It’s one of the questions I get most: can I give ChatGPT a client’s contract, or a spreadsheet full of names? In other words, is ChatGPT GDPR compliant? It works like any other cloud software: you can use it with client data, but not with just any account or in just any way. Here is what I would do, based on what the law, the AEPD (Spain’s data protection authority) and the companies themselves say in September 2026.

This isn’t legal advice. If you handle sensitive or health data (a clinic, a psychology practice, a care home), talk to whoever handles your data protection before you put anything in.

Is ChatGPT GDPR compliant? The short answer

It’s a trick question: you are the one who has to comply with GDPR, because you decide what data goes in and why. What the tool brings to the table depends on the account:

  • Personal account (Free, Go, Plus, Pro or Max). There’s no data processing agreement: the company handles what you type under its own policy and may use it for training depending on your settings and consent. Fine for work with nobody’s data in it, but not for client data.
  • Business account. Check that the specific service has a processing agreement and suitable terms for your data. ChatGPT Business and Claude Team do not train on your content by default. With Gemini, enterprise protections depend on the Workspace licence; using your work email is not enough.
  • Health data and other specially protected data: not even with a business account without checking first. OpenAI’s and Anthropic’s data processing addenda both say they don’t expect to receive it.

Whatever the account, leave out what isn’t needed. To answer an email or summarise a contract, the AI almost never needs anyone’s name, ID number or phone number.

Personal or business account: the difference that matters

What matters here is which service and licence the agreement covers, as well as the model you can use. Check the plan terms before uploading data. This comparison covers the named plans in September 2026:

What to check ChatGPT Business Claude Team Workspace Business Starter with Gemini
Minimum 2 users 2 people 1 user
Price per user per month €21 billed annually, €26 monthly €18 + VAT billed annually, €21.04 + VAT monthly Business Starter, €6.80 + VAT with an annual commitment
Trains on your data? No, by default No, by default Not outside your organisation without permission, and no human review
Processing agreement Included in its business agreement Included in its commercial terms Cloud Data Processing Addendum
Can you keep data in Europe? Only on Enterprise and Edu No, it stores it in the US For Gemini, not on the Business plans

OpenAI’s site doesn’t say whether the €21 includes VAT. Of these three options, Workspace Business Starter allows one user and includes Gemini in Gmail and the Gemini app. Other editions, such as Workspace Individual, do not offer the same protections for the Gemini app.

Data ending up in the US doesn’t stop you using them: their contracts cover that transfer with the European Commission’s standard contractual clauses or other safeguards allowed by GDPR. But you have to say so in your privacy notice.

What about a paid personal account with training switched off? Better than nothing, but you still have no processing agreement. And the business account only works if the whole team uses it: if someone puts client data into their personal ChatGPT, your contract doesn’t cover it.

The settings to change today in ChatGPT, Claude and Gemini

Even if you use your personal account without anyone’s data, I would change these today:

  • ChatGPT. Open your account menu, Settings, Data controls, and turn off «Improve the model for everyone». It applies to your whole account and covers Codex tasks too. While it remains temporary, a chat is not used for training; a copy may be kept for up to 30 days for safety. Saving it as a regular chat makes your account settings apply.
  • Claude. Settings, Privacy, and turn off the option to help improve its models. With it on, Anthropic keeps your chats for up to five years, and turning it off doesn’t remove what has already been used, so do it before you put anything in. Incognito chats aren’t used for training either.
  • Gemini. On gemini.google.com, click Activity and, near the top, click «On» and then «Turn off». That’s the «Keep Activity» setting, on by default if you’re 18 or over. While it’s on, Google can use your chats to train its models, with human reviewers, and reviewed chats are kept for up to three years even if you delete your activity. One catch: on a personal account, with that setting off, Gemini can’t use Gmail or Drive. Even with activity off, chats may be kept for up to 72 hours. For work, check your account licence and data protections.

And in all three, watch the thumbs. If you rate an answer, OpenAI and Anthropic can use that whole conversation for training even with training switched off, and Google sends it for review. With client data, leave them alone.

