Skip to content
biwak

Guides

Law & privacy

ChatGPT at work: what is allowed under data protection law?

What businesses need to clarify on data protection before using ChatGPT, from the plan and the DPA to transfers to the USA and the AI policy.

Responsible:

Published

Updated 11 min read

Can a business use ChatGPT at all?

Yes. It only becomes sensitive under data protection law when personal data goes in: names, email addresses, customer numbers, content from personnel files, including in uploaded files. For each such processing operation, you need a legal basis under Art. 6(1) GDPR, such as performance of a contract (point (b)) or a legitimate interest, provided the interests of the data subjects do not override it (point (f)). For special categories such as health data, the narrow exceptions of Art. 9 GDPR also apply.

The simplest approach is to work without personal references: texts without names, tables with customer numbers instead of names, invented examples. For you, however, pseudonymised data remains personal data as long as you can link it to individuals. And data you collected for one purpose may not simply be used for another (purpose limitation, Art. 5(1)(b) GDPR). So before you start, write down what ChatGPT will be used for.

Personal accounts or business plan: what is the difference?

The difference lies in OpenAI's role: with personal accounts, OpenAI decides on the data itself as the controller, for users in the EEA OpenAI Ireland Limited, according to its privacy policy for Europe. On the business plans, OpenAI processes the data on your behalf under a data processing agreement (the “Data Processing Addendum”, DPA).

Personal plans and business plans according to OpenAI, retrieved in September 2026
Personal plans (Free, Go, Plus, Pro)ChatGPT BusinessChatGPT Enterprise and API
Training on your contentPossible until you opt out (“Improve the model for everyone” switch)No by defaultNo by default
Role of OpenAIControllerProcessorProcessor
Data processing agreement under Art. 28 GDPRNoYesYes
DeleteTemporary chats: copy kept for up to 30 days for security reasonsDeleted chats are removed within 30 days, unless required by law or to protect against harmEnterprise: retention controllable by administrators; API: up to 30 days, zero retention on request for eligible cases
Storage in EuropeNot offeredNot offeredSelectable for new Enterprise workspaces and API projects
AdministrationIndividual accountWorkspace with SAML SSO and multi-factor sign-inEnterprise additionally with SCIM, customer-managed keys (EKM) and roles

Even with training switched off, a personal account remains a personal account: there is no DPA, the company has no access, and according to OpenAI, anyone who rates an answer with a thumbs up or down releases the entire associated conversation for training. The Datenschutzkonferenz (DSK), the joint body of the German data protection supervisory authorities, also advises using work accounts, partly because personal accounts can create profiles of employees.

Employers should provide devices and accounts for employees' professional use of AI applications.
DSK (German data protection conference), guidance on artificial intelligence and data protection of 6 May 2024, para. 41

May the data go to the USA, and does storage in Europe help?

Yes, if there is a sound transfer mechanism. For customers based in the EEA or Switzerland, OpenAI concludes the DPA via OpenAI Ireland Ltd.; according to the Data Processing Addendum (valid since 1 January 2026), OpenAI bases transfers to group companies or third parties outside the EEA on standard contractual clauses or an adequacy decision of the Commission.

For certified US companies, the adequacy decision on the EU-US Data Privacy Framework applies (Implementing Decision (EU) 2023/1795 of 10 July 2023). The General Court of the EU dismissed the action against it on 3 September 2025 (Case T-553/23, Latombe). According to official publications, the appeal to the Court of Justice (C-703/25 P, lodged on 31 October 2025) had not been decided by 23 September 2026. Whether a US recipient is certified is shown in the list at dataprivacyframework.gov.

OpenAI offers storage in Europe only for new workspaces in ChatGPT Enterprise and Edu and for API projects. It covers stored content such as conversations, files and custom GPTs; according to OpenAI, account data, billing and metadata may be held outside the region. Even the additionally available inference residency, in which model computation stays in the region, does not guarantee, by OpenAI's own account, that all processing takes place there.

