Previous Article Back to Blog
August 31, 2026 Kévin Lefèvre (Consultant & AI Expert) 7 min read GDPR

Is ChatGPT (or Copilot, Gemini) GDPR-Compliant for Your Business in 2026?

Executive summary
  • GDPR compliance is a property of how your company configures and uses ChatGPT, Copilot, or Gemini, not of the tools themselves. The same tool can be compliant in one company and a live breach risk in the next.
  • The two decisions that matter most: which plan you’re on (consumer vs. enterprise/API with a Data Processing Agreement), and what your employees actually paste into the prompt box.
  • 77% of employees who use AI tools at work have pasted company or customer data into a prompt, and most of those pastes happen from personal, unmanaged accounts your company can’t see or control.
77%
Employees Who’ve Pasted Company Data

into an AI chatbot prompt, most from unmanaged personal accounts.

€20M
Maximum GDPR Fine

or 4% of global annual turnover, whichever is higher, for unlawful processing.

In brief: Consumer ChatGPT, free-tier Copilot, and personal Gemini accounts process your prompts under the provider’s own terms, not yours. There’s no Data Processing Agreement in place, no contractual guarantee your data won’t train future models, and no audit trail. Enterprise and API tiers change this, but only if your company configures them and writes a policy employees follow.

Key takeaways

  • There’s no single “GDPR-compliant” checkbox for an AI chatbot. Compliance depends on your account tier, your Data Processing Agreement, your written policy, and what data flows into it.
  • A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 when AI use involves systematic profiling, automated decisions with legal effect, or large-scale sensitive data processing. That’s not every chatbot use case, but it reaches further than most companies expect.
  • The CNIL and the EDPB both published guidance in 2025 on how GDPR applies to AI system development and use. A company can no longer claim this is a grey area it didn’t know about.

The Real Question: Is Your Use of ChatGPT Compliant

Ask ten SMEs whether ChatGPT is GDPR-compliant and you’ll get ten different answers, because it’s the wrong question. OpenAI, Microsoft, and Google all offer enterprise agreements with Data Processing Agreements (DPAs), EU data residency options, and commitments not to train models on your inputs. They also all offer free or consumer-grade tiers with none of that. The tool is the same underlying model. The compliance posture depends on which door your employees walked through, and whether anyone in your company decided that on purpose.

Most SMEs haven’t decided on purpose. An employee finds ChatGPT useful, signs up with a personal email, and starts using it for real work within a week. Multiply that across a team, and compliance ends up with an AI processing operation nobody has documented, nobody manages, and nobody can audit, running through browser tabs the compliance team has never seen. For a broader look at baseline requirements, consult our GDPR Compliance Checklist for SMEs .

What determines compliance, concretely

1. Legal basis for processing

If personal data (customer names, employee records, candidate CVs) goes into a prompt, you need a lawful basis under GDPR Article 6: typically legitimate interest or consent, documented rather than assumed. The CNIL’s February 2025 recommendations on AI and data subject rights are the clearest current guidance on how this applies in practice. “We didn’t think about it” is no longer a defensible position for a company operating in France.

2. Data Processing Agreement (DPA)

Enterprise and API-tier agreements from OpenAI, Microsoft (Copilot for Microsoft 365), and Google (Gemini Enterprise) include a DPA defining who’s the controller, who’s the processor, and what happens to your data. Consumer tiers generally do not. If your company’s real AI usage runs through unmanaged personal accounts, no DPA covers that usage, regardless of what your enterprise contract says on paper.

3. Training data opt-out

Even on paid tiers, training-data behavior varies by provider and product. Confirm in writing, not by assumption, whether prompts and outputs are used to improve the underlying model. For any tool processing client or employee data, get a documented “no,” or put a compensating control in place if you can’t. When reviewing software options, explore our AI Act compliance tools buyer's guide .

4. Data minimization at the point of use

This is the control most companies skip, and the one that matters most day to day. A written policy telling employees what can and can’t go into a prompt — no client PII, no unreleased financial data, no health or biometric data — reduces real exposure more than any contract clause. A contract doesn’t stop someone pasting a spreadsheet at 6pm to save time.

