Knowledge  /  Rules

Is ChatGPT GDPR-compliant for customer data?

Not by default. The consumer app trains on your inputs and stores them outside your control. The enterprise and API tiers can be made compliant — but only with a signed DPA, the right settings, and a lawful basis. Here's what separates the two.

Rules & compliance

“The question isn't whether ChatGPT is GDPR-compliant. It's which ChatGPT, on which contract, with which data.”

The answer in 30 seconds

  • The free/Plus consumer app is not GDPR-compliant for customer data: it can train on your inputs, there's no Data Processing Agreement, and you don't control where the data sits.
  • ChatGPT Enterprise and the API can be: OpenAI offers a DPA, doesn't train on your data by default, and lets you set data residency and retention.
  • Compliance is never the tool alone. You still need a lawful basis, a signed DPA, records of processing, and a way to honour deletion and access requests.
  • Safest pattern: minimise and pseudonymise before the prompt, use a business tier under contract, and keep an audit log of what was sent.

Why isn't the consumer app compliant by default?

Three reasons. First, the consumer ChatGPT can use your conversations to improve its models unless you turn that off — and even then you're relying on a setting, not a contract. Second, there's no Data Processing Agreement, which the GDPR requires whenever a processor handles personal data on your behalf. Third, you have little control over retention or where the data is stored. Paste a customer's name, email or support history into the free app and you've almost certainly made an uncontrolled transfer of personal data. That's the gap the business tiers exist to close.

GDPR requirementConsumer app Enterprise / API
Data Processing AgreementNoneAvailable, signed
Training on your dataOn by defaultOff by default
Data residency / retention controlNoneConfigurable
Deletion & access supportLimitedContractual

What makes the enterprise and API tier different?

A contract and a set of defaults built for processors. On ChatGPT Enterprise and the API, OpenAI acts as your data processor under a signed DPA, doesn't train on your business data, and gives you controls over retention and, on eligible plans, data residency. That's the legal scaffolding the GDPR expects. It doesn't make you compliant on its own — it makes compliance possible, which the consumer app does not.

[ figure — the compliance conversation: lawful basis, DPA, and who's allowed to paste what ]

Compliance is a team decision before it's a tool setting: lawful basis, DPA, and who's allowed to paste what.

What do you still have to do yourselves?

The tier gives you the contract; you supply the rest. You need a lawful basis for feeding personal data to an AI at all, an entry in your records of processing activities, a data protection impact assessment if the processing is high-risk, and a working way to honour access and deletion requests — including anything the model logged. None of that comes in the box. It's the difference between “a compliant tool” and “compliant use of a tool.”

What's the safest pattern for customer data?

Minimise first. Strip or pseudonymise names, emails and account numbers before anything reaches the prompt — most tasks don't need the real identifiers. Run on a business tier under a signed DPA, never the consumer app. And keep an audit log of what was sent to which model, so an access or deletion request is a lookup, not an archaeology dig. Minimise, contract, log: that's the pattern that survives a regulator's questions.

Questions your team will ask

Is turning off training in the consumer app enough?

No. It reduces one risk but you still have no DPA, no retention control and no processor contract — the parts the GDPR actually requires.

Can we send any personal data if we have Enterprise?

Only what you have a lawful basis to process and have minimised. The tier permits it contractually; it doesn't decide necessity for you.

Where is the data processed?

Depends on your plan and region settings. Check the current sub-processor list and residency options in your contract — and record what you find.

Is this legal advice?

No. It's a practical map of where the compliance line sits. Confirm your specific case with your DPO or counsel before relying on it.

The line, in one sentence

A compliant tool isn't compliant use. You supply the basis, the minimising and the log.

Tisser keeps the DPA, the settings and the audit trail in one place — so “are we compliant?” has an answer you can show.