Do you need a data protection impact assessment?

Often, yes. A data protection impact assessment (DPIA) under Art. 35 GDPR is required if processing is likely to result in a high risk to data subjects, and according to the Datenschutzkonferenz, this is “often the case” when AI applications are used. It is preceded by a preliminary assessment of the nature, scope, purpose and circumstances of the processing.

Without personal data, the question does not arise. A DPIA is likely to be needed for employee data and job applications, for health or client data, for assessments of people and for large volumes of data. For the assessment, you depend on the provider's information about how the tool works; the Datenschutzkonferenz advises making sure at the selection stage that the provider supplies it. A framework for the DPIA is in the article Data protection impact assessment for AI.

What belongs in an AI policy for employees?

An AI policy sets out in writing which tools are allowed for which purposes with which data. The Datenschutzkonferenz recommends clear, documented instructions with examples of permitted and prohibited uses, because otherwise there is a risk that employees use AI on their own initiative and without control; it also considers a works agreement suitable.

Minimum content of an AI policy
  • Approved tools and plans; personal accounts prohibited for work data.
  • Permitted purposes with examples, prohibited purposes with examples.
  • Data classes: what never goes in (such as health data, personnel files, professional secrets, credentials) and what only goes in without names.
  • Settings: training off, history kept only as long as necessary, no automatic publication of results.
  • Duty to check: check results before use; no decisions about people made by AI alone.
  • Reporting channel for errors and possible data breaches; a notifiable breach must be reported to the supervisory authority without undue delay and, where feasible, within 72 hours (Art. 33 GDPR).
  • Training under Art. 4 of the EU AI Act and a contact person for questions.

Does the works council have to agree?

You always have to inform it, and it often has to agree. § 90(1) no. 3 BetrVG (German Works Constitution Act) requires the works council to be informed in good time about the planning of working procedures “including the use of artificial intelligence”. Under § 87(1) no. 6 BetrVG, it has a right of co-determination over technical devices designed to monitor employees' behaviour or performance; according to case law, it is enough for a system to objectively record such data.

A workspace with personal accounts and history quickly meets this test: in ChatGPT Business, administrators can view and export users' conversations, and in Enterprise there is an audit log via an API. Which metrics a pilot may collect and what belongs in a works agreement is covered in the article Works councils and AI.

What applies to law firms, tax offices and medical practices?

For professionals bound by confidentiality, data protection is not enough. Anyone who makes client or patient secrets accessible to a service provider needs authorisation under Section 203(3) of the German Criminal Code (StGB) and must comply with professional law, such as § 43e BRAO for lawyers and § 62a StBerG for tax advisers.

  • Careful selection of the service provider and a contract in text form obliging it to confidentiality, with instruction on the criminal consequences (§ 43e(2) and (3) BRAO).
  • For services abroad: only if the protection of secrets there is comparable to that in Germany, or if the protection of the secrets does not require it (§ 43e(4) BRAO).
  • If the service directly serves an individual client matter: only with the client's consent (§ 43e(5) BRAO).
  • Who at the provider may read along: for ChatGPT Business, OpenAI names authorised employees for technical support, abuse review and legal obligations, as well as service providers bound by confidentiality who only review for abuse; for Enterprise, access for troubleshooting, with explicit permission or where required by law.

The two reviews, data protection and professional secrecy, run in parallel and do not replace each other. The details are in the article AI in the law firm: § 203 StGB and § 43e BRAO.

Is there a seal for “GDPR-compliant” AI?

No. The GDPR does not provide for an official seal declaring an AI tool as a whole compliant with data protection law. Art. 42 only provides for voluntary certification of specific processing operations, valid for a maximum of three years; the European Data Protection Board keeps approved schemes in a register.

