# Is ChatGPT GDPR compliant? An AI policy for UK firms

> ChatGPT is not GDPR compliant by itself: it depends on the plan, the contract and the use. The UK GDPR duties, OpenAI's terms and a short AI policy.

Guide · Safe AI in regulated firms · By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026
Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.
Canonical: https://vexralabs.com/insights/chatgpt-client-data-policy

Short answer

**No AI tool is GDPR compliant by itself.**UK GDPR puts its duties on the firm that uses ChatGPT, not on the product. Whether a firm’s use complies depends on three things: the plan it buys, the contract it signs with OpenAI, and how staff use the tool with client personal data.

This guide is for owners and compliance leads in UK accounting, advice and immigration firms whose staff use ChatGPT or a similar tool. The question matters because the same product gives two answers: OpenAI says it may train its models on content from its services for individuals, and does not do so by default on its business plans. The sections below cover the vendor’s role, what each plan does with inputs, the legal duties, the good practice on top, a short policy and the checks for any vendor’s terms.

**Diagram: What decides whether a firm's use of ChatGPT complies with UK GDPR.** Five things decide compliance, in order. The plan: a business plan or a personal account. The contract: a signed data processing agreement. The role: whether the vendor acts only on the firm's instructions or also uses inputs for its own purposes. The use: a lawful basis, the minimum data and a risk assessment. The evidence: records that show all of this if a client or the regulator asks.

*The product is the same at every step. The plan, the contract and the firm's own conduct change the answer.*

## What is a GDPR-compliant use of ChatGPT?

A compliant use is one where the firm meets its own duties under UK GDPR, the UK’s version of the General Data Protection Regulation, for the personal data staff put into the tool. ChatGPT is the AI chat assistant provided by OpenAI. Personal data is any information relating to an identified or identifiable person ([Article 4(1)](https://www.legislation.gov.uk/eur/2016/679/article/4)).

UK GDPR places its duties on the controller. A controller is the body that “determines the purposes and means of the processing of personal data” (Article 4(7)). A firm is the controller for its client work. Article 5(2) makes the controller “responsible for, and be able to demonstrate compliance with” the data protection principles ([Article 5](https://www.legislation.gov.uk/eur/2016/679/article/5)). No vendor’s certificate or marketing page moves that duty.

## Is OpenAI a processor or a controller?

The role depends on who decides the purposes and means of the processing, not on the type of vendor. A processor is a body that “processes personal data on behalf of the controller” (Article 4(8)). On a business plan with a data processing agreement, the vendor normally acts as the firm’s processor.

A vendor that uses inputs for its own purposes, such as training its models, decides that purpose itself. It is a controller for that use, and a processor contract alone does not cover the firm. The Information Commission, the UK data protection regulator that took over from the Information Commissioner on 30 September 2026 and still publishes as the ICO, puts it this way in its [guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/): “Organisations that determine the purposes and means of processing will be controllers regardless of how they are described in any contract about processing services.”

The same guidance says an organisation can be “a controller or joint controller for some phases or purposes, and a processor for others”. [Article 28(10)](https://www.legislation.gov.uk/eur/2016/679/article/28) adds that a processor which determines the purposes and means of processing is treated as a controller for that processing. The ICO tells firms to assess and document the status of each organisation they work with.

## What do OpenAI’s plans do with the data staff enter?

OpenAI treats its services for individuals and its business plans differently, and says so on two of its own pages. The table quotes those pages as they read on 8 October 2026.

| Question | Services for individuals | ChatGPT Business, ChatGPT Enterprise and the API |
| --- | --- | --- |
| Are inputs used to train OpenAI's models? | “We may use your content to train our models.” A user opts out under Settings > Data controls ([OpenAI Help Center](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance)) | “By default, we do not use your business data for training our models”, unless the customer opts in ([Enterprise privacy at OpenAI](https://openai.com/enterprise-privacy/)) |
| Does OpenAI offer a data processing agreement? | The Enterprise privacy page does not list these services among those with one | “We are able to execute a Data Processing Addendum (DPA) with customers for their use of ChatGPT Business, ChatGPT Enterprise, and the API” |
| Who controls retention? | Each user, in their own account settings | ChatGPT Business: workspace admins control retention. Deleted or unsaved conversations are removed within 30 days, unless law or protection from harm requires longer |

One exception sits inside the opt-out. OpenAI’s help page says that when a user gives feedback on a response, such as a thumbs up, “the entire conversation associated with that feedback may be used to train our models”, even after opting out. OpenAI dates its Enterprise privacy page 8 January 2026. Vendor terms change, so read both pages again before approving the tool.

