Back to blog
GDPRAI ActAI SecurityProfessional ServicesData Protection

Can Your Firm Use ChatGPT With Client Data? What GDPR and the AI Act Require

More professionals use ChatGPT for everyday tasks. But entering client data in the free version can break GDPR and, since August 2026, the AI Act too.

Digital Transformations Team October 7, 2026
Can Your Firm Use ChatGPT With Client Data? What GDPR and the AI Act Require

TL;DR: Pasting a client's name or real case details into free ChatGPT can breach GDPR without anyone noticing. Since 2 August 2026, the AI Act — the EU's artificial intelligence law — adds another layer of obligations on top. The fix isn't banning AI at your firm: it's signing the right agreement with the provider before using it with real data.

At some point this week, someone on your team probably copied a paragraph with a client's name into ChatGPT and asked it to summarise or rewrite it. It's fast, it works, and almost certainly nobody stopped to ask whether that's actually allowed.

The question that matters here — the one behind using ChatGPT with client data without landing your firm in trouble — is simple: what does that tool do with what you just told it?

What changed on 2 August 2026?

The AI Act — Regulation (EU) 2024/1689, the first European law specifically regulating artificial intelligence — didn't arrive all at once. It entered into force in the summer of 2024 and has been rolling out in phases since.

The first phase, covering the most serious prohibitions and the obligation to give staff at least minimal AI training, has been enforceable since 2 February 2025. The second, much broader phase — including the duty to disclose when someone is talking to an AI or reading AI-generated content — applies from 2 August 2026.

Put plainly: if your firm uses AI with client-facing work today, it's no longer in "not yet" territory. It applies now.

Here's the nuance most people miss: the AI Act doesn't replace GDPR, the EU's General Data Protection Regulation. It sits on top of it. You can be fully compliant with the AI Act and still get data protection wrong, because the two are separate layers, and both apply at the same time.

Why the free version is the problem — not "AI" in general

This is where the common mistake creeps in: assuming free ChatGPT and enterprise ChatGPT are the same tool at a different price point. They're not, at least not on the point that matters for your clients.

On individual services, such as ChatGPT on a Free or Plus plan, OpenAI may use your conversations to train its models unless you turn that setting off yourself. On business plans — ChatGPT Team, ChatGPT Enterprise — and through the API, the default runs the other way: your data isn't used for training unless the organisation explicitly opts in to share it.

It's the difference between leaving a letter on the counter of any shop and handing it to a courier who has signed a contract not to open it. The envelope looks the same. Who gets to read it doesn't.

If your team uses the free version to draft a generic email with nobody's data in it, nothing happens. The problem starts the moment that text carries a real client's name, case details or financial information. At that point it stops being a draft — it becomes processing of personal data, and GDPR has plenty to say about who you hand that to.

What exactly is a DPA, and why does your firm need one?

A DPA (Data Processing Agreement) is the contract your firm signs with the AI model provider to guarantee that client data isn't used to train the model and that GDPR conditions are met.

Without that contract in place, no matter how good the tool is or how correct the output looks, your firm has no written guarantee of what happens to the information it just handed over. And in data protection, what isn't signed doesn't exist when you need to defend yourself to a client or a regulator.

The good news is that getting this contract doesn't require an in-house legal team: it's usually enough to switch to the corresponding business plan and keep the documentation the provider gives you with it.

What to do this week, without disrupting the firm

This doesn't need a six-month project. Three short steps cover the essentials.

First, look at which AI tools your team actually uses today, not the ones you approved a year ago. Second, for any use touching client data, check whether the plan you're on has a signed DPA or whether it's a personal plan without one. Third, if you find the latter, switch plans before the next query involving real data — not after.

Would your firm know how to answer today, if a client or an inspector asked, what happened to the data someone pasted into ChatGPT last week? If that question makes you uneasy, that's a sign it's time to check — not that something has gone badly wrong, because most firms are exactly at that point right now.

Before deciding what to change, it helps to know where your firm actually stands on AI use, beyond a gut feeling. Digital Transformations' Digital Maturity Calculator gives you a breakdown by area — not a single score — so you can see clearly where you stand and what to fix first.

Check it here: https://www.digitransformations.com/madurez-digital

Content developed with AI assistance and reviewed by the Digital Transformations editorial team

Frequently asked questions

Is it illegal for a firm to use ChatGPT?

No. The issue isn't the tool, it's which version you use and what data you feed it. With a plan that has no contractual guarantees and real client data, the risk shows up; with the right plan, it doesn't.

What is a DPA?

It's the contract the firm signs with the AI model provider to guarantee that client data isn't used to train the model and that GDPR conditions are met.

Since when does the AI Act apply?

In phases: the prohibitions and the minimum staff training obligation have been enforceable since 2 February 2025; the bulk of the regulation, including transparency obligations, applies from 2 August 2026.

Does the paid ChatGPT Plus plan already have a DPA?

Not necessarily. ChatGPT Plus is a personal plan: by default it still allows your conversations to be used for model training unless you turn that off. A formal DPA comes with business plans or API access.

I've already entered client data into free ChatGPT. What now?

Review and disable the option to share data for training in your account settings, document what happened, and consider moving that use case to a business plan with a signed DPA before it happens again.

Related articles