The question is slightly wrong — and the distinction matters. GDPR compliance is a property of processing, not of a tool: the ICO is explicit that accountability lies with the controller, i.e. the organisation using it. What you can assess is OpenAI’s data terms. Consumer ChatGPT trains on your conversations by default unless you opt out. Business products are different: ChatGPT Business, Enterprise, and the API do not train on your data by default, support a Data Processing Addendum, and offer retention controls. Whether your use is compliant depends on what personal data you put in, on what lawful basis — which is where minimisation and masking come in.
What OpenAI actually commits to, tier by tier
On the consumer side (Free and Plus), OpenAI’s own help centre says ChatGPT improves by training on conversations "unless you opt out". The opt-out is real — Settings → Data Controls — and turning it off keeps chats in history without using them for training. Deleted personal data is removed from systems within 30 days under the European privacy policy, subject to legal-obligation and security exceptions; temporary chats are deleted after 30 days.
On the business side, the enterprise privacy page states: "By default, we do not use your business data for training our models" — covering ChatGPT Business (formerly Team), Enterprise, and the API. OpenAI executes Data Processing Addenda for those products, holds SOC 2 Type 2 attestation, and gives workspace admins retention controls; API inputs may be retained up to 30 days for abuse detection, with zero-data-retention available for eligible endpoints. For EEA users the controller is OpenAI Ireland, with the Irish DPC as lead supervisory authority; the declared lawful basis for training is legitimate interests.
Why "is the tool compliant" is the wrong question
The ICO’s AI guidance puts overall accountability for data protection compliance on the controller — your organisation, not the vendor. The same tool can sit inside a perfectly lawful workflow or a plainly unlawful one, depending on what data goes in, on what basis, with what safeguards. So the useful question is: is our use of ChatGPT compliant? That turns on lawful basis, transparency to data subjects, minimisation, and your ability to demonstrate the controls you applied.
This is also why regulatory history around OpenAI is easy to over-read. The Italian regulator temporarily restricted ChatGPT in 2023 and later issued a €15m fine — which an Italian court annulled in March 2026, with the underlying allegations never finally ruled on. The accurate takeaway is that regulators actively scrutinise AI data practices, not that any authority has settled whether ChatGPT "is" compliant.
The minimisation shortcut
The strongest simplification available to any firm is to stop personal data entering the tool at all. If client names, contact details, and identifiers are masked in the browser before the prompt is submitted, the hardest GDPR questions — lawful basis for sending personal data to a third-party model, international transfers, retention at the provider — shrink dramatically, because the provider receives de-identified text. You still need policy and appropriate terms, but you are no longer betting compliance on a vendor’s data pipeline.
The short version
- GDPR compliance belongs to your processing — the ICO puts accountability on the controller, not the tool.
- Consumer ChatGPT trains on conversations by default (opt-out available); business tiers do not train by default and support DPAs.
- Deleted data is removed within 30 days, with legal-obligation exceptions; API zero-retention exists for eligible endpoints.
- Masking identifiers before submission shrinks the compliance surface regardless of tier.
Related questions
Can we sign a DPA with OpenAI?
Yes — OpenAI states it executes Data Processing Addenda for ChatGPT Business, ChatGPT Enterprise, and API use. Consumer Free/Plus accounts are not designed for that relationship, which is one reason client work does not belong on personal accounts.
If we opt out of training, is free ChatGPT safe for client data?
No. The opt-out stops training use; it does not change the confidentiality analysis, the retention rules, or your controller obligations. UK guidance — from the Law Society to the tribunal in Munir — treats identifiable client data in public AI tools as the problem, however the training toggle is set.
Didn’t OpenAI get fined under GDPR in Italy?
The Italian Garante fined OpenAI €15m in late 2024, but an Italian court annulled the fine in March 2026 — the merits were never finally decided. Use that history as evidence of regulatory scrutiny, not as a compliance verdict either way.
This page is general information, not legal advice. Where third-party guidance or law is summarised, read the originals via the source links before relying on them. Last reviewed: 17 July 2026.
This is the control in action
Identifiable data is masked in the browser before the prompt ever leaves — try it yourself with a sample prompt, or bring one low-risk workflow to a 20-minute review.
Advise Sarah Thompson, NI AB123456C, on the settlement offer.
Advise <PERSON_7K9X>, NI <NI_8W1R>, on the settlement offer.