GDPR

Is ChatGPT GDPR compliant for businesses?

GDPR compliance is not a feature of a piece of software: it is the organisation, as controller, that has to demonstrate it. This guide covers the legal texts, the guidance of France’s data protection authority (CNIL) and what OpenAI provides for its business plans.

Published on Updated on 6 min readBy the Tacite-IA editorial team

Contents
  1. ChatGPT and the GDPR: the right question
  2. Controller and processor
  3. What France’s CNIL recommends for generative AI
  4. What OpenAI provides for businesses
  5. Data transfers outside the European Union
  6. Data breaches and penalties
  7. The steps towards compliant use
  8. Frequently asked questions
  9. Sources

“Is ChatGPT GDPR compliant?” is one of the questions most often asked by business leaders and data protection officers. It calls for a two-part answer: what the vendor makes available, and what the organisation must do itself. The regulation does not certify software: it governs the processing of data, for which the organisation remains responsible.

ChatGPT and the GDPR: the right question

The GDPR does not provide for a “compliant” label awarded to a tool. It sets out principles (lawfulness, purpose limitation, data minimisation, security and so on) that any processing of personal data must respect (Article 5).1 The useful question therefore becomes: does the way my organisation uses ChatGPT comply with the GDPR?

The answer depends on three things: the plan used (personal account or business plan), the data sent (brainstorming ideas is not the same as a payroll file), and the framework put in place around it (rules, information, oversight).

Controller and processor

When an employee uses ChatGPT for work, the organisation determines the purpose of the processing: in principle, it is the controller. The GDPR requires it to implement appropriate measures and to be able to demonstrate compliance (Article 24).1 When it entrusts data to a provider that processes it on its behalf, a contract must govern that processing (Article 28).1

This is where the type of account changes everything. With a business plan, the organisation can sign that contract with the vendor. With an employee’s personal account, there is no agreement between the organisation and the vendor: the data leaves outside any contractual framework, and the applicable terms are those of the consumer services.12

What France’s CNIL recommends for generative AI

In its Q&A of 18 July 2024 on the use of generative AI systems, the CNIL (the French data protection authority) makes several recommendations2:

  • govern use through internal policies or charters that clearly define permitted and prohibited uses;
  • for non-confidential uses, a consumer service may be considered with dedicated work email addresses and appropriate safeguards, avoiding accounts created with personal addresses and, where applicable, turning off reuse of the data by the provider;
  • involve the data protection officer and, where appropriate, carry out a data protection impact assessment (DPIA);
  • train users and make them accountable for how the tool works, its limits and its permitted uses.

Above all, the CNIL points out that the user organisation bears legal responsibility if its staff misuse AI.2 It has also published guidance sheets to help small and medium-sized businesses use generative AI.11

What OpenAI provides for businesses

For ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu and its API platform, OpenAI states that it does not train its models on customer data by default, and that it can sign a data processing addendum (DPA) “to support their compliance with the GDPR” for ChatGPT Business, ChatGPT Enterprise and the API.3 The vendor also mentions encryption of data at rest and in transit and a SOC 2 audit.3 For some eligible Enterprise, Edu and API customers, content can be stored at rest in Europe.4

Other vendors offer comparable frameworks for their business plans. Microsoft, for example, places Copilot under its Data Protection Addendum, with Microsoft acting as processor.13 These safeguards are real, but they only cover accounts subscribed to by the organisation. They say nothing about personal accounts used by employees outside any contract.

Data transfers outside the European Union

The GDPR governs transfers of data to third countries (Articles 44 to 46).1 For the United States, the European Commission adopted an adequacy decision on 10 July 2023, the EU-US Data Privacy Framework.5 On 3 September 2025, the General Court of the European Union dismissed an action for annulment of that decision (Latombe case).6 The framework is therefore in force at the time of writing; it is still worth checking, for each provider, what legal basis its transfers rely on.

Data breaches and penalties

Pasting a customer file into an unauthorised service may constitute a personal data breach. The GDPR then requires the organisation to notify the supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals (Article 33).1

72hours
  1. Hour 0 The organisation becomes aware of the breach (for example, a customer file pasted into an unauthorised service).
  2. Assess Which data, how many people, what risk to their rights and freedoms?
  3. 72 hours at most Notification to the supervisory authority, unless the breach is unlikely to result in a risk.
The deadline for notifying a personal data breach to the supervisory authority (the CNIL in France) under GDPR Article 33. Source 1.

The maximum amounts of administrative fines are set by Article 83:

€20m
Maximum fine
For the most serious infringements (Article 83(5)).
4%
of total worldwide annual turnover
For an undertaking, if this amount is higher.
72h
To notify a breach
At the latest, after becoming aware of it (Article 33).
Figures taken from the GDPR (source 1). These are legal ceilings, not typical amounts.

