Guides

Is ChatGPT GDPR compliant? What a UK business has to check, plan by plan.

By Zain M · 30 September 2026 · 13 min read

ChatGPT can be used in line with UK GDPR, and the plan decides how much work that takes. Content from ChatGPT Business, Enterprise and Edu workspaces and from the API is not used to train OpenAI’s models by default, a data processing addendum with the standard contractual clauses is available, deleted conversations are removed within 30 days, and Enterprise adds custom retention and UK data residency. The consumer plans, Free, Go and Plus, use conversations for training unless the individual turns it off, and retention sits with that individual. Processing happens outside the UK on the standard plans, lawfully under the UK Addendum. Compliance is then the firm’s to finish: a lawful basis, a processor record, a DPIA where the use is high risk, and a written policy on what staff may paste in.

Training on your dataNo on Business, Enterprise, Edu, API
Consumer plansYes unless the user opts out
UK residencyEnterprise only

The honest answer is “it depends on the plan and on you”

No software is GDPR compliant on its own. Compliance belongs to a processing activity: who the controller is, the lawful basis, what data goes in, where it goes, how long it stays, and whether the people it is about have been told. What a vendor can do is make each of those questions easy or hard to answer, and OpenAI makes them easy on its business products and leaves the consumer products to the individual user. The ICO’s guidance on AI does not treat a chat assistant differently from any other processor; it expects the controller to have done the thinking.

Training and retention, plan by plan

OpenAI states that by default it does not use content from ChatGPT Business, Enterprise, Edu or ChatGPT for Healthcare workspaces to train its models, and the same applies to the API. Workspace owners control retention and memory settings; deleted conversations are removed from OpenAI’s systems within 30 days unless legally required to be kept; Enterprise owners can set a custom retention period from 90 days and can obtain zero data retention for the API. The consumer plans are the opposite by default: Free, Go and Plus conversations may be used to improve the models unless the user turns that off under data controls, and the decision is the individual’s.

For a UK employer that is the whole argument for the Business plan. A few pounds a seat moves the decision from each employee’s settings page to the firm’s admin console and contract.

PlanTraining on your contentRetentionWho controls it
Free, Go, PlusYes unless the user opts outPer the user’s settingsEach individual
BusinessNo by defaultWorkspace controlled; deleted within 30 daysYour admin
Enterprise, EduNoCustom from 90 days; UK residency availableYour admin and contract
APINo by defaultPer the developer terms; zero retention availableYour developers and contract

OpenAI data controls, enterprise privacy and developer data pages, read September 2026.

The contract and the transfer

Business customers get a data processing addendum incorporating the standard contractual clauses, and for transfers subject to UK GDPR the ICO’s International Data Transfer Addendum, which is the lawful mechanism the ICO requires for a restricted transfer to a country without adequacy regulations. The Data (Use and Access) Act 2025 restated the transfer test as whether protection would be “not materially lower”, and the ICO’s guidance page confirms all of the Act’s data protection provisions are now in force. OpenAI publishes SOC 2 and its enterprise privacy commitments, and Enterprise offers data residency options that include the UK for firms that need processing to stay in the country.

The gap in most UK firms is not OpenAI’s paperwork but whether the firm has recorded OpenAI as a processor, holds the DPA, and can produce it when a client’s procurement team asks. The ICO’s contract checklist lists the eight clauses a processor contract must cover; the DPA covers them, and the firm’s record of processing should say so.

What the ICO expects you to do, in order

The same nine steps as for any AI assistant, and none takes more than a day for a firm with its records in order.

01Decide the tasks and whether each involves personal data at all
02Pick the plan to match: Business or above for any personal data; Enterprise where residency or a fixed retention period is required
03Record OpenAI as a processor with the DPA reference and the transfer mechanism
04Settle the lawful basis per task, usually legitimate interests for internal work and contract for client work; never consent from an employee for a required tool
05Run a DPIA where the use is likely to be high risk under the ICO’s screening criteria
06Update the client and staff privacy notices in plain language
07Adopt a one-page acceptable-use policy with examples of what may and may not go in
08Set workspace retention deliberately, short enough for subject access, long enough to reconstruct advice
09Review it every six months and when the plan or terms change

Connectors, memory and Codex

Three features widen what the workspace can see. Connectors let ChatGPT read Google Drive, SharePoint and other sources, and OpenAI switched them on by default for Business workspaces when the company-knowledge search launched; decide whether that is right for you on day one, because they show people whatever the connected drive already lets them see. Memory keeps context across conversations and is a workspace setting to decide deliberately. Codex, the coding agent, inherits the plan’s position: from a Business or Enterprise seat, the firm’s code is covered by the commercial terms; from a personal Plus account, the consumer training choice applies. Developers on personal accounts working on client code are the most common way a firm breaks this without noticing.

ChatGPT or Claude on data

The two vendors’ business plans are, for a UK firm, the same shape: no training by default, a DPA with the UK Addendum, SOC 2, deleted data removed within days, and Enterprise tiers with custom retention. Anthropic additionally publishes ISO 27001 and ISO 42001; OpenAI offers UK data residency on Enterprise where Anthropic’s first-party plans process in the United States. Both consumer tiers train by default or ask the user with the option switched on. The decision between them is about the work, not the paperwork, and our comparison guide makes it by role.

Common questions

Is ChatGPT GDPR compliant?

It can be used in compliance with UK GDPR on the Business, Enterprise, Edu and API plans, which are not trained on by default and come with a DPA and the UK Addendum. Compliance is the firm’s responsibility as controller: lawful basis, records, a DPIA where needed, a staff policy.

Does ChatGPT train on my data?

On Free, Go and Plus, yes, unless you turn it off in data controls. On Business, Enterprise, Edu and the API, no, by default.

Is ChatGPT Business GDPR compliant?

It is the plan most UK SMEs should use: no training by default, admin-controlled retention, deleted conversations gone within 30 days, a DPA. You still record OpenAI as a processor and set a policy.

Is ChatGPT Plus safe for business use?

It is risky for client data, because conversations are used for training unless the user opts out and retention sits with the individual. For one person with the setting off, it is usable; for a firm, Business.

Where does ChatGPT process data?

Outside the UK on the standard plans, lawfully under the standard contractual clauses and the UK Addendum. Enterprise offers UK data residency.

Does OpenAI have a data processing agreement?

Yes, for Business, Enterprise and API customers, incorporating the standard contractual clauses and the UK Addendum.

How long does ChatGPT keep our conversations?

Deleted conversations are removed within 30 days. Workspace owners control retention; Enterprise can set a custom period from 90 days; the API can be run with zero data retention.

Do I need a DPIA to use ChatGPT?

Only where the processing is likely to be high risk under the ICO’s criteria: systematic profiling, special-category data at scale, or automated decisions with significant effects. Everyday drafting usually does not; candidate screening or patient triage usually does.

Is ChatGPT allowed in the UK?

Yes. OpenAI contracts with UK businesses and provides the ICO’s UK Addendum for the transfer of data outside the UK.

ChatGPT or Claude for GDPR?

The business plans are the same shape on data. Anthropic adds ISO 27001 and ISO 42001; OpenAI adds UK residency on Enterprise. Choose by the work.

Need the paperwork done, not just described?

We set UK firms up on ChatGPT or Claude with the processor record, the lawful-basis map per task, the DPIA where one is needed and the one-page staff policy, at a fixed price.

Start a conversation →