Analysis

ChatGPT and GDPR: governing the use of AI in the business

Your teams already use AI. The question is no longer whether to allow it, but how to govern it — and a ban that cannot be enforced governs nothing.

The letters “AI” followed by a question mark, written in marker on a whiteboard
The question is not the tool, but what you hand it

In most businesses, the question of ChatGPT and the GDPR is not asked before use: it is asked afterwards. A salesperson has summarised meeting notes in it, an assistant has reworded a letter to a client, a manager has pasted a spreadsheet to format it. None of this was forbidden, because nothing had been decided. And each of these actions may have taken personal or confidential data out of the business.

The most common reaction is a ban. It is rarely kept: the tool is available from any browser and any phone, and it is useful. A ban that cannot be enforced pushes use out of sight, where it is riskiest. The question is no longer whether to allow AI, but how to govern it.

What happens to data entered into an online AI

A question asked of an online assistant does not disappear once the answer appears. Depending on the offer and the settings, it may be kept in a history, accessed in some cases by the provider, and used to train future models.

OpenAI states it clearly in its help centre, in the version consulted in September 2026: for its services for individuals, including ChatGPT, the company may use content to train its models, unless the user switches off the relevant option in their settings or requests it through its privacy portal. Conversations held in temporary mode are not used for training. For its business offers — ChatGPT Business, ChatGPT Enterprise and its API — OpenAI states on the contrary that it does not train its models on customers’ data by default.

The distinction is decisive, and most users miss it. An employee using a free personal account for work puts the business’s data under the regime of a consumer offer, with whatever settings they have — or have not — chosen. The terms also change regularly: what is true today must be checked again before each decision.

ChatGPT and GDPR: what the regulation says

The GDPR does not mention ChatGPT, but it applies as soon as personal data — a name, an address, a client file, an employee appraisal — is entered into the tool. That entry is processing, and the business is responsible for it. Several principles of the regulation apply directly:

  • lawfulness: processing must rest on a legal basis, and sending data to a third party for an unplanned use rarely has one;
  • minimisation: only necessary data may be processed — a client’s name is rarely needed to reword a letter;
  • processing contracts: a provider processing data on the business’s behalf must be bound by a contract compliant with Article 28;
  • transfers: data sent outside the Union must be sent on a recognised basis;
  • security: the business must protect the data it processes, including against its own employees’ uses.

The CNIL draws a simple recommendation from this: do not enter personal or confidential data into consumer generative AI services, and, if the use requires it, favour on-site deployments or offers whose contract forbids reuse of the data. Supervisory authorities do more than recommend: in Italy, the Garante fined OpenAI fifteen million euros in December 2024, notably for processing personal data to train its models without an adequate legal basis.

Finally, the GDPR only covers part of the risk. A draft contract, a sales proposal in preparation, a manufacturing formula or a financing plan do not necessarily contain personal data; yet they are confidential data, protected by trade secrecy or by commitments made to clients. Pasting them into a consumer tool raises the same question — who can access them, and for what use — without the regulation answering it. The internal rule must therefore cover both categories.

Consumer and business offers: the differences

CriterionConsumer offerBusiness offer
Training on the dataPossible by default, can be switched off by the userNot by default, according to the vendor
Who decides the settingsEach userThe business, for everyone
Processing contractGeneral terms of useProcessing agreement offered
Account managementPersonal accounts, out of controlManaged accounts, revocable on departure
Law applicable to the operatorThe provider’sThe provider’s

The last row is a reminder of what the business offer does not change. It clearly improves contractual control, but the operator remains subject to its own law — for a US provider, the CLOUD Act included. For the most sensitive data, the question then moves to another level, that of sovereign AI: a model run on infrastructure whose operator is subject to no extraterritorial law, or on the business’s own hardware.

Governing use: policy, approved tools, training

The CNIL recommends, for any generative AI deployment, starting from a concrete need, defining a list of permitted and prohibited uses, choosing a secure system and deployment mode, and training users. Translated for a small business, that comes down to three decisions.

Write the rule into the policy

Which tools are permitted, for which uses, with which data. The most useful rule fits in one sentence: no personal or confidential data in a tool that has not been approved. It belongs in the IT usage policy, which makes it enforceable.

Provide an approved tool

It is the condition for the rule to be kept. A team told it may not use the tool it relies on, without being offered another, will go on using the first. A business offer, with accounts managed by the business and the contract reviewed, usefully replaces personal accounts — and, for sensitive uses, a controlled environment, such as Maeliom’s sovereign AI offer in early access, completes the arrangement.

Train, briefly

An hour is often enough: what may be entered and what may not, how to anonymise a request, why an answer must be reviewed before it is used. The CNIL insists on that last point: the user remains responsible for what they reuse.

One use that rules often forget remains: the artificial intelligence built into the tools the business already uses. Office suites, email and customer relationship software are adding generative features, sometimes switched on by default. They process the same data as the tool that hosts them, under terms that may differ from the original contract. Listing them and reviewing their terms is part of the same workstream — and it is often where the most widespread, and least visible, use lies.

Common questions

Can ChatGPT be used in a business in compliance with the GDPR?

Yes, provided use is governed: a business offer with a processing agreement, rules on what data may be entered, and trained users. Without these conditions, the use of personal accounts exposes the business.

Is data entered into ChatGPT used to train the model?

For offers aimed at individuals, it may be, unless the user switches this off. For business offers, OpenAI states that it does not train its models on customers’ data by default. These terms change and should be checked before deciding.

Should employees be banned from using ChatGPT?

A total ban is hard to enforce and pushes use out of sight. It is generally more effective to allow a governed tool and forbid entering personal or confidential data anywhere else.

Sources: OpenAI, How your data is used to improve model performance (consulted 19 September 2026); CNIL, Q&A on using a generative AI system and deploying generative AI (July 2024); GDPR, Chapter II; Garante per la protezione dei dati personali (December 2024).


Next article

GEO or SEO: the dilemma does not exist, the trade-off does

Read

A transformation to support?