Can you put client data into ChatGPT? A UK GDPR answer
Free and Plus can train on what staff paste, and your firm has no contract with OpenAI. What Business and Enterprise change, and what to do if it has happened.
On a personal ChatGPT account, usually not. Free, Plus and Pro can use what staff paste to train OpenAI’s models unless each person opts out, and your firm has no contract with OpenAI covering any of it. On ChatGPT Business or Enterprise it can be lawful, if the client contract allows it and you’ve covered the data protection basics.
Is ChatGPT GDPR compliant?
It’s the question most people type, and it can’t be answered as asked. ChatGPT is legal to use in the UK. UK GDPR puts its duties on whoever decides what happens to personal data, and when someone at your firm pastes a client’s details into a chat window, that’s your firm. So the useful question is whether your use of it is lawful, and that comes down to four things you control.
- You need a lawful basis for sending the data to OpenAI at all.
- You need a contract that makes OpenAI your processor. Article 28 of UK GDPR requires one whenever another company handles personal data on your behalf.
- Clients need to know their information may go to an AI provider, usually through your privacy notice or engagement terms.
- Only the data the task needs should go in.
Personal accounts fail the second test outright. If a member of staff signs up with their own email, the agreement is between them and OpenAI. Your firm isn’t a party to it, so there is no processor contract, whatever the account settings say.
What does your client contract allow?
Check this before GDPR, because it’s often stricter. Engagement letters and NDAs commonly limit who may see client information and require consent before it goes to a third party. An AI provider is a third party. If the contract says client material stays with named people or approved subcontractors, pasting it into any AI tool may breach the contract even where data protection law would allow it.
The contract also covers information GDPR doesn’t touch. A client’s pricing or unpublished accounts aren’t personal data, but they’re usually confidential, and a chatbot has no way of telling the difference.
Regulated professions add their own duty. The SRA’s code requires solicitors to keep clients’ affairs confidential unless the law requires or permits disclosure or the client consents. Where a rule like that applies, put AI use into the engagement terms and get the client’s agreement there, before anyone pastes anything.
Which ChatGPT plan are your staff on?
The plan decides most of the data protection answer. This is what OpenAI’s own pages said when we checked them on 6 October 2026.
| Free, Plus and Pro | Business | Enterprise | |
|---|---|---|---|
| Trains on what you paste | Yes, unless the user opts out | No, by default | No, by default |
| Contract with your firm | None. The account is an agreement between that person and OpenAI | Data processing addendum available | Data processing addendum available |
| Where the data is handled | No choice offered | OpenAI’s US company, under the UK’s international transfer clauses | Storage in the UK available to eligible customers |
Opting out on a personal plan doesn’t close the gap. OpenAI says that if someone rates a reply with a thumbs up or down, the whole conversation can still be used for training, and opting out does nothing about the missing contract.
OpenAI renamed ChatGPT Team to ChatGPT Business on 29 August 2025, so an older policy that approves “Team” means Business. Temporary chats don’t appear in your history, but OpenAI may keep a copy for up to 30 days. The 2025 court order that made OpenAI keep chats ended for new data on 26 September 2025, and OpenAI says it no longer has to keep conversations from the UK.
If your firm already pays for Microsoft 365, look at Copilot Chat before buying anything. Signed in with a work account, Microsoft processes prompts inside its Microsoft 365 service boundary and doesn’t use them to train its foundation models. It handles them under the data protection terms you already have with Microsoft. Web searches it runs through Bing sit outside that boundary.
What can staff paste safely?
Even on an approved business plan, set a floor. Some data shouldn’t go into any AI tool without a specific decision by whoever owns AI use:
- health details and other special category data, such as ethnicity or religion, and criminal records
- bank details, passport numbers and passwords
- anything a client contract or NDA restricts
- whole documents, when a paragraph would do
For everything else, strip out what identifies people before pasting. Replace names with roles, take out addresses, account numbers and dates of birth, and summarise the situation instead of pasting the full email chain. That cuts the risk a long way. It doesn’t always take the data outside GDPR, because a detailed enough description can still point to one person.
Is it safe to use ChatGPT at work?
Yes, with an approved tool on a business plan and a rule staff can remember. The risk sits with personal accounts used for client work, because nobody at the firm can see what goes into them or delete it. The NCSC has warned that providers can retain and access what’s submitted to public chatbots, and that sensitive information shouldn’t go into them.
Banning personal accounts outright rarely works, and the shadow AI guide covers why. Giving people an approved tool that does the same job usually does. Before you approve one, the seven questions to ask before you approve a new AI tool cover what it does with your data and who owns it afterwards. If the tool handles personal data, the DPIA screening test for AI tools tells you whether it needs a fuller assessment.
What if client data has already gone in?
Deal with it the same day.
- Find out what went in, from which account, on which plan, and whether training was switched on.
- Delete the chat. OpenAI schedules deleted chats for permanent deletion within 30 days.
- Decide whether it’s a personal data breach. Under UK GDPR that includes the unauthorised disclosure of personal data, and sending client data to a provider you have no contract with can count.
- If it is a breach and it’s likely to result in a risk to the people involved, report it to the ICO within 72 hours of becoming aware of it. If the risk to them is high, tell them as well.
- Read the client contract. It may require you to tell the client whatever the GDPR answer turns out to be.
- Write down what happened and what you decided. UK GDPR requires a record of every personal data breach, reported or not.
Plenty of these turn out to be low risk, such as a first name and a vague description in a chat nobody else can see. If the data was sensitive or the client is regulated, take legal advice before deciding not to report.
Write the rule down
One line in your acceptable use policy covers most of this:
Client information goes only into the AI tools on our approved list, through our accounts. Personal AI accounts are never used for client work.
Name the approved tools, and the plan for each, in a list under the rule. The acceptable use policy guide covers the rest of what staff need telling, and the AI policy template puts it inside a full policy.