Can we use ChatGPT under GDPR?
Yes, often, with the right plan and contracts in place. But not the free version, and not for all data. Here is how to draw the line for your company.
Yes, in many cases, but it comes down to three things: which version you use, what data you send in, and which contracts you have in place. The free version and Plus lack a data processing agreement and are effectively ruled out for personal data. The business versions (Team, Enterprise and the API) do not train on your data by default, offer a DPA, and can be configured for data processing within the EU. But for sensitive personal data and confidential material, a structural problem remains: your data is processed by a US company under a transfer framework that is currently under review. Getting this wrong can cost up to 4 percent of global turnover or 20 million euros, whichever is higher.
What does GDPR require when we use an AI service?
When your employees send text to ChatGPT, your company is the data controller and OpenAI the data processor. That triggers four basic requirements: a data processing agreement (DPA) under Article 28, a legal basis for the processing, information to the data subjects, and a data protection impact assessment (DPIA) if the processing carries high risk. If data leaves the EU/EEA, the rules on third country transfers apply on top.
Enforcement is not theoretical. Italy's data protection authority fined OpenAI 15 million euros in December 2024, and the Irish DPC is now the lead supervisory authority for OpenAI in Europe.
Does it matter which ChatGPT version we use?
It is the single most important question. The differences are significant:
| Version | Data processing agreement (DPA) | Trains on your data | Data storage in the EU |
|---|---|---|---|
| Free / Plus | No, consumer terms | Yes, unless disabled per account | No |
| Team / Business | Yes | No, by default | Depends on plan, must be verified |
| Enterprise | Yes | No, by default | Yes, as an option for new workspaces |
| API | Yes | No, by default | Yes, per project and endpoint |
Two things to note. EU residency is never the default: it has to be actively configured per workspace or project, and only covers certain features and endpoints. And the most common mistake is not choosing the wrong plan, it is employees using private Plus accounts with customer data. Consumer terms are not a data processing agreement, no matter what the account costs.
Isn't the problem solved if OpenAI doesn't train on our data?
No. Training is one of five questions. Still open: where the data is actually processed, how long it is stored, which subprocessors are involved (OpenAI's infrastructure effectively runs on Microsoft), and the biggest question of all: the legal basis for transferring data to the US in the first place.
What is happening with EU-US transfers right now?
Today's transfers rest on the EU-US Data Privacy Framework, the third framework of its kind. Safe Harbor was invalidated in 2015 and Privacy Shield in 2020, both after legal challenges. The EU General Court upheld the current framework in September 2025, but in June 2026 the US Supreme Court struck down the independence of the FTC, the American oversight body, and precisely that independence is a load-bearing part of the EU's adequacy decision. The European Data Protection Board has demanded that the Commission review the decision, and a new legal challenge is being prepared.
The framework remains in force for now, and you do not need to switch legal basis today. But history speaks clearly: do not build your long-term AI strategy on the assumption that it survives.
What data should never be sent to cloud-based AI?
Regardless of contracts, there are categories where the risk is rarely worth it: special categories of personal data under Article 9 (health, trade union membership, ethnicity and more), information under statutory confidentiality in healthcare, legal services and defence-adjacent work, plus source code and trade secrets. The last two are not a GDPR issue, but the risk profile is the same: the information leaves your control. Organisations under NIS2 or DORA also have their own requirements on supply chain control.
When is the cloud still the right choice?
More often than you might think. For marketing copy, general research, ideation and code without secrets, ChatGPT Enterprise or the API with a signed DPA, training disabled, EU residency and a clear internal policy is both cheaper and simpler than running your own infrastructure. If your data can tolerate being handled by a US company with the right contracts in place, use the cloud. Buying your own AI infrastructure for data that does not need it is the wrong call.
When does the AI need to run inside your own walls?
When the answer to "can this leave the building?" is no, regardless of what contracts exist. Then neither a DPA nor EU residency helps, because the core problem is that a third party processes the data at all. It also applies if you want to stop monitoring every contract change, every new subprocessor and every turn in the transfer saga: if you own the whole chain, there is no third country transfer to assess.
How we solve it with Blackbox
Blackbox is a machine we deliver to your office. It runs KairosOS with Chat, Index and Codex: an AI workspace for the whole team, on hardware you own. Prompts, documents and code never leave the building. No API keys, no cloud, no third country transfer to assess. Fully air-gapped environments are updated via cryptographically signed deliveries on USB.
We are happy to bring a Blackbox to your office and show it live. Book a demo or read more about the software at kairos.athlas.io.
Quick checklist before letting ChatGPT in
- A business agreement with a signed DPA. Never private accounts at work.
- Training on your data confirmed off.
- EU residency configured where available, per workspace and project.
- An internal policy that spells out which data types must never be pasted in.
- A DPIA completed if personal data is processed at scale.
- A plan B if the transfer framework falls.
This is a guide, not legal advice. Check your specific situation with your data protection officer or legal counsel.
Sources
Cloud vs your own AI over 3 years
Run your own numbers with the same assumptions as this guide. Free, on the page.
Open the calculator →AI Pilot. 4 weeks. Fixed price.
One contained use case on your data, delivered in four weeks.
Book a scoping call →Want to see this live?
Fifteen minutes, your use case, a concrete next step. We show local AI running on hardware you could own.
Follow the build. One email when we publish.