Back to Insights
GDPR ·29 August 2026 ·7 min read

Are you allowed to run customer data through ChatGPT?

Under GDPR it's allowed under conditions: a lawful basis, data minimisation, and — when OpenAI acts as a processor — a data processing agreement. But a personal ChatGPT account is not the same as ChatGPT Business, Enterprise or the API.

Yes, GDPR does allow customer data to be processed with ChatGPT in certain circumstances. It is not automatically prohibited, but the organisation needs a lawful basis for the processing, must minimise the personal data being disclosed, needs appropriate security measures and should determine the role played by the AI provider. If OpenAI is processing personal data on your organisation's behalf, a data processing agreement will generally be required.

The version of ChatGPT matters considerably. A personal ChatGPT account is governed differently from ChatGPT Business, Enterprise or the API. Consumer conversations can be used to improve OpenAI's models when the relevant setting is enabled, whereas inputs and outputs from OpenAI's business products and API are excluded from model training by default. ChatGPT Team was renamed ChatGPT Business in August 2025.

Consumer ChatGPT and business AI are not the same thing

A common problem occurs when employees treat the public ChatGPT interface like a search engine and paste customer information into it without considering where that information goes. Personal ChatGPT accounts include a setting called "Improve the model for everyone". When enabled, conversations may be used to improve OpenAI's models. Users can disable this setting. Temporary Chats are not used for model training and are deleted after the applicable retention period described by OpenAI.

Turning off training, however, does not automatically turn a personal ChatGPT account into an appropriate system for confidential customer records. Training is only one part of the privacy assessment. Retention, contractual protections, access controls, security, subprocessors and international transfers matter as well.

It is also misleading to reduce the distinction to "free versus paid". Personal Plus and Pro accounts are still consumer services. The more relevant distinction is between services intended for individuals and products supplied under business terms, including ChatGPT Business, Enterprise and the API.

When do you need a data processing agreement?

If your organisation determines the purpose and essential means of processing customer information and an AI provider handles that information on your behalf, the provider will commonly be acting as a processor. GDPR requires this relationship to be governed by a contract or other legal act containing specific processor obligations.

OpenAI provides a Data Processing Addendum for its business services. The current DPA states that, where OpenAI processes Customer Data on the customer's behalf, OpenAI acts as a data processor. It also addresses matters including security, subprocessors, deletion and international data transfers.

Having a DPA does not make every use of customer data lawful. The controller still has to establish that the information can legitimately be supplied to the processor in the first place. OpenAI's DPA similarly places responsibility on customers for having the necessary rights, notices, consents or other authorisations required to provide the data.

You still need a lawful basis

A secure AI platform and a signed processing agreement do not themselves create a lawful basis under GDPR. Your organisation must be able to explain why the personal data is being processed.

Depending on the circumstances, a lawful basis might include performance of a contract, compliance with a legal obligation, consent or legitimate interests. Legitimate interests require an additional balancing exercise against the interests and fundamental rights of the individual.

Suppose an organisation wants an AI system to summarise an email from a customer. The relevant compliance question is therefore not simply whether the model can perform the task. The organisation should also consider whether disclosing those personal details to an external processor is necessary for the purpose and compatible with the reason the information was collected.

Data minimisation should happen before the prompt

GDPR requires organisations to process only the personal data necessary for the intended purpose. Sending an entire CRM record to a language model when only two sentences need to be categorised is difficult to reconcile with that principle.

A better architecture removes unnecessary information before the API request is made. Names, email addresses, telephone numbers, addresses, account identifiers and financial identifiers can often be removed or replaced. Instead of submitting an entire support history, the system might send only the passage required to perform the particular task.

Pseudonymisation can reduce risk, but pseudonymised information remains personal data when it can be linked back to an individual using additional information. True anonymisation is a much higher threshold. This distinction matters when building AI integrations: privacy protection should ideally be enforced by the application or data pipeline rather than by asking the language model to "ignore personal information" after the information has already been transmitted.

Special-category data changes the risk

Ordinary personal information and special-category data are not treated identically under GDPR. Names, business email addresses and delivery addresses are ordinary personal data. Special categories include information concerning health, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic information, certain biometric information, sex life and sexual orientation.

Processing these categories requires more than the normal Article 6 lawful basis. A separate Article 9 condition must also apply, such as explicit consent or another applicable legal exception.

The everyday word "sensitive" is also broader than GDPR's technical category of special-category data. A customer's bank details, financial difficulties or confidential legal correspondence may not necessarily fall within Article 9, but they can still create substantial privacy and security risks. Criminal-conviction data is subject to a separate GDPR regime as well. This is why healthcare, legal, HR and similarly sensitive workflows require more scrutiny than a generic customer-service question. A DPA alone is not a green light to upload complete files.

Does the data stay in Europe?

The location of processing is another part of the assessment. GDPR establishes additional requirements when personal data is transferred outside the European Economic Area. Depending on the destination and provider, a transfer may rely on an adequacy decision or safeguards such as the European Commission's Standard Contractual Clauses.

Under OpenAI's current DPA, EEA customer data is processed under the agreement through OpenAI Ireland. When that data is subsequently transferred to OpenAI affiliates or third parties outside the EEA, the DPA provides for mechanisms including Standard Contractual Clauses or an applicable European Commission adequacy decision. OpenAI's current subprocessor list also shows infrastructure and processing locations in both Europe and the United States, among other regions.

Consequently, "our supplier has an EU entity" should not be interpreted as "our data can never leave the EU". Organisations should examine the specific product configuration, data-residency options, subprocessors and transfer mechanisms actually being used.

What does a defensible setup look like?

For business processes involving customer information, a controlled business environment is generally easier to govern than allowing employees to use personal ChatGPT accounts independently — the same principle behind air-gapped AI for even more sensitive records.

An API-based workflow can, for example, remove identifiers automatically before making a request, restrict which employees or applications are authorised to access the model, log which categories of information are processed and block particularly sensitive fields. A managed business workspace can similarly provide more appropriate contractual and organisational controls than an unmanaged consumer account.

Governance is still necessary. Organisations should define which AI use cases are permitted, which categories of customer information may be processed, which information must never be submitted, which provider and configuration are approved and what retention rules apply. The useful compliance question is therefore not simply, "Can ChatGPT receive personal data?" It is: "Can we demonstrate that this particular processing operation is lawful, necessary, proportionate, contractually controlled and adequately protected?"

Conclusion

Yes, GDPR can permit customer information to be processed through ChatGPT or the OpenAI API, but organisations should not treat a personal consumer account as interchangeable with a managed business service. Establish a lawful basis, minimise the information sent, use an appropriate data processing agreement when OpenAI acts as a processor, secure the workflow and address international data transfers. Apply considerably greater scrutiny to special-category or otherwise sensitive information. This is general information rather than legal advice; before customer data is routinely processed through an external AI service, have the actual contracts, data flows and technical setup reviewed for your organisation's specific legal situation.

GDPR-proof AI for customer data

Not sure if your AI usage is GDPR-proof?

We help with data minimisation, processor agreements and an architecture where customer data doesn't just flow into an external API by default. Want us to review this for your organisation?