Skip to content

Data Protection

Is ChatGPT GDPR Compliant? A Guide for UK Businesses

Can UK businesses use ChatGPT under UK GDPR? We explain training settings, business plans, data processing agreements, what not to paste in, and how to use ChatGPT safely at work.

SmarterBiz Editorial TeamUK SME Technology DeskUpdated 3 min read

Quick answer

ChatGPT can be used in a UK GDPR-compliant way, but compliance depends on how you use it. Use ChatGPT Business or Enterprise, where OpenAI does not train on your data by default and offers a data processing agreement; switch off model training on individual plans; avoid entering special category data; update your privacy notice; and keep a human reviewing outputs about people.

Key takeaways

  • No tool is 'GDPR compliant' on its own — your usage decides.
  • Business and Enterprise plans are designed for company data; free and Plus plans are consumer products.
  • Turn off 'improve the model for everyone' on individual accounts used for work.
  • Regulators take this seriously: Italy's data protection authority fined OpenAI €15 million in December 2024.

The short answer

UK GDPR applies to you — the business deciding to put personal data into a tool — not just to the tool's maker. Using ChatGPT with no personal data (drafting a blog post, brainstorming product names) carries little data-protection risk. Using it to summarise customer complaints, screen CVs or analyse staff performance is processing personal data and needs the usual safeguards.

Which ChatGPT plan should a business use?

PlanTraining on your dataAdmin controlsSuitable for client data?
Free / PlusOn by default — can be switched offNoOnly with training off and minimal personal data
Business (formerly Team)Off by defaultYesYes, with a DPA and policy
EnterpriseOff by defaultAdvanced (SSO, retention, data residency options)Yes — best for regulated firms

How to use ChatGPT safely at work

  1. Use a Business or Enterprise workspace for company use, or switch off training in data controls.
  2. Accept OpenAI's data processing addendum and keep a copy.
  3. Set a rule: no special category data (health, ethnicity, religion, biometrics), no passwords, no payment details.
  4. Pseudonymise where you can — 'Customer A' works as well as a real name for most drafting.
  5. Keep a human in the loop for anything that affects a person (hiring, credit, complaints).
  6. Mention AI tools in your privacy notice and record them in your data map.

The same principles apply to Claude, Gemini and Copilot. See our UK GDPR and AI checklist for a policy template, and the ICO's AI guidance for the official position.

Frequently asked questions

Is ChatGPT GDPR compliant?

ChatGPT can be used in a GDPR-compliant way if you choose an appropriate plan (ideally Business or Enterprise), accept the data processing addendum, avoid unnecessary personal data and keep people informed. Compliance depends on how you use it.

Does ChatGPT store my data?

Yes, conversations are stored to provide the service. On consumer plans they may be used to improve models unless you switch that off; on Business and Enterprise plans OpenAI says it does not train on your data by default.

Can I put customer data into ChatGPT?

Only with safeguards: a business plan or training switched off, a data processing agreement, a lawful basis, an updated privacy notice and no special category data. Pseudonymise wherever possible.

SmarterBiz Editorial Team

Our editors test AI and business software against the realities of running a UK small business: sterling pricing and VAT, UK GDPR, HMRC's Making Tax Digital rules and British English output.

How we test · Report a correction

Keep reading