Skip to content
ORTHODROMECONSULTING
AI & GDPR

Your employees are using ChatGPT with client data: what does the GDPR say?

An employee pastes part of a client file into ChatGPT? That is personal-data processing under the GDPR — and your company answers for it, not the employee. Nothing illegal as such: neither the CNIL nor EU law bans generative AI at work. The real risk: personal accounts, services that may reuse what you submit, no contract, no control over transfers. Banning moves the problem. A framework solves it: controlled tools, a short policy, training, a list of data never to submit.

Updated 04 August 2026

This resource provides general information, accurate as of the date shown. It does not constitute legal advice and does not replace analysis by a qualified professional in light of your situation.

What actually happens when an employee pastes client data into ChatGPT?

The prompt lands on the provider’s servers, often outside the EU — unless a business plan with EU data residency is in place. Consumer ChatGPT plans, free or paid: conversations may by default be used to improve the models (an opt-out exists). Team, Enterprise and the API: no training on your content by default. Check the rules, plan by plan.

Legally, it is simple: as soon as a prompt can identify someone — a name, an email, a contract detail — it is personal-data processing. Your company is accountable, even for individual, spontaneous use.

“Shadow AI” is not misconduct: the tools simply arrived before the rules.

Is it illegal under the GDPR?

No. No text prohibits generative AI on personal data. The CNIL frames the practice rather than banning it. The European Data Protection Board even accepted (Opinion 28/2024) that legitimate interest can be a valid basis for AI-model processing — under conditions.

You still have to tick every box: a defined purpose, a legal basis, data minimisation, informing the individuals, controlled retention, an Article 28 processor agreement, and a lawful mechanism for transfers outside the EU. On the US side, the Data Privacy Framework was upheld by the EU General Court on 3 September 2025 — but an appeal is still pending before the Court of Justice: do not build everything on it.

A spontaneous personal account ticks none of them. The tool is not the problem — the configuration is.

What are the real risks for the company?

The fine, first. Article 83 of the GDPR allows up to 10 million euros or 2% of worldwide annual turnover — 20 million or 4% for the most serious infringements (core principles, individuals’ rights, transfers). Regulators scale sanctions to gravity, duration and cooperation.

For an SME, the contractual risk weighs at least as much: client data in an uncontrolled service can breach your confidentiality commitments and expose know-how.

Then the breach: personal data exposed with a risk to individuals leaves you 72 hours, from becoming aware of it, to notify the supervisory authority. Hard to do when you don’t know what was submitted, by whom, or when.

Should you ban ChatGPT?

Tempting, but ineffective. Usage migrates to personal phones and accounts: nothing left to see, configure or trace.

The CNIL does not recommend a ban: rather a clear policy, no accounts on personal email addresses, and the provider’s reuse of usage data switched off.

The AI Act follows the same logic: since 2 February 2025, Article 4 requires measures to foster the development of staff AI literacy, whatever your size. An obligation of means, clarifies Regulation (EU) 2026/1744, in force since 27 July 2026: nothing requires guaranteeing a given level for a given individual. Since 2 August 2026, Article 50 adds transparency for AI-generated content and conversational systems.

How do you set a framework without blocking your teams?

Four workstreams, in order.

Provide a controlled alternative. Shadow AI thrives where no official tool exists. Company account or API: processor agreement, no training on your data, verified settings. Highly sensitive data? The CNIL recommends on-premise deployment, with no transmission to a third party.

Write a short policy. One page: permitted uses, prohibited uses, and above all the data never to submit — anything identifying a client, health or other sensitive data, HR data, trade secrets, anything under a confidentiality undertaking.

Train — the most concrete answer to Article 4. No seminar: cases from your own business, plus the reflex of checking outputs — never reuse an answer as-is, says the CNIL.

Finally, simple governance: an AI lead, the data protection officer where one exists, a periodic review.

Where do you start when the practice is already widespread?

With an assessment, not sanctions. Hunting for culprits guarantees one thing: next time, nobody will say anything. Map actual usage — tools, teams, data. Fix the two or three most exposed situations first: a controlled instance, the list of prohibited data, team training.

Bonus: your employees already know where AI genuinely helps. A good framework protects your data and reveals where AI creates value — and where it does not. Better this diagnosis now than rules written in a hurry after an incident.

Frequently asked questions

An employee has already submitted client data to ChatGPT: must we notify the authorities?
Not automatically. Qualify the incident: what data, what account type, which reuse settings. A breach with a risk to individuals? 72 hours from becoming aware of it to notify the supervisory authority. Document the analysis either way.
Do ChatGPT’s paid plans solve the problem?
Only partly. Team, Enterprise and the API do not use your content for training by default: one major risk gone. Article 28 terms, transfers outside the EU, minimisation and informing individuals remain. The tool does not replace the framework.
Can we submit anonymised client data?
Yes, if the anonymisation is genuine: no one can be re-identified, even by cross-referencing. Merely pseudonymised data (initials, internal IDs) is still personal data. Rephrasing the question without a named case is often safer than anonymising a file.
Is an AI usage policy mandatory?
No text requires one as such. But the CNIL recommends internal policies on permitted and prohibited uses, and Article 4 of the AI Act requires measures fostering staff AI literacy — an obligation of means, confirmed by Regulation (EU) 2026/1744. The policy answers both.
Does the AI Act replace the GDPR for generative AI?
No — they apply in parallel. The GDPR, whenever personal data is processed. The AI Act adds staff AI literacy (Article 4, since February 2025) and transparency for generated content (Article 50, since 2 August 2026).

Sources

So where do you start?

Describe your situation: you get a heading, a scope and a quote in return. No commitment.

Reply within 48 business hours · No commitment · Confidential