AI and GDPR: which data your SME can put into ChatGPT, Copilot or Claude
ChatGPT, Copilot, Claude, Gemini, Mistral: what happens to your data plan by plan, a four-level decision grid, and what actually changed in 2026. Written for SME owners, not lawyers.
Flavien Bittar
September 23, 2026
Yes, your SME can use generative AI with customer data, on three conditions. A business plan that does not train the models on your data and includes a data processing agreement (DPA). A written rule that tells your team what they may and may not put into it. And a privacy notice that informs the people concerned, as with any other service provider. So the question is not "is ChatGPT GDPR compliant?" but "with which plan, and for which data?".
Almost every business owner I meet asks it the wrong way. A recent example: a client uses ChatGPT on a Plus subscription, paid out of pocket, and pastes non-anonymised customer data into it. Nothing strategic: names, exchanges, amounts. The idea behind it: I pay, so I'm covered. Wrong, and we'll see why.
Here is where things stand on 23 September 2026, tool by tool. This is not legal advice: if your case involves health data or professional secrecy, have it checked by your DPO or your lawyer.
The real dividing line: personal account or business plan, not free or paid
What matters is the contract under which you use the tool, not what you pay. All the major providers split the world in two:
- Consumer plans (personal account, free or paid). The provider is the controller: it processes what you type on its own behalf, under its privacy policy, and may use it to train its models. There is no DPA.
- Business plans (team, enterprise, API). The provider acts as a processor, commits not to train its models on your content, and a DPA is part of the contract.
That is the trap of the individual subscription. ChatGPT Plus, ChatGPT Pro, Claude Pro, Claude Max and Google AI Pro follow the same rules as their free version. Paying $20 a month buys capacity and features, not a different contractual status. That is exactly my client's case: on Plus, OpenAI Ireland is the controller for European users, training stays on until you switch it off, and OpenAI's DPA only covers Business, Enterprise and the API.
On the business side, contracts are concluded with a European entity: OpenAI Ireland, Anthropic Ireland, Microsoft Ireland, Google Cloud EMEA or Mistral AI SAS. Anthropic's commercial terms, for instance, state that Anthropic "may not train models on Customer Content from Services", and that the DPA is "incorporated into these Terms by reference": nothing separate to sign.
The French data protection authority says the same in its Q&A on generative AI: never share personal data when using a consumer service, and sign a processing agreement as soon as customer or employee data is involved.
The simulator: which plan for your data
Pick the type of data, what your company already uses and your team size: the simulator sorts the 14 plans of the five tools into "good to go", "with conditions" and "avoid", with the monthly cost. Everything comes from the providers' official terms, checked on 23 September 2026. The full table is available at the bottom of the tool.
Full table of all 14 plans
| Tool and plan | Training | DPA | EU storage | Price excl. VAT / seat / month |
|---|---|---|---|---|
| ChatGPT Free, Plus or Pro | yes | no | no | $20 |
| ChatGPT Business (formerly Team) | no | yes | no | $20 (2 seats min.) |
| ChatGPT Enterprise | no | yes | yes | On quote |
| Claude Free, Pro or Max | your choice | no | no | $17 |
| Claude Team | no | yes | no | $20 (2 seats min.) |
| Claude via AWS Bedrock or Google Cloud | no | yes | yes | Pay as you go |
| Copilot personal Microsoft account | yes | no | no | Free |
| Copilot Chat Microsoft 365 work account | no | yes | with exceptions | Included |
| Microsoft Copilot Business licence | no | yes | with exceptions | €18.20 |
| Gemini personal Google account | yes | no | no | Free |
| Gemini in Google Workspace | no | yes | no | Included |
| Mistral Vibe Free or Pro | yes | no | by default | €14.99 |
| Mistral Vibe Team | to check | yes | by default | €24.99 (2 seats min.) |
| Mistral Enterprise | no | yes | by default | On quote |
A few traps behind these results. Names change fast: ChatGPT Team has been called Business since 29 August 2025, Mistral Le Chat became Vibe in 2026, and Microsoft 365 Copilot is now called Microsoft Copilot. Mistral, for its part, rewrote the training rule of its Team plan three times in five months: in September 2026, its help centre says the administrator "can disable" training, which suggests it is on by default. If you choose Team, check the setting in the console. And for Copilot on a personal account, Microsoft excluded European users from training in 2024; its current FAQ no longer lists the European Economic Area among the exclusions. When in doubt, switch the option off.
The thumbs-up trap
Even with training switched off, one click on thumbs up or thumbs down is enough to send the conversation to training. OpenAI writes: "If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models". Mistral's commercial terms carve out the same exception for feedback. At Anthropic, conversations sent as feedback are kept for five years. Put it plainly in your internal rule: no thumbs on a conversation that contains customer data.
