Blog · Small business guide · ChatGPT · GDPR

ChatGPT at work: what GDPR lets you put in it

Your team already uses it, usually from a personal account. Allow or forbid is no longer the useful question. What remains: which plan protects your data, what must never go into a prompt, and who answers if a client file turns up in a chat.

Open notebook on a blank page with a pen beside it
Short answer

The problem is not ChatGPT, it is the account it runs on

On a personal account, conversations are used by default to train the models. On a business account or through the API, they are not. Same interface, same model, two different legal regimes.

The personal account

A salesperson opens ChatGPT with a Gmail address and pastes a client contract in to get a summary. No record on the company side, no data processing agreement, no way to know what left the building.

The business account

ChatGPT Business changes three things: your content stays out of training, OpenAI signs a data processing agreement, and accounts live in one workspace you can close the day someone leaves.

What does not change

You are still the controller. No subscription moves that responsibility elsewhere. It is held in place by written rules, a note to your staff and one line in your record of processing.

The plans

Personal accounts, Business, API: what actually differs

Three families of plans, three levels of commitment from OpenAI. Price matters less than the contract line describing what happens to your content. The detail sits on OpenAI's enterprise privacy page. When data must not leave the country, the question moves from the contract to the infrastructure, and self-hosted n8n stays the simplest answer there.

Free, Go, Plus, Pro

Personal accounts

Training on by default.

Switched off in settings, with no retroactive effect.

No contract between OpenAI and your company.

ChatGPT Business

The baseline for a small company

Content excluded from training by default.

Signed processing agreement, managed accounts.

No European data residency at this tier.

Enterprise, Edu, API

When the data is sensitive

At-rest hosting in Europe available.

On the API, 30 days of retention, cut to zero on approval.

Custom pricing, at a seat count few small companies reach.

Method

Four decisions to make before the subject comes up again

01

Give business accounts to whoever touches data

Sales, admin, HR, management: as soon as someone handles contracts, prices or client files, they work from a managed account. For the rest of the team, a personal account with no company data in it is often enough.

02

Write the list of what never leaves

One page, not fifteen. Client names and contact details, payslips, health data, bank details, source code, contracts under an NDA. Everything else can go through.

03

Turn training off where it is still running

On the personal accounts already used for work: settings, data controls, then the switch that allows model improvement. Ten seconds of work, and it only counts from now on, never for what has already gone.

04

Add one line to your record of processing

Purpose, categories of data, processor, retention period, legal basis. One line. That document is the first thing you will be asked for if an employee or a client raises a question.

Limits

What stays out of a prompt, even on a business account

A managed account protects you from training, not from leaking. The data still crosses the Atlantic, still passes through a vendor, and still lands in a history that anyone opening the session can read. Three categories stay outside.

Anything that identifies a person

Name, address, national insurance number, salary, sick leave. A first name on its own is fine. A full payroll table is not: anonymise before you paste.

Anything owned by a client

Plenty of B2B contracts forbid passing information to a third party without written consent. An AI vendor is a third party. Read the clause before, not after.

Access keys

Passwords, API keys, tokens, server access. Pasted once into a chat, treat them as compromised and rotate them.

Those three rules cover almost every incident I see on consulting work. The rest nearly always comes from someone who had no idea they were doing something risky.

Timeline

Since 3 August 2026, training your team is no longer a nice idea

Article 4 of the European AI Act asks companies deploying an AI system to make sure the people using it have a sufficient level of AI literacy. The obligation has been in force since 2 February 2025. What changed on 3 August 2026 is that national authorities are now in place and the penalties set by each member state become applicable.

For a small company it comes down to three pieces of evidence: a written policy, a dated training session, and the list of who attended. Nothing impossible, but nothing you can improvise on inspection day either. The European Commission keeps the official AI Act framework page up to date.

Talk through your usage rules

FAQ

Frequently asked questions

Is ChatGPT GDPR compliant?

Compliance sits with the processing, not the tool. On a business account, OpenAI signs a data processing agreement and does not train its models on your content. Your company remains the controller, so it still has to inform staff, keep a record of processing activities and write its own usage rules.

Should a company ban ChatGPT?

A flat ban pushes the work onto personal phones, where the company sees nothing at all. Opening business accounts for the people who need them and writing one page of rules protects more than an internal memo.

Which ChatGPT plan should a small business choose?

ChatGPT Business covers most small companies: content excluded from training by default, a signed data processing agreement, and accounts managed from a single workspace. Enterprise and the API earn their price when data is sensitive or when at-rest hosting in Europe is required.

Does data sent to ChatGPT stay in Europe?

Not by default. OpenAI offers at-rest data residency in Europe for new Enterprise and Edu workspaces and for eligible API customers. On the other plans, processing leaves the European Union and relies on standard contractual clauses.

What goes into an AI usage policy?

One page is enough: the list of approved tools, the list of data that never leaves the building, the rule that a human reads anything before it reaches a client, and the name of the person to ask. Longer than that and nobody reads it.

Next

Where to go from here

Writing the rules takes an hour. Knowing which ones apply to your business takes a little longer, and that is exactly what the AI audit covers. The first automations come after, once the framework is in place.

The AI audit

90 minutes on your tasks, and you leave with a plan ranked by priority. The step to take when everything looks urgent at once.

AI training for your team

Four private sessions, the policy written with you, and the attendance list. Enough to cover the training obligation without buying a catalogue.

Custom AI agents

I install the system on your accounts, with your rules. You review, you approve, and the task runs without you.