Guide

    Is ChatGPT GDPR-compliant?

    Not as such. The consumer version is usually not GDPR-compliant for personal data; the business versions can be, with the right settings and a data processing agreement.

    S

    Soren Colton · updated 10 August 2026 · 9 min read

    Short answer

    ChatGPT is not GDPR-compliant as such. The consumer version usually isn't for personal data: training is on by default and there is no data processing agreement. The business versions (Business, Enterprise, the API) can be GDPR-compliant, with the right settings and a data processing agreement.

    Free, Plus and Pro (consumer)
    Usually not GDPR-compliant: training on by default, no data processing agreement
    Business, Enterprise and the API
    Can be GDPR-compliant, with the right settings and a data processing agreement
    Without personal data
    No GDPR issue, in any version
    When in doubt
    Don't paste it, or anonymise first

    Picture this: Laila works at an advisory firm. Friday afternoon, four o'clock. She pastes a client note with names and a few private details into the free version of ChatGPT and asks for a tidy summary. Done in seconds. Handy. Until a colleague asks: is that actually allowed under the GDPR?

    The honest answer is not black and white. Together, the version you use and what you put into it decide whether it's fine or better avoided. Below you'll read what the GDPR actually asks, where ChatGPT falls short, and how to capture conversations safely.

    One thing first: this is general information based on the GDPR, the European supervisory authorities and OpenAI's own policies, checked in August 2026. It is not legal advice for your situation. In the United Kingdom, the UK GDPR sets out the same rules.

    What does GDPR-compliant actually mean?

    GDPR-compliant means you process personal data in line with the General Data Protection Regulation: with a lawful basis, with the right agreements in place, and without the data ending up somewhere you no longer control.

    Personal data is any information about an identifiable person: a name, an email address, a case file, a health detail. If none of that is in your input, the GDPR is not an issue for that one prompt. If it is, the rules below apply.

    What does the GDPR ask when you use AI?

    The GDPR does not change because the label says AI. As soon as personal data goes in, the same rules apply as always. Whether you call it ChatGPT or simply an AI tool, the same four requirements apply.

    • A lawful basisA valid reason to process the data (GDPR Article 6).
    • Data minimisationYou process no more than your purpose needs.
    • A data processing agreementWith the party that processes the data on your behalf (GDPR Article 28).
    • Sight of your dataYou know where the data goes and how long it is kept.

    When does ChatGPT become a GDPR problem?

    ChatGPT mainly runs into trouble in two places: the consumer version, and sensitive content. Three things deserve attention.

    Training on your input

    In the consumer versions (Free, Plus and Pro), OpenAI can use your conversations by default to improve its models, unless you switch that off yourself under "Improve the model for everyone". In the business versions (Business, Enterprise and the API), it is off by default. Switching it off works for new conversations, not retroactively.

    The data processing agreement

    For the consumer version, OpenAI does not enter into a data processing agreement. Process personal data there and you are missing exactly the agreement the GDPR requires. For Business, Enterprise and the API, the agreement exists. What belongs in a data processing agreement, we cover separately.

    Where your data goes

    Deleted chats are removed within 30 days (unless a legal hold forces longer retention), but for consumers the processing runs on servers outside the EEA, mostly in the United States. European data residency exists, but only for Enterprise, Edu and the API; the consumer version offers no such choice. You can read why data location and jurisdiction matter at keep your data in the EU.

    The supervisory authorities have been clear. The Dutch supervisory authority warns that pasting personal data into an AI chatbot can itself be a data breach, and has received reports of exactly that. The ChatGPT taskforce of the European supervisory authorities set out its preliminary view in May 2024 that responsibility for GDPR compliance rests with OpenAI and must not be shifted onto the user. And the Italian authority fined OpenAI 15 million euros in late 2024 over training, transparency and age verification; a court set that decision aside in March 2026 on competence grounds, and the file now runs through the Irish regulator. The question on this page is genuinely open at the highest level.

