The scenario above plays out in offices across the EU every single day. ChatGPT is free, fast, and genuinely useful for drafting, summarising, translating, and untangling half-formed ideas. The problem is rarely the tool itself. The problem is that the data inside the chat box often isn't yours. It belongs to your customer, your employer, or a colleague who never agreed to appear in an American language model's training data.
Why GDPR isn't just bureaucracy
Under the GDPR, personal data means any information relating to an identified or identifiable person — a name, an email address, a phone number, a customer ID. Paste any of that into ChatGPT and you are "processing" it. When you do so for work, your employer is the data controller and must have a lawful basis for that processing. If you act without that basis, the company — not you personally, but the company — faces fines of up to €20 million or 4% of global annual turnover, whichever is higher.
There is a second, quieter risk: the notification duty. If OpenAI suffers a breach and personal data you entered is involved, your employer may have to notify the supervisory authority and the affected people. Try explaining to a client that their contact details ended up in a breach report because someone wanted a faster email draft.
What ChatGPT actually does with your text
Three facts matter here, and none of them is hidden in the small print:
1. Your text leaves the EU. When you type a prompt, it is sent to OpenAI's servers and processed outside the EU unless your company has a special enterprise agreement with data-handling terms. OpenAI legally relies on tools such as standard contractual clauses for these transfers — valid under GDPR, but it means your chats are not stored "in Europe" by default.
2. Free and Plus accounts can be trained on your chats. OpenAI states that conversations from free and Plus accounts may be used to improve its models unless you switch the setting off. Business plans behave differently, as you'll see below.
3. GDPR applies to OpenAI directly. OpenAI Ireland Limited is the data controller for users in the European Economic Area, according to the company's privacy policy. That gives you rights: access, correction, deletion, and objection. It also means your employer can't just shrug and say "it's an American tool, nothing we can do."
Which ChatGPT plan keeps your data out of training
Not every ChatGPT account is the same. The table below is based on OpenAI's published pricing and plan descriptions:
| Plan | Price | Are your chats used for training? | Best for |
|---|---|---|---|
| Free | €0 / $0 | Possible; you can opt out in settings | Trying the tool, no business data |
| Plus | US$20/month excl. VAT (EUR price varies slightly by country) | Possible; you can opt out in settings | Individuals, non-sensitive tasks |
| Team | US$25/user/month billed annually, or US$30 monthly | No training on your data by default | Small teams that need admin controls |
| Enterprise | Custom pricing | No training; zero data retention options | Companies with legal, HR, or client data |
The contrast is stark: a €0 personal account and a business contract do not carry the same legal weight. If your work touches anyone's personal data, the honest answer is that your employer should procure a business plan instead of letting employees quietly use personal accounts.
Six steps before you say a word to your boss
Don't walk into the conversation empty-handed. Do these first:
1. Check what your employer already allows. Many companies already have an IT acceptable-use policy. If ChatGPT is explicitly banned, you now know what you're dealing with — and continuing to use it quietly becomes a disciplinary issue, not just a privacy one.
2. Switch off training and memory. In ChatGPT, open Settings → Data controls. Turn off "Improve the model for everyone" and clear any saved memory that contains work information. These two clicks remove the most uncomfortable part of the conversation: "my chats may be training future models."
3. Set a personal rule for what never enters the chat. Decide it before you're tempted. My suggestion: no customer names, no colleague details, no salaries, no health information, no passwords, no API keys. Ever.
4. Collect two or three concrete examples of real value. A meeting summary that saved you an hour. A tricky email that you drafted in your own words and AI polished. A translation you checked with a native speaker. Results speak louder than features.
5. Write down what you'd change. Would you use it more if the company provided a Team or Enterprise account? Which tasks would stay out of AI entirely? A short list shows you've thought about boundaries.
6. Prepare a two-week trial. Propose a limited test with clear rules — for instance, no client data, only internal drafts — and a date to review how it went. It is far easier for a boss to approve a trial than to approve "AI forever."