Copilot: one name, two different contracts
Microsoft gave the same name to two products, and it is the confusion I run into most often. Copilot Chat with a work account (Entra ID) benefits from enterprise data protection: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs", according to Microsoft's documentation. It is included at no extra cost in eligible Microsoft 365 plans. Copilot with a personal Microsoft account, on copilot.com or in the app, falls under consumer terms: training by default, 18-month retention, no DPA.
If your team already runs on Microsoft 365, you probably have an AI tool covered by a DPA without knowing it. Just make sure your staff sign in with their work account.
EU hosting: rare in SME plans
A DPA does not say where your data is stored. And EU hosting is rarely included in the plans an SME picks:
- ChatGPT: Enterprise, Edu and the API only. Not Business.
- Google: for Gemini, Workspace Enterprise Plus only. Not Business.
- Claude: not directly. You have to go through AWS Bedrock or Google Cloud, where EU regions cost 10% more.
- Microsoft: yes, through the EU Data Boundary, with exceptions. Web queries go through Bing, the Anthropic models offered in Copilot are "currently excluded from the EU Data Boundary", and "flex routing", on by default for tenants created since 25 March 2026, allows processing in the United States, Canada or Australia at peak times. Your administrator can switch it off.
- Mistral: EU hosting by default according to its help centre; for the API, only the EU endpoint launched on 11 August 2026 guarantees it, at +10%.
Should it be a requirement? Not necessarily. A transfer to a US provider remains lawful (see below). But if your customers, your key accounts or your sector demand it, this is the criterion that shortens the list.
The decision grid: four levels of data
Rather than a list of prohibitions nobody reads, give your team a grid. Four levels are enough.
Level 1: public. Your website content, published product sheets, press releases, marketing copy. Any tool will do, even a free version.
Level 2: internal, no personal data. Procedures, meeting notes without names, aggregated figures, code, strategy documents. This is not a GDPR matter, it is trade secrets. The Trade Secrets Directive 2016/943 only protects information as a trade secret if it has been subject to "reasonable steps" to keep it secret. Letting your strategy be pasted into a tool that trains on it weakens that protection. Business plans only.
Level 3: ordinary personal data. Names and contact details of customers or prospects, sales exchanges, order history. Business plan with a DPA, processing entered in your record, provider named in your privacy notice, and the minimum data needed. Replacing names with initials costs nothing and cuts the risk a lot.
Level 4: sensitive data. Health, HR data (appraisals, sick leave, disciplinary measures), data covered by professional secrecy, industrial secrets. The default answer is no in a general-purpose assistant. For health data and the other categories of Article 9 GDPR, you need a specific exception on top of the usual legal basis, and an impact assessment becomes mandatory as soon as the processing is large-scale (Article 35(3)).
I have seen a whole project built by ignoring level 4. A developer, not a client, was launching a platform built by "vibe coding": it invited users to enter health data, which went straight to a commercial AI model for analysis. No Article 9 exception, no impact assessment, no thought about hosting. I warned them, and I believe the project has since stopped. The model did what it was asked. Nobody had asked "what kind of data am I processing?", and without that question the project was unlawful from the first sign-up.
What the GDPR asks of you
Switching plans settles the provider's position. It does not settle yours. When your SME decides to use an AI tool for its own needs, it is the controller. The CNIL says so directly: it is the user organisation that bears legal liability when its staff misuse AI. In practice:
- A contract that meets Article 28 with the provider. That is its DPA: check that it covers your plan.
- A legal basis for each use. To draft a reply to a customer or summarise a file, performance of a contract or legitimate interest are the bases usually relied on.
- Information to the people concerned (Articles 13 and 14): your privacy notice must name the provider among the recipients, along with any transfers outside the EU.
- An entry in your record of processing (Article 30). The under-250-employees exemption does not apply to processing that is not occasional, and daily use on customer data is not.
- An impact assessment depending on the use, not as a matter of principle. Neither the CNIL list nor the Belgian DPA list names generative AI as such. Drafting emails does not need one. Profiling employees, monitoring their activity or processing sensitive data at scale does.
- A human who decides. Article 22 prohibits decisions based solely on automated processing that significantly affect a person. Screening CVs with a language model and then following its ranking without real review exposes you to it: in the SCHUFA judgment, the Court of Justice held that a score computed by a third party can be a decision when the decision-maker "draws strongly" on it.
What about transfers to the United States?
They are lawful today, with a caveat. The adequacy decision of 10 July 2023, the Data Privacy Framework, covers US companies certified under it. The EU General Court dismissed Philippe Latombe's action against this framework on 3 September 2025. An appeal is pending before the Court of Justice (case C-703/25 P): the risk of invalidation remains open until the ruling.