When you need a data processing agreement

As soon as someone processes personal data on your behalf. Article 28 of GDPR requires you to choose someone with sufficient guarantees and to have a written contract (electronic is fine) setting out what they do with the data, under what instructions and security, and what happens to it at the end. You probably already have one with your gestor.

With AI you need it if you put in other people’s data: clients, patients, employees. Truly anonymous data doesn’t need one, but writing «Client A» doesn’t make a document anonymous if the rest gives away who it is about. That is pseudonymisation, and under Recital 26 of GDPR it is still personal data.

With the business accounts you already have it:

  • ChatGPT Business. Its business agreement includes the addendum, and for European customers it’s signed by OpenAI Ireland. If you want a signed copy, there’s a form on its enterprise privacy page.
  • Claude Team. The addendum, with the EU standard contractual clauses, is part of the commercial terms you accept when you sign up.
  • Google Workspace. Google recommends accepting its addendum if you’re not sure you already have it. As a super admin, in the Admin console: Menu, Account, Account settings, Legal and compliance, then «Review and Accept».

If you want to see what it should contain, the AEPD has guidelines with a template (in Spanish).

How to anonymise a document before you upload it

If you ask the AI to anonymise a document, you have already sent it the whole thing. The work happens before, on your computer. With a client’s lease, this is how I would do it:

  1. Copy only what you need into a new document, for example the rent and notice clauses. That also leaves out comments, tracked changes and the author’s name. If you upload the whole Word file, run the Document Inspector first (File, Info, Check for Issues, Inspect Document).
  2. Swap the data for placeholders with Find and Replace: [CLIENT_A], [COMPANY_B], [ID_1], and the same with phone numbers, emails, addresses and bank details. The list of who is who stays on your computer, and you use it to put the names back when the AI returns its work.
  3. Look for what identifies someone without a name: a cadastral reference, a number plate, a policy number, a date of birth, «the only chemist’s in the village», an unusual diagnosis.
  4. Check before you upload. Search for an @, the surname and the ID number. If you blacked out a PDF with boxes, copy the covered area and paste it into a text editor: if the text shows up, it’s still there.

The AI can help without seeing the document:

In a while I'll send you [a commercial lease / a client report]. First I want to remove the personal data on my own computer, so I'm not sending it yet.
Tell me what data a document like this usually contains that could reveal who it is about, directly or indirectly, what placeholder you would use for each item, such as [CLIENT_A] or [ID_1], and what I can leave in because it identifies nobody.

And with the clean copy:

In this document I have replaced personal data with placeholders such as [CLIENT_A] or [ID_1]. Keep them exactly as they are, don't try to guess who they refer to and don't make up names.
Task: [for example, «summarise the tenant's obligations, the key dates and the penalties»].
Before you start, tell me if you spot any data I missed that could identify someone. Don't repeat it: just tell me where it is.

That last check is only a safety net: if something slipped through, you’ve already sent it, but you can remove it from your copy and delete that chat. The full method for reviewing contracts is in how to compare quotes and contracts with AI.

If you want an AI to do the anonymising for you, it has to run on your computer, with free programs such as LM Studio or Ollama and a downloaded model, not one of their cloud models. It can still miss things, so check anyway. The AEPD and the European Data Protection Supervisor explain it well in 10 misunderstandings related to anonymisation.

Agents and connectors: the new risk

With agents and connectors, the AI goes into your email, your Drive or your CRM and reads what it needs. ChatGPT Work, Claude and Gemini already do this, and ChatGPT can start a task by itself when a new email lands in Gmail. That brings two risks.

The first is far more data: an inbox is full of client data. On personal accounts, OpenAI may also train on what it reads through its apps if «Improve the model for everyone» is on. Anthropic says it doesn’t use raw connector content, only what ends up copied into the chat.

The second is prompt injection: instructions hidden in an email, a PDF or a web page, in white text for example, which the agent reads and obeys. The AEPD gives the example of an email the agent summarises, carrying out its hidden instruction without you clicking anything. OpenAI and Anthropic keep improving their defences, but both admit the risk doesn’t go away.

