OpenAI GDPR compliance is not a simple yes-or-no question for businesses using ChatGPT, the OpenAI API or Azure OpenAI.
OpenAI provides privacy documentation, contractual terms and business controls designed to support compliance, but your own obligations depend on the product you use, the personal data involved and how the service is configured.
This guide explains OpenAI’s current GDPR status, how its main products differ and what businesses need to do when using them.
OpenAI’s GDPR compliance status right now
Since February 15, 2024, OpenAI Ireland Limited has provided services such as ChatGPT to users in the European Economic Area and Switzerland. This generally makes Ireland’s Data Protection Commission the lead authority for OpenAI’s cross-border EU processing.
However, OpenAI’s regulatory position is not fully settled.
Key dates
In December 2024, Italy’s data protection authority fined OpenAI €15 million over issues involving model training, transparency, a 2023 data breach and safeguards for children. The decision followed the Garante’s temporary restriction of ChatGPT in Italy in 2023.
In March 2026, the Court of Rome annulled the decision following OpenAI’s challenge. This removed the Italian enforcement action, but it did not amount to a general ruling that OpenAI’s processing complies with the GDPR.
Poland’s data protection authority also opened proceedings after a 2023 complaint concerning allegedly unlawful processing, transparency and the handling of GDPR rights requests. As of August 2026, no final public decision had been identified. This forms part of a broader debate about how data protection rules apply to generative AI.
The practical takeaway is that there is no universal “OpenAI is GDPR compliant” certificate. OpenAI can support your compliance, but your own position still depends on the product, data, lawful basis, settings, disclosures and safeguards involved.
Does OpenAI publish a GDPR compliance statement?
OpenAI does not publish one document certifying that every product and use case is GDPR compliant.
Instead, it provides several documents covering different parts of the compliance picture, including its privacy policies, Data Processing Addendum, Services Agreement, enterprise privacy information and API data-control documentation.
OpenAI’s GDPR regulatory timeline
| Date | What happened |
|---|---|
| September 2023 | Poland’s UODO announces that it is handling a complaint concerning ChatGPT |
| February 15, 2024 | OpenAI Ireland Limited becomes the service provider for EEA and Swiss users |
| December 2024 | Italy’s Garante announces a €15 million fine against OpenAI |
| August 2, 2025 | EU AI Act obligations for general-purpose AI model providers begin to apply |
| March 18, 2026 | The Court of Rome upholds OpenAI’s challenge against the Italian decision |
| August 2, 2026 | EU enforcement powers over general-purpose AI providers begin to apply |
GDPR and the AI Act overlap, but they are separate legal frameworks. GDPR governs personal data processing, while the AI Act introduces obligations based on how AI models and systems are developed and used.
ChatGPT, the OpenAI API and Azure OpenAI
“OpenAI” is not one product with one compliance answer. The contractual terms, controls and retention rules differ depending on how your business accesses the models.
ChatGPT GDPR compliance
On ChatGPT Free, Plus and Pro, conversations may be used to improve OpenAI’s models when “Improve the model for everyone” is enabled. Users can turn this off under Settings → Data Controls.
OpenAI says data from ChatGPT Business and Enterprise is not used to train its models by default. These plans also offer additional data-retention, administrative and security controls, with the exact features depending on the plan.
Personal accounts are therefore generally less suitable for processing customer, applicant or employee data. Business plans provide a more appropriate contractual and organizational framework, but they do not make every use automatically lawful.
Organizations must still assess whether the data should be entered, OpenAI’s role, their lawful basis, transparency requirements and any additional rules for sensitive data or automated decisions.
OpenAI API GDPR compliance
OpenAI says API data is not used to train its models by default.
Many endpoints retain content for up to 30 days, although eligible customers can request Zero Data Retention. European data residency is also available for some customers.
Where OpenAI acts as a processor, its Data Processing Addendum should be in place.
Azure OpenAI GDPR compliance
Azure OpenAI is supplied through Microsoft Azure rather than through ChatGPT or the OpenAI API.
Microsoft states that data submitted to Azure-hosted models is not made available to OpenAI, is not shared with other customers and is not used to train foundation models without the customer’s permission.
Where processing takes place depends on the deployment type.
With a regional deployment, prompts and responses are generally processed within the selected geography. An EU Data Zone deployment may process them across approved EU regions, while a Global deployment may process them more broadly.
Businesses with strict EU residency requirements should therefore check the model, region, and deployment type rather than assume all Azure OpenAI processing stays in the EU.
Microsoft’s Data Protection Addendum governs Azure’s handling of customer and personal data. Azure OpenAI may suit organizations already using Microsoft’s enterprise environment, but it still needs to be configured and assessed correctly.
What your business needs to do
Choosing the right product is only the first step.
1. Match the product to the risk
Avoid using personal ChatGPT accounts for business processes involving customer, employee, applicant, or other confidential personal data.
Depending on the use case, a more appropriate choice may be
- ChatGPT Business or Enterprise
- the OpenAI API under business terms and a DPA, or
- Azure OpenAI under a Microsoft enterprise agreement
2. Define the parties’ GDPR roles
Do not assume that OpenAI or Microsoft is always a processor, controller or subprocessor. The difference between a data controller and a data processor depends on the processing activity and contractual relationship.
3. Put the required processing terms in place
Where the provider acts as your processor, Article 28 generally requires a Data Processing Agreement.
For OpenAI business and API services, review the applicable OpenAI Data Processing Addendum. For Azure OpenAI, review Microsoft’s DPA and Product Terms.
A DPA is important, but it does not make the entire use case compliant on its own.
4. Minimize data and retention
Check the actual settings and retention behavior for the product, workspace, endpoint, or deployment you use.
