Your employees are using ChatGPT with client data: what does the GDPR say?
An employee pastes part of a client file into ChatGPT? That is personal-data processing under the GDPR — and your company answers for it, not the employee. Nothing illegal as such: neither the CNIL nor EU law bans generative AI at work. The real risk: personal accounts, services that may reuse what you submit, no contract, no control over transfers. Banning moves the problem. A framework solves it: controlled tools, a short policy, training, a list of data never to submit.
Updated 04 August 2026
This resource provides general information, accurate as of the date shown. It does not constitute legal advice and does not replace analysis by a qualified professional in light of your situation.
What actually happens when an employee pastes client data into ChatGPT?
The prompt lands on the provider’s servers, often outside the EU — unless a business plan with EU data residency is in place. Consumer ChatGPT plans, free or paid: conversations may by default be used to improve the models (an opt-out exists). Team, Enterprise and the API: no training on your content by default. Check the rules, plan by plan.
Legally, it is simple: as soon as a prompt can identify someone — a name, an email, a contract detail — it is personal-data processing. Your company is accountable, even for individual, spontaneous use.
“Shadow AI” is not misconduct: the tools simply arrived before the rules.
Is it illegal under the GDPR?
No. No text prohibits generative AI on personal data. The CNIL frames the practice rather than banning it. The European Data Protection Board even accepted (Opinion 28/2024) that legitimate interest can be a valid basis for AI-model processing — under conditions.
You still have to tick every box: a defined purpose, a legal basis, data minimisation, informing the individuals, controlled retention, an Article 28 processor agreement, and a lawful mechanism for transfers outside the EU. On the US side, the Data Privacy Framework was upheld by the EU General Court on 3 September 2025 — but an appeal is still pending before the Court of Justice: do not build everything on it.
A spontaneous personal account ticks none of them. The tool is not the problem — the configuration is.
What are the real risks for the company?
The fine, first. Article 83 of the GDPR allows up to 10 million euros or 2% of worldwide annual turnover — 20 million or 4% for the most serious infringements (core principles, individuals’ rights, transfers). Regulators scale sanctions to gravity, duration and cooperation.
For an SME, the contractual risk weighs at least as much: client data in an uncontrolled service can breach your confidentiality commitments and expose know-how.
Then the breach: personal data exposed with a risk to individuals leaves you 72 hours, from becoming aware of it, to notify the supervisory authority. Hard to do when you don’t know what was submitted, by whom, or when.
Should you ban ChatGPT?
Tempting, but ineffective. Usage migrates to personal phones and accounts: nothing left to see, configure or trace.
The CNIL does not recommend a ban: rather a clear policy, no accounts on personal email addresses, and the provider’s reuse of usage data switched off.
The AI Act follows the same logic: since 2 February 2025, Article 4 requires measures to foster the development of staff AI literacy, whatever your size. An obligation of means, clarifies Regulation (EU) 2026/1744, in force since 27 July 2026: nothing requires guaranteeing a given level for a given individual. Since 2 August 2026, Article 50 adds transparency for AI-generated content and conversational systems.
How do you set a framework without blocking your teams?
Four workstreams, in order.
Provide a controlled alternative. Shadow AI thrives where no official tool exists. Company account or API: processor agreement, no training on your data, verified settings. Highly sensitive data? The CNIL recommends on-premise deployment, with no transmission to a third party.
Write a short policy. One page: permitted uses, prohibited uses, and above all the data never to submit — anything identifying a client, health or other sensitive data, HR data, trade secrets, anything under a confidentiality undertaking.
Train — the most concrete answer to Article 4. No seminar: cases from your own business, plus the reflex of checking outputs — never reuse an answer as-is, says the CNIL.
Finally, simple governance: an AI lead, the data protection officer where one exists, a periodic review.
Where do you start when the practice is already widespread?
With an assessment, not sanctions. Hunting for culprits guarantees one thing: next time, nobody will say anything. Map actual usage — tools, teams, data. Fix the two or three most exposed situations first: a controlled instance, the list of prohibited data, team training.
Bonus: your employees already know where AI genuinely helps. A good framework protects your data and reveals where AI creates value — and where it does not. Better this diagnosis now than rules written in a hurry after an incident.
Frequently asked questions
- An employee has already submitted client data to ChatGPT: must we notify the authorities?
- Not automatically. Qualify the incident: what data, what account type, which reuse settings. A breach with a risk to individuals? 72 hours from becoming aware of it to notify the supervisory authority. Document the analysis either way.
- Do ChatGPT’s paid plans solve the problem?
- Only partly. Team, Enterprise and the API do not use your content for training by default: one major risk gone. Article 28 terms, transfers outside the EU, minimisation and informing individuals remain. The tool does not replace the framework.
- Can we submit anonymised client data?