Authorities have already taken up the issue. In Italy, the Garante (the Italian data protection authority) imposed a EUR 15 million fine on OpenAI in December 2024; it was later annulled by the Court of Rome, in a judgment published on 18 March 2026.7,8 Above all, this case shows that the relationship between generative AI and the GDPR is still taking shape.

The steps towards compliant use

There is no single procedure, but the obligations of the GDPR and the recommendations of the French CNIL outline a coherent path.1,2 Bear in mind the European AI Act as well: its Article 4 on AI literacy has applied since 2 February 2025.9 It was rewritten by Regulation (EU) 2026/1744: organisations must take measures to support the development of AI literacy among their staff, without any obligation to guarantee a specific level for each person.10

  1. Map current useWho uses which tool, for which tasks, with which data.
  2. Choose a contractual frameworkBusiness plan and data processing agreement (Article 28).
  3. Record the processingPurposes, categories of data, recipients, transfers (Article 30).
  4. Assess the need for a DPIAImpact assessment if the processing is likely to result in a high risk (Article 35).
  5. Set internal rulesPolicy: permitted uses, prohibited uses, data never to be entered.
  6. Inform and trainInformation for data subjects and AI literacy for teams.
  7. Secure and reviewTechnical measures appropriate to the risk (Article 32) and regular review.
A typical path, built from Articles 28, 30, 32 and 35 of the GDPR and the recommendations of the French CNIL (sources 1 and 2).

The last step deserves particular attention. Written rules are not enough if nothing helps employees at the moment they paste a text. On-device control tools can detect personal data before it is sent and offer to anonymise it; Tacite-IA is one of them, alongside the policy, training and the choice of business plans.

Frequently asked questions

Is ChatGPT GDPR compliant?

The GDPR does not certify tools: it governs processing. It is the organisation, as controller, that must demonstrate that its use is compliant. OpenAI’s business plans provide useful elements (no training by default according to the vendor, a data processing agreement available), but the organisation must also set rules, inform people and minimise the data it sends.

What does France’s CNIL say about ChatGPT and generative AI?

In its Q&A of 18 July 2024, the CNIL, the French data protection authority, recommends governing use through an internal policy, involving the DPO, carrying out an impact assessment where needed and training users. It points out that the user organisation is responsible if its staff misuse the tool.

Do you need a DPIA to use ChatGPT?

Not systematically. Article 35 of the GDPR requires one when processing is likely to result in a high risk to individuals. The French CNIL recommends carrying one out where appropriate, involving the data protection officer.

Is an employee pasting customer data into ChatGPT a data breach?

It can be, depending on the data and the service used. If so, and if there is a risk to individuals, Article 33 of the GDPR requires the organisation to notify the supervisory authority within 72 hours of becoming aware of it.

Sources

  1. Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). EUR-Lex. Accessed on 5 October 2026.
  2. Les questions-réponses de la CNIL sur l’utilisation d’un système d’IA générative. CNIL (French data protection authority), 18 July 2024. In French. Accessed on 5 October 2026.
  3. Enterprise privacy at OpenAI. OpenAI, page updated on 8 January 2026. Accessed on 5 October 2026.
  4. Business data privacy, security, and compliance. OpenAI. Accessed on 5 October 2026.
  5. Press release IP/23/3721: adequacy decision for EU-US data flows. European Commission, 10 July 2023. Accessed on 5 October 2026.
  6. Press release No 106/25, Case T-553/23, Latombe v Commission. General Court of the European Union, 3 September 2025. Accessed on 5 October 2026.
  7. Press release of 20 December 2024 and notice of withdrawal of provvedimento no. 755. Garante per la protezione dei dati personali (Italian data protection authority). In Italian. Accessed on 5 October 2026.
  8. Tribunale Roma annulla multa da 15 milioni di euro del Garante Privacy a OpenAI. ANSA, 20 March 2026. In Italian. Accessed on 5 October 2026.
  9. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). EUR-Lex. Accessed on 5 October 2026.
  10. Regulation (EU) 2026/1744 of 8 July 2026 (digital omnibus on AI). EUR-Lex. Accessed on 5 October 2026.
  11. Utiliser l’IA générative dans les TPE et PME. CNIL (French data protection authority). In French. Accessed on 5 October 2026.
  12. How OpenAI handles data in consumer services. OpenAI Help Center. Accessed on 5 October 2026.
  13. Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat. Microsoft Learn. Accessed on 5 October 2026.
One measure among others

Govern AI use without slowing your teams down

Tacite-IA detects sensitive data in messages and files before they are sent to AI assistants in Chrome and Edge, and in coding assistants (Claude Code, Cursor, Windsurf, Codex, Gemini CLI, Copilot CLI). Analysis runs 100% on the device, with no AI, and comes with an admin console and an audit mode. Desktop apps (the ChatGPT desktop app, the Chat tab in Claude Desktop, Copilot in Windows) are not covered.

€6 excl. VAT per user per month billed annually, €8 excl. VAT billed monthly. 3-month trial.

Further reading