a product. Compliance is not a property of the tool. It's a property of how you use it. The moment you enter personal data into ChatGPT, you — or your organisation — decide why and how that data is processed. That makes you the data controller under the UK GDPR and the Data Protection Act 2018. You carry the legal responsibility, not OpenAI.
Why compliance depends on you, not the tool
The UK GDPR is the UK version of the GDPR after Brexit. The Data Protection Act 2018 (DPA 2018) is the UK law that sits alongside it. Together they set the rules when you process personal data.
Here's the key point. When you paste a client's name, an email or an HR file into ChatGPT, you process personal data. You decide the “why” and the “how.” That makes you the data controller. The UK regulator, the Information Commissioner's Office (ICO), is clear on this. The UK GDPR obligations apply in full to AI. They cannot be set aside because AI is probabilistic or opaque.
In practice, everything still applies: lawful basis, fairness, transparency, purpose limitation, data minimisation, accuracy and accountability. These principles hold for any processing of personal data through an AI tool.
What the ICO expects: lawful basis, DPIA, transparency
Three expectations come up again and again in the ICO's guidance. Let's take them one at a time.
First, the lawful basis. Every use of personal data in AI needs one. The ICO notes the right basis can differ by phase. The model-training phase and the deployment phase (the model running on live data) are not treated the same way. You must identify and document the basis for each activity.
Next, the DPIA. A DPIA is a Data Protection Impact Assessment. The ICO says using AI on personal data will, in the vast majority of cases, be high-risk processing. That legally triggers the duty to carry out a DPIA under Article 35. AI sits on the ICO's list of innovative technologies that require a DPIA. And where a high risk remains, you must consult the ICO before you start.
Finally, transparency. When you collect personal data, individuals should get clear privacy information. Put plainly: the purpose and lawful basis, in plain language, before their data is used. In December 2024, the ICO published its response to a consultation series on generative AI, launched in January 2024. Its conclusion: legitimate interest is likely the only viable basis for collecting data to train these models (for example, web scraping). But it's a hard test to satisfy. And weak transparency around training could become an area of enforcement.
Consumer vs business: the difference that matters
The UK GDPR (Article 28) requires a written contract with your processor. OpenAI offers a Data Processing Addendum (DPA) and controller/processor terms for its business products: ChatGPT Business, ChatGPT Enterprise and the API. That contract helps you meet the Article 28 requirement.
The consumer ChatGPT experience does not provide an executed DPA. You get limited control over retention, data residency, and whether your inputs improve the models. That's why UK guidance treats using consumer ChatGPT for personal data as high-risk.
The training setting widens the gap further. On personal plans (Free, Plus, Pro), your conversations may, by default, be used to improve the models. Unless you turn off the training toggle in settings. OpenAI states it does not train on business data (Team, Enterprise, API) unless the customer explicitly opts in. This default difference is central to warnings against pasting client or staff personal data into consumer ChatGPT.
| You assume | The reality (UK GDPR) |
|---|---|
| “ChatGPT is UK GDPR compliant” | The tool isn't compliant on its own — your use is or isn't |
| “OpenAI is responsible for my data” | You become the data controller the moment you enter it |
| “A consumer account is fine for work” | No executed DPA, so Article 28 isn't covered |
| “No DPIA needed for a simple chat” | AI on personal data is treated as high-risk → DPIA |
The fix: shrink the scope before you send
There's a simple lever, backed across UK guidance: data minimisation. The principle is direct. Only input the personal data that is strictly necessary. And remove or anonymise identifiers before you send text to an external AI.
The logic is mechanical. The less personal data leaves your organisation, the smaller the scope being processed. So your UK GDPR exposure shrinks too. One caveat: de-identification is not foolproof. A residual re-identification risk can remain. But cutting data at the source is still the most effective step.
- Send only what's strictly needed — not the whole file.
- Anonymise names, emails and identifiers before sending.
- For regular work use, choose a business plan with an executed DPA.
- Document your lawful basis and run a DPIA when the ICO requires it.
- 1Spot the personal data in your text.
- 2Replace it with reversible tokens in the browser.
- 3Send only the anonymized text to the AI.
- 4Restore the real values in the reply, locally.
That's what ONYRI Sanitize is for. The engine detects sensitive data and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser, and only anonymized text reaches the model. ChatGPT finds only tokens — not the real identities. You shrink the scope of personal data that leaves your organisation, which is exactly what the UK GDPR and the ICO expect under minimisation.
Frequently asked questions
- Is ChatGPT UK GDPR compliant?
- Not on its own. Consumer ChatGPT is not “UK GDPR compliant” as a product; compliance depends on how you use it. The moment you enter personal data, you become the data controller under the UK GDPR and the Data Protection Act 2018. You then carry the obligations: lawful basis, transparency, and often a DPIA.
- Do I need a DPIA to use ChatGPT with personal data?
- Usually, yes. The ICO says using AI on personal data will, in the vast majority of cases, be high-risk processing, which triggers the DPIA duty under Article 35. If a high risk remains, you must consult the ICO before you start.
- Is a consumer ChatGPT account enough for business use?
- For personal data, no. The consumer account provides no executed DPA, which the UK GDPR's Article 28 requires, and your inputs may feed training by default. Business plans (with a DPA) and anonymising before you send both reduce the risk.
Sources & references
- ICO — Guidance on AI and data protection (how UK GDPR principles apply to AI: lawful basis, transparency, fairness, accountability) — Information Commissioner's Office (ICO)
- ICO — When do we need to do a DPIA? (AI and innovative technology as triggers for a mandatory Data Protection Impact Assessment) — Information Commissioner's Office (ICO)
- Osborne Clarke — ICO updates its views on using personal data in generative AI in the UK (Dec 2024 consultation response, lawful basis and transparency) — Osborne Clarke LLP
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.