AI & Legislation
Using ChatGPT safely at work: GDPR, data breaches and what's allowed
Published:

Key Takeaways: Your employees are probably already using ChatGPT, often through a private account and without any agreements in place. That delivers productivity, but also real GDPR and data breach risk: personal data and trade secrets ending up in a consumer tool you have no control over. The solution is not to ban it (that pushes usage under the radar), but to facilitate it: a secure business version, clear agreements about what is and isn't allowed, and an explanation for your team. This article sets out the risks, gives a concrete "allowed/not allowed" list, and shows how to set up business AI use in a GDPR-compliant way.
The real risk: shadow AI
The biggest risk is not ChatGPT itself, but shadow AI: employees using AI tools without you knowing about it or having arranged anything. A salesperson pastes a customer list into ChatGPT to draft a mailing. An HR employee has a termination letter drawn up with real names in it. A developer pastes company code to get a bug fixed. Each one understandable, and each one a potential data breach.
With the free and consumer versions, the data you enter can be retained and used for model improvement by default. You have then handed personal data or trade secrets to a third party without a data processing agreement, without control over the retention period, and without knowing where the data ends up. Under the GDPR that is a problem, and under the EU AI Act transparency and documentation obligations are added on top.
What may and may not go into an AI tool?
The practical rule of thumb: would you pin it to a public notice board? If not, then it doesn't belong in a consumer version without data protection agreements.
Don't do (without a business version + agreements):
- Personal data of customers or employees: names combined with contact details, social security numbers, medical or financial data.
- Trade secrets: non-public strategy, pricing models, contract details.
- Source code or confidential technical documentation.
- Anything covered by a confidentiality obligation.
Perfectly fine (also in a consumer version):
- General questions, brainstorms, explanations and summaries of public information.
- Rewriting or translating text without personal data or confidential content.
- Code snippets that contain no trade secrets or credentials.
The difference isn't that "AI is dangerous", but which data you put into it and which version you use.
The tool choice makes the difference
Whether business AI use is safe depends heavily on which version you use.
A business version (ChatGPT Enterprise or Team, or Microsoft Copilot in your M365 environment) does not use your data for model training by default, offers a data processing agreement and stricter retention and security arrangements. The same applies to the API with the right settings, on which you can build your own applications. Want even more control, for example because you work with sensitive data, then a privately hosted, privacy-friendly model is an option.
The free consumer version is fine for harmless use, but it is not the place for company or customer data. The most common mistake among SMEs is that the whole company uses the free version for work where it doesn't belong. A comparison of the options can be found in ChatGPT vs Claude vs Copilot for businesses and Microsoft Copilot for SMEs.
Banning doesn't work, facilitating does
The reflex to ban AI is understandable but counterproductive. A ban does not stop usage; it moves it to private accounts and private phones, out of your sight and out of your control. That increases the risk rather than reducing it.
The approach that works has three parts. One: give your team a secure business version, so they don't have to resort to unsafe tools. Two: draw up a clear, short AI usage policy that says in plain language what is and isn't allowed. Three: give a short explanation, so employees understand the rules instead of ignoring them. This is also exactly what the AI literacy obligation from the EU AI Act asks of you, and for which SLIM subsidy is available.
How to set it up safely
Start with a short inventory: who currently uses which AI tools, and for what? The answer is often a shock. Then choose one secure business version as the standard, lay down the allowed/not-allowed rules in a one-page policy, and give the team half an hour of explanation. Evaluate after a few months and adjust. That way you turn shadow AI into controlled, productive AI, without putting the brakes on.
Stratalytic helps you arrange it safely
We help you make AI use both productive and GDPR-compliant:
- AI scan: we map out which AI tools are currently in use and where the risks lie.
- Secure setup: choosing and setting up the right business version or a privately hosted, privacy-friendly arrangement.
- Policy: a workable AI usage policy plus an explanation for your team, compliant with the EU AI Act.
- Subsidy: training often falls under SLIM; we process that along with it.
Schedule a 30-min intro call and we'll look at how safe your current AI use is.
Frequently asked questions
Am I allowed to use ChatGPT for business under the GDPR? Yes, but with conditions. No personal data or confidential information in a consumer version without agreements. With a business version and a clear policy, it can be GDPR-compliant.
What should I not put into ChatGPT? No personal data, trade secrets, source code or contract details in a consumer version without data protection agreements. Rule of thumb: would you pin it to a public notice board?
Is my data used to train the model? With free/consumer versions, yes by default, unless switched off. With business versions and the API with the right settings, no.
Should I ban ChatGPT at work? No, banning pushes usage under the radar. Facilitate a secure version with a clear policy and explanation.
Get the AI-subsidy radar
1 email per month. New subsidies, deadlines, and what changed for SMEs. 5-minute read.
Unsubscribe with one click. No spam, ever.
Keep reading
Related articles

AI & Legislation
Writing an AI usage policy for your company (with template)
An AI usage policy is no longer a luxury since the EU AI Act took effect, it is a requirement. This article shows what belongs in a workable policy, gives a ready-to-use template, and explains how to keep it alive instead of letting it gather dust in a drawer.
Read more →

AI & Machine Learning
Running your own AI model: open source LLMs for privacy and control
For companies with sensitive data, sending everything to a cloud AI is not always desirable. Open source language models that you run yourself offer privacy and control, but also their own costs and management. This article explains when running your own LLM is smart and when cloud AI is enough.
Read more →

AI & Legislation
AI literacy is now mandatory: how Dutch SMEs can use the SLIM subsidy to comply
The EU AI Act requires AI literacy by August 2026. The Dutch SLIM subsidy covers up to 60% of training costs. Here is what your business needs to know.
Read more →
Let's talk business
Do you want to know how we can help you grow your business? Schedule free consultation with one of our experts and discover the possibilities.


