The short answer
With a free or personal account: no. With a business licence where you have signed a data processing agreement, training on your data is off and you know where data is stored: yes, provided you also have a legal basis, it is in your processing register and your people know what is allowed. The tool is the easiest of those five.
The five things that have to be arranged
| What | Why | Where you arrange it |
|---|---|---|
| Data processing agreement | Required as soon as a supplier processes personal data for you | With the vendor, standard on business licences |
| Training switched off | Otherwise your data can end up in a future model | Off by default on business licences; check it anyway |
| Knowing where data is stored | Transfers outside the EU need a legal basis | Storage inside Europe can be selected on business plans |
| Legal basis and processing register | You must be able to explain why you do this with this data | In your own records, not with the supplier |
| Instruction for your people | Most incidents are an employee pasting something into a private account | A short work instruction and a place where it is allowed |
The difference between free and business
With ChatGPT Team and Enterprise you sign a data processing agreement, training on your data is off by default and you can choose storage inside Europe. With a free or personal account you have none of those three. That is the whole difference, and it costs around twenty dollars per person per month.
The same reasoning applies to the business plans of Claude and to Microsoft 365 Copilot. See the comparison between ChatGPT and Copilot.
Where it goes wrong in practice
- An employee pastes a customer email into their own free account because the office account was requested too late.
- A business account exists, but nobody checked the training setting.
- There is an agreement with the AI supplier, but your own customers were never told AI is part of the process.
- There is a one-page policy nobody read, instead of a five-line work instruction next to the work itself.
The practical route
Arrange the business licence and the processing agreement first, because that is an afternoon of work. Then describe per process which data may go in and which may not, and give people a place where it is allowed. Whoever only forbids without an alternative gets shadow use in private accounts, which is exactly the risk you wanted to avoid.
What that boundary looks like per workflow sits on the page about control and security and in the Bankproof method.
Frequently asked questions
May I put customer data into a free ChatGPT account?
No. There is no data processing agreement, you have no certainty about training and you do not know where the data is stored. For personal data that is three problems at once.
Is a business licence enough to be GDPR compliant?
No, it is the first of five things. You also need a legal basis, an entry in your processing register, clarity about storage outside the EU and an instruction for your people.
Do I have to tell my customers that I use AI?
If you process personal data about them, it belongs in your privacy statement. Beyond that it is simply wise: customers who find out later react differently from customers who knew.
What do I do about employees using their own account anyway?
Give them a working business account and a short work instruction next to the work itself. Shadow use almost always appears because the official alternative is missing or arrives too late.
