Where your data goes when your team uses ChatGPT
Which account tiers train on what you paste, what a deletion promise is worth in practice, and how to find out what has already left your business.
8 min read
If nobody in your business has been told which AI tools are allowed, some of your work is already sitting in someone else's system. Not because your team is careless, but because pasting a customer email into a chat window is the fastest way to rewrite it, and nobody said otherwise.
The question worth answering is not whether it is happening. It is what happens to the text once it arrives: who keeps it, for how long, whether it trains a model, and what you would be able to tell a customer who asks.
The account tier decides almost everything
People argue about whether ChatGPT is GDPR compliant as though the product were one thing. It is at least four, and they behave differently.
Free and Plus accounts are consumer products. By default, conversations can be used to improve the models. There is a switch for it, under Settings and then Data controls, and most people have never opened that screen. Anything typed before it was switched off was already in scope.
Team, Enterprise and Edu workspaces are business products. Business data in them is not used to train models by default, an admin controls retention, and you can sign a data processing agreement. That is the difference that actually matters, and it usually costs less per month than the meeting you would otherwise hold about it.
The API has not trained on customer data by default since 2023. Inputs and outputs are kept for a limited window for abuse monitoring, and zero retention can be agreed for eligible cases.
Anything with a chat box bolted on: a browser extension, a free AI writing site, a plugin somebody installed last spring. This is the category to worry about, because there is no contract, often no clear provider, and no log.
Two practical notes. Defaults and switches move, so treat the list above as the shape of the question and confirm the current wording in the terms and the DPA before relying on it. And an account paid for on someone's own card is a consumer account no matter what they use it for.
What a deletion promise is actually worth
Vendors delete data on the schedule they publish, until a court tells them not to. In 2025 a US court order in the New York Times copyright case required OpenAI to preserve output data it would otherwise have deleted, including conversations users had deleted themselves. The scope of that order changed over the following months, and the detail matters less than the principle: a retention policy is a promise made inside one legal system, and your text sits in whichever system the vendor lives in.
The same goes further down the chain. The tool your team likes may be a thin layer over someone else's model, with its own logging, its own retention and its own subprocessors. One prompt can be stored three times: in the app, at the model provider, and in whatever error monitoring the app installed on the way.
None of that makes these tools unusable. It makes "we deleted it" a weaker answer than most people assume when a customer asks what happened to their information. If that answer needs to be stronger, the next question is where the data should live instead.
How to find out what has already left
You cannot write a sensible rule until you know what is happening. This takes a morning.
- Pull the financial trail. Search card statements and expense claims for AI vendors. A personal subscription put through as an expense is the most common route by which business data ends up on a consumer tier.
- Pull the identity trail. In Google Workspace, look at Admin console, then Security, then API controls, for third-party apps connected to work accounts. In Microsoft Entra ID, look at enterprise applications and the sign-in logs. Anything that used "sign in with Google" or "sign in with Microsoft" is listed there.
- Check the browser. An extension with page access can read whatever is on screen, including your CRM. Ask IT for the installed extension inventory, or ask people to send a screenshot of their extensions list.
- Ask once, with an amnesty. Three questions: which AI tools do you use for work, for what, and what kind of information goes into them. You will get honest answers exactly once, and only if it is obvious that nobody is in trouble.
- Sort what comes back into three buckets: personal data (customers, staff, applicants), commercially sensitive material (pricing, contracts, roadmaps, source code), and neither. The third bucket is most of it and needs no policy at all.
- Decide per bucket, then hand people the approved tool. A rule that bans something without providing an alternative moves the activity onto personal phones, where you see nothing.
Writing the result down is its own job, and there is a step-by-step guide to an AI policy people will actually follow that covers it.
What you have done under the GDPR, in plain terms
When an employee pastes a customer's personal data into a tool, your business has processed personal data through a processor it never vetted. In practice that means four things:
- You need a lawful basis for the processing, and "it was quicker" is not one.
- You need a data processing agreement with the provider. A consumer account does not come with one.
- The processing belongs in your Article 30 record, which is the first document a supervisory authority asks to see.
- If data went somewhere you cannot account for, you have an incident to assess rather than an awkward conversation to have.
This is why the tier question is not a technicality. Running the same activity inside a business workspace with a signed DPA turns an unauthorised disclosure into ordinary, documented processing.
When a policy is the wrong answer
If your team uses these tools to draft marketing copy, summarise public documents and tidy up their own sentences, the risk you are managing is close to zero, and a heavy policy will cost more in lost speed than it saves.
Two more honest cases. If everything that matters already happens inside a business workspace you pay for, you may be finished: no EU hosting project, no custom build, one switch checked and one page written. And if the real problem is that nobody knows which tool to use for what, that is a training problem wearing a compliance costume.
The consultancy answer here would be to sell you infrastructure. Most businesses at this stage need a paid tier, a page of rules and an hour with their team. The case for building something you own starts when the tool has to reach into your systems, and then the honest comparison is what that costs over three years.
The failure mode to picture
A support agent pastes a full complaint thread into a free account to soften the tone: name, address, order history, and the reason the customer was upset. The reply is good. Nothing goes wrong that day.
Six months later the same customer makes a subject access request and asks specifically where their data has been. You now have to answer for a transfer to a provider you have no contract with, on an account you do not control, belonging to an employee who has since left and taken the account with them. There is no log, and no way to retrieve or delete the content.
The cost is never the paste. It is the answer you cannot give afterwards, and the likelihood that the same thing has happened a hundred times since.
If you would rather map this with someone, it is part of what an AI Readiness Audit covers, and the rest of the compliance guides pick up where this one stops.
Frequently asked questions
Is using ChatGPT at work a GDPR violation?
Not by itself. It becomes one when personal data is processed without a lawful basis, without a data processing agreement, or outside your Article 30 record. The same task inside a business workspace with a signed DPA is ordinary processing.
Does switching off "improve the model for everyone" fix it?
It stops future conversations on that account being used for training. It does not give you a data processing agreement, retention control or an audit trail, and it does nothing about what has already been sent.
Should we block AI tools on the company network?
Blocking without providing an approved alternative moves the activity to personal phones, where you have no visibility at all. Provide a sanctioned tool first, then restrict the rest.
How do we find out which tools staff are actually using?
Check expense claims, the third-party apps connected to your Google or Microsoft accounts, and installed browser extensions, then ask people directly under an amnesty. The survey finds the tools the logs miss, and the logs find the tools people forget to mention.