Certification is checked company by company, on the official list: do it for your US providers. And EU hosting with a US provider removes the transfer within the meaning of the GDPR, but not exposure to the CLOUD Act, which lets US authorities request data stored outside the United States. No European authority prohibits these services on that ground; it is a residual risk to know about, nothing more.
What changed in 2026, and what other articles missed
Most guides on the subject were written before the summer. Three things have moved since.
The AI Omnibus has been in force since 27 July 2026. Regulation (EU) 2026/1744 amends the AI Act. Obligations for Annex III high-risk systems, including CV screening and employee evaluation, are postponed to 2 December 2027; those for Annex I (regulated products) to 2 August 2028. Article 4 on AI literacy becomes a best-efforts obligation: companies "take measures to foster the development of AI literacy" among their staff, without having to guarantee a specific level. It has not been removed. The transparency obligations of Article 50 have applied since 2 August 2026, as planned. I cover what this means for an SME in our article on the AI Act.
The GDPR part of the Omnibus has not been adopted. In November 2025 the Commission proposed amending the GDPR: a new definition of personal data, legitimate interest for training AI, breach notification within 96 hours. As of 1 August 2026, according to the European Parliament, no committee vote was scheduled and the Council had no mandate. You may read elsewhere that "the GDPR has been relaxed for AI": it has not, none of this is law.
The €15 million fine against OpenAI was annulled. The Italian Garante fined OpenAI in December 2024. The Court of Rome annulled the decision on 18 March 2026 for lack of jurisdiction: OpenAI having been established in Ireland since February 2024, it was for the Irish authority to act, under the one-stop-shop mechanism. The court did not rule on the merits. Mostly, remember that the big cases are now played out in Dublin, and that they target the providers, not you.
Belgium, France, Switzerland, the Netherlands: what really differs
The GDPR is the same across the EU, but the authorities have not all said the same thing, and labour law changes the picture.
- Belgium. In May 2026, the Belgian DPA published a review of chatbots, "Sous la loupe", stressing the allocation of roles between providers and a prior impact assessment: what is technically possible is not automatically necessary or proportionate. On the labour side, collective agreement no. 39 requires informing and consulting staff representatives at least three months before introducing a new technology with significant collective consequences, in companies with at least 50 workers.
- France. From 50 employees, the works council (CSE) must be consulted before new technologies are introduced (Article L2312-8 of the Labour Code). In February 2025, the Nanterre court suspended the rollout of five AI tools in summary proceedings because the consultation was not complete.
- Switzerland. The revised Data Protection Act applies directly to AI, as the Federal Data Protection Commissioner points out. Two differences from the GDPR: no 72-hour deadline to report a breach (it is "as soon as possible", and only for high risk), and the criminal fine, up to CHF 250,000, targets the responsible individuals, not the company.
- Netherlands. The Dutch authority is the most advanced on the subject. In July 2026, consulted by the municipality of Haarlemmermeer, it found that the Microsoft 365 Copilot rollout as planned would infringe the GDPR, notably for lack of transparency on telemetry and unknown retention periods. It adds that Microsoft's lack of transparency does not relieve the municipality of its duty to comply with the GDPR. The opinion concerns a public body; in my view, the reasoning applies to an SME too.
Shadow AI: an employee pasted the customer file into ChatGPT, now what?
This is the most likely scenario in your SME. Most of the time it is a busy employee using a personal ChatGPT account, because nobody gave them anything else.
The Dutch authority settled how to qualify it back in August 2024: when an employee uses a chatbot on their own initiative, against the company's rules, and enters personal data, "this means there is a data breach". A GP practice and a telecom operator reported this kind of incident. And it is the company that answers for it: in the Deutsche Wohnen judgment, the Court of Justice held that a legal person is liable for infringements committed by anyone acting in the course of its business and on its behalf.
The steps to follow:
- Stop. Have the conversation deleted. At both OpenAI and Anthropic, a deleted conversation is erased from their servers within 30 days.
- Document. Every breach goes into your breach register, including those you do not notify.
- Assess. Unless the breach is unlikely to result in a risk to people, notify your authority within 72 hours.
- Inform if the risk is high. That is Article 34: the people concerned must be told without undue delay, in clear language, with the likely consequences and the measures taken.
- Fix the cause. Banning does not work if you offer nothing instead. Provide a business tool and a rule.
As of September 2026, I found no published fine against a company solely because its employees entered data into an AI tool. What costs you today is the incident to manage, the customer who finds out, and the key account asking for your AI policy in its supplier questionnaire. The fine may come one day, but it is not the first risk.
The one-page AI policy
A twenty-page charter will not be read. Here is the outline I use, to adapt:
- Approved tools. Name them, with the plan: "Copilot Chat with your work account", "Claude Team". Everything else is off limits for work, including your paid personal account.
- The four-level grid, with one concrete example per level from your own business.
- What never goes in. Health data, individual HR files, passwords and access keys, data covered by professional secrecy.