5. DPIA triggers

Under Article 35, a DPIA is required when processing involves two or more of: systematic evaluation or profiling, automated decision-making with legal or similarly significant effects, large-scale processing of special-category data, or innovative technology use at scale. Using an AI chatbot to draft internal emails doesn’t trigger this. Using AI to screen job applicants, score customer creditworthiness, or make automated decisions about individuals very likely does.

A practical DPIA-trigger table

Use case Likely DPIA trigger? Why
Drafting internal emails or documents ❌ No No profiling, no automated decision, no special-category data at scale
Summarizing customer support tickets ⚠️ Usually no, review if PII-heavy Depends on volume and data sensitivity
Screening CVs or ranking candidates ✅ Yes Automated evaluation with effects on individuals
Chatbot handling customer service with account access ⚠️ Often yes Personal data at scale, potential profiling
Internal code generation, no personal data ❌ No No personal data involved
Fraud-risk or credit scoring assistance ✅ Yes Automated decision-making with legal/financial effect

What to actually do this month

  1. Find out what’s really being used. Ask department heads which AI tools their teams use day to day, not what IT approved. Expect the answer to include tools nobody signed off on.
  2. Move real usage onto enterprise/API tiers with a signed DPA. If a tool is genuinely useful to the business, pay for the version that comes with a contract, not the free one that doesn’t.
  3. Write a one-page usage policy. What can go into a prompt, what can’t, who to ask when unsure. A short policy people actually read beats a long one nobody opens.
  4. Run the DPIA-trigger check against your real AI use cases , not a generic list. Document the ones that don’t trigger a DPIA too — that documentation is itself evidence of a compliance process if you’re ever asked.
  5. Revisit your AI literacy record under Article 4 of the EU AI Act. Article 4 requires organizations to ensure sufficient AI literacy among staff using AI systems, and it has applied since 2 February 2025. A ChatGPT usage policy with no training or documented awareness effort behind it doesn’t satisfy this requirement. Follow our roadmap in the guide to complying with the EU AI Act in 5 steps .

Frequently Asked Questions

Is it illegal to use ChatGPT at work under GDPR?
No. Using ChatGPT at work is not itself illegal under GDPR. What matters is what data goes into it, on what account tier, and under what legal basis. Consumer-tier use with customer or employee personal data pasted into prompts is the highest-risk pattern. Enterprise-tier use with a DPA, a written policy, and data minimization is a different, defensible posture.
Does ChatGPT Enterprise or the API automatically make my company GDPR-compliant?
No. A DPA and enterprise-tier data handling terms are necessary conditions, not sufficient ones. You still need a documented lawful basis for any personal data processed, a policy governing what employees can enter, and a DPIA where the use case triggers one under Article 35.
Do I need a Data Protection Impact Assessment just to use ChatGPT?
Not for every use case. A DPIA is required when the processing involves two or more high-risk factors under Article 35: systematic profiling, automated decisions with legal effect, or large-scale special-category data processing, among others. Routine drafting and summarization tasks typically don’t trigger this. Recruitment screening and automated customer decisions usually do.
What’s the actual risk if we do nothing?
Two separate risks. First, a real data protection failure: sensitive data pasted into a consumer AI tool with no contractual protection, potentially used to train a model or exposed in a provider-side incident. Second, regulatory exposure. Fines under GDPR reach €20 million or 4% of global annual turnover, whichever is higher, for the most serious violations, and both the CNIL and other EU regulators have shown they will act on AI-specific data protection failures.
Kévin Lefèvre

Kévin Lefèvre is a Data Scientist specializing in multimodal document intelligence and large-scale AI pipelines, and an expert AI consultant at Themio, ensuring every platform recommendation is fully traceable to its legal source. EPITA engineering graduate, AWS and Deep Learning certified.

Themio.ai maps your GDPR and AI Act obligations for internal tools and employee workflows, and identifies what policies, contracts, and assessments must be in place (in under 2 minutes), with every finding traceable to the exact article it comes from. See how it works →