The GDPR has been in force since 2018. For years, organisations have been required to manage databases, cookies and user consent. However, the widespread adoption of generative AI tools has introduced a new source of risk that many data protection officers have not yet fully mapped.
When an employee opens ChatGPT and pastes a client’s email into a prompt to draft a reply, they are processing personal data using a third-party tool. The GDPR has something to say about that, and in many cases, the answer is not favourable.
What constitutes data processing in the context of AI?
The GDPR defines the processing of personal data broadly: any operation performed on data that identifies or can identify a natural person. In practice, this includes pasting a customer’s name and email address into a ChatGPT prompt, uploading a contract containing employee data to an AI tool for summarisation, or processing job applicants’ CVs using automated screening systems.
The problem with free AI tools
The free versions of ChatGPT, Gemini and similar tools generally do not meet the GDPR requirements for processing personal data on behalf of an organisation. There are three main reasons.
The first is the absence of a Data Processing Agreement (DPA). Free versions do not provide the data processing agreement required under Article 28 of the GDPR when a third party processes personal data on behalf of an organisation.
The second is the potential use of data for model training. Some free versions state in their terms that user inputs may be used to improve the model, meaning that any information entered by employees could become part of the training process.
The third concerns international data transfers. OpenAI and Google primarily process data on servers located in the United States, which requires appropriate safeguards under the GDPR to ensure that those transfers are lawful.
Do enterprise versions solve these issues?
ChatGPT Enterprise, Microsoft 365 Copilot and Google Workspace for Business are designed to address these concerns. They include Data Processing Agreements, contractual commitments not to use customer data for model training, and mechanisms that support compliance with international data transfer requirements.
However, if an employee uses the free version through a web browser, those safeguards do not apply, even if another department within the organisation has purchased an enterprise licence. In practice, this is one of the most common scenarios.
The specific risks
An organisation may breach Article 28 of the GDPR if employees process personal data using AI tools that do not provide a Data Processing Agreement.
There may also be an unlawful international transfer if personal data is processed on servers located in third countries without appropriate safeguards.
In addition, confidentiality may be compromised when strategic or sensitive information is processed using tools that do not provide contractual guarantees.
These three risks can occur simultaneously during a routine task: an employee simply using the most accessible AI tool to complete their work.
What should organisations do?
The first step is to conduct an audit: identify which AI tools employees are using, what types of data they process, and under what conditions.
The second step is data classification: define which categories of data may be processed and specify which AI tools are authorised for each type.
The third step is to establish a clear AI policy and provide training: document what is permitted, communicate it to employees, and ensure that everyone understands it. A policy that no one knows cannot protect the organisation.
It is not only a data protection issue
It is easy to treat this purely as a legal matter and leave it entirely to the Data Protection Officer. In reality, the issue goes much deeper.
When an employee pastes customer data into a free AI tool, they are not always knowingly breaching the rules. In many cases, they do not realise that they are processing personal data, that there is a significant difference between a free version and an enterprise version, or what actually happens when they click “Send”.
The GDPR establishes the legal boundaries. AI literacy—now a legal obligation in its own right under the AI Act—is what enables people to understand why those boundaries exist.
Complying with the law without educating the people responsible for applying it is like putting up traffic signs for drivers who have never learned the rules of the road.
Frequently Asked Questions
Does using ChatGPT with customer data violate the GDPR?
It can. If personal data is processed using a third-party AI tool without an appropriate legal basis or a signed Data Processing Agreement, there is a potential GDPR breach. The free version of ChatGPT does not provide the contractual safeguards required under the GDPR for processing personal data on behalf of an organisation.
What agreement do I need with an AI provider to comply with the GDPR?
You need a Data Processing Agreement (DPA) that complies with Article 28 of the GDPR. ChatGPT Enterprise, Microsoft 365 Copilot and Google Workspace for Business provide DPAs. Free versions generally do not.
Are transfers of personal data to ChatGPT considered international data transfers?
Yes. OpenAI and Google primarily process data on servers located in the United States. These transfers require appropriate safeguards under the GDPR, such as participation in the EU–US Data Privacy Framework or the use of Standard Contractual Clauses (SCCs). Enterprise services generally provide these safeguards; free versions may not.