- Yes, if the anonymisation is genuine: no one can be re-identified, even by cross-referencing. Merely pseudonymised data (initials, internal IDs) is still personal data. Rephrasing the question without a named case is often safer than anonymising a file.
- Is an AI usage policy mandatory?
- No text requires one as such. But the CNIL recommends internal policies on permitted and prohibited uses, and Article 4 of the AI Act requires measures fostering staff AI literacy — an obligation of means, confirmed by Regulation (EU) 2026/1744. The policy answers both.
- Does the AI Act replace the GDPR for generative AI?
- No — they apply in parallel. The GDPR, whenever personal data is processed. The AI Act adds staff AI literacy (Article 4, since February 2025) and transparency for generated content (Article 50, since 2 August 2026).
Read next
- Sovereign AI: what it actually means for a smaller companyHosting, applicable law, control of the model, exit: four separate questions behind the word “sovereign”, and how a smaller company should decide.
- Getting an AI to answer from your internal documents: what it delivers, what it demandsLetting an AI answer questions from your company’s internal documents: how RAG works in plain terms, what makes it succeed, the pitfalls — and when it is not worth doing.
- EU AI Act: what a company that only uses AI must doWhat the EU AI Act requires of a company that uses AI without building it: AI literacy, transparency duties, prohibited uses, and the real 2026 timeline.
- AI built around your problem — not the other way roundBring AI into your company without gimmicks or needless risk: a tool built around your problem, your data protected. Paris, and across France.
Sources
- https://www.cnil.fr/fr/les-questions-reponses-de-la-cnil-sur-lutilisation-dun-systeme-dia-generative — recommandations de la CNIL sur l’usage des IA génératives : chartes internes définissant usages autorisés et interdits, pas de comptes personnels, désactivation de la réutilisation des données d’usage, restriction des données confidentielles selon le mode de déploiement (cloud vs sur site), vérification des sorties
- https://www.cnil.fr/fr/ia-et-rgpd-la-cnil-publie-ses-nouvelles-recommandations-pour-accompagner-une-innovation-responsable — page du 7 février 2025 annonçant de nouvelles recommandations de la CNIL (information des personnes, exercice des droits) : l’autorité organise l’usage de l’IA au regard du RGPD plutôt qu’elle ne l’interdit
- https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf — avis 28/2024 du CEPD (17 décembre 2024) : l’intérêt légitime peut fonder les traitements liés aux modèles d’IA sous conditions ; anonymat des modèles apprécié au cas par cas
- https://help.openai.com/fr-fr/articles/7730893-faq-sur-les-contr%C3%B4les-de-donn%C3%A9es — politique OpenAI : par défaut, les contenus des offres grand public peuvent servir à améliorer les modèles (option de refus disponible) ; les offres Team, Enterprise et l’API ne sont pas utilisées pour l’entraînement par défaut
- https://www.capstan.fr/articles/2692-formation-des-salaries-a-lia-5-questions-sur-vos-obligations-demployeur/ — article 4 de l’AI Act applicable depuis le 2 février 2025 (analyse de mai 2025, antérieure à la réécriture de l’article 4 par le règlement (UE) 2026/1744)
- https://eur-lex.europa.eu/eli/reg/2026/1744/oj — règlement (UE) 2026/1744 (« Digital Omnibus on AI »), publié au JOUE le 24 juillet 2026 et en vigueur depuis le 27 juillet 2026 : réécriture de l’article 4 du règlement (UE) 2024/1689 en obligation de moyens — fournisseurs et déployeurs « prennent des mesures pour favoriser le développement de la maîtrise de l’IA » de leur personnel
- https://www.blogdumoderateur.com/ia-act-2-aout-2026/ — obligations de transparence de l’article 50 de l’AI Act applicables au 2 août 2026 (contenus générés par IA, systèmes conversationnels)
- https://www.cnil.fr/fr/violations-de-donnees-personnelles-les-regles-suivre — notification d’une violation de données à la CNIL sous 72 heures après la prise de connaissance en cas de risque pour les personnes (article 33 RGPD)
- https://www.donneespersonnelles.fr/article-83-rgpd — plafonds des amendes RGPD (article 83) : 10 M€ ou 2 % du CA annuel mondial, portés à 20 M€ ou 4 % pour les manquements les plus graves (principes, droits des personnes, transferts) ; modulation par la CNIL selon gravité, durée et coopération
- https://www.twobirds.com/en/insights/2025/euus-data-privacy-framework-survives-legal-challenge-what-the-latombe-decision-means-for-internation — Tribunal de l’UE, 3 septembre 2025 : rejet du recours Latombe, le Data Privacy Framework UE–États-Unis reste valide
- https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20251201-european-court-of-justice-to-review-challenge-to-eu-us-data-privacy-framework — un recours contre le Data Privacy Framework reste pendant devant la Cour de justice de l’UE