- The anonymisation reflex. Initials instead of names, no customer numbers or IBANs.
- No thumbs on a conversation that contains customer data.
- Reread before sending. AI gets things wrong with confidence, and you are the one signing.
- No decision about a person (hiring, appraisal, credit) without real human review.
- An incident? Report it to a named person, with no penalty for reporting quickly.
Add two hours of training per person and you have also met Article 4 of the AI Act, in its relaxed version.
What it costs for a team of 20
At public prices on 23 September 2026, excluding VAT:
- Microsoft Copilot Chat: €0 extra if your team already has an eligible Microsoft 365 plan. The Microsoft Copilot Business licence adds €18.20 per user, or €364 a month.
- Gemini in Google Workspace: included in Business Standard at €13.60 per user, or €272 a month, office suite included.
- ChatGPT Business: $20 per user on annual billing, or $400 a month.
- Claude Team: $20 per user on annual billing, or $400 a month.
- Mistral Vibe Team: €24.99 per user, or about €500 a month.
Compared with the cost of a single data breach to handle, or a customer lost because their data ended up in a personal account, the maths is quick. And note the irony of my client's case: ChatGPT Plus costs $20 a month, exactly the price of an annual Business seat. They were already paying the right amount, for the wrong contract.
My view as a consultant
So far, facts. Now my view, and I own it.
If your SME already runs on Microsoft 365, start with Copilot Chat on work accounts: it costs nothing extra, it is covered by the DPA you have already signed, and your team finally has an approved alternative to personal accounts. For deeper work (analysis, long-form writing, automation), I currently recommend Claude Team to my clients. No training, contractually; the DPA is built in; the contracting entity is Irish. Its limitation, I'll say plainly: Anthropic does not offer EU storage directly. If that is a requirement for you, use Claude on AWS Bedrock or Google Cloud in a European region, or look at Mistral Enterprise.
Choosing the tool is the easy part. The part that takes work is knowing which uses your team already has, with which data, and turning that into a rule they will follow. That is what we map during a diagnostic: a picture of your real uses (it is not a legal audit) and a plan to frame them. If you want to talk about it, book a 30-minute call. And for data governance more broadly, our GDPR guide for SMEs takes over from here.
FAQ
Frequently asked questions
Is ChatGPT GDPR compliant?
It depends on the plan, not the tool. With ChatGPT Free, Plus or Pro, your conversations are used to train the models by default and there is no data processing agreement: OpenAI processes the data on its own behalf. With ChatGPT Business, Enterprise or the API, there is no training and a DPA is concluded with OpenAI Ireland. Only the second setup lets you put customers' personal data into it, and you still need a record of processing, a privacy notice and an internal rule.
Which AI tools respect the GDPR?
No tool is "compliant" in itself: your use of it is or is not. Some plans, however, make compliance possible because they do not train models on your data and include a DPA with a European entity. As of September 2026, that covers ChatGPT Business and Enterprise, Claude Team and Enterprise, Microsoft Copilot and Copilot Chat with a work account, Gemini in Google Workspace and Mistral Enterprise. Personal accounts, even paid ones, do not offer these guarantees.
Do I need a DPIA to use ChatGPT or Copilot?
Not automatically. Neither the French CNIL list nor the Belgian DPA list names generative AI as such. A data protection impact assessment becomes mandatory depending on the use: large-scale processing of health or other sensitive data, HR profiling, employee monitoring, or two of the EDPB risk criteria combined. Drafting sales emails does not require one; plugging Copilot into all your HR files probably does.
Is Mistral more compliant because it is European?
It simplifies one point, not everything. Mistral AI is a French company that hosts in the EU by default, so the service itself involves no transfer to the United States under the GDPR. But its free and Pro plans train models by default, like ChatGPT, and the wording of its Team plan changed three times in 2026. The provider's nationality does not replace the contract, the training setting or your internal rule.
What should I do if an employee put customer data into an AI tool?
Treat it as a personal data breach. Have the conversation deleted, log the incident in your breach register, then assess the risk: unless the breach is unlikely to result in a risk to people, notify your data protection authority within 72 hours, and inform the people concerned if the risk is high. The Dutch authority explicitly considers unauthorised input into a chatbot to be a data breach. Then fix the cause: an approved business tool and a written rule.
What does Article 34 of the GDPR say?
Article 34 requires you to inform the people concerned, without undue delay, when a breach of their data is likely to result in a high risk to their rights and freedoms. The message describes in clear and plain language the nature of the breach, its likely consequences, the measures taken and a contact point. It is not required if the data was encrypted, if later measures removed the high risk, or if it would involve disproportionate effort, in which case a public communication replaces it.
Ready to transform your digital ecosystem?
Discover how DigitalEasy helps SMEs navigate their digital transformation.
calendar_monthBook a Discovery Call