ChatLock

Is ChatGPT GDPR Compliant? What European Businesses Need to Know

Can you use ChatGPT at work without breaking GDPR? A clear look at training, data transfers, retention and the Italian fine, plus a checklist for choosing a GDPR-friendly AI assistant.

8 min read

European companies adopting AI keep asking the same question: can we use ChatGPT and still comply with the GDPR?

It depends on which version you use, what data you put into it, and what controls you have around it. ChatGPT is legal in Europe. Using the consumer version with personal data and no internal controls, though, is very hard to defend in front of a data protection authority.

This guide explains why, and what a GDPR-friendly setup looks like.

When the GDPR applies

The GDPR applies as soon as you process personal data: a client's name in an email you ask ChatGPT to rewrite, a CV you ask it to summarise, a customer complaint you paste in for a draft reply. In all those cases your company is the data controller, and the AI provider is at best your processor.

So you need to be able to answer these questions, with evidence:

  • What is the legal basis for sending this data to the AI provider?
  • Is there a Data Processing Agreement (DPA) in place?
  • Where is the data processed, and is the transfer outside the EU lawful?
  • How long is it kept, and is it reused for other purposes such as model training?

If you can't answer them, the gap is in your compliance file, whatever tool you use.

What European regulators have already done

ChatGPT has a history with EU regulators:

  • In March 2023, the Italian data protection authority (Garante) temporarily blocked ChatGPT in Italy over the lack of a legal basis for training, missing age verification and transparency issues. The service returned a month later after OpenAI made changes.
  • In December 2024, the Garante fined OpenAI €15 million for GDPR violations linked to how personal data was used to train ChatGPT. OpenAI announced it would appeal.
  • The European Data Protection Board set up a ChatGPT taskforce to coordinate investigations across member states.

You can still use the tool. Regulators are watching, though, and "everybody uses it" won't work as a defence.

Consumer ChatGPT vs. business plans

The distinction that matters most is between the consumer product (Free and Plus) and the business offerings (Team, Enterprise, API).

With consumer ChatGPT, conversations can be used to improve OpenAI's models unless the user opts out in settings. There is no DPA between your company and OpenAI, because the contract is between OpenAI and the individual employee. And your company can't see what employees paste in.

Business plans and the API don't use your data for training by default, come with a DPA, and on some plans offer European data residency.

If your team uses personal ChatGPT accounts for work, you almost certainly have a GDPR gap. Moving to a business plan closes part of it.

What a business plan leaves open

Even with a DPA and no training, three structural issues remain.

The provider can still technically access your data. Prompts are decrypted on the provider's servers to run the model, and what limits access is policy and contract. For sensitive data (health, legal, HR, financial), you need to document that risk in your Data Protection Impact Assessment.

Someone else decides on retention. Even "deleted" conversations may be retained for abuse monitoring or because of legal obligations. In 2025, a US court order in the New York Times lawsuit temporarily required OpenAI to preserve consumer ChatGPT conversations, including deleted ones, so users' retention depended on a US court.

OpenAI is a US company. Even with EU data residency, laws such as the US CLOUD Act can give US authorities a route to request data held by US providers. Since the Schrems II ruling, every DPO has to assess this.

A GDPR checklist for any AI assistant

Before approving an AI tool for work involving personal data, check:

  1. A DPA is available and signed with your organisation, not with individual users.
  2. Your data is not used for training, by default and in writing.
  3. You know where inference runs and which law governs the provider.
  4. You know how long prompts, files and outputs are kept, and whether you can verify deletion.
  5. You know whether the provider's staff or the cloud provider can technically read your data.
  6. You can find, export and delete data relating to a specific person.
  7. An internal policy says which data categories employees may and may not enter.

Most tools meet the first two today. Points 3 to 5 are where they usually fall short.

Making access technically impossible

Article 25 of the GDPR asks for data protection by design and by default. You meet it most convincingly when nobody can technically access the data, which is a stronger position than a contract forbidding them to.

ChatLock is built that way. Prompts are encrypted in your browser and only decrypted inside a hardware-secured enclave (a Trusted Execution Environment) where the model runs. Neither ChatLock, the cloud provider nor the model's developer can read the data while it's processed, and you can verify this through cryptographic attestation. Nothing is retained after the response or used for training. Your chat history is stored locally, encrypted with a key only you hold. Processing can stay within the European Union, and business customers get a DPA.

For the technical details, read our guide to confidential computing.

FAQ

Is ChatGPT banned in the EU?

No. ChatGPT is legally available in all EU countries. It was temporarily blocked in Italy in 2023, and OpenAI has been fined there, but companies can use it as long as they meet their own GDPR obligations.

Can I put customer data into ChatGPT?

Not into personal, consumer accounts. With a business plan and a DPA it can be possible, but you should still assess the risk, minimise the data and document the decision. For special categories of data, use a tool where the provider cannot access the content.

Does ChatGPT Enterprise solve GDPR?

It solves the most obvious problems (training, DPA, data residency). Provider access and US jurisdiction remain, and whether that is acceptable depends on the data you process and your risk assessment.

What is a GDPR-compliant alternative to ChatGPT?

Look for an assistant that offers a DPA, EU processing and no training, and ideally end-to-end encryption with confidential computing, so compliance doesn't rest only on the provider's promises. ChatLock was built for this.