Bernard Sonnenschein
21.8.2026

GDPR compliant AI: using ChatGPT and similar tools within the law

Illustration of a floating laptop with safety shield on the screen
Download Article

The moment an AI tool is running inside a company and handling personal data, data protection law applies. That covers ChatGPT answering customer enquiries just as much as Claude running analysis, or Gemini sitting inside your office suite. And the first question mid-sized companies ask us is not "which model is best?" but "am I even allowed to use this?".

The answer is yes. GDPR compliant AI is achievable with ChatGPT, Claude and Gemini alike, but none of them is compliant automatically. It depends on which plan you use, how the data transfer is secured and whether you have done a bit of organisational groundwork. Those are exactly what we work through here.

Is ChatGPT GDPR compliant? And Claude and Gemini?

The honest answer applies equally to all the common AI tools, whether ChatGPT, Claude, Gemini or Microsoft Copilot. None is GDPR compliant out of the box, but with the right setup all of them are perfectly usable. What matters is usually not the model but exactly what you plan to use it for. Which AI tools are currently on the market and where each provider leads is set out in our market overview of AI tools 2026.

Free and consumer versions: unsuitable for business

The same dividing line runs through all the major tools. The free and consumer versions – ChatGPT Free, Claude Free and Pro, the Gemini apps – are not suitable for processing personal data in a company, because they process inputs on servers outside the EU and as a rule use them as training data to improve the models. For customer or employee data, that is a non-starter.

Business and enterprise versions: usable with a data processing agreement

The business and enterprise tiers are the ones fit for company use: ChatGPT Enterprise and Team, Claude for Work or the API, Gemini in Google Workspace, Microsoft Copilot via Microsoft 365. At that level, a data processing agreement is part of the terms, inputs do not flow into the providers' training data, and the third-country transfer to the US is covered by the EU-U.S. Data Privacy Framework or standard contractual clauses.

Server location and sensitive data

One difference does remain: where the servers sit. If you need a guarantee that data is processed inside the EU, the route varies by tool – for ChatGPT via the EU data residency of the enterprise version or Azure OpenAI; for Claude via a cloud provider such as AWS Bedrock or Google Vertex AI in an EU region; for Gemini via Google Workspace or Vertex AI with EU endpoints; for Microsoft Copilot via the Microsoft 365 EU data boundary. Which path is right depends on your existing infrastructure and your AI applications.

Regardless of the tool, particularly sensitive data such as health or financial information does not belong in a cloud AI tool even on a business plan. A data protection impact assessment is also needed before deployment.

European alternatives

If you want EU data processing from the outset, European providers such as Mistral AI (France) or Aleph Alpha (Germany) offer capable alternatives with data held in the EU. The trade-off is smaller ecosystems. Which European providers and models are worth it in detail is set out in our overview of European AI.

What GDPR compliant AI actually requires

None of these tools is compliant by default. But all of them can be deployed in line with data protection law if four conditions are met. We recommend measuring every tool against this checklist before you deploy it:

  • A business plan rather than a free or consumer version (Enterprise, Team or API)
  • A concluded data processing agreement under Art. 28 GDPR, including clear technical and organisational measures
  • A secured third-country transfer (Data Privacy Framework or standard contractual clauses), ideally EU hosting via Azure, AWS Bedrock or Vertex AI
  • Contractual exclusion of training on your data, plus a completed data protection impact assessment

Meet those conditions and ChatGPT, Claude, Gemini and Copilot are all equally usable on a sound legal footing. Compliance lies less in the model than in the setup.

AI and GDPR: what companies need to watch

The General Data Protection Regulation makes no exception for artificial intelligence. As soon as an AI tool processes personal data – names, email addresses, IP addresses, job applications or customer records – its core requirements apply in full. And you end up processing personal data sooner than you might think. An AI chatbot that answers a customer enquiry and uses the customer's real name is already covered.

Every act of processing needs a legal basis, such as consent, performance of a contract or legitimate interest. There is also the principle of data minimisation, being transparent with data subjects, and their rights of access, erasure and objection. AI data protection calls for particular care here, because these systems process large volumes of data and their processing logic is often hard to trace. In their guidance, Germany's data protection authorities stress that AI deployment should normally be treated as carrying elevated risk.

Worth keeping straight: data protection and the GDPR are not the same thing as the EU AI Act. The GDPR governs the handling of personal data. The AI Act governs AI systems as a technology, regardless of whether personal data is involved. Both regimes apply in parallel, and it is precisely this distinction that causes confusion in practice.

Where the EU AI Act comes in

The EU AI Act has been in force since August 2024. It adds a second layer alongside the GDPR. Its focus is not data protection but the safety and trustworthiness of AI systems. It follows a risk-based approach with four tiers: prohibited practices, high-risk AI systems, general-purpose AI models (GPAI, such as ChatGPT, Claude or Gemini), and low-risk applications, where the obligations are essentially about transparency.

