AI Tools & Data Protection (e.g. ChatGPT at Work)
AI tools such as ChatGPT are fully subject to the GDPR when a company uses them: entering or processing personal data requires a legal basis under Article 6, transparency towards the people concerned and, with external providers, a data processing agreement under Article 28. Transfers to third countries such as the United States have to be safeguarded as well.
In practice
Before you use AI productively, check whether the provider offers a business or enterprise version with a data processing agreement and without using your inputs for model training, because free consumer versions often lack those guarantees. Customer data, health data and other sensitive information should not go into prompts at all unless you have an explicit legal basis and contractual cover. Extensive or high-risk use may also call for a data protection impact assessment under Article 35 GDPR; an internal AI policy for staff creates additional clarity. Alongside the GDPR, the transparency obligations in Article 50 of the AI Act have applied since 2 August 2026, such as disclosing that users are interacting with an AI system and labelling AI-generated content.