A quiet reading corner in a modern office at blue hour, an armchair and floor lamp by tall glazing

Data protection

Is ChatGPT GDPR compliant, and does my data train the model?

No AI tool is compliant or non compliant on its own. UK GDPR regulates what you do with personal data, so the same product can be used lawfully by one business and unlawfully by another. What genuinely differs between plans is whether your content may be used to improve the model, and that is decided by the terms of the exact plan you are on.

Last checked 19 September 2026

Why the question as asked cannot be answered #

People search for this in the tens of thousands, and every confident yes or no is wrong in the same way. UK GDPR does not certify software.

It places duties on the organisation deciding why and how personal data gets processed, which in this situation is you. A tool can make those duties easy or nearly impossible to meet, but it cannot discharge them.

Which means the useful questions are about your use, not the product: what personal data are you putting in, whose is it, what is your lawful basis for it, have you told the people concerned, and is there a contract with the supplier. That list is set out in full in what UK GDPR asks of a business using AI.

The training question, which is the real one #

Underneath the compliance wording, what most people actually want to know is simpler: if I paste a client's email in here, does it end up inside the model, and could it come out somewhere else.

The honest answer is that it depends on the exact plan and on settings you may have control over, and that providers change these terms. Consumer plans, business and enterprise plans, and developer access are typically governed by different documents with different defaults. This is precisely why the search results are full of people asking the question separately for each tier: the answers genuinely are not the same.

Because those terms change, we are not going to state them here and let the page go stale. The durable method is to check yours directly.

How to check your own plan, in about ten minutes

  1. Find the exact name of the plan on your billing page

    Not the product, the plan.

  2. Open the provider’s terms for that plan

    Search the page for the words train, improve and retention. Read those paragraphs rather than the marketing page.

  3. Look for a setting in the account controlling whether your content improves the model

    Record which way it is set and who can change it.

  4. Find out how long conversations are kept, and whether you can delete them

  5. Write down what you found and the date you found it

    That record is what demonstrates you took a decision rather than drifted into one.

Training and using are different things, and the ICO treats them that way #

This is the part most summaries miss. The ICO's guidance on lawfulness in AI is explicit that developing an AI system and deploying one are distinct purposes, and that a lawful basis appropriate for using a system may not be appropriate for processing personal data to develop one. It advises separating each processing operation and identifying a purpose and a lawful basis for each.

The free account problem #

A common and awkward situation is that nobody bought anything. Staff signed up individually, often with personal email addresses, and client information has been going into consumer accounts for months. Three things follow.

  1. Your obligations are unchanged

    Processing personal data for business purposes through a personal account is still your processing.

  2. You probably have no contract with the supplier in the form UK GDPR expects

    Consumer terms are not written to be one.

  3. You cannot answer a subject access request properly

    You do not know what is in those accounts.

This is common enough to be worth treating as an ordinary management problem rather than a scandal, and the sequence for dealing with it is in your staff are already using AI.

What a business plan does and does not fix #

Moving to a paid business or enterprise plan generally improves two things, and what it does not do is answer the questions that were always yours.

What the plan improves

  • The terms governing whether your content trains the model
  • Your ability to administer accounts, see who has one and remove them

Both matter.

What stays yours either way

  • A lawful basis
  • Having told people what you do with their data
  • A written contract with the required terms
  • Deciding what is allowed in there

The contract point is not optional: UK GDPR requires a written agreement whenever a processor handles personal data on your behalf, and what it must contain is set out in what a data processing agreement is for.

The pragmatic position most businesses land on #

Having worked through it, most arrive somewhere similar. Use the tools for work that does not involve personal data at all, which is a surprisingly large share of the benefit: drafting, rewording, summarising your own notes, working through a problem. Put a plan in place with terms you have actually read before anything involving clients goes near it. Write down what is allowed and tell people.

That position is defensible, cheap and available this week, which is more than can be said for waiting until the whole subject is settled. What the regulator has and has not said so far is covered in what the ICO actually says about AI, and if you want to know where your repeated work is before any of this matters, the cost of admin time calculator is the place to start.

Questions people ask

Is ChatGPT GDPR compliant?
The question does not have a yes or no answer, because compliance is a property of what you do with a tool rather than of the tool itself. The same product can be used lawfully by one business and unlawfully by another. What does differ between versions is whether your content may be used to improve the model, and that is set in the terms for the exact plan you are on.
Does my data train the model?
It depends entirely on which plan you are on and what you have switched on, and providers change these terms. Business, enterprise and developer plans commonly differ from consumer ones here. Read the current terms for your exact plan rather than trusting a summary, including this one.
Does the free version count as a supplier under UK GDPR?
If you are putting personal data into it for work purposes, you are using a processor and the ordinary rules apply, including the need for a written contract. Signing up with a personal account does not change your obligations as a business, it just makes them harder to demonstrate.
What is the safest thing to do while we work this out?
Keep personal data out of it. A tool used for drafting, summarising and rewording with the names and identifying details stripped out raises far fewer questions than one fed live client records, and it captures most of the day to day benefit.

Where these numbers come from

  1. ICO, Guidance on AI and data protection , read 19 September 2026 . Last updated 15 March 2023, and carrying a notice that it is under review following the Data (Use and Access) Act.
  2. ICO, How do we ensure lawfulness in AI? , read 19 September 2026 . Treats developing an AI system and using one as distinct purposes needing their own lawful basis.
  3. ICO, Contracts and liabilities between controllers and processors , read 19 September 2026

Last checked 19 September 2026.

Our workings are on the methodology page .

Free audit

Find out what the repeated work costs you

The audit counts every job the business repeats, ranks them by the hours they eat, and maps the five worth automating first. It is free, you keep everything, and there is no obligation at the end of it.

AI automation, explained

Plain answers to what businesses ask before they automate anything.

All of ai automation, explained

Read next