What matters for deployers

For most mid-sized companies using AI as deployers, three parts of the AI Act matter. The prohibitions (Art. 5) have applied since February 2025, the GPAI transparency obligations since August 2025, and Art. 4 requires employers to ensure a sufficient level of AI literacy among staff – something executives in particular should push for early. What that looks like in practice is covered in our article on AI training for employees. For compliance, training and documentation are part of the picture from day one.

What changed in the 2026 timeline

The timeline shifted significantly in 2026. Through what is known as the Digital Omnibus, the strict obligations for standalone high-risk AI systems are being pushed back from August 2026 to 2 December 2027, and for systems embedded in products to 2 August 2028.

That change is now confirmed. The European Parliament voted in favour on 16 June 2026, and the Council of the EU gave its final green light on 29 June 2026, with publication in the Official Journal to follow. Only the enforcement dates are being deferred, not the substantive requirements, and the prohibitions as well as the GPAI and transparency obligations remain untouched. The EU keeps up-to-date overviews and guidance on implementation.

In practice this is reassuring news. Most deployer companies do not operate high-risk AI at all and were barely affected by the August deadline anyway. The real job is still classifying your own AI systems by risk. That is what determines which obligations apply.

Seven steps to legally sound AI use

To turn theory into a robust process, this sequence works well in our experience:

  1. Take stock. Build an AI register: which tools are in use, for what purpose, with which data, in which departments, with what storage location?
  2. Assess risk. Assign every system to an AI Act risk class. Most tools fall into the lower tiers. But deploying AI in HR, in candidate selection for instance, or in credit decisions can qualify as high risk.
  3. Write an internal AI policy. Set out which tools are permitted, which data must not be entered, how output is reviewed and who is responsible – a data protection officer, for example. Employees should use company accounts only, with chat history switched off.
  4. Run a data protection impact assessment (DPIA). For AI systems, a DPIA is usually required under Art. 35 GDPR. It documents the risks to data subjects, the safeguards and the proportionality of the processing, and helps spot problems early.
  5. Conclude a data processing agreement. Sign one with every external provider. Check that the provider is contractually bound to act only on your instructions, and look closely at sub-processors and at technical and organisational measures. Also verify that use of your data as training data is excluded.
  6. Train your people. Your teams are the key. They need to know which data may go into AI tools, how to spot hallucinations and how to react to a data incident.
  7. Monitor continuously. AI law is developing fast. Check at least annually whether your AI systems still meet the requirements, and document any changes.

Specifics for mid-sized companies

Alongside the general requirements there are points that affect mid-sized companies in particular. Where AI tools are capable of monitoring or assessing employee performance, the works council has a right of co-determination in Germany. That extends to productivity tools which analyse workflows. A works agreement creates clarity here early on.

Then there is the question of resources. Many mid-sized companies have neither their own data protection officer nor IT security specialists. The legal obligations and compliance requirements apply regardless. This is where an external data protection consultant, a specialist law firm or an AI compliance provider that does this day in, day out can help.

How other companies have solved exactly these hurdles in practice – from legally sound rollout through to everyday work with AI – is best learned from the people who have done it. That transfer is the whole point of the SME Stage at d:u27 on 13 and 14 April 2027 in Münster.

Conclusion: GDPR compliant AI is achievable

The legal requirements around AI tools are complex, but they are far from impossible to meet. What matters is a structured approach that takes account of both the GDPR and the AI Act, since the two regimes apply in parallel. Planning early and carefully helps avoid expensive retrofitting and fines. No deep legal expertise is required, but a solid basic understanding is – along with clear processes and responsibilities inside the company.

AI offers enormous opportunities for mid-sized companies in particular, through efficiency gains, cost reductions and a better basis for making decisions. To realise that potential safely and within the law, investing in AI literacy and continuous training is essential. That way your company can make full use of the technology's advantages while ensuring the legal requirements are met.

If you want to deploy AI in your company on a sound legal footing, without expensive compliance retrofits, you will find the answers at d:u27 on 13 and 14 April 2027 in Münster. Around 17,000 participants come together across six stages, with more than 80 masterclasses and over 350 speakers. The GDPR and the EU AI Act, AI governance and legally sound AI implementation are all on the agenda, discussed directly with compliance leads, IT leads and managing directors. And alongside the legal framework, the focus is firmly on concrete applications: AI use cases from a wide range of industries, plus the latest AI tools and hacks. Secure your tickets for d:u27 now!

GET YOUR TICKETS NOW
for the d:u27!
On April 13 & 14, 2027 the data:unplugged Festival, d:u27, will take place for the fourth time in Münster.