Does using ChatGPT at work violate the GDPR? What the law says and how to fix it
Key takeaways
- Using ChatGPT is not illegal in itself, but pasting personal data without governance exposes the company to concrete GDPR violations.
- The problem is not limited to ChatGPT: it applies equally to Claude, Gemini, Microsoft Copilot, and Perplexity.
- The main risks: no legal basis (Art. 6), no agreement with the AI provider (Art. 28), transfer of data outside the EU (Art. 44 ff.), privacy by design ignored (Art. 25).
- Fines reach up to EUR 20 million or 4% of global turnover, and the most effective measure is technical: mask the data on the device, before the prompt reaches the AI service.
The short answer
Using ChatGPT at work does not automatically violate the GDPR. What violates it is ungoverned use. The moment an employee pastes personal data about clients, colleagues, or suppliers into a public chatbot, that data leaves the company's control and reaches a third-party provider, often outside the European Union and, in some configurations, reusable to train the model. That is where the violation begins.
And this is not only about ChatGPT. It applies equally to Claude, Gemini, Microsoft Copilot, Perplexity, and every other public AI assistant: ChatGPT is simply the most widely used and the most searched, but the mechanism that exposes data is the same everywhere.
And it is not a rare occurrence. According to Cyberhaven's 2025 AI Adoption and Risk Report, 34.8% of the corporate data employees paste into AI tools is classified as sensitive, more than triple the 10.7% of two years earlier. The risk is not theoretical: it is daily and widespread.
What happens to data when you paste it into an AI
Every prompt containing personal data triggers processing under the GDPR. The data leaves the corporate perimeter and is transmitted to the provider's servers (OpenAI for ChatGPT, Anthropic for Claude, Google for Gemini, Microsoft for Copilot, and so on). Depending on the plan and settings, it may be retained, reviewed by provider staff for security purposes, or used to improve the models.
The problem is compounded by the fact that most of this usage happens outside any control. According to LayerX's Enterprise AI and SaaS Data Security Report 2025, 45% of employees use generative AI tools, 77% of them paste data into chats, and 82% of those pastes come from personal accounts, outside any contract or company oversight. In practice: the company is the data controller, but often does not even know the processing is happening.
The concrete GDPR violations
When usage is not governed, the obligations that get skipped are specific and identifiable.
No legal basis (Art. 6)
Every processing of personal data requires a valid legal basis. Sending a client's data to an external AI service to rewrite an email almost never falls under a documented legal basis: there is no consent, no contract providing for it, and legitimate interest is hard to sustain for an unnecessary transfer.
No agreement with the data processor (Art. 28)
When an external provider processes personal data on the company's behalf, it becomes a data processor, and a Data Processing Agreement (DPA) is required to govern its obligations and safeguards. If an employee uses an AI with a personal account, that DPA does not exist: the processing lacks the contractual framework the GDPR requires.
Transfer outside the EU without safeguards (Art. 44 ff.)
Many AI services process data on servers in the United States or elsewhere. Chapter V of the GDPR permits such transfers only with adequate safeguards, such as an adequacy decision, standard contractual clauses, or binding corporate rules. A spontaneous paste is covered by none of these.
Privacy by design and by default ignored (Art. 25)
The regulation requires data protection to be embedded in processes by default. An organization that leaves it to individuals to decide what to paste into a chatbot has adopted no preventive technical measure: it is the exact opposite of privacy by design.
Weak transparency and information (Art. 13-14)
Data subjects, whether clients or employees, have the right to know where their data ends up. No privacy notice contemplates it being pasted into a chatbot by an employee in a hurry.
What you actually risk
Fines for the most serious violations reach up to EUR 20 million or 4% of annual global turnover, whichever is higher (Art. 83). This is not an abstract risk: in December 2024 the Italian data protection authority fined OpenAI EUR 15 million for violations related to ChatGPT, including the lack of an adequate legal basis for processing user data. The fine was later suspended on an interim basis by the Court of Rome in March 2025, pending the merits, but the signal to the market is clear: regulators are watching.
On top of this comes the direct cost of an incident. According to the IBM Cost of a Data Breach Report 2025, the average global cost of a breach is USD 4.44 million, and shadow AI (the use of unapproved AI tools) adds an average of USD 670,000, with one in five organizations already hit by a breach linked to these tools. In sectors like banking, finance, and legal, reputational damage often weighs more than the fine.
Why blocking or writing a policy is not enough
The instinctive reaction is to block AI services at the corporate perimeter. The result is predictable: employees switch to their phone or a personal account, and the problem becomes invisible rather than disappearing. Written policies, for their part, are not consulted in the moment when someone is under pressure and wants a quick answer. And network DLP does not help: traffic to these services is encrypted, so prompt content cannot be inspected without invasive measures.
Even the enterprise editions do not solve everything. Business editions like ChatGPT Enterprise or Claude for Work offer a DPA and, by configuration, do not use the data for training: they cover the relationship with the provider, but they do not stop an employee from pasting a client's data that should not have left the company anyway. The DPA is necessary, not sufficient.
How to become compliant: the checklist
1. Map real AI usage
You cannot govern what you cannot see: start by measuring shadow AI across all tools, not just ChatGPT.
2. Define a clear policy and train your people
It is needed, but do not rely on it alone: on its own it does not hold in the moment of need. It must be paired with a control that acts in real time.
3. Enable enterprise editions with a DPA and opt-out from training
Where available, they are the contractual foundation. It is a necessary step, not the complete solution.
4. Minimize (Art. 5)
Make sure personal data never reaches the prompt: this is the principle that neutralizes the risk at the source.
5. Apply local-first masking
A tool like Talmur intercepts and replaces sensitive data directly in the browser, across all major AI assistants (ChatGPT, Claude, Gemini, Copilot, Perplexity), before sending and with on-device analysis. It satisfies privacy by design (Art. 25) and prevents the unauthorized transfer at the source.
6. Document and monitor in aggregate form
Accountability (Art. 5.2) requires being able to demonstrate the measures adopted: you need aggregate, anonymous metrics, never prompt content.
In conclusion
Being compliant does not mean giving up AI. It means moving control to the right place: on the user's device, before data leaves the browser. The question is not how we block ChatGPT or the other assistants, but how we make using them, by default, the compliant choice.
Protect AI usage in your organization.
See how Talmur masks sensitive data before it leaves the browser.
Book a Demo