Data Protection
Is ChatGPT GDPR Compliant? A Guide for UK Businesses
Can UK businesses use ChatGPT under UK GDPR? We explain training settings, business plans, data processing agreements, what not to paste in, and how to use ChatGPT safely at work.
Quick answer
ChatGPT can be used in a UK GDPR-compliant way, but compliance depends on how you use it. Use ChatGPT Business or Enterprise, where OpenAI does not train on your data by default and offers a data processing agreement; switch off model training on individual plans; avoid entering special category data; update your privacy notice; and keep a human reviewing outputs about people.
Key takeaways
- No tool is 'GDPR compliant' on its own — your usage decides.
- Business and Enterprise plans are designed for company data; free and Plus plans are consumer products.
- Turn off 'improve the model for everyone' on individual accounts used for work.
- Regulators take this seriously: Italy's data protection authority fined OpenAI €15 million in December 2024.
The short answer
UK GDPR applies to you — the business deciding to put personal data into a tool — not just to the tool's maker. Using ChatGPT with no personal data (drafting a blog post, brainstorming product names) carries little data-protection risk. Using it to summarise customer complaints, screen CVs or analyse staff performance is processing personal data and needs the usual safeguards.
Which ChatGPT plan should a business use?
| Plan | Training on your data | Admin controls | Suitable for client data? |
|---|---|---|---|
| Free / Plus | On by default — can be switched off | No | Only with training off and minimal personal data |
| Business (formerly Team) | Off by default | Yes | Yes, with a DPA and policy |
| Enterprise | Off by default | Advanced (SSO, retention, data residency options) | Yes — best for regulated firms |
How to use ChatGPT safely at work
- Use a Business or Enterprise workspace for company use, or switch off training in data controls.
- Accept OpenAI's data processing addendum and keep a copy.
- Set a rule: no special category data (health, ethnicity, religion, biometrics), no passwords, no payment details.
- Pseudonymise where you can — 'Customer A' works as well as a real name for most drafting.
- Keep a human in the loop for anything that affects a person (hiring, credit, complaints).
- Mention AI tools in your privacy notice and record them in your data map.
The same principles apply to Claude, Gemini and Copilot. See our UK GDPR and AI checklist for a policy template, and the ICO's AI guidance for the official position.
Frequently asked questions
Is ChatGPT GDPR compliant?
Does ChatGPT store my data?
Can I put customer data into ChatGPT?
SmarterBiz Editorial Team
Our editors test AI and business software against the realities of running a UK small business: sterling pricing and VAT, UK GDPR, HMRC's Making Tax Digital rules and British English output.