    What can you do instead?

    You can use AI in a perfectly GDPR-compliant way. It just takes a few choices up front.

    • Keep personal data outThe simplest: put no personal data in a free consumer chatbot. Take names and details out, or make them unrecognisable, before you paste anything.
    • Or choose a business versionIf you do want to work with real data, use a business version with a data processing agreement and switch training off.
    • Or choose a tool that has this sortedA tool that processes in the EU, does not train on your data and comes with a data processing agreement. European alternatives exist, from national language models to tools built for one task.

    Six myths, and the facts.

    Plenty of half-truths circulate about ChatGPT and the GDPR. Below are the most popular ones, with what is actually true.

    Six claims about ChatGPT and the GDPR, with a verdict and explanation, sources checked August 2026
    Claim Is it true? Why
    "ChatGPT is simply banned for work." Not true It depends on the version and what you put in. Without personal data, or with a business version plus a data processing agreement, it can be fine.
    "Paying for Plus makes it safe enough." Not true Plus is still the consumer version: training is on by default and there is no data processing agreement. Paying is not the same as business.
    "OpenAI trains on everything you type anyway." Partly true In the consumer versions usually yes, unless you switch it off. On Business, Enterprise and the API, training is off by default. It differs per version.
    "My data is safe as long as it sits in an EU region." Not true An EU region settles where your data sits, not which law the company answers to. You can read why that matters at keep your data in the EU.
    "Under the GDPR, an AI simply may not process personal data." Not true It may, with a lawful basis and the right agreements. The GDPR does not ban AI; it sets conditions.
    "If I delete the chat, my data is gone." Partly true Deleted chats normally go within 30 days, but what already sits in a training set does not come back out. And the pasting itself can already count as a data breach.

    Under all those myths sits one pattern: the problem is rarely AI as such. It sits in the version, and in what you put into it.

    Is your AI use GDPR-compliant?

    Run through these five questions before you paste anything into an AI tool. Five times yes and you are probably fine. One no, and there is work to do.

    1. Is there personal data in what I am entering (a name, a case file, a health detail)? If so, read on.
    2. Am I using a business version, not a free consumer account?
    3. Do I have a data processing agreement with the provider?
    4. Is training on my input switched off?
    5. Do I know where my data is processed and how long it is kept?

    This is the short version. For a step-by-step way to assess a tool, on the processor, the technology and the retention period, read how Notuly handles security.

    ChatGPT is not one thing, it's two.

    This is what most people miss. The same name, the same interface, but the consumer version and the business version treat your data in opposite ways. With one, training is on by default and there is no data processing agreement; with the other, training is off and the agreement exists.

    That is why "is ChatGPT GDPR-compliant" has no yes-or-no answer. The real question is: which ChatGPT, and for what.

    When ChatGPT is a perfectly good choice.

    For a great deal of work, ChatGPT is a fine choice, and we are honest about that. Rewriting a blog post, summarising a public report, explaining code, tidying up an email, brainstorming without sensitive content: the GDPR is no issue there, simply because no personal data goes in.

    The business ChatGPT (Enterprise) is technically strong and well secured too, with a data processing agreement, configurable retention and European data residency. It pinches in one place: confidential conversations and personal data in the consumer version. That calls for different tooling.

    If you want to use ChatGPT to turn a conversation into a report, more comes into play than the GDPR alone. We make that comparison separately at ChatGPT for meeting notes.

    How to capture conversations safely.

    For a sensitive conversation you want to worry about the conversation, not about the technology behind it. That is why we made Notuly the way we did: the AI notetaker for every conversation, discreet in-person, hybrid and online. At the table you put your phone in the middle; for meetings via Teams, Zoom or Google Meet you use the desktop app for macOS and Windows.

    This is what that looks like on a Tuesday. Half past two, a conversation at the table. The phone lies in the middle. Sam presses the record button and the conversation simply carries on.

