This article provides general informational guidance. See Legal Disclaimer .
- GDPR compliance is a property of how your company configures and uses ChatGPT, Copilot, or Gemini, not of the tools themselves. The same tool can be compliant in one company and a live breach risk in the next.
- The two decisions that matter most: which plan you’re on (consumer vs. enterprise/API with a Data Processing Agreement), and what your employees actually paste into the prompt box.
- 77% of employees who use AI tools at work have pasted company or customer data into a prompt, and most of those pastes happen from personal, unmanaged accounts your company can’t see or control.
In brief: Consumer ChatGPT, free-tier Copilot, and personal Gemini accounts process your prompts under the provider’s own terms, not yours. There’s no Data Processing Agreement in place, no contractual guarantee your data won’t train future models, and no audit trail. Enterprise and API tiers change this, but only if your company configures them and writes a policy employees follow.
Key takeaways
- There’s no single “GDPR-compliant” checkbox for an AI chatbot. Compliance depends on your account tier, your Data Processing Agreement, your written policy, and what data flows into it.
- A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 when AI use involves systematic profiling, automated decisions with legal effect, or large-scale sensitive data processing. That’s not every chatbot use case, but it reaches further than most companies expect.
- The CNIL and the EDPB both published guidance in 2025 on how GDPR applies to AI system development and use. A company can no longer claim this is a grey area it didn’t know about.
The Real Question: Is Your Use of ChatGPT Compliant
Ask ten SMEs whether ChatGPT is GDPR-compliant and you’ll get ten different answers, because it’s the wrong question. OpenAI, Microsoft, and Google all offer enterprise agreements with Data Processing Agreements (DPAs), EU data residency options, and commitments not to train models on your inputs. They also all offer free or consumer-grade tiers with none of that. The tool is the same underlying model. The compliance posture depends on which door your employees walked through, and whether anyone in your company decided that on purpose.
Most SMEs haven’t decided on purpose. An employee finds ChatGPT useful, signs up with a personal email, and starts using it for real work within a week. Multiply that across a team, and compliance ends up with an AI processing operation nobody has documented, nobody manages, and nobody can audit, running through browser tabs the compliance team has never seen. For a broader look at baseline requirements, consult our GDPR Compliance Checklist for SMEs .
What determines compliance, concretely
1. Legal basis for processing
If personal data (customer names, employee records, candidate CVs) goes into a prompt, you need a lawful basis under GDPR Article 6: typically legitimate interest or consent, documented rather than assumed. The CNIL’s February 2025 recommendations on AI and data subject rights are the clearest current guidance on how this applies in practice. “We didn’t think about it” is no longer a defensible position for a company operating in France.
2. Data Processing Agreement (DPA)
Enterprise and API-tier agreements from OpenAI, Microsoft (Copilot for Microsoft 365), and Google (Gemini Enterprise) include a DPA defining who’s the controller, who’s the processor, and what happens to your data. Consumer tiers generally do not. If your company’s real AI usage runs through unmanaged personal accounts, no DPA covers that usage, regardless of what your enterprise contract says on paper.
3. Training data opt-out
Even on paid tiers, training-data behavior varies by provider and product. Confirm in writing, not by assumption, whether prompts and outputs are used to improve the underlying model. For any tool processing client or employee data, get a documented “no,” or put a compensating control in place if you can’t. When reviewing software options, explore our AI Act compliance tools buyer's guide .
4. Data minimization at the point of use
This is the control most companies skip, and the one that matters most day to day. A written policy telling employees what can and can’t go into a prompt — no client PII, no unreleased financial data, no health or biometric data — reduces real exposure more than any contract clause. A contract doesn’t stop someone pasting a spreadsheet at 6pm to save time.
5. DPIA triggers
Under Article 35, a DPIA is required when processing involves two or more of: systematic evaluation or profiling, automated decision-making with legal or similarly significant effects, large-scale processing of special-category data, or innovative technology use at scale. Using an AI chatbot to draft internal emails doesn’t trigger this. Using AI to screen job applicants, score customer creditworthiness, or make automated decisions about individuals very likely does.
A practical DPIA-trigger table
| Use case | Likely DPIA trigger? | Why |
|---|---|---|
| Drafting internal emails or documents | ❌ No | No profiling, no automated decision, no special-category data at scale |
| Summarizing customer support tickets | ⚠️ Usually no, review if PII-heavy | Depends on volume and data sensitivity |
| Screening CVs or ranking candidates | ✅ Yes | Automated evaluation with effects on individuals |
| Chatbot handling customer service with account access | ⚠️ Often yes | Personal data at scale, potential profiling |
| Internal code generation, no personal data | ❌ No | No personal data involved |
| Fraud-risk or credit scoring assistance | ✅ Yes | Automated decision-making with legal/financial effect |
What to actually do this month
- Find out what’s really being used. Ask department heads which AI tools their teams use day to day, not what IT approved. Expect the answer to include tools nobody signed off on.
- Move real usage onto enterprise/API tiers with a signed DPA. If a tool is genuinely useful to the business, pay for the version that comes with a contract, not the free one that doesn’t.
- Write a one-page usage policy. What can go into a prompt, what can’t, who to ask when unsure. A short policy people actually read beats a long one nobody opens.
- Run the DPIA-trigger check against your real AI use cases , not a generic list. Document the ones that don’t trigger a DPIA too — that documentation is itself evidence of a compliance process if you’re ever asked.
- Revisit your AI literacy record under Article 4 of the EU AI Act. Article 4 requires organizations to ensure sufficient AI literacy among staff using AI systems, and it has applied since 2 February 2025. A ChatGPT usage policy with no training or documented awareness effort behind it doesn’t satisfy this requirement. Follow our roadmap in the guide to complying with the EU AI Act in 5 steps .
Frequently Asked Questions
Is it illegal to use ChatGPT at work under GDPR?
Does ChatGPT Enterprise or the API automatically make my company GDPR-compliant?
Do I need a Data Protection Impact Assessment just to use ChatGPT?
What’s the actual risk if we do nothing?
Themio.ai maps your GDPR and AI Act obligations for internal tools and employee workflows, and identifies what policies, contracts, and assessments must be in place (in under 2 minutes), with every finding traceable to the exact article it comes from. See how it works →
This article provides general information to help you understand GDPR and AI compliance obligations. It does not constitute legal advice and does not replace review by a qualified lawyer, DPO, or compliance specialist familiar with your organization's specific situation. Regulatory requirements and thresholds can change — always verify current obligations against primary legal sources. Last reviewed: August 31, 2026.