These facts answer the role question for a firm’s own use. On a business plan with a signed DPA and no opt-in, OpenAI acts on the firm’s instructions. On a personal account with training switched on, OpenAI uses client data for a purpose the firm did not set.

## Which UK GDPR duties apply when staff use an AI tool with client data?

The firm, as controller, carries the duties below whenever client personal data goes into an AI tool. These are legal requirements, including the main ones for this use; UK GDPR contains others, such as the rules on international transfers and individuals’ rights.

| Duty | Provision | What it means for an AI tool |
| --- | --- | --- |
| Lawful basis | [Article 6(1)](https://www.legislation.gov.uk/eur/2016/679/article/6) | Processing is lawful only if one of the listed bases applies. Identify the basis for the task the tool is used for |
| Transparency | [Article 13(1)(c) and (e)](https://www.legislation.gov.uk/eur/2016/679/article/13) | The privacy information given to clients states the purposes, the legal basis and the recipients or categories of recipients of their data |
| Processor with sufficient guarantees | [Article 28(1)](https://www.legislation.gov.uk/eur/2016/679/article/28) | Use only processors that give sufficient guarantees of appropriate technical and organisational measures |
| Written contract | Article 28(3) and 28(9) | A contract governs the processor's work and is in writing, including in electronic form |
| Security | [Article 32(1)](https://www.legislation.gov.uk/eur/2016/679/article/32) | Controller and processor implement measures that give a level of security appropriate to the risk |
| Data minimisation | Article 5(1)(c) | Personal data is limited to what is necessary for the purpose. Paste the passage, not the file |
| Special category data | [Article 9(1)](https://www.legislation.gov.uk/eur/2016/679/article/9) | Processing data revealing health, ethnic origin, religious beliefs and the other listed types is prohibited unless an Article 9(2) condition applies |
| Data protection impact assessment (DPIA) | [Article 35(1)](https://www.legislation.gov.uk/eur/2016/679/article/35) | Required before processing that is likely to result in a high risk to individuals |
| Accountability | Article 5(2) | The firm is able to demonstrate that it meets the principles |

The data processing agreement, which OpenAI calls a data processing addendum, is the Article 28(3) contract. Article 28(3) sets out the terms it must contain, from acting only on documented instructions to deleting or returning the data at the end. Our guide to [what a processor contract must say under UK GDPR Article 28(3)](https://vexralabs.com/insights/uk-gdpr-article-28-processor-contract)lists every term to look for in a vendor’s DPA.

On the DPIA, the ICO’s guidance says: “In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA.” A firm that decides its use is not high risk still needs to document how it reached that view. Our guide to [when a UK firm needs a DPIA for an AI tool](https://vexralabs.com/insights/dpia-for-ai-tools) explains that assessment.

## What is good practice rather than law?

A written AI policy, an approved-tools list and a person checking every output are good practice, not named UK GDPR requirements. They are the simplest way to meet and evidence the duties above.

| Practice | Legal status | Why it helps |
| --- | --- | --- |
| Written AI policy | Required only “where proportionate in relation to processing activities” ([Article 24(2)](https://www.legislation.gov.uk/eur/2016/679/article/24)) | Gives staff one rule set and gives the firm a document to show |
| Approved-tools list | Not required by name | Keeps client data in tools the firm has a contract with |
| Business plan, not personal accounts | Not required by name | Puts the contract, the training setting and retention under the firm's control |
| A person checks every output | Not required by UK GDPR for drafting help | AI output can be wrong; the firm remains answerable for the work it sends |
| A note of AI use on the client file | Not required by name | Supports the Article 5(2) duty to demonstrate compliance |

## What should a short AI policy say?

One page is enough for a small firm. Six rules cover the duties and the practices above:

1. Use only tools on the firm’s approved list for client work.
2. Put client personal data only into tools covered by a signed data processing agreement.
3. Use the firm’s business account, never a personal one.
4. Remove names, reference numbers and anything else the task does not need; keep special category data out of general tools.
5. Have a qualified person check every output before it is used or sent.
6. Report a mistake or suspected leak to the firm’s named data protection lead the same day.

