Guide7 min read

Is It Safe to Put Customer Data Into ChatGPT?

No, not in the consumer version: customer data is personal data, and entering it triggers your GDPR liability as controller. What actually lowers the risk.

By Pierre de ONYRI
Worried about your data? Anonymize it before AI

No: pasting customer data (names, emails, phone numbers, addresses, purchase histories, support tickets) into the consumer version of ChatGPT is not safe from a compliance standpoint. This information is personal data, and the mere act of entering it triggers your company's liability under the GDPR — you remain the data controller, even when a third-party provider then processes the data. The cautious reflex: never feed in identifiable customer data, or anonymize it beforehand. Two paths lower the risk without giving up the tool — anonymize on the user side, or move to a contractually governed enterprise offering.

Why customer data in ChatGPT is a GDPR problem

As soon as a piece of data can identify a person — a name, an email, a phone number, an account history — it's personal data. The company that decides to enter it into an AI tool remains the data controller: it stays legally accountable for how the data is used, and bears the legal liability if the tool misuses the information. Yet transferring that data to an AI provider without a legal basis violates the GDPR. Consent is rarely available — your customers generally haven't agreed to this transfer — and the people concerned must be informed under Articles 13 and 14. The CNIL, in its February 2025 recommendations, states that as a rule individuals must be informed when their data feeds an AI model.

Consumer vs enterprise: the difference that changes everything

The risk isn't the same depending on the offering. By default, OpenAI may reuse conversations from the consumer version of ChatGPT to train its models, unless you opt out. By contrast, the enterprise/business offerings and the API don't use inputs and outputs for training by default, and retain API data for about 30 days before deletion (barring legal obligations). This is detailed on OpenAI's “Enterprise privacy” page and the help center article “How your data is used to improve model performance.” For compliant use with personal data, a data processing addendum (DPA) and transfer safeguards are also expected — absent from a plain consumer account used without a contract.

CriterionConsumer ChatGPTContracted enterprise / API
Reuse for trainingYes by default (unless opt-out)No by default
Data processing addendum (DPA)Absent without a contractProvided
RetentionVariable, loosely governedAPI ~30 days, then deletion
Cross-border transfer safeguardsNot negotiatedSCCs / DPA in place
After OpenAI's “Enterprise privacy” page and the help center article “How your data is used to improve model performance.”

The concrete risks: fines, leaks, lost trust

These aren't theoretical risks. On 20 December 2024, the Italian data protection authority (Garante) fined OpenAI 15 million euros, faulting it for using personal data to train ChatGPT without an adequate legal basis, breaching the transparency principle and the duty to inform, the absence of a proper age verification system, and the failure to notify a data breach that occurred on 20 March 2023 (OpenAI announced it would appeal). The EDPB, in its Opinion 28/2024 adopted in December 2024, also stresses that it falls to data controllers to properly manage the risks tied to generative AI across the lifecycle, and provides a three-step test to assess whether legitimate interest can serve as a legal basis.

  • Financial penalty: a GDPR breach exposes you to fines — the Garante case is the quantified illustration.
  • Technical leak: no online service is immune. On 20 March 2023, a bug in the open-source redis-py library let users see other users' conversation titles and exposed, for about 1.2% of active ChatGPT Plus subscribers in a given window, payment data (name, email, billing address, last four digits and card expiry).
  • Internal leak: in March 2023, shortly after allowing ChatGPT, Samsung found at least three cases of internal information leaking via employees — source code pasted to debug, confidential meeting notes, optimizing a chip test sequence — leading it to restrict the tool.
  • Lost trust: beyond the fine, exposing customer data lastingly damages the relationship and reputation.
Diagram: at top, a customer record (name, email, phone in amber) is pasted as-is into ChatGPT and arrives readable at the provider (exposed data); at bottom, the same record passes through anonymization that replaces the values with cobalt tokens marked by a check, and only the neutralized text reaches the AI.
After the EDPB (Opinion 28/2024), CIO Dive and The Hacker News; OpenAI's “Enterprise privacy” offering and transfer policy (DPA, SCCs / Data Privacy Framework) cited by name.

The two fixes that genuinely lower the risk

Giving up AI isn't the only option. Two paths let you use it on customer cases while controlling the risk, and they can be combined:

  1. 1Anonymize or pseudonymize customer data before sending — replace identifiers with reversible tokens on the user side, so the real values never leave the controlled environment. The AI only ever sees tokens.
  2. 2Move to a contractually governed enterprise offering — signed DPA, standard contractual clauses (SCCs), no reuse for training, limited retention — rather than a consumer account with no framework.
  3. 3Whenever you systematically integrate ChatGPT into processes involving personal data, run a data protection impact assessment (DPIA), which is very likely required.

On cross-border transfers, this framing matters too: data entered into ChatGPT may be transferred to the United States. OpenAI states it governs these transfers with standard contractual clauses (SCCs) or relies on the Data Privacy Framework adequacy decision (July 2023) — elements described in its Data Processing Addendum, but which presuppose a contract, not a plain consumer account.

That's exactly what ONYRI Sanitize does for the first fix: the engine spots names, emails, phone numbers and other identifiers and replaces them with reversible tokens before sending. Detection and the token↔value mapping stay in your browser — only anonymized text reaches the tool. What ChatGPT receives, logs or reuses then contains only tokens, never your customers' real data.

Frequently asked questions

Is it safe to put customer data in ChatGPT?
No, not in the consumer version. Customer data (names, emails, phone numbers, histories) is personal data: entering it triggers your GDPR liability as data controller, with no legal basis and no notice to the people concerned. The safe reflex is to never feed in identifiable data, or to anonymize it before sending.
Is my company liable if OpenAI misuses the data?
Yes. By choosing to enter customer data into the tool, your company remains the data controller and stays legally accountable for its use, even when a third-party provider processes it. The legal liability falls on you if the tool misuses the information.
How can I use AI on customer data and stay compliant?
Two combinable paths: anonymize the data before sending (reversible tokens on the user side, so the real values don't leave your environment) and/or move to a contracted enterprise offering (DPA, SCCs, no reuse for training, limited retention). A data protection impact assessment (DPIA) is very likely required once you integrate it systematically.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next