Knowledge · AI at work · 8 minutes

Can you paste company data into ChatGPT? GDPR and plans

What you can and cannot paste into ChatGPT at work. Free, Plus, Business and Enterprise compared, the training setting and what GDPR regulators say.

Last updated: October 5, 2026

Can you paste personal data into ChatGPT?

Pasting personal data into an AI chat is processing under the GDPR. The company needs a legal basis (Article 6), must limit data to what is necessary (Article 5) and, if the vendor processes data on its behalf, needs a data processing agreement with it (Article 28).

Individual plans come with no such agreement with your company. According to OpenAI's enterprise privacy page (updated 8 January 2026), OpenAI signs a DPA for ChatGPT Business, ChatGPT Enterprise and the API platform.

The practical takeaway: customer data pasted into an employee's personal account is data the company no longer controls. You cannot apply a retention policy to it or check who had access.

ChatGPT Free, Plus and Pro: are conversations used for training?

According to the OpenAI Help Center (article on how data is used to improve models), content from services for individuals, including ChatGPT, may be used to train models. You can turn this off: Settings, Data controls, switch off Improve the model for everyone. When signed in, the setting applies across devices.

Two exceptions few people know about. First, rating a response with thumbs up or down can make the whole conversation available for training even with the setting off. Second, turning training off does not delete saved chats; they stay in your history.

A temporary chat does not appear in history and is not used for training, but according to OpenAI it may be retained for up to 30 days for safety purposes.

ChatGPT Business and Enterprise: what changes?

According to OpenAI, inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu and the API are not used for model training by default. The company keeps rights to its data, and OpenAI encrypts it at rest (AES-256) and in transit (TLS 1.2 or later).

In Business, workspace admins can view, export and delete users' conversations. Deleted conversations are removed from OpenAI's systems within 30 days unless the law requires retention. In Enterprise and Edu, admins set the retention period.

A business plan does not solve everything. You still need a legal basis, notices for the people whose data it is, and an assessment of whether data leaves the European Economic Area. OpenAI will not do that for you. We look at the tool more broadly in is ChatGPT safe for business data.

ChatGPT and GDPR: what do regulators say?

On 24 May 2024 the European Data Protection Board (EDPB) adopted the report of its ChatGPT taskforce. It pointed to issues with legal basis, transparency and data accuracy, and noted that the controller cannot shift responsibility for GDPR compliance onto users.

The Polish data protection authority (UODO) has not issued a dedicated position on pasting data into ChatGPT; we could not find one on its website as of 5 October 2026. On 6 August 2026 it did publish question lists for assessing AI tools before deployment, including a version for small and medium companies. Earlier it advised caution with DeepSeek, which we cover in is DeepSeek safe.

What not to paste into ChatGPT at work

Without a business plan and explicit permission in your company policy, do not paste: personal data of customers, patients or employees (full names, national ID numbers, addresses, phone numbers), health data, passwords, API keys, tokens and config files, contract or offer text, unpublished financial data or proprietary source code.

Generally fine: public text, general questions, drafts without identifying details, data anonymised so that no person can be re-identified. Removing a name is often not enough, because a person can be identified by job title, city and date.

Secrets are easy to miss in a log or an error dump. Before you paste such a snippet, you can check it for keys and tokens. The check runs in your browser and nothing is sent anywhere.

How to anonymise data before pasting it into ChatGPT

The GDPR distinguishes anonymised from pseudonymised data. Anonymised data no longer allows a person to be identified by any means reasonably likely to be used, and the GDPR does not apply to it (Recital 26). Pseudonymised data, for example with a name replaced by 'Customer A', is still personal data if the company holds a key that links it back to the name (Article 4(5)).

In practice, before pasting: remove names, addresses, national ID and tax numbers of individuals, phone numbers, emails and contract numbers. Replace dates with relative ones ('three months later') and round amounts if they do not matter for the question. Remove details that point to a specific person in a small company or town, such as an unusual job title.

Often you can ask without any data at all. Instead of pasting a whole customer email thread, describe the issue in your own words and ask for a draft reply. Instead of pasting a spreadsheet, paste only the column headers and ask for a formula. Same result, no risk.

How to use ChatGPT safely at work: 5 steps

1. Give your team accounts on a business plan instead of tolerating personal accounts. 2. Sign a data processing agreement with the vendor. 3. Write down which data may be pasted in a short policy. You will find a template in AI use policy for companies.

4. If someone uses an individual plan, have them switch off Improve the model for everyone and use temporary chats for one-off tasks. 5. Check for AI tools running in the company that you do not know about. This has a name: shadow AI.

What to do if data has already been pasted into ChatGPT

Delete the conversation and check whether training was on for that account. If a key or password was pasted, revoke it and issue a new one, because deleting the chat does not undo the exposure.

If personal data was involved, tell whoever is responsible for data protection. The company must assess whether it is a personal data breach. If it is and there is a risk to people, Article 33 of the GDPR requires notifying the supervisory authority within 72 hours of becoming aware of it.

Whatever the outcome, record what happened: when, which data, in which tool and on which account. Article 33(5) of the GDPR requires documenting all breaches, including those not notified. Then fix the cause, for example by giving that person a company account or clarifying the policy.

In short

  • Do not paste personal data, passwords, keys or trade secrets into a personal ChatGPT account. The company has no data processing agreement with OpenAI there.
  • On Free, Plus and Pro, conversations can be used for training until you switch off Improve the model for everyone. A thumbs rating can still make that conversation available for training.
  • ChatGPT Business and Enterprise do not train on your data by default and offer a DPA, but the legal basis and transparency duties stay with the company.
  • The Polish authority UODO has no dedicated position on ChatGPT. It has AI tool assessment question lists published on 6 August 2026.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is ChatGPT GDPR compliant?

There is no one-line answer, because compliance depends on how you use it. A business plan with a DPA is a necessary condition, but the company remains responsible for legal basis, data minimisation and informing people.

Does ChatGPT remember what I type?

Conversations stay in your account history, and the memory feature can store information about you. Whether conversations are used for training depends on the plan and the Improve the model for everyone setting.

How do I stop ChatGPT from training on my conversations?

Go to Settings, then Data controls, and switch off Improve the model for everyone. You can do the same in the OpenAI Privacy Portal with the Do not train on my content option.

Is ChatGPT temporary chat safe for company data?

Temporary chats are not used for training and do not appear in history, but according to OpenAI they may be kept for up to 30 days. They do not replace a business plan or a DPA.

Is pasting customer data into ChatGPT a data breach?

It can be a personal data breach, especially on a personal account without a DPA. The company has to assess it and, if there is a risk to people, notify the supervisory authority within 72 hours.

Sources

  1. OpenAI Help Center: Data controls in ChatGPT
  2. OpenAI Help Center: How your data is used to improve model performance
  3. OpenAI: Enterprise privacy (updated 08.01.2026)
  4. Regulation (EU) 2016/679 (GDPR), EUR-Lex
  5. EDPB: Report of the work undertaken by the ChatGPT Taskforce (24.05.2024)
  6. Personal Data Protection Office (UODO): GDPR question lists for AI tools (06.08.2026)

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also