Am I Allowed to Enter Customer Data into ChatGPT?
The short answer: in free ChatGPT, no. With a business account and the right agreements in place, yes, under certain conditions. And in the vast majority of cases, it's the wrong question to begin with.
Why it's the wrong question is coming up. First, here's what you need to know.
What actually counts as customer data
The GDPR talks about personal data. That's any information that can be used to identify a person. That includes the name, the address, the email address, the phone number. But it also includes the customer number, if you can match it to a person. And the combination of profession, place of residence, and age, if it's specific enough.
As soon as data like that goes into an AI tool, you're processing it. And every processing activity needs a legal basis, plus the recipient has to handle the data securely.
The problem with the free account
If you use ChatGPT for free, your inputs go to servers in the US. They can be used to train the model. You don't have a contract with OpenAI that regulates what happens to the data.
Legally, that means you're missing what's called a data processing agreement, the written agreement stating that a service provider processes data on your behalf and according to your instructions. Without one, that provider's processing of personal data is legally vulnerable to challenge.
This isn't a theoretical worry. Data protection authorities have already reviewed AI services, and in Italy, ChatGPT was temporarily blocked in 2023. What matters for you as a business: a violation can result in a fine, and a customer who finds out about it has a legitimate problem with it.
What's different with a business account
OpenAI, Anthropic, Google, and Microsoft all offer business accounts. There, as a rule: your inputs aren't used for training, there's a data processing agreement in place, and in some cases you can set processing to take place within the EU.
Microsoft Copilot goes furthest in this regard, because it can run within Microsoft 365 with an EU Data Boundary. DeepL is a German provider with servers in the EU. Both are the more convenient routes for businesses.
But even with a business account, you still need: an entry in your record of processing activities, information given to your employees, and a check on whether the specific processing is even necessary.
Why it's usually the wrong question
And now for the actual point. In nine out of ten cases where someone wants to enter customer data into an AI, the AI doesn't actually need that data at all.
You want to draft a reply to a complaint email? The AI doesn't need to know that the customer is Mr. Bernhard Grasegger from 42 Lindwurm Street. It needs to know: a customer is complaining about a late delivery, you want to apologize and offer to refund the shipping costs.
Instead of: "Reply to the complaint from Bernhard Grasegger, 42 Lindwurm Street, customer number 88421 …", better: "Reply to a customer's complaint about a delivery that's two weeks late. I want to refund the shipping costs. Tone: understanding, but businesslike."
The result is identical. You copy the text, fill in the name and salutation, done. The difference: in the second case, no personal data ever left your computer.
This technique is called anonymization with placeholders. It's the single most important trick for working with AI, and the reason why in most cases you don't need a data processing agreement at all.
The rule of thumb for everyday use
Before every input, ask yourself: could someone use this information to identify which person it's about?
- Name, address, phone number, email address: take it out, replace with [Name], [Address].
- Health data, banking details, ID numbers: these must never go into an AI tool, under any circumstances.
- Customer numbers and invoice numbers: take them out, they can be traced back to a person.
- The situation itself, what happened, what you want to achieve: harmless.
If you follow this rule, you can use AI in almost every everyday situation without having to worry.
When you need a contract anyway
There are cases where personal data can't be avoided. You want to have a hundred customer inquiries automatically categorized. You want to pre-sort job applications. You want to extract appointments from emails.
In that case, you need a business account with a data processing agreement, an entry in your record of processing activities, and an honest assessment of whether the benefit justifies the risk. For job applications and health data, the answer will often be "no."
What businesses should concretely do
- Decide which AI tools are allowed in your business, and write it down.
- Inform all employees about the placeholder rule. One page is enough.
- Turn off training on your data in the tools' settings, wherever that's possible.
- Add an entry to your record of processing activities as soon as you use AI for business purposes.
- Check every AI output before it goes out. A human stays responsible.
And if something has already happened?
If you've accidentally entered customer data in the past: no reason to panic, but a reason to act. In most tools, you can delete individual conversations and turn off storage in the settings.
A single incident is not a reportable data breach. Systematically entering customer data over months is more likely to be one. When in doubt, talk to a data protection officer, the call is cheaper than the fine.
This article offers general, easy-to-understand orientation, but it is not legal advice. For specific questions about processing personal data in your business, please consult a qualified advisor or your data protection officer.
Want to go deeper?
Our guide "AI Starter Kit with GDPR Guide" gives you ready-made templates to copy, usable right away.
See the guide →