Introduction: Between Innovation and Responsibility
The use of ChatGPT and other large language models (LLMs) is now firmly embedded in the European business landscape. But with this innovation come growing demands on data protection, IT security, and regulatory compliance. This guide examines the data protection challenges of working with LLMs like ChatGPT, the impact of the EU AI Act from August 2025 onward, and offers pragmatic courses of action for businesses looking to stay compliant across Europe.
How ChatGPT Works: Technical Understanding as the Foundation for Compliance
ChatGPT is based on a General Purpose AI system (GPAI) trained on billions of publicly accessible texts. A critical point from a data protection perspective is that, under certain conditions, user inputs can be used to further develop the models. This is exactly where the data protection challenge lies: clearly defining which data is stored, processed, or used for model training and how is often only possible to a limited extent. This requires businesses to have a deep understanding of how AI systems process data.
Data Protection Challenges with LLMs at a Glance
Integrating ChatGPT into business processes brings specific data protection risks. Here are the main issues businesses need to address:
Data Flows & Data Processing: The Crux of Third-Country Transfers
Many businesses use ChatGPT via cloud platforms like Azure OpenAI. But even with EU hosting, uncertainty often remains around data disclosures, complex sub-processor structures, and their impact on third-country transfers (e.g., to the US). Without clean contractual arrangements — in particular Data Processing Agreements (DPAs) and a Transfer Impact Assessment (TIA) — companies risk violating GDPR principles and facing steep fines.
Transparency & Information Obligations: Difficult to Implement for AI Models
Under Articles 13 and 14 of the GDPR, data controllers are required to fully disclose the purpose, nature, and scope of data processing to data subjects. With LLMs, this information is often hard to pin down due to their complexity and the dynamic nature of data processing. This makes it nearly impossible to provide GDPR-compliant disclosure to users and employees about how AI uses their data, without appropriate technical and organizational measures.
Practical Risk Areas in a Business Context: Where the Dangers Lurk
Careless use of ChatGPT can lead to significant data protection violations across various business areas. Here are typical scenarios and the associated data protection risks posed by AI:
- Marketing: When generating text or content suggestions, there's a risk that prompts contain confidential CRM data such as customer information or strategic plans.
- Human Resources (HR): In areas like candidate communication or training materials, processing special categories of personal data (e.g., health data or an applicant's ethnic origin) poses a significant risk.
- Legal & Compliance: When using AI for research or contract review, there's a risk that the AI output is used as the basis for legal decisions despite a lack of traceability, or that confidential legal documents are entered into the system.
- Customer Service: Tasks such as answering frequently asked questions or handling support chats carry the risk of unintentionally disclosing personal customer data, including names, addresses, or order history.
- Research & Development: When generating code or analyzing data, businesses risk entering trade secrets or protected data that could then be used for model training.
The EU AI Act: New Requirements for AI Security and Transparency Starting August 2025
On August 2, 2025, additional EU AI Act requirements come into force, specifically targeting GPAI models like ChatGPT. For businesses using these tools, this creates indirect but highly relevant obligations to ensure lawful use of AI:
- Documentation and transparency obligations: Users must be able to demonstrate how and why AI is used in internal processes. This also includes logging AI usage.
- Security measures and misuse protection: Businesses are required to implement safeguards against manipulation and log critical inputs to minimize AI security risks.
- Governance processes for internal AI use: Introducing usage policies, targeted employee training, and risk assessments for AI use is essential to ensure AI compliance.
The voluntary, yet effectively mandatory, "Code of Practice" for LLMs is becoming increasingly important. Providers like Microsoft and OpenAI are increasingly aligning their products with it — with direct implications for the compliance of the businesses using them.
Recommendations for GDPR- and AI Act-Compliant AI Use
To integrate LLMs like ChatGPT into your business in a secure, GDPR-compliant way, proactive measures are essential. Here are our best practices for AI compliance:
- Define the usage context: Clearly define which departments are allowed to use ChatGPT and for what purposes. A clear AI usage policy is essential.
- Risk-based classification: Conduct a detailed risk assessment for AI applications. What data may be processed? Which tools access personal data, and which don't?
- Technical & organizational measures (TOMs): Implement technical safeguards such as logging AI inputs, input filters to anonymize data, and strict access controls.
- Contractual safeguards: Sign Data Processing Agreements (DPAs) with providers and, where third countries are involved, carry out a Transfer Impact Assessment (TIA) to ensure international data transfers are legally sound.
- Employee training on AI literacy: A training requirement for all employees working with AI systems is essential. Raise awareness of data protection risks in AI use.
- Governance and control mechanisms: Establish clear policies for AI use, define audit procedures, and assign responsibilities for AI compliance.
heyData's Role: Enablement, Not Legal Advice
heyData does not offer traditional legal AI Act consulting. Our AI-related services are designed to empower businesses and provide smart solutions:
- Risk assessment of AI use in your company.
- Trainings on AI literacy & the GDPR-compliant use of AI systems.
- Providing GDPR-compliant templates and policies for AI use
Conclusion: Regulation Doesn't Have to Slow Down Innovation — Navigate Safely with heyData
ChatGPT and similar AI systems are here to stay. But anyone who wants to stay on the safe side long-term needs clear internal processes, technical safeguards, and a solid understanding of the regulatory framework. The EU AI Act and the GDPR aren't obstacles here — they're guardrails for responsible and innovative AI use.
With heyData, businesses get exactly the tools, training, and structures they need to drive innovation safely, in compliance with both the GDPR and the AI Act.
FAQ
Can ChatGPT even be used in compliance with data protection law?
Can ChatGPT even be used in compliance with data protection law?
Yes, compliant use is possible, but it requires proactive measures. Companies must take special precautions, such as using enterprise versions (e.g., ChatGPT Enterprise or Team), consistently avoiding the input of sensitive or personal data, and establishing clear internal usage policies. These steps are crucial for meeting the principles of data protection and data minimization.
What are the biggest data protection risks for my company when using ChatGPT?
What are the biggest data protection risks for my company when using ChatGPT?
The main risks lie in the unintentional disclosure of confidential or personal data in prompts, which could be used for model training or in logs. Another major issue is the transfer of data to third countries, especially the USA. Legally compliant contractual arrangements such as Data Processing Agreements (DPAs) and Transfer Impact Assessments (TIAs) are essential here to meet GDPR requirements.
How are the EU AI Act and the GDPR related?
How are the EU AI Act and the GDPR related?
The EU AI Act and the GDPR are complementary but separate laws. The GDPR focuses on the protection of personal data in general. The AI Act, on the other hand, introduces specific requirements for the safety, transparency, and governance of AI systems, including GPAI models such as ChatGPT. The AI Act thus creates a new compliance layer that must be met in addition to existing GDPR obligations. When using AI systems, both sets of rules often apply at the same time.
What new obligations does the EU AI Act bring from August 2025?
What new obligations does the EU AI Act bring from August 2025?
From August 2, 2025, new indirect but highly relevant obligations take effect for companies using GPAI systems such as ChatGPT. These include the need to document AI use in a traceable way, implement security measures to protect against misuse, and establish clear governance processes. Companies must ensure that they can make their AI use traceable and justifiable in line with the new transparency and security standards.
What practical steps should my company take now to prepare for these regulations?
What practical steps should my company take now to prepare for these regulations?
As a first step, a company should define a clear policy for AI use. It's crucial to conduct a risk assessment for every AI application, put the necessary contractual agreements (such as DPAs) in place with providers, and train all employees on "AI literacy" and the associated data protection risks.







