Is ChatGPT GDPR-compliant? What actually leaves your browser
“Is ChatGPT GDPR-compliant?” is the wrong question. A tool is never compliant in the abstract — a specific use of it is. Compliance depends on the plan you subscribe to, the data-processing agreement, how international transfers are covered, whether training on your conversations is off, and — the only factor fully in your hands — what your prompts actually contain.
A prompt is a data transfer
If a prompt contains personal data, sending it to an AI provider is processing under the GDPR: the provider becomes a processor (art. 28, DPA required), the persons concerned must be informed, a legal basis is needed (art. 6), and transfers outside the EU must be covered (art. 44+, standard contractual clauses or an adequacy framework). None of this is exotic — it is the same analysis as any SaaS, applied to the most casual copy-paste in the office.
Where the analysis usually breaks down
- Plan mismatch: the guarantees people cite (no training, retention limits) often belong to enterprise or API plans — not to the consumer subscription actually used at their desk.
- Default settings: on consumer plans, using conversations to improve models is frequently the default. Check yours; policies evolve.
- Sub-processors: your data’s real journey includes hosting and inference partners you have never named in any register.
- Shadow usage: the analysis covers the sanctioned tool — not the personal accounts your team actually uses.
Minimisation: the control you fully own
GDPR article 5 requires processing only the data necessary for the purpose. For summarising, drafting or analysing, the AI almost never needs real identities. Replace them on-device with placeholders — [PERSON_1], [IBAN_1] — and the compliance surface shrinks: what crosses the border no longer carries the identifiers you detected and replaced. Keep the legal framing honest, though: under EU guidance pseudonymised text generally remains personal data (the mapping exists — on your device only), so redaction reduces transfer risk and exposure rather than abolishing the rules, and the review screen shows exactly what leaves. This is reversible redaction: the mapping stays on your machine, answers are restored on screen.
Prove it, don't declare it
You cannot audit OpenAI. You can audit what you send it: per-message visibility of what left the device, a GDPR audit report, an EU AI Act (art. 50) transparency attestation. When a DPO or a client asks “what exactly went to the AI?”, the answer should be a document, not a shrug.
Try it on a real example. Neutralyse redacts sensitive data on your device before it reaches ChatGPT, Claude or a fully local AI, then restores the answer on screen. Free locally, no credit card.
Open the protected chat →Last editorial review: September 1, 2026 — internal Neutralyse review (AIGENGO team), no external legal validation to date. This article is general information, not legal advice.