The ChatGPT API can be used in compliance with the GDPR, but compliance depends on how it is used: using the API on OpenAI's business terms, with the right safeguards in place, is a very different arrangement from staff pasting customer information into the consumer chat interface, which offers none of those safeguards.
This guide sets out the six steps for using the API with personal data, together with the documents you should be able to produce if a regulator or a client asks.
Get articles like this every Tuesday. Compliance Engineering, practical AI compliance for engineers and founders. Free and weekly, written by a CIPP/E certified practitioner.
Need the detailed setup walkthrough? Click paths, code, a worked DPIA and the EU AI Act overlay: the practitioner's setup guide for 2026.
Need this reviewed for your own setup? A £500 scoping review covers your provider configuration, data processing agreement, data flows and DPIA requirements, with a written report within one week.
The consumer service and the API are different products
Most GDPR problems with ChatGPT arise from treating the consumer product and the API as if they were the same.
Consumer ChatGPT (chat.openai.com):
- Conversations may be stored and used for training unless the user opts out
- No data processing agreement
- No guaranteed data residency
- No retention controls
- Suitable for personal use, but not for business data
ChatGPT API (api.openai.com):
- Data is not used for model training by default
- A data processing agreement is available
- Retention can be reduced, down to zero for approved accounts
- EU data processing options are available
Where staff enter customer names, order numbers or complaints into chat.openai.com, the risk arises from that use of the consumer service. If the data consists of client files rather than customer records, a duty of confidentiality applies in addition to the GDPR, which is covered in can my firm use Claude or ChatGPT on client files?
Step 1: Put the data processing agreement in place
Article 28 of the GDPR requires a written contract whenever a third party processes personal data on your behalf. These are the eight clauses to check when reviewing a data processing agreement with an AI provider.
OpenAI provides a standard data processing agreement in your account settings, and a current summary is available in the OpenAI compliance review. For the agreement in detail, including how to execute it, see the OpenAI DPA explained. It covers:
- the data processed and the purposes of processing
- the security measures OpenAI applies
- the list of sub-processors
- OpenAI's obligations in the event of a personal data breach
- your audit rights
The agreement should be in place before development starts, because it is the first document a regulator is likely to ask for when reviewing the use of an AI processor.
Step 2: Minimise retention and apply for zero data retention
By default, OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, and it does not use API data for model training.
For sensitive data, apply for zero data retention. It is available for qualifying and enterprise accounts and is subject to approval by OpenAI, so it is a request you submit (through the Compliance APIs settings, or by contacting OpenAI) rather than a setting you can switch on. Once approved, confirm in your dashboard that retention shows as zero on the relevant endpoints, and keep the written confirmation.
Reducing what the processor retains supports compliance with the storage limitation principle, which requires that personal data is not kept longer than necessary for its purpose.
Step 3: Send only the data the task requires
A common error is sending complete customer records to the API when the task needs only part of the information.
Excessive:
"Customer John Smith (john@email.com, account #45678,
DOB 15/03/1985, address: 42 Oak Street, London)
is asking about their recent order."
Minimised:
"A customer is asking about order status. Their question:
'When will my order arrive?' Order date: March 10.
Expected delivery: March 15."
Data minimisation in this context is therefore a design decision about how each API call is constructed, which means removing names, email addresses, account numbers and other identifiers that the model does not need to answer the question.
Where personal data must be included, for example in medical, legal or financial queries, record the reason in your DPIA.
Step 4: Carry out a DPIA
A data protection impact assessment documents that you identified and addressed the risks before the system went live.
For an AI API integration, the DPIA should cover:
The personal data that passes through the API. Be specific: "customer first name, support query text and order reference number" rather than "customer data".
The lawful basis and necessity. For most business chatbots, the lawful basis will be legitimate interests (providing efficient customer support) or performance of a contract (providing a service the customer has signed up for).
The risks. These include a breach at the processor, retention beyond what you expect, and the possibility of outputs exposing other users' data, which is very unlikely with the API but worth recording as considered.
The safeguards. For example: the data processing agreement, reduced retention, data minimisation in API calls, encryption in transit, access controls on your side and staff training.
If you are unsure whether a DPIA is required, this explains the Article 35 test for AI systems. If one is required, this guide sets out how to write it.
Free download
Get the AI Vendor Due Diligence Checklist
The questions we work through before a client signs with an AI vendor, covering data handling, contracts and transfers, security and operations, model and product risk, and exit risk.
For engineers and technical leads assessing an AI vendor before integration.
- ·What personal data actually goes to the vendor, and whether it trains the model by default
- ·The DPA, the subprocessor chain, and the transfer mechanism if data leaves the UK or EEA
- ·Exit risk: whether data and logs can be exported, what lock-in exists, and your fallback if the vendor changes pricing or terms
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Step 5: Update your privacy notice
Individuals need to be told that you use an AI processor, in a clear and concise explanation that covers:
- the AI processing you carry out (for example, "We use AI to help answer your support questions")
- the processor (OpenAI, or whichever provider you use)
- where the data is processed, which is relevant to international transfers
- how long the data is retained
- the individual's rights, including access, erasure and objection
This information belongs in your privacy notice. Where AI is used in a chatbot, it is also good practice to say so at the start of the conversation.
