Back to blog
AI & Automation6 September 20269 min read

Is It Safe to Put Customer Data into ChatGPT?

Pasting a client email into an AI tool feels harmless. Where the real GDPR line sits, why the free version is the problem, and simple rules that keep you safe.

Is It Safe to Put Customer Data into ChatGPT?

You have a difficult email to write to a customer. You paste the whole thread into ChatGPT and ask it to make you sound calmer. Or you drop in a quote and ask it to tidy the wording. Or a supplier contract, to explain a clause you do not understand.

Almost everybody does this, most people never think twice about it, and in some circumstances it is a genuine data protection problem. Here is where the line actually sits, without the scaremongering.

General information, not legal advice. If you handle a lot of sensitive data, get your setup reviewed properly.

The short answer

It depends on two things: what is in the text, and which version of the tool you are using. The same prompt can be perfectly fine or a breach depending on those two answers, which is why blanket advice like "never use AI at work" or "it is all fine" are both useless.

The bit almost nobody knows

Under the GDPR, if someone processes personal data on your behalf, you need a data processing agreement with them. That is not a formality, it is the legal basis for handing that data over at all.

OpenAI provides a data processing agreement for its business tiers: ChatGPT Business, Enterprise and the API. It does not provide one for the free consumer version.

That single fact does most of the work here. Pasting a customer's personal details into free consumer ChatGPT means personal data you are responsible for is being processed by a company you have no processor agreement with. Doing the same on a business account with a signed DPA is a completely different legal position.

Other providers work the same way, with consumer and business tiers on different terms. The question to ask of any AI tool is simply: is there a DPA, and have we signed it?

What counts as personal data here

Wider than people assume. A name, an email address, a phone number, a postal address, a NIF, a photo of someone, a vehicle registration, or any combination that makes a person identifiable. In a customer email thread, that is usually all of it.

Some data is stricter still: health information, and anything revealing political views, religion, trade union membership, sexual orientation or biometrics. That category should never go into a general AI tool, full stop.

The situations that actually catch small businesses

  • Pasting a customer contract or quote in to reword it. Personal data plus commercial confidentiality in one go.
  • Summarising a WhatsApp thread with a client. The customer never agreed to their messages being sent to a third party.
  • Uploading a customer spreadsheet to clean up or deduplicate. The single riskiest habit on this list, because it is hundreds of people at once.
  • Screening job applications or CVs. This one carries extra weight, see below.
  • Staff doing any of the above on their personal accounts, which you will not know about unless you have told them where the line is.

Six rules that keep you on the right side

  1. Anonymise by default. Replace names and addresses with placeholders. "Draft a firm but polite reply to a customer disputing an invoice" works just as well as pasting the real thread, and carries no risk at all.
  2. Use a business tier if real customer data is genuinely involved, and make sure the DPA is actually accepted rather than just available.
  3. Never paste special-category data. Health, biometrics and the rest. No exceptions, no anonymising your way around it.
  4. Check the training setting. Know whether your inputs are used to improve the model, and turn it off where you can. Business tiers generally do not train on your data by default; consumer ones may.
  5. Mention it in your privacy notice if AI tools genuinely process customer data, in the same way you list your hosting and email providers. See what your website legally needs in Spain.
  6. Give your team one clear rule, not a policy document. Something like: no customer names or client documents into any AI tool, use placeholders instead. One sentence people remember beats ten pages nobody reads.

The EU AI Act, in proportion

You will hear a lot about this, much of it from people selling compliance services. Some perspective.

From 2 August 2026 the AI Act's obligations for high-risk systems apply. But "high-risk" has a specific meaning: consequential uses such as screening job applicants, assessing creditworthiness, or biometric identification. Those carry real duties around documentation, logging and human oversight.

A plumber using ChatGPT to draft a customer email is not operating a high-risk AI system, and nobody should tell you otherwise. The one place a normal small business can wander into scope is recruitment, so if you are using AI to sift CVs, that is worth proper advice.

For everyone else, the binding constraint is the GDPR, which has applied all along and is what the rest of this article is about.

The risk that is not legal at all

Worth saying plainly: for most small businesses the realistic downside is not a regulator knocking. It is confidentiality and trust.

If a client discovered you had pasted their contract, their dispute or their personal circumstances into a public AI tool, the damage would be to the relationship, long before anyone mentioned the GDPR. That instinct is usually a better guide than the regulation: if you would not forward it to a stranger, do not paste it into a chatbot.

Frequently asked questions

Can I use the free version of ChatGPT for work at all?

Yes, for plenty of things: drafting generic copy, explaining a concept, structuring an article, brainstorming. What you should not do is put identifiable customer or employee data into it, because there is no data processing agreement covering that.

Does using a paid plan make it compliant?

It removes one significant obstacle by giving you a DPA, but it does not make everything automatically lawful. You still need a legal basis, transparency with the people whose data it is, and sensible limits on what goes in.

What if I remove the names first?

Genuinely anonymised text is much lower risk and is the approach we would recommend for most day-to-day use. Be careful that the remaining detail does not identify someone anyway, which happens easily in a small town.

Does the AI Act apply to my small business?

Its high-risk obligations, which began applying on 2 August 2026, are aimed at consequential uses such as recruitment screening, credit scoring and biometrics. Ordinary use of an assistant to draft text is not high-risk. Be sceptical of anyone telling you otherwise while holding an invoice.

Is an AI chatbot on my website the same risk?

It is a different situation, and generally a better-controlled one, because a properly built chatbot runs on business terms with a DPA, only handles what visitors choose to type, and can be configured not to retain data. That is precisely the difference between a tool you have set up deliberately and staff pasting things into a personal account.

None of this means avoiding AI. It means being deliberate about which tool handles customer data and on what terms. If you would like AI working in your business without that question hanging over it, our AI chatbots and automation are set up with this in mind, or get in touch and we will tell you honestly which of your current habits are fine and which are not.

Need Help With This?

We implement everything we write about. Let us handle the technical stuff for you.

Get a Free Consultation