Is ChatGPT GDPR-compliant for businesses?
It depends on the plan and the settings. How Free, Plus, Business and Enterprise differ on data protection, and what to check before your team uses it with customer data.
The short answer: ChatGPT is neither GDPR-compliant nor non-compliant on its own. It depends on which plan your team uses, how it is configured, and what goes into it. An employee summarising a client contract on a personal free account is a different case from a company on ChatGPT Enterprise with a signed agreement and a clear rule.
This article sorts the plans, lists what to check, and says where Verselo fits and where it does not.
Why is there no simple yes or no?
The GDPR has no list of approved software. It makes you, the controller, responsible for being able to show that every processing of personal data meets its principles. That is Article 5(2) and Article 24 GDPR. An AI tool is a tool, and whether a tool fits depends on the job.
The European Data Protection Board set up a task force on ChatGPT specifically. Its report from May 2024 makes two points every business user should know: technical impossibility is no excuse for not meeting GDPR duties, and the model's answers about people can be wrong. If you use ChatGPT at work, that problem comes with it.
National regulators go into practical detail. The German data protection conference (DSK) published a guidance paper on AI and data protection in 2024 that works through the questions a company should ask: legal basis, training on inputs, contracts with the provider, informing staff. It reads well even outside Germany.
How do the ChatGPT plans differ on data protection?
This is where the real difference sits. OpenAI separates personal and business plans sharply. As of October 2026, according to OpenAI:
| Plan | Inputs used for training | Data processing agreement | Storage in Europe |
|---|---|---|---|
| Free, Plus, Pro | yes, unless the user switches it off | no | no |
| Business (formerly Team) | no, by default | yes | for newly created workspaces |
| Enterprise, Edu | no, by default | yes | selectable for new workspaces |
| API | no, by default | yes | through European projects |
Sources: OpenAI on business data, OpenAI on data residency in Europe, and for the Business plan a Netzwoche report of 7 September 2026. Check the current state with the provider before you decide. These details change.
Two things the table leaves out. Data residency in Europe covers stored data. Where a request is processed at the moment of answering is a separate question, and worth getting in writing. And the best business plan does nothing if half the team keeps using personal accounts on the side.
What should you check before rolling it out?
Seven points for any company from five people up:
- The plan. Personal accounts used for work are the most common mistake. The German regulators explicitly recommend that employers provide company accounts (DSK guidance, section 2.4).
- A data processing agreement. If a provider processes personal data on your behalf, Article 28(3) GDPR requires a contract. No contract, no customer data.
- Training. Find out whether inputs and outputs are used to train models. Tools that do not train on your data are the better choice from a data protection point of view, as the DSK puts it.
- Location and transfers. Where is data stored, where is it processed, and on what basis does it leave the EU, if it does? Transfers to third countries fall under Chapter V GDPR.
- A data protection impact assessment. Required under Article 35 GDPR where processing is likely to result in a high risk. With AI and personal data, expect it to apply.
- An internal rule. In writing, with examples: what may go in and what never does. If you have a works council or staff representatives, involve them early.
- Training your people. Since February 2025, the EU AI Act requires measures on AI literacy. More in the article on AI literacy under Article 4.
If you do not know today which accounts your team uses, start there. The article on shadow AI in the workplace shows how to find out without starting a witch hunt.
Which data should never go into a personal ChatGPT account?
Personal customer data, such as names with ID or bank details. Contracts and internal documents with confidential terms. Staff data: salaries, sick notes, job applications. And anything covered by professional secrecy.
This is not red tape. On a personal account, OpenAI is not your processor for that data, and you have no say over what happens to it next. If your team needs AI for exactly this kind of work, and most teams do, it needs a tool with a contract and controls.
Where does Verselo fit?
Verselo is an AI workspace for small and mid-sized companies. Your team chats with models from Anthropic (Claude) and OpenAI, asks questions of the company's own documents, and gets answers with the source. On data protection, this is what applies:
- AI requests run in EU data centres: AWS Bedrock in Frankfurt and Microsoft Azure in EU regions. Database and files sit with Supabase in Frankfurt, servers with Hetzner in Germany.
- Customer data trains no model. The model providers are bound to zero data retention.
- Admins see who uses AI and what it costs, set the allowed models and how long chats are kept, and remove a user's access in one click. An audit log keeps twelve months of activity.
- The data processing agreement comes with the launch.
One exception, better told by us than found in the small print: when someone uses web search, the search terms go to Google. Files, chats and company knowledge stay where they are. If you do not want that, an admin switches web search off.
And what Verselo does not do: take the responsibility off you. With Verselo you still need an internal rule, trained staff and, depending on the use, an impact assessment. Verselo makes the technical questions on the list easier to answer. The organisational ones stay with you.
Until launch, we show you the platform on a call.
What is a sensible next step?
If your team already uses ChatGPT, and in most companies it does, there are two clean routes. Move everyone to an OpenAI business plan, sign the agreement and write the rule. Or pick a workspace built for companies in the EU. Either beats the state where everyone has their own account and nobody knows what ends up where.
Frequently asked questions
Can my team use ChatGPT with customer data?
Not on a personal Free or Plus account, at least not without more. Those plans come without a data processing agreement under Article 28 GDPR, and inputs can be used for training unless the user switches it off. On a business plan such as ChatGPT Business or Enterprise, with a signed agreement and an internal rule on which data may go in, it can work. Your company stays responsible either way.
Is turning off model training in the settings enough?
No. It stops your inputs from improving the model. It does not replace a data processing agreement, does not decide where the data is stored, and does not show you who puts what into the tool. On personal accounts, the setting also belongs to each employee, not to you.
Is there a GDPR certification for ChatGPT?
No, and there is no blanket one for any AI tool. The GDPR assesses processing, not products. What complies or not is your specific use: which plan, which contracts, which data and which internal rules. A provider can make that easier or harder. It cannot do it for you.
How does Verselo differ from ChatGPT on data protection?
Verselo processes AI requests in EU data centres, with AWS in Frankfurt and Microsoft Azure in EU regions, and stores files with Supabase in Frankfurt. Customer data trains no model. Verselo states the exception openly: web search sends the search terms to Google, and admins can switch web search off. The data processing agreement comes with the launch.