Step 6: Document the international transfer mechanism
Because OpenAI is a US company, processing UK or EU personal data through its API involves an international transfer, and the EU-US Data Privacy Framework register should be checked before the transfer mechanism is recorded. OpenAI has no entry on the register, active or inactive, so the Framework does not cover these transfers, although a number of published vendor summaries state otherwise.
OpenAI's data processing agreement relies on the Standard Contractual Clauses, with the UK Addendum applied to UK transfers. Customers in the EU and EEA contract with OpenAI Ireland, and the Standard Contractual Clauses apply to its onward transfers to the US.
Record the Standard Contractual Clauses and the UK Addendum in your records of processing activities, and carry out a transfer risk assessment. If your records currently name the Data Privacy Framework for OpenAI, correct the entry.
The EU AI Act: Article 50 transparency duties (in force since 2 August 2026)
The GDPR is not the only regime that applies, because where the ChatGPT API powers a system that interacts with people, such as a support chatbot, an assistant or an intake tool, Article 50 of the EU AI Act has required since 2 August 2026 that users are told they are interacting with an AI system. Where the system generates synthetic content, marking obligations also apply. These are transparency obligations, separate from the GDPR steps above, and they apply regardless of how the data processing is configured.
The Article 50 guide explains who owes which duty and the relevant exemptions, and the free Article 50 Duty Mapper identifies your duties in a few questions. If you would like your setup reviewed against them, the £250 Article 50 compliance check provides a fixed-fee written gap note within 72 hours.
Other providers
OpenAI is one of several providers, and the OpenAI, Anthropic and Google comparison sets out the main differences side by side, and CompanyScope publishes a vendor profile for each of the major AI vendors.
Anthropic (Claude API): transfers rely on the Standard Contractual Clauses, with the UK and Swiss addenda and Irish law governing the clauses. Anthropic has no Data Privacy Framework record, so the Standard Contractual Clauses carry the transfer. API data is not used for training by default. Configuration details are in is the Claude API GDPR compliant.
Microsoft 365 Copilot: not an API, but included because many organisations already use it. Microsoft acts as processor under its Data Protection Addendum, and Graph data is not used for training, so the main exposure lies in your own SharePoint permissions. Two administrative settings move processing outside the EU Data Boundary. See the Copilot guide.
Google (Gemini API): on the free AI Studio tier, Google uses your data for training and it may be reviewed by people. The paid Gemini API and Vertex AI do not use your data for training. Vertex AI adds the Cloud Data Processing Addendum, EU data residency, and a transfer position based on Google LLC's Data Privacy Framework certification, which was active on the register when checked on 14 September 2026, with the Standard Contractual Clauses as a fallback. Configuration details are in is the Gemini API GDPR compliant.
Mistral: a French company based in the EU, which simplifies data residency questions. A data processing agreement is available.
Self-hosted open models (such as Llama): the data remains within your own infrastructure, so there is no external processor and no international transfer, at the cost of higher infrastructure and maintenance effort.
The right choice depends on your requirements: where data residency is the main concern, a self-hosted model or an EU-based provider simplifies the analysis, and where model performance is the priority, OpenAI or Anthropic, correctly configured, is a reasonable choice.
Regulatory attention
Data protection authorities are paying attention to AI, and in 2023 the Italian data protection authority temporarily restricted ChatGPT over GDPR concerns relating to the consumer service.
Enforcement for failing to put governance measures in place does not depend on AI either. In February 2026 the ICO fined MediaLab.AI, which operated Imgur in the UK until September 2025, £247,590. Imgur allowed children under 13 onto the platform without any means of establishing their age, so it had no valid lawful basis for processing their data, and it had not carried out a DPIA before offering the service to children. The penalty notice cites Articles 5(1)(a), 6, 8 and 35 of the UK GDPR, including the missing DPIA.
Using an AI API without a data processing agreement, a DPIA or data minimisation leaves the same kind of gap. The risk increases further once a system can take actions rather than only return text: this Register entry analyses how liability was allocated when an autonomous coding agent deleted a live database during an explicit change freeze.
Checklist before going live
Before using the ChatGPT API, or any similar model, with personal data in production:
- Data processing agreement in place with the provider
- Zero or minimum retention configured
- Data minimisation applied to API calls
- DPIA completed and recorded
- Privacy notice updated to describe the AI processing
- Lawful basis identified (legitimate interests or contract)
- Transfer mechanism recorded (Standard Contractual Clauses and UK Addendum)
- Staff instructed not to use the consumer service for business data
- Deletion process in place for data you store
- Breach response plan covers incidents at the AI processor
Summary
Using the ChatGPT API does not prevent GDPR compliance, provided the service is used on its business terms and the governance steps are completed: the data processing agreement, reduced retention, data minimisation, a DPIA, an updated privacy notice and a documented transfer mechanism.
