Is ChatGPT GDPR compliant? What companies need to know
ChatGPT is not GDPR compliant on its own. It depends on your plan, configuration, a signed DPA, a legal basis, and above all what you type in. Here is the breakdown.
In short: ChatGPT is not GDPR compliant on its own. Compliance is not a switch inside the tool. It is the result of several building blocks. It depends on the plan (free, Team or Enterprise, API or consumer), on the configuration (training turned off, retention), on a signed Data Processing Agreement (DPA), on a valid legal basis — and above all on what you type in. If you enter personal data without settling these points, you carry the full risk yourself.
The short answer for companies
"GDPR compliant" is not a property of a product. It is a state you create as the controller. ChatGPT can be part of a compliant process — or an open flank. The difference lies in these points:
- The plan: consumer versions and business offerings treat your data differently.
- The contract: without a signed DPA, the legal basis for processing on your behalf is missing.
- The legal basis: every processing of personal data needs a lawful ground under Article 6 GDPR.
- The configuration: training on inputs, retention, and access rights must be set correctly.
- The content: what you do not enter cannot leak. That is the strongest lever.
Consumer, Team/Enterprise and API compared
Not every "ChatGPT" is the same. The key difference for companies is between the consumer version and the business offerings. According to OpenAI, inputs from Business, Enterprise, and API products are not used to train the models by default; the free and Plus consumer versions are handled differently (source: OpenAI Enterprise Privacy documentation). Check the current version, because these rules change.
- Free / Plus (consumer): according to OpenAI, inputs may be used to improve the models unless you turn this off in settings. Not suited for company data without clear rules.
- Team / Enterprise (business): according to OpenAI, no training on your business data by default; a DPA is available; more control over retention and administration.
- API: according to OpenAI, no training on data sent via the API by default; suited for your own controlled integrations.
- Important: "no training" does not mean "no storage". Data may be stored for a limited time for abuse detection — details are in the vendor documentation.
Training on your inputs — what OpenAI says
A core GDPR concern is what happens to your text after you hit send. According to OpenAI, inputs in the consumer version may be used to improve the models unless you turn it off. In the Business and API products, training on your data is off by default according to OpenAI. Always cross-check these statements against the current documentation, because vendors adjust their policies regularly.
- 1Check in settings whether "improve the model for everyone" is active, and turn it off if needed.
- 2Clarify retention: how long are chats and history stored?
- 3Record which plan is in use — the rules differ per product.
- 4Document the setting as part of your record of processing activities.
The DPA and your legal basis
When a vendor processes personal data on your behalf, Article 28 GDPR requires a Data Processing Agreement (DPA, called AVV in Germany). Without this contract, the legal basis for sharing is missing. OpenAI provides a DPA for Business and API customers; the plain consumer version is not intended for this. In addition, you need a legal basis under Article 6 GDPR for the processing itself.
- Sign a DPA: only with a business or API contract, not with a private account.
- Determine the legal basis: consent, contract, or legitimate interest — depending on the use case.
- Check third-country transfers: if data is processed outside the EU, you need suitable safeguards (e.g. standard contractual clauses).
- Secure data subject rights: access, erasure, and objection must remain feasible.
- Consider a DPIA: for sensitive or large-scale data, a data protection impact assessment may be required.
What the data protection authorities say
European supervisory authorities watch generative AI closely. The European Data Protection Board (EDPB) set up a ChatGPT taskforce and published a report on 23 May 2024 on open questions such as legal basis, transparency, and accuracy of outputs. Germany's Datenschutzkonferenz (DSK) issued its "Orientierungshilfe KI und Datenschutz" with practical guardrails for using AI applications. The shared message: whoever deploys the AI stays responsible — not the vendor alone.
- EDPB taskforce: reviews legal basis and accuracy, among other things; the work is not finished according to the EDPB.
- DSK guidance: recommends clear purposes, data minimisation, and no sensitive data in open AI services.
- Supervisory practice: authorities such as the BfDI and the state DPAs expect documented decisions, not spontaneous use.
- Principle: pseudonymised or aggregated data reduces risk but does not replace a legal basis.
Decision table and data minimisation
Before you roll out ChatGPT in your company, work through these points. The table shows, per plan or setting, what you should check. The most effective and simplest lever is at the end: do not enter personal data in the first place. That is data minimisation under Article 5 GDPR in practice.
| Plan / setting | What you must check | Why it matters |
|---|---|---|
| Free / Plus (consumer) | Turn off training in settings; enter no personal data | According to OpenAI, inputs may otherwise be used to improve the model |
| Team / Enterprise (business) | Sign a DPA; set retention and admin rights | No training on business data according to OpenAI, but a contract is needed |
| API | Check the DPA; document data flow and storage | No training by default according to OpenAI; the integration stays your responsibility |
| Legal basis (Art. 6) | Determine consent, contract, or legitimate interest | Without a lawful ground, the processing is not permitted |
| Third-country transfer | Check safeguards such as standard contractual clauses | Processing outside the EU needs suitable protection |
| Input / content | Remove or replace names, customer data, and secrets first | What is not sent cannot leak — the strongest lever |
This is exactly where a tool like ONYRI Sanitize helps. It detects sensitive data in your prompt and replaces it with reversible placeholders (tokens) before the text goes to the AI. The mapping between token and original value stays in your browser and never leaves it. After the answer comes back, the real values are restored. To be honest and precise: this is pseudonymisation, not anonymisation. Pseudonymised data remains personal under Recital 26 of the GDPR. The approach reduces exposure and supports data minimisation — but it replaces neither a DPA nor a legal basis.
Bottom line: treat ChatGPT like any other processor. Settle the plan, contract, legal basis, and configuration — and minimise what you enter at all. Then an open flank becomes a controlled building block.
Frequently asked questions
- Is the free version of ChatGPT GDPR compliant?
- Not out of the box. According to OpenAI, inputs in the consumer version may be used to improve the models unless you turn this off. It also lacks a DPA and proper configuration for company data. Do not enter personal data here.
- Do I need a DPA to use ChatGPT at work?
- Yes, if personal data is processed. Article 28 GDPR requires a Data Processing Agreement. OpenAI provides a DPA for Business and API customers, not for private accounts. You also need a legal basis under Article 6.
- Are my inputs used for training?
- It depends on the product. According to OpenAI, Business, Enterprise, and API data is not used for training by default, while consumer inputs may be. Check OpenAI's current documentation, as the rules change.
- Does anonymising before sending make ChatGPT legally safe?
- It helps, but it is not a free pass. Tools like ONYRI Sanitize pseudonymise your data and reduce exposure. Pseudonymised data remains personal under Recital 26. A DPA, a legal basis, and documentation are still required.
Sources & references
- Report of the work undertaken by the ChatGPT Taskforce (23 May 2024) — European Data Protection Board (EDPB)
- Guidance on AI and data protection (Orientierungshilfe) — Datenschutzkonferenz (DSK), Germany
- GDPR — Regulation (EU) 2016/679 (Art. 5, 6, 28, Recital 26) — EUR-Lex, Publications Office of the EU
- Enterprise Privacy — how customer data is handled — OpenAI (vendor documentation)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.