My rules:

  • Connect only what the task needs, and disconnect it afterwards.
  • Specific jobs, such as «summarise today’s emails from the courier about order 114». Never «review my emails and take whatever action is needed», which is exactly the example OpenAI gives of what not to do.
  • Make it ask before sending, deleting or paying. In ChatGPT’s app permissions, «Always ask» or at most «Allow read actions»; OpenAI warns that «Allow all actions» carries elevated risk. In Claude, manual approval whenever client data is involved.
  • The rule of two the AEPD describes. An agent shouldn’t combine, without you supervising, reading outside content, accessing sensitive information and acting on its own. If a job needs all three, have it ask you at every step.

Business accounts matter here too: on ChatGPT Business, what it reads through connectors isn’t used for training by default. If you’re choosing an agent, I compare the two big ones in Claude Cowork vs ChatGPT Work.

What the AEPD says

What Spain’s data protection authority has published in 2026 that matters if you use AI at work:

  • «Cuidado con lo que le confIAs» (in Spanish), January 2026. Its ten tips for the public: don’t upload personal data, describe made-up cases and, at work, don’t put in confidential data about your company (it mentions contracts and reports), your staff or your clients.
  • Guidance on agentic AI, February 2026. The risks agents pose to personal data, including prompt injection and the rule of two.
  • AI voice transcription, January and April 2026. If you record or transcribe meetings, you are the controller: tell everyone before you start and make it visible that you are recording. If you rely on consent, «by joining you agree» doesn’t count, and it only covers that recording. Also check whether the provider retrains its AI on the recordings, because people often listen to them.
  • AI to screen CVs (in Spanish), 23 September 2026. A preventive warning to a company planning to score candidates with AI: it has to explain this to candidates, and whoever decides must genuinely weigh the score.
  • Its own rules, January 2026. The ones it set for its own use of generative AI: business versions, checking beforehand whether the provider trains on the data and where it stores it, and no personal data in unapproved tools.

Do I have to tell my clients I use AI?

If AI only helps you prepare your work (an email you then review, a contract summary, a table of invoices), the EU AI Act doesn’t require you to say anything. Since 2 August 2026, its Article 50 does require a notice in these cases:

  • If an AI talks to your clients, in a chat on your website or on WhatsApp, they must know from the first message that it’s an AI, unless that’s obvious. That falls mainly on whoever makes the tool, but if you set it up yourself, check that it says so.
  • If you publish deepfakes, meaning images, audio or video representing existing people, places or other things that falsely appear authentic, you must disclose this. There are legal exceptions and adapted disclosure rules for artistic, satirical or fictional works.
  • If you publish AI-generated text to inform the public on matters of public interest, unless a person reviews it and someone takes editorial responsibility for it.

The July 2026 Omnibus only gave makers of tools already on the market more time, until 2 December 2026, to mark what they generate so that a machine can detect it. Your part applies from August 2026.

On the GDPR side:

  • Using a provider under a processing agreement doesn’t count as disclosing the data. Article 33 of Spain’s data protection law (in Spanish) says so, so you don’t need separate permission from each client for that.
  • Your privacy notice does need to be up to date. Article 13 of GDPR requires you to say who receives the data and whether it leaves the EU, with what safeguards. The safe option is to name your AI providers, even as a category, and the transfer to the US has to be there.
  • If an AI decides on its own something that really affects a person, such as rejecting a CV, you’re in the territory of Article 22 of GDPR. The simple fix is to have a person make the decision, genuinely looking at what the AI suggests.

And if you have staff using AI, the law also has something to say about their training: I explain it in is AI training mandatory.

My advice for this week: today, the settings on your personal accounts. Then choose the business account that fits what you already use, put in writing that client data only goes there, and review your privacy notice.

Sources, checked on 26 September 2026: GDPR, the AI Act, Spain’s data protection law and the AEPD’s guides on processor contracts, anonymisation, using AI and agentic AI.

Privacy reviewed on 30 September 2026: Gemini protections by licence, Temporary Chat in ChatGPT and Gemini activity.