Guides
ChatGPT and data protection: what's allowed in, what isn't?
The concern is valid: whatever you enter into an AI program leaves your business. The good news: for most everyday tasks, you don't need any personal data at all. With a few rules, you can use AI safely.
By Marvin Pirner · Last updated: September 2026 · Reading time approx. 3 min.
- No names, contact details, health or financial data of customers or staff in free AI programs.
- Use placeholders instead of real data.
- Turn off the setting that trains the model on your data.
- Working with personal data requires a business version with a data processing agreement.
- Always check the results.
Why this matters
When you enter customer data into an AI program, another company processes that data – often outside the EU. Under the General Data Protection Regulation (GDPR), you need a legal basis for that and, as a rule, a data processing agreement (DPA, Art. 28 GDPR) with the provider. Free personal accounts usually don't come with this agreement. Providers may also use your inputs to improve their models, depending on the settings.
The traffic light: what's allowed in and what isn't
- Green – no concern: general texts with no personal reference, notices, job ads, product descriptions, ideas, explanations, translations of general texts.
- Yellow – only with placeholders: customer emails, quotes, complaints. Replace names, addresses and numbers with "Customer A", "[address]".
- Red – never into general-purpose AI programs: health data, banking and payment data, personnel files, job applications, client or patient files, passwords, business secrets.
Five rules for your business
- Placeholders instead of real data. The AI doesn't need the name to write a good answer.
- Turn off training. In the settings of most programs, you can specify that your inputs are not used to improve the AI.
- A business version for real data. If you want to regularly work with personal data, use a business version where the provider offers a data processing agreement, and check where the data is processed.
- A clear rule for the team. Write down on one page which programs are allowed and what doesn't belong in them. This also helps with the AI literacy obligation.
- Check the results. AI can invent facts. Whatever you send or publish is your responsibility.
Example: a customer email with placeholders
Customer A complained that the delivery to [address] arrived two days late. Write a short apology with a 10 percent voucher for their next order. Informal tone, maximum 100 words.
You add the name and address only in your own email program.
What about the privacy policy?
If you only use AI internally with placeholders, this usually changes nothing for your website. If you use AI where customers interact with it directly – such as a chatbot on your website – that belongs in your privacy policy, and since August 2026 the AI Act requires that customers can recognize they're talking to an AI. It's best to clarify this with your data protection officer or a law firm.
Frequently asked questions
Is ChatGPT allowed in Germany?
Yes. What matters is which data you enter and which version you're using.
Is it enough to leave out the name?
Not always. Even a combination of street, occupation and context can identify a person. When in doubt, phrase it more generally.
Which program is the safest?
That depends less on the name than on the version, the agreement and the settings. I recommend what fits your business, regardless of provider.
This article is a practical overview, not legal advice. For binding guidance, consult a lawyer or your data protection officer.
Prefer to start together?
In the free consultation, we'll look at where to start in your business.