Skip to content
← All posts
· 6 min read· By

Using ChatGPT in Your Business in Compliance with GDPR: DPA, Business vs. Free, EU Data Residency

When your business needs a data processing agreement for ChatGPT, which plan provides one, what happens to your data – and when EU data residency matters.

GDPRChatGPTAI consultingdata protectionSMB

Many businesses already use ChatGPT in their day-to-day work – drafting quotes, handling customer communication, writing internal documentation. Very few have checked whether their chosen plan actually permits this under data protection law. The difference between a Free account and a Business or Enterprise plan is not a matter of convenience; it is a matter of compliance.

Note: This article does not constitute legal or data protection advice. It describes the technical and contractual framework. For a binding assessment of lawfulness in your specific situation, consult a data protection officer or legal counsel. Last updated: July 2026.

When does a business need a data processing agreement (DPA)?

As soon as personal data is entered into ChatGPT, a data processing agreement (DPA) is required under Article 28 GDPR. Personal data is not limited to customer names and email addresses – it is sufficient if individuals could be identified from the text, for example through a combination of job title, location, and situation.

Practical examples that trigger the DPA requirement:

  • Drafting quotes or demand letters that contain customer information
  • Summarising application documents or employee data
  • Processing customer complaints or support cases
  • Structuring personal notes or meeting minutes

A DPA is only unnecessary if exclusively anonymous or entirely fictional text is being processed – which is the exception, not the rule, in day-to-day business.

Violations of Article 28 GDPR can result in fines of up to €10 million or 2 % of global annual turnover – whichever is higher.

Which ChatGPT plan provides a DPA – and which does not?

Only the paid business tiers (Business, Enterprise, Edu) and the API allow you to enter into a DPA with OpenAI. For Free and Plus accounts, no Data Processing Addendum is available.

Plan DPA available? Training data use EU data residency
Free No Yes (opt-out available) No
Plus No Yes (opt-out available) No
Business (formerly Team) Yes No (default) No
Enterprise Yes No (default) Yes
API Yes No (default) Yes

The current OpenAI DPA was updated on 1 January 2026 and covers GDPR Standard Contractual Clauses (SCCs), UK GDPR, Swiss Data Protection Act, and CCPA. For EU-based businesses, the SCCs are the critical legal basis for transferring data to the United States, since OpenAI is headquartered in San Francisco.

Sources: OpenAI Data Processing Addendum, OpenAI Enterprise Privacy

What happens to my inputs – are they used for training?

On Free and Plus accounts, conversations are used for training OpenAI's models by default; this default can be turned off in the settings, but it does not resolve the absence of a DPA. From ChatGPT Business upwards, inputs are not used for training unless the user explicitly enables this.

The opt-out on Free and Plus accounts does not solve the problem: without a DPA, there is no contractual basis for the data processing. A technical measure (no training) does not substitute for a GDPR-compliant contractual arrangement.

Source: OpenAI – How your data is used

When is EU data residency necessary?

EU data residency is not mandatory for all businesses, but it can be appropriate – or contractually required – where particularly sensitive data is involved. The SCCs included in the OpenAI DPA provide a valid legal basis for transfers to the United States, and for many small and medium-sized businesses this is sufficient.

Organisations for which EU data residency deserves its own assessment:

  • Medical practices, pharmacies, counselling services: Health data falls under special categories of personal data (Article 9 GDPR); a demonstrably high level of protection is required.
  • Law firms and tax advisors: Client data is subject to statutory confidentiality obligations.
  • Public-sector contractors: Some tender requirements mandate EU data sovereignty.

Since 16 January 2026, OpenAI has offered Enterprise and API customers not only EU-based data storage but also GPU inference in Europe – meaning that the processing of requests itself takes place on European servers. ChatGPT Business does not include this option.

Source: OpenAI – Introducing Data Residency in Europe

What guidance has the German data protection authority issued?

In May 2024, the German Data Protection Conference (DSK) published a guidance document on AI and data protection that sets out concrete requirements for the business use of AI tools such as ChatGPT. Key points for operational practice:

  • Define the purpose of AI use in writing before deployment
  • Identify the legal basis for data processing (for external AI services: DPA + SCCs)
  • Do not enter employees' real names into accounts; use functional email addresses
  • Inform staff about permissible and impermissible inputs

Source: DSK Guidance on AI and Data Protection (PDF, May 2024)

What steps should every business take?

An internal ChatGPT usage policy does not have to be lengthy, but it must exist. The following checklist covers the essential points:

  1. Clarify your plan: Use Free and Plus only for completely anonymised text; for business processes involving personal data, use at least ChatGPT Business with a signed DPA.
  2. Review and file the DPA: Download the OpenAI DPA and keep it as part of your GDPR documentation.
  3. Communicate input restrictions: Inform staff in writing about which categories of data must not be entered into ChatGPT (e.g. national insurance numbers, banking details, special-category data under Article 9).
  4. Account hygiene: No personal Free accounts for business tasks; use centralised company accounts with clear assignment.
  5. Record of processing activities (RPA): Add ChatGPT as a processing activity, including purpose, legal basis, and recipient.
  6. Annual review: OpenAI updates its privacy policies regularly – check DPA changes and adjust your measures accordingly.

Conclusion

ChatGPT can be used in GDPR-compliant ways – but not with every plan and not without a contractual basis. Businesses processing operational data today with a Free or Plus account are doing so without a DPA and therefore outside the requirements of GDPR. Switching to ChatGPT Business is the practical first step: a DPA is available, model training on your data is off by default, and costs are manageable.

For organisations with stricter data sovereignty requirements – healthcare providers, law firms, public-sector service providers in Recklinghausen, the Ruhr region, and beyond – assessing ChatGPT Enterprise or the API with EU data residency is worth the effort.

Would you like to know which plan and which policies are the right fit for your business? I am happy to help companies in Recklinghausen and the Ruhr area introduce ChatGPT and other AI tools in a GDPR-compliant way – in a free initial consultation.

Note: The articles on this blog are produced with the help of AI and are editorially reviewed before publication. Editorial responsibility lies with Emre Yurtbay (see the Impressum).

Discuss your project