AI and Data Protection: What Employees Must Know About ChatGPT & Co.

As soon as you enter personal data into ChatGPT, Copilot or Gemini, that is a completely normal processing operation under the GDPR (Art. 4(2)), the same rules apply as everywhere else: a legal basis under Art. 6 and the principles from Art. 5. The most important everyday rule: no real personal data in unapproved, free AI tools without a data processing agreement. The safe approach is to anonymize names and identifiers before entering them.
From the Provimedia editorial team · As of July 2026 · This article is general information and not legal advice.
Is a ChatGPT Prompt a "Processing Operation" Under the GDPR?
Yes. Art. 4(2) GDPR defines processing very broadly: any handling of personal data, with or without automated means. A prompt containing a customer's name or a customer number falls under this, regardless of how short or informal it seems. As with any other processing, it therefore requires a legal basis under Art. 6(1) GDPR and compliance with the principles under Art. 5(1). In addition, for many AI services: inputs are transmitted to the provider's servers, often outside the EU, and at some services may be reused to train the model.
The Most Important Rule: No Personal Data in Unapproved AI Tools
Names, contact details, application documents, personnel files or customer lists do not belong in free AI tools that have not been approved by your company. The reason: without approval, there is usually no data processing agreement under Art. 28 GDPR with the provider, and without a DPA, a service provider must not be entrusted with real personal data. That applies to AI services just as much as to any other cloud provider (more on this in our article DPA / data processing agreement).
The Safe Approach: Anonymize Before Entering Data
You still want to use an AI tool for a task with real data? Replace identifying information with neutral placeholders before entering it: "Complaint from Ms. Meier, customer no. 4711" becomes "Complaint from customer A", and specific locations and company names become "Location X" and "Company B". An AI does not need real names to draft a text or provide a summary, data minimization (Art. 5(1) GDPR) and AI use are not mutually exclusive.
When AI Decides About People: Art. 22 GDPR
It becomes especially sensitive when AI systems prepare or make decisions about people, for example in an automated pre-selection of job applicants or a creditworthiness assessment. Under Art. 22(1) GDPR, a decision based solely on automated processing that has a legal or similarly significant effect is only permissible as an exception. A human must have the ability to review the outcome and intervene. In practice, this means: AI may support the process, for example by pre-sorting applications, but responsibility and the final decision remain with a human.
Security and Impact Assessment for AI Systems
AI systems are subject to the same security requirements as any other processing: appropriate technical and organizational measures, proportionate to the risk (Art. 32(1) GDPR). Where there is likely to be a high risk to the rights and freedoms of people, for example with extensive processing or novel technology, a data protection impact assessment (DPIA) is often required (Art. 35(1) GDPR). As an individual employee, you do not need to carry out a DPIA yourself, but you should report new AI projects to your data protection officer early on.
AI Literacy Is an Additional Requirement, Under a Different Law
Alongside the GDPR, a further, independent requirement has applied since February 2, 2025: Art. 4 of the EU AI Act (Regulation (EU) 2024/1689) obliges providers and deployers of AI systems to ensure sufficient AI literacy among their staff. According to the European Commission, a certificate is explicitly not required for this, an internal record of the training is sufficient. Data protection and AI literacy are two different legal bases with a different focus: the GDPR regulates which data you may entrust to an AI, the EU AI Act regulates how competently you handle AI systems in general.
Frequently Asked Questions (FAQ)
Am I Allowed to Enter Customer Data Into ChatGPT?
Only if the tool has been approved by your company and a data processing agreement exists with the provider. In all other cases, you should anonymize names and identifiers beforehand.
Can the Free Version of ChatGPT Be Used in a GDPR Compliant Way?
For anonymized texts without any personal reference, this is generally unproblematic. For real customer or employee data, the free, private use version generally lacks the necessary data processing agreement.
Do I Need a DPA With the AI Provider?
Yes, as soon as the AI service processes personal data on your behalf (Art. 28 GDPR), exactly as with any other external service provider that has data access.
What Does the EU AI Act Have to Do With Data Protection?
The EU AI Act (Art. 4) requires, in addition to the GDPR, sufficient AI literacy among staff in handling AI systems. Both frameworks apply in parallel and complement each other, but do not replace one another.
Do you want to systematically build competent, data protection aware handling of AI within your team? Our AI certificate covers AI fundamentals and the AI literacy requirement from Art. 4 of the EU AI Act, the in depth GDPR fundamentals training covers data protection, both together are available in the compliance package. You can read how to demonstrate accountability overall in our article accountability under the GDPR.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 4(2), Art. 5(1), Art. 6(1), Art. 22(1), Art. 28, Art. 32(1), Art. 35(1): eur-lex.europa.eu
- Regulation (EU) 2024/1689 (EU AI Act), Art. 4: eur-lex.europa.eu
- European Commission, AI Literacy: Questions & Answers: digital-strategy.ec.europa.eu
Share this article
Stay up to date
Get the latest articles, insights and industry updates straight to your inbox.
Decide for yourself what Google shows you
Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.
Add provimedia.de to my preferred sourcesRelated articles
More articles you might find interesting.
Phishing and Social Engineering: How Your Employees Can Spot an Attack
Phishing, spear phishing, CEO fraud, and smishing target people, not systems. The warning signs a phishing employee training should teach, and why a successful attack quickly turns into a reportable data breach.
GDPR Fines: Real Cases from Germany and What Companies Can Learn from Them
Four real GDPR fine cases from Germany show how authorities calculate the amount, and that courts can also significantly reduce them afterward.
Information Security Training vs. GDPR Training: What Companies Actually Need
Information security protects systems and information, data protection protects people and their data. The difference, the overlap under Art. 32 GDPR, and what the new NIS2 training duty means for management boards.
Bereit für den dokumentierten Schulungsnachweis?
Die DSGVO-Grundlagenschulung für Ihr Team – online, in rund 90 Minuten, mit datiertem Teilnahmezertifikat je Person.