A certification pursuant to this Article does not reduce the responsibility of the controller or the processor for compliance with this Regulation […].
Art. 42(4) GDPR

Evidence such as SOC 2 or ISO 27001 proves the provider's security processes, not the lawfulness of your processing. “GDPR-compliant” is therefore not a property of a tool but the result of your assessment.

What to check instead
  • Plan: a business plan with central administration instead of personal accounts.
  • Contract: DPA under Art. 28 GDPR concluded, list of sub-processors read.
  • Training: off by default, also clarified for feedback and connected apps.
  • Location and access: where data is stored, who can access it from where, which transfer mechanism applies.
  • Retention and deletion: periods and settings defined.
  • Purpose and legal basis documented for each use, record of processing activities updated (Art. 30 GDPR).
  • Data protection impact assessment checked and, where necessary, carried out.
  • Privacy notices for customers and employees updated.
  • AI policy, training and works council dealt with.
  • For professional secrets: § 203 StGB and professional law checked.

How does Biwak process your data?

Processing happens in the EU, Biwak does not use your content for training, and our DPA applies to businesses (biwak.ai/avv). Even so, the same checklist also applies to Biwak.

This article contains no performance comparison. How Biwak and the business ChatGPT plans differ in file tasks, team features and data processing is shown in the comparison Biwak or ChatGPT.

Frequently asked questions

May employees use ChatGPT with personal accounts for work?

Not for work data. With personal accounts, OpenAI itself is the controller, there is no DPA, and content may be used for training until someone opts out. The Datenschutzkonferenz recommends that employers provide accounts and devices.

Is it enough to switch off training in ChatGPT?

No. The “Improve the model for everyone” switch prevents training on new conversations, but replaces neither a DPA nor a legal basis. In addition, OpenAI may use a conversation for training if someone rates an answer.

Is there GDPR-compliant AI?

No tool is GDPR-compliant on its own; what is lawful or not is your specific processing. A tool can make it easier: with a DPA, without training on your data, with clear storage and deletion and a sound transfer mechanism. Check these points for every AI tool, whether ChatGPT, Biwak or another.

Is ChatGPT Enterprise hosted in the EU?

Partly, on request: new Enterprise and Edu workspaces can store conversations, files and other content in Europe, and eligible customers can also keep model computation there. According to OpenAI, account data, billing and metadata may be held outside the region. OpenAI does not mention this option for ChatGPT Business.

May we enter customer data in ChatGPT?

Only with a legal basis, on a business plan with a DPA, and only as much as the purpose requires. Also check the transfer to the USA and whether a data protection impact assessment is needed. Where possible, work with customer numbers instead of names.

Is the transfer to the USA secure after the Latombe judgment?

The adequacy decision on the EU-US Data Privacy Framework applies: the General Court of the EU dismissed the action on 3 September 2025. The appeal to the Court of Justice had not been decided by 23 September 2026. Keep standard contractual clauses ready as a fallback and check the status before every reassessment.

Sources

  1. OpenAI: Enterprise privacy at OpenAI (updated on 8 January 2026)
  2. OpenAI Help Center: How your data is used to improve model performance
  3. OpenAI: Europe Privacy Policy (updated on 24 August 2026)
  4. OpenAI: Data Processing Addendum (valid since 1 January 2026)
  5. OpenAI Help Center: Data residency and inference residency for ChatGPT
  6. OpenAI Help Center: Temporary Chat FAQ
  7. DSK (German data protection conference): Guidance on artificial intelligence and data protection, 6 May 2024
  8. Regulation (EU) 2016/679 (GDPR), Art. 5, 6, 9, 28, 30, 33, 35, 42 and 45
  9. General Court of the EU, judgment of 3 September 2025, T-553/23, Latombe v Commission
  10. Appeal C-703/25 P, lodged on 31 October 2025, Official Journal of 22 December 2025
  11. European Commission: EU-US data transfers
  12. European Data Protection Board: Register of certification mechanisms, seals and marks

This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.

Further reading

All articles