If you are building an AI system that processes personal data and want the compliance documentation prepared alongside it, see our services.
Michael K. Onyekwere is a CIPP/E certified data protection professional at Janus Compliance. For a review of your provider setup, transfers, DPIA and retention, start with a £500 scoping review. If you also need the system built, see our AI Chatbot + Compliance Package.
Free download
Get the AI Vendor Due Diligence Checklist
The questions we work through before a client signs with an AI vendor, covering data handling, contracts and transfers, security and operations, model and product risk, and exit risk.
For engineers and technical leads assessing an AI vendor before integration.
- ·What personal data actually goes to the vendor, and whether it trains the model by default
- ·The DPA, the subprocessor chain, and the transfer mechanism if data leaves the UK or EEA
- ·Exit risk: whether data and logs can be exported, what lock-in exists, and your fallback if the vendor changes pricing or terms
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.
Frequently Asked Questions
Is using ChatGPT at work a GDPR violation?
Using the consumer version of ChatGPT (chat.openai.com) for business data carries significant risk, because conversations may be stored and used for model training, there is no data processing agreement in place, and you have no control over retention. The ChatGPT API, used on OpenAI's business terms with a signed data processing agreement and appropriate configuration, is a different arrangement and can be used in compliance with the GDPR.
Does OpenAI store data from API calls?
By default, OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, and it does not use API data for model training. Zero data retention is available for qualifying and enterprise accounts, but it is subject to approval by OpenAI rather than a self-service setting. You request it through the Compliance APIs settings or by contacting OpenAI, and should then confirm in your dashboard that retention shows as zero.
Do I need a data processing agreement with OpenAI?
Yes, if you process personal data of individuals in the UK or EU through the API. Article 28 of the GDPR requires a written contract with any processor that handles personal data on your behalf. OpenAI provides a standard data processing agreement, available in your account settings, and it should be in place before the system goes live.
Can I use the ChatGPT API for customer data?
Yes, with safeguards. Put the data processing agreement in place, minimise retention, record the data flows in a DPIA, send only the data the task requires, and explain the use of an AI processor in your privacy notice. You should also apply your own retention and deletion rules to any data you store.
Is the Claude (Anthropic) API more GDPR-friendly than ChatGPT?
Both can be used in compliance with the GDPR. Neither uses API data to train its models by default; OpenAI's documentation states that data sent to the API is not used to train or improve its models unless you opt in, which has been its position since 1 March 2023. Anthropic's data processing addendum relies on the Standard Contractual Clauses with Irish law governing the clauses. The practical differences lie in retention defaults and the law governing the transfer clauses. The choice should be based on your technical requirements, followed by configuring the service correctly.
Done-for-you templates
£15ChatGPT / OpenAI API Data Processing Pack
You have read the guide. This is the filled-out paperwork: the DPA, the DPIA, the privacy-notice wording, and the records, drafted by a CIPP/E practitioner so you can evidence it instead of starting from a blank page.
- An Article 28 DPA review checklist, plus a controller-to-processor DPA template with OpenAI as a named sub-processor
- An LLM-API DPIA-lite, pre-filled with the current OpenAI facts
- A Legitimate Interest Assessment mini-template and a ready-to-paste privacy-notice paragraph
- A configuration and go-live checklist plus a Records of Processing entry
- Current as at August 2026: the 30-day retention default, approval-gated zero-retention, the SCCs and UK Addendum transfer position, and the litigation-hold status
Start with a £500 scoping review
If you need GDPR documentation, AI Act work, or a compliant AI build, the first step is a written scoping review. You get a written report you can act on.
Related Articles
GDPR
Is the Gemini API GDPR Compliant? It Depends Which Gemini You Use (2026)
Google offers Gemini through products with very different data terms. The free Google AI Studio tier uses your content to improve Google's products and it may be reviewed by people. The paid Gemini API and Vertex AI do not use your data for training, and Vertex AI adds the Cloud Data Processing Addendum, EU data residency and retention controls. How to tell them apart, and how to configure the compliant path.
GDPR
Is the Claude API GDPR Compliant? It Depends Where You Run It (2026)
The Claude (Anthropic) API can be used in compliance with the GDPR. Its Data Processing Agreement is part of the Commercial Terms, API data is not used for training, and inputs and outputs are deleted within thirty days by default. This guide covers the DPA, retention and zero data retention, where the model runs and who the processor is, data minimisation, the DPIA, international transfers, the Microsoft Copilot routing issue and the privacy notice.
GDPR
A Customer Questionnaire Asks for Your UK GDPR Representative: How to Answer It
UK customers ask suppliers outside the UK whether they have appointed a representative under Article 27 of the UK GDPR. What the question is checking, the five honest answers, and what to attach.