    An hour later the recording stops, and within ten minutes the meeting report is in everyone's inbox: the summary, the decisions and the action points with an owner and a deadline ("Sam sends the proposal to Ben on Friday", "Nora schedules the follow-up for Tuesday"). If you choose, the transcript comes along as a .txt attachment. Notuly understands more than 90 spoken languages and delivers the report in English or Dutch.

    What you don't see is the route underneath. The whole AI step, from speech to text to the summary, runs on our own models on servers in Amsterdam. Your conversations are not used as training data and are not for sale, and the audio is deleted within a minute of processing: no archive, no searchable storage. What's said stays yours.

    Run the self-test above and every question is answered in advance. The data processing agreement (GDPR Article 28) is available on Team and above: exactly the document the GDPR asks of your organisation. No setting you have to get right yourself.

    Read how Notuly keeps conversations secure →

    Sources.

    Based on public, authoritative sources, checked August 2026. Law and company policy change; check the source for the current position.

    General information based on the sources above, not legal advice.

    Frequently asked questions.

    Is ChatGPT GDPR-compliant?+

    Not as such. The consumer version is usually not GDPR-compliant for personal data, because training on your content is on by default and there is no data processing agreement. The business versions (Business, Enterprise, the API) can be GDPR-compliant, with the right settings and a data processing agreement.

    Can I put client data into ChatGPT?+

    Better not, in the consumer version. You have no data processing agreement and your input can be used for training, which European regulators treat as a possible data breach. With a business version plus a data processing agreement, or after anonymising, it can be done.

    Where does ChatGPT store my data, and for how long?+

    Deleted chats are removed from OpenAI's systems within 30 days, unless OpenAI is legally required to retain them. For consumers, processing runs on servers outside the EEA, mostly in the United States. European data residency exists for Enterprise, Edu and the API (as at August 2026); ChatGPT Business and the consumer versions do not offer it.

    What is a GDPR-compliant alternative to ChatGPT?+

    A GDPR-compliant alternative processes in the EU, does not train on your data and comes with a data processing agreement. The options range from European language models to tools built for a single task. Notuly is such a tool for capturing conversations.

    Can I have a report of a conversation written by AI?+

    Yes, if you do it properly. If you are allowed to record the conversation, you process it with a provider under a data processing agreement, and the data stays under control, an AI-written report can be perfectly GDPR-compliant.

    What is zero retention?+

    Zero retention means your data is not kept once the task is done. With Notuly, the audio is deleted within a minute of processing and there is no searchable archive: what remains is the report, in the inboxes you choose.

    Does OpenAI train on what I type, and can I switch that off?+

    In the consumer versions, yes, by default (as at August 2026), unless you switch it off under "Improve the model for everyone". On Business, Enterprise and the API, training is off by default. Switching it off works for new conversations, not retroactively.

    Do I need a data processing agreement for ChatGPT?+

    If you process personal data in it, yes. The GDPR requires a data processing agreement with the party that processes on your behalf (Article 28). The consumer version does not come with one; Business, Enterprise and the API do.

    Is pasting personal data into ChatGPT a data breach?+

    It can be. European supervisory authorities warn that entering personal data into an AI chatbot can itself amount to a data breach, especially on consumer versions where it is unclear what happens to the data. When in doubt: don't, or anonymise first.

    Do we get a data processing agreement with Notuly?+

    Yes. A data processing agreement (GDPR Article 28) is available on Team and above: exactly the document the GDPR asks of your organisation. Processing runs on Dutch servers in Amsterdam and Notuly does not train on your conversations.

    What does a GDPR-compliant notetaking tool like Notuly cost?+

    With Notuly you start free: three conversations per month, no payment details needed. Paid plans are per licence, with one invoice for teams; the current prices are on the pricing page.

    Capture conversations without thinking about a setting.

    Phone on the table or the desktop app on. The report is made in Amsterdam, never leaves the EU, and the audio is deleted within a minute of processing. Three conversations free, no payment details needed.