Artificial intelligence ChatGPT opens up many new opportunities for companies, but also for the self-employed and private individuals. For example, ChatGPT answers simple and complex questions, plans birthday parties, or writes a Python script for you. Companies have also recognized this potential.
In companies, ChatGPT can be used, for example, to create text for flyers, websites, or social media accounts. But general questions that used to require tedious googling can also be answered by ChatGPT.
Artificial intelligence is a new, constantly improving technology. However, like many new technologies, ChatGPT encounters old, existing law. For this reason, new technologies must be designed and used in compliance with the law. In the case of online services, this concerns data protection law in particular.
What all of this means for you in detail, we will explain in the following article. After that, you will know what you need to pay attention to regarding data protection when using ChatGPT!
ChatGPT and data protection
The General Data Protection Regulation (GDPR) governs the processing of personal data (data that identifies or can identify an individual) in the EU. Such processing also occurs when data is provided to ChatGPT. In doing so, the strict requirements governing the processing of personal data must be met.
Transparent processing
The principles of processing personal data are set out in Art. 5 GDPR. These serve to ensure the lawful and appropriate handling of personal data.
One of these data protection principles governing the processing of personal data is transparent processing. The principle of transparency requires that all information regarding data processing and how AI functions be easily accessible, understandable, and written in clear and simple language.
Because of the proprietary algorithm and other complex processes that take place in the background with ChatGPT, such informed, transparent processing is not possible.
💡 Note:
The ChatGPT algorithm—meaning how ChatGPT works—is not transparent. As a result, the data protection principle of transparent processing of personal data cannot be complied with when using ChatGPT.
Commercial use
For the commercial use of the OpenAI API (not ChatGPT), paying customers are provided access via a programming interface, also known as an API. To this end, the operator offers OpenAI LP offers a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR. This serves to regulate the processing and data transfer between OpenAI and the customers.
However, the legal situation regarding responsibilities has not been clearly established. It remains unclear whether this constitutes a data processing agreement (processor relationship) or whether there is joint or separate responsibility. These concerns arise from the fact that OpenAI processes the data not only for training purposes, but presumably also for advertising purposes. As a result, OpenAI also pursues its own interests, which could contradict the requirements for data processing on behalf of a controller pursuant to Art. 28 (3) sentence 2 lit. a) GDPR.

According to Art. 26 para. 1 sentence 1 GDPR, joint controllership exists when two or more controllers jointly determine the purposes and means of processing.
However, it is unlikely that both conditions are met, since the company using the API is unlikely to have much influence on the processing at OpenAI and the means of processing are not jointly determined.
Since only one's own OpenAI's DPA offered, the legal situation regarding sub-processing is also unclear. The company using the API might potentially act as a data processor for its own customers, which would make OpenAI a sub-processor. This aspect would need to be transparently clarified in the Data Processing Agreement (DPA) between the company and its customers.
💡 Note:
Since OpenAI uses the data for internal training purposes, joint controllership presumably arises between ChatGPT and the user who uses ChatGPT. As a result, it is necessary to enter into a joint controllership agreement pursuant to Art. 26 GDPR.
Data transmission
Articles 44 et seq. of the GDPR set forth specific requirements for the transfer of personal data to third countries. The United States of America is classified as a non-adequate third country, which means that data transfers must be based either on the company’s certification under the EU-U.U.S. Data Privacy Framework, or the standard contractual clauses pursuant to Article 28(7) of the GDPR should be included in data processing agreements along with additional security measures.
The OpenAI API is provided by the US company OpenAI LP, which is why data is transferred to the USA with every input.
OpenAI is not certified under the new U.S.-EU Data Privacy Framework, which is why the transfer is governed by the AVV Standard Contractual Clauses. These clauses continue to require the conduct of a Transfer Impact Assessment (TIA) for the transfer and the assurance of security through appropriate technical and organizational measures.
💡 Note:
ChatGPT is a U.S.-based tool that, like Microsoft or Google tools, transfers personal data to third countries. In general, give preference to tools, software, or even Host, which have their headquarters in Europe—or better yet, in Germany—and are therefore subject to the General Data Protection Regulation.
Dealing with AI
As a general rule, the transfer of personal data or other sensitive data to artificial intelligences such as ChatGPT should be avoided. Since all data could be reused as training data, there is a possibility that entered data might later be disclosed by the AI to third parties.
In this regard, the OpenAI API offers greater security, as the processing of data is defined in the AVV. If the OpenAI API is used in a way that involves the disclosure of personal data, the data subjects whose data is being disclosed must be notified accordingly, in accordance with Article 13 of the GDPR.
For all projects that utilize artificial intelligence, a Data Protection Impact Assessment (DPIA) should also be conducted. A Data Protection Impact Assessment is an instrument for identifying, describing, evaluating, and minimizing risks to the rights and freedoms of natural persons regarding the processing of their personal data.
Pursuant to Article 35(1) GDPR, a data protection impact assessment must generally be carried out whenever the processing of data is likely to result in a high risk to the rights and freedoms of natural persons. To determine this, a risk analysis must be conducted prior to the commencement of data processing. If this analysis determines that the intended processing is likely to result in a high risk to data subjects, a DPIA is mandatory.
💡 Note:

You should not enter any personal information—such as your name, address, email address, or IP address—or other sensitive data into ChatGPT. There is no guarantee that this information will not be shared or further processed.
Conclusion on Data Protection & ChatGPT
The company advises against using ChatGPT with personal data. Even if the use of one’s own data for training purposes is disabled in the settings, it is not possible to determine with certainty exactly how the data will be processed.
In this case, the OpenAI API offers greater security, as certain security guarantees are provided by the DPA and standard contractual clauses. However, even here, it is not transparent how data is processed precisely, which is why the entry of personal or corporate data should still be avoided.
When using artificial intelligence, it is recommended to take data protection into account from the very beginning of the implementation process. Company policies, transparent documentation, conducting a Data Protection Impact Assessment (DPIA), and employee training are key components of a secure and lawful approach to artificial intelligence.


