Introduction: Between Innovation and Responsibility

The use of ChatGPT and other large language models (LLMs) is now firmly embedded in the European business landscape. But with this innovation come growing demands on data protection, IT security, and regulatory compliance. This guide examines the data protection challenges of working with LLMs like ChatGPT, the impact of the EU AI Act from August 2025 onward, and offers pragmatic courses of action for businesses looking to stay compliant across Europe.

How ChatGPT Works: Technical Understanding as the Foundation for Compliance

ChatGPT is based on a General Purpose AI system (GPAI) trained on billions of publicly accessible texts. A critical point from a data protection perspective is that, under certain conditions, user inputs can be used to further develop the models. This is exactly where the data protection challenge lies: clearly defining which data is stored, processed, or used for model training and how is often only possible to a limited extent. This requires businesses to have a deep understanding of how AI systems process data.

Data Protection Challenges with LLMs at a Glance

Integrating ChatGPT into business processes brings specific data protection risks. Here are the main issues businesses need to address:

Data Flows & Data Processing: The Crux of Third-Country Transfers

Many businesses use ChatGPT via cloud platforms like Azure OpenAI. But even with EU hosting, uncertainty often remains around data disclosures, complex sub-processor structures, and their impact on third-country transfers (e.g., to the US). Without clean contractual arrangements — in particular Data Processing Agreements (DPAs) and a Transfer Impact Assessment (TIA) — companies risk violating GDPR principles and facing steep fines.

Transparency & Information Obligations: Difficult to Implement for AI Models

Under Articles 13 and 14 of the GDPR, data controllers are required to fully disclose the purpose, nature, and scope of data processing to data subjects. With LLMs, this information is often hard to pin down due to their complexity and the dynamic nature of data processing. This makes it nearly impossible to provide GDPR-compliant disclosure to users and employees about how AI uses their data, without appropriate technical and organizational measures.

Practical Risk Areas in a Business Context: Where the Dangers Lurk

Careless use of ChatGPT can lead to significant data protection violations across various business areas. Here are typical scenarios and the associated data protection risks posed by AI:

  • Marketing: When generating text or content suggestions, there's a risk that prompts contain confidential CRM data such as customer information or strategic plans.
  • Human Resources (HR): In areas like candidate communication or training materials, processing special categories of personal data (e.g., health data or an applicant's ethnic origin) poses a significant risk.
  • Legal & Compliance: When using AI for research or contract review, there's a risk that the AI output is used as the basis for legal decisions despite a lack of traceability, or that confidential legal documents are entered into the system.
  • Customer Service: Tasks such as answering frequently asked questions or handling support chats carry the risk of unintentionally disclosing personal customer data, including names, addresses, or order history.
  • Research & Development: When generating code or analyzing data, businesses risk entering trade secrets or protected data that could then be used for model training.

The EU AI Act: New Requirements for AI Security and Transparency Starting August 2025

On August 2, 2025, additional EU AI Act requirements come into force, specifically targeting GPAI models like ChatGPT. For businesses using these tools, this creates indirect but highly relevant obligations to ensure lawful use of AI:

  • Documentation and transparency obligations: Users must be able to demonstrate how and why AI is used in internal processes. This also includes logging AI usage.
  • Security measures and misuse protection: Businesses are required to implement safeguards against manipulation and log critical inputs to minimize AI security risks.
  • Governance processes for internal AI use: Introducing usage policies, targeted employee training, and risk assessments for AI use is essential to ensure AI compliance.

The voluntary, yet effectively mandatory, "Code of Practice" for LLMs is becoming increasingly important. Providers like Microsoft and OpenAI are increasingly aligning their products with it — with direct implications for the compliance of the businesses using them.

Recommendations for GDPR- and AI Act-Compliant AI Use

To integrate LLMs like ChatGPT into your business in a secure, GDPR-compliant way, proactive measures are essential. Here are our best practices for AI compliance:

  1. Define the usage context: Clearly define which departments are allowed to use ChatGPT and for what purposes. A clear AI usage policy is essential.
  2. Risk-based classification: Conduct a detailed risk assessment for AI applications. What data may be processed? Which tools access personal data, and which don't?
  3. Technical & organizational measures (TOMs): Implement technical safeguards such as logging AI inputs, input filters to anonymize data, and strict access controls.
  4. Contractual safeguards: Sign Data Processing Agreements (DPAs) with providers and, where third countries are involved, carry out a Transfer Impact Assessment (TIA) to ensure international data transfers are legally sound.
  5. Employee training on AI literacy: training requirement for all employees working with AI systems is essential. Raise awareness of data protection risks in AI use.
  6. Governance and control mechanisms: Establish clear policies for AI use, define audit procedures, and assign responsibilities for AI compliance.

heyData's Role: Enablement, Not Legal Advice

heyData does not offer traditional legal AI Act consulting. Our AI-related services are designed to empower businesses and provide smart solutions:

  • Risk assessment of AI use in your company.
  • Trainings on AI literacy & the GDPR-compliant use of AI systems.
  • Providing GDPR-compliant templates and policies for AI use

Conclusion: Regulation Doesn't Have to Slow Down Innovation — Navigate Safely with heyData

ChatGPT and similar AI systems are here to stay. But anyone who wants to stay on the safe side long-term needs clear internal processes, technical safeguards, and a solid understanding of the regulatory framework. The EU AI Act and the GDPR aren't obstacles here — they're guardrails for responsible and innovative AI use.

With heyData, businesses get exactly the tools, training, and structures they need to drive innovation safely, in compliance with both the GDPR and the AI Act.