How to open the conversation
Start with the output, not the tool. Show the email, the summary, or the spreadsheet — then admit how it was made. A useful opening sounds something like: "I used an AI assistant to help draft this. I switched off model training and I have not put any customer data into it. I'd like us to agree on how I use it responsibly."
Then let the other person react. If your boss worries about GDPR, you've already neutralised the biggest objection: you know which setting controls training, and you have named what you won't paste. If the worry is quality, you can offer to double-check everything AI produces — because you already do. If the worry is fairness, acknowledge it: for some tasks AI is simply not appropriate, and your proposal can say so explicitly.
This is not a conversation about asking forgiveness. It is a conversation about agreeing on guardrails — and most European managers, once they see you understand the privacy side, prefer an honest colleague with guardrails over a silent one with a free account.
The EU AI Act is starting to apply
GDPR is not the only law in play. The EU AI Act classifies ChatGPT as a general-purpose AI system, and its obligations for such models have been applying since August 2025. In practice, this means several things for European workplaces:
Transparency. Providers must document how models work and respect EU copyright law. OpenAI has publicly committed to cooperating with the EU's AI Office and signed the EU's voluntary AI Pact alongside hundreds of other companies.
Employee guidance. More employers will introduce AI usage policies because the AI Act pushes organisations, especially in regulated sectors, to train staff and document how AI is used. That's an opportunity: if your workplace is about to create an AI policy, you can volunteer to help write it — from the employee side.
Labeling. When AI-generated text is presented to other people in some professional contexts, the AI Act's transparency obligations may apply. A simple habit — noting "drafted with AI, reviewed by a human" in internal documents — keeps you on the safe side regardless of whether it's legally required in your specific case.
What you can and cannot paste: a quick reference
| Type of information | Example | Safe to paste? |
|---|---|---|
| Public information | Text from your company website | Yes |
| Your own draft | An email you wrote yourself | Yes |
| Pseudonymised notes | "Client A, invoice #1234" without real names | With care |
| Customer contact details | Name, email, phone number | No — pseudonymise first |
| HR and salary data | Colleague's salary, performance review | No |
| Health information | Any medical detail | Never — special category under GDPR |
| Trade secrets and source code | Proprietary algorithms, internal code | No — unless covered by an enterprise contract |
| Passwords and API keys | Credentials of any kind | Never |
When ChatGPT is the wrong tool
Sometimes the answer to "how do I stay compliant?" is not ChatGPT at all. In healthcare, law, and finance, many employers will reasonably prefer providers offering EU data residency. Microsoft's Azure OpenAI, for example, allows organisations to process models in EU data centres under a company contract. European providers such as Mistral offer an EU-based alternative with the same practical value for many writing tasks.
And for the most sensitive data — think salary spreadsheets or client lists — the strongest option is a local model running entirely on your own machine. We test this exact setup on our own AI Arena rig with local LLMs via Ollama: no data ever leaves the building, which is the most GDPR-compliant choice possible. It's not as effortless as ChatGPT, but for a handful of sensitive documents, it's hard to beat.
Can my employer forbid me from using ChatGPT at work?
Yes. Employers may set IT usage policies, and under GDPR they must implement safeguards for any personal data processing. A ban is legal. A wiser employer, however, will offer a compliant alternative — such as a business ChatGPT plan — rather than pushing employees to use personal accounts in secret.
Does turning off chat history also stop model training?
No, they are separate controls in ChatGPT. Chat history affects whether conversations are saved to your account; the "Improve the model for everyone" toggle in Data controls governs training. Switch both off on personal accounts, or use a Team or Enterprise plan where training is off by default.
Is it legal to use my personal ChatGPT account for work tasks?
It's risky rather than cleanly "illegal." Personal accounts lack a business data-processing agreement, may use your chats for training, and put the burden on your employer to justify the processing. The safest route is asking your employer to provide a business account — which is exactly the conversation this guide prepares you for.