This list is a summary. The full wording, with scope, roles and a review date, is in our [AI policy template for UK accounting firms](https://vexralabs.com/insights/ai-policy-template-accounting-firms), which firms in other regulated sectors can adapt.

## What should a firm check in any AI vendor’s terms?

The same five checks apply to every vendor and every plan. Check each one in the vendor’s own published terms, in writing, before approving a tool:

- Training: whether inputs are used to train the vendor’s models, on which plans, and how the setting is controlled.
- Contract: whether the vendor signs a data processing agreement for the plan the firm is buying.
- Retention: how long prompts and files are kept, and who can delete them.
- Location: where data is stored and processed, and the safeguards for any transfer outside the UK.
- Access: who at the vendor and at the firm can read conversations, and whether the firm controls staff accounts centrally.

## When should a firm move beyond a general AI tool?

A firm should move a task into a purpose-built workflow when the task repeats and carries client personal data each time. A workflow applies the rules in software, so compliance does not depend on each person remembering the policy.

We learnt this building Filyst, our case management product for immigration firms. Filyst requires a second person to approve a case stage, and the server rejects an attempt to approve your own work. A rule the system enforces leaves a record; a rule that lives only in a policy document does not.

This post covers one control: staff use of a general AI tool. Our pillar guide, [AI in regulated industries: UK rules and human review](https://vexralabs.com/insights/ai-in-regulated-firms), sets out the full set of controls that this policy is one part of.

Not legal advice

This guide reflects UK GDPR, ICO guidance and OpenAI’s published pages as read on the date checked. The ICO states that its [guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/)is under review because of changes made by the Data (Use and Access) Act and may change. Vendor terms also change. Check the current terms of any tool before approving it, and take advice on your own firm’s position.

## Frequently asked questions

### Is ChatGPT GDPR compliant in the UK?

No tool is compliant by itself. UK GDPR puts the duties on the firm using it. A firm's use can comply when it has a lawful basis, a written processor contract under Article 28, no more data than the task needs and a DPIA where the risk is high.

### Is ChatGPT Business GDPR compliant?

The plan makes compliance possible but does not deliver it. OpenAI says it does not train on ChatGPT Business data by default and will sign a Data Processing Addendum. The firm still needs a lawful basis, transparency to clients, data minimisation and, in most cases, a DPIA.

### Does OpenAI train its models on what staff type into ChatGPT?

OpenAI's help page says it may use content from its services for individuals to train its models unless the user opts out. It says inputs and outputs from ChatGPT Business, ChatGPT Enterprise and the API are not used by default.

### Do we need a data processing agreement with OpenAI?

Yes, where OpenAI processes client personal data on the firm's behalf. UK GDPR Article 28(3) requires a contract with each processor, and Article 28(9) requires it to be in writing.

### Can staff paste health information into ChatGPT?

Keep it out of general AI tools. UK GDPR Article 9(1) prohibits processing special category data, including health data, unless an Article 9(2) condition applies, and the ICO expects a DPIA for most uses of AI.

## Sources

1. [UK GDPR Article 4 (definitions: personal data, controller, processor), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/4)
2. [UK GDPR Article 5 (principles and accountability), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/5)
3. [UK GDPR Article 6 (lawfulness of processing), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/6)
4. [UK GDPR Article 9 (special categories of personal data), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/9)
5. [UK GDPR Article 13 (information to be provided), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/13)
6. [UK GDPR Article 24 (responsibility of the controller), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/24)
7. [UK GDPR Article 28 (processor), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/28)
8. [UK GDPR Article 32 (security of processing), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/32)
9. [UK GDPR Article 35 (data protection impact assessment), legislation.gov.uk](https://www.legislation.gov.uk/eur/2016/679/article/35)
10. [ICO, What are the accountability and governance implications of AI?](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/)
11. [ICO, Guidance on AI and data protection: about this guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/about-this-guidance/)
12. [OpenAI, Enterprise privacy at OpenAI (updated 8 January 2026)](https://openai.com/enterprise-privacy/)
13. [OpenAI Help Center, How your data is used to improve model performance](https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance)