This may include:
– disabling training on personal ChatGPT accounts;
– confirming business data is excluded from training;
– requesting Zero Data Retention for eligible API endpoints;
– selecting an appropriate Azure region or EU Data Zone; and
– preventing employees from entering unnecessary personal or confidential data.
5. Update your privacy information
Where your use of an AI service affects how you process personal data, your privacy notice should explain it.
Depending on the use case, this may include:
– the AI provider
– the personal data involved
– why you use the service
– your lawful basis
– relevant processors or recipients
– international transfers
– retention periods, and
– automated decision-making or profiling
The description should reflect the provider’s actual role. OpenAI should not automatically be labeled a subprocessor in every privacy policy.
Using AI tools to process personal data?
iubenda’s Privacy and Cookie Policy Generator lets you flag AI-powered services and add the relevant disclosures to your privacy policy.
6. Establish a lawful basis
A DPA does not provide your lawful basis for processing.
Your organization must identify an appropriate basis under Article 6 of the GDPR and, where special-category data is involved, a condition under Article 9.
7. Complete a DPIA where required
A Data Protection Impact Assessment may be necessary where the use of AI is likely to create a high risk to individuals.
This may include uses involving sensitive data, profiling, systematic monitoring, employment decisions or decisions with significant legal effects.
8. Prepare for data subject requests
You also need a process for handling GDPR data subject rights requests, including access, correction and deletion.
Consider where personal data is stored, whether it can be retrieved or deleted, and what assistance the provider offers.
9. Review outputs before acting on them
Generative AI can produce inaccurate information, including false statements about identifiable people.
Human review is particularly important where outputs could affect employment, credit, healthcare, education or legal rights.
10. Track the EU AI Act separately
GDPR and the AI Act are separate compliance tracks.
A business using ChatGPT internally may have different obligations from one building and selling an AI product on top of an OpenAI model. Your responsibilities depend on whether you act as a user, deployer or provider.
OpenAI GDPR compliance and its DPA
OpenAI’s Data Processing Addendum supplements its Services Agreement for business and developer services.
Where OpenAI processes customer data on behalf of a business, the DPA covers areas including:
- processing instructions
- security
- subprocessors
- international transfers
- assistance with data subject requests, and
- compliance information
The DPA also relies on transfer mechanisms such as the European Commission’s Standard Contractual Clauses where applicable.
Signing it does not provide your lawful basis, complete a DPIA, write your privacy notice or satisfy your separate AI Act obligations. Those responsibilities remain with your organization.
EU AI Act enforcement timeline
The EU AI Act adds another layer of rules for AI providers and deployers.
| Date | Obligation |
|---|---|
| August 1, 2024 | The AI Act enters into force |
| February 2, 2025 | Most prohibited AI practices and AI-literacy obligations begin to apply |
| August 2, 2025 | Obligations for general-purpose AI model providers begin to apply |
| August 2, 2026 | Enforcement powers over GPAI (General Purpose AI Models) providers and general transparency rules begin to apply |
| August 2, 2027 | Older GPAI models must comply with the GPAI rules |
| December 2, 2027 | Rules for certain high-risk AI systems begin to apply |
| August 2, 2028 | Rules for high-risk AI embedded in regulated products begin to apply |
The deadlines that matter depend on what your business does with the model.
Many obligations applying directly to general-purpose AI providers sit with OpenAI. However, businesses using or building on its models may still have responsibilities involving transparency, AI literacy, human oversight and risk management.
The 2026 AI Omnibus deferred some high-risk-system deadlines, but the August 2 transparency requirements still apply. Read our breakdown of what changed under the AI Omnibus.
FAQ
Is OpenAI GDPR compliant?
There is no single answer that applies to every OpenAI product and use case.
OpenAI provides an Irish establishment, a DPA and business data, retention and residency controls. However, these measures do not automatically make a customer’s use compliant.
Your organization must still assess the product, data, purpose, roles, lawful basis, transparency, retention and safeguards involved.
Can I use ChatGPT under GDPR?
Yes, provided you use it in a way that meets your own GDPR obligations.
For business activities involving personal data, ChatGPT Business or Enterprise will generally offer more appropriate contractual, administrative and data controls than a personal account.
You should also minimize the data entered, identify a lawful basis, provide appropriate privacy information and complete a DPIA where necessary.
Does OpenAI have a Data Processing Agreement for the EU?
Yes.
OpenAI’s DPA forms part of its Services Agreement for business and developer services. For EEA and Swiss customers, it is entered into with OpenAI Ireland Limited.
It covers processing instructions, security, subprocessors, international transfers, data subject requests and compliance information.
What does the EU AI Act mean for OpenAI users?
Many of the obligations applying directly to general-purpose AI model providers sit with OpenAI.
However, businesses using the models may have their own obligations as deployers. Companies that build, brand, or market their own systems on top of OpenAI models may also take on provider obligations.
The requirements depend on the organization’s role and the intended use of the system.
Where this leaves your business
OpenAI’s compliance position cannot be reduced to a badge or single statement.
Its DPA, Irish establishment and business controls give organizations useful tools for managing GDPR obligations. But businesses must still assess each use case and configure the service appropriately.
In practice, that means choosing the right product, limiting the personal data you send, putting the required terms in place, documenting your lawful basis, updating your privacy notice and preparing for data subject requests.
iubenda’s Privacy and Cookie Policy Generator helps you create and update the disclosures your privacy policy needs as the services used by your business change.
For the broader requirements, see our guide to GDPR compliance.
This article provides general information and does not constitute legal advice. The requirements that apply will depend on your organization’s role, use case, configuration, and jurisdiction.