Keywordsgdpr and chatgpt at workBlogai for workai at workworkplace aiai for professionalshow to use ai at workai productivity
Related searchesgdpr chatgpt at workis chatgpt gdpr compliantpersonal data in chatgptchatgpt lawful basisgdpr ai at workgdpr and chatgpt at work
A chat box is still processing, and GDPR still applies
GDPR still applies when you use ChatGPT. Personal data, purpose, and a lawful basis do not disappear because the interface is a chat box. If a customer name, a staff file, or a thread that identifies someone goes into the model, you are processing personal data. The vendor's product page does not take that off your books. Helpful is not a legal basis. Someone named in your organisation still has to say what the purpose is, whether the data may leave that system, and what you will tell a data subject if they ask. This essay is practice for teams, not counsel.
If you cannot name the personal data, the purpose, and the lawful basis, do not paste. You are still hoping a chat box is outside the regulation.
Four GDPR questions the chat box does not answer for you
Is it personal data. A name plus a complaint usually is. A ticket number linked to a person often is. Anonymous is a high bar. What is the purpose. Rewriting a reply is one purpose. Building a secret staff profile is another. What is the lawful basis. Legitimate interests is not a shrug. Who is the processor, and is there a contract. Public ChatGPT and an enterprise workspace are different facts. Give the team a one-page map: data, purpose, tool, basis, owner. Counsel or the DPO still own the hard cases. A fluent privacy paragraph is not an assessment.
| Question | If yes | What you do |
|---|---|---|
| Is a person identifiable | Treat it as personal data | Approved tool or do not paste |
| Do we have a purpose | Write it in one sentence | No purpose, no paste |
| Is there a contract for this tool | Check the workspace, not the logo | If no, do not send personal data |
| Could a person ask us what we did | You must be able to say | Log the use or do not do it |
Decide the processing before you open the chat
Write the purpose first, on paper if you have to. Name the data. If it identifies someone, stop and check the approved tool list. If the tool is public ChatGPT and the data is personal, most small teams should not paste. Rebuild with synthetic details when you only need structure. When the organisation has an enterprise workspace, a contract, and a recorded purpose, stay inside that workspace and still minimise. Keep a saved brief for a processing note: data, purpose, tool, basis, owner. GDPR work is a habit of stopping. A stable note is how that habit survives a customer waiting on a reply.
Role: You are helping me write a short processing note I will keep on file.
Task: Turn the facts I state into a note: data, purpose, tool, basis, owner.
Context: I will describe the artefact and the ChatGPT workspace I planned to use.
Constraints:
- Do not invent a lawful basis, a contract, or a regulator position I did not state.
- If a fact is missing, write [missing] instead of guessing.
- Do not ask me to paste the personal data in order to write the note.
Output: A one-page note plus a recommendation: approved workspace, synthetic example, or do not use a model.
Quality checks: Which lines a DPO would say are still a hope rather than a basis.If the note shows [missing] on basis or contract, you have already been saved a bad paste. Those gaps are the point of the prompt. Save the processing note in a shared place so the next rewrite does not skip the question. Keep the version a DPO could read, and retire the habit of calling it internal because the reply was only a rewrite. A written basis beats a hopeful paste.
Special category creep, vendor confusion, and a rights request you cannot answer
Special category creep is the expensive failure. Health, trade union, and similar data need more than a casual legitimate-interests story. A support thread can contain them without a label. Vendor confusion is next: assuming ChatGPT is compliant because a blog said so, without knowing which product, which region, and which contract you actually have. The third failure is a rights request. If a person asks what you did with their data, a pile of unsigned chats is not an answer. Fluency in the reply you sent them does not document the processing. You still need a purpose, a tool you can name, and a person who will speak to counsel. The chat box will not attend that meeting.
| Mistake | What it looks like | What to do instead |
|---|---|---|
| It is just a rewrite | Personal thread in public chat | Purpose, class, approved tool |
| Anonymous enough | Real case, swapped first name | Synthetic, or do not paste |
| Vendor said compliant | A logo instead of a contract | Which product, which DPA |
| No record | Chats nobody can find | A note you can show a DPO |
A nicer customer reply is not worth undocumented processing. If the basis and the tool are unclear, type the reply yourself in the source system.
Related reading on StudyGrid
Read next: What Not to Paste into ChatGPT Workplace AI Policy for Small Teams Risk, Security and Governance. Those essays sit beside this one. Use them when you need the neighbouring skill, not as a substitute for the check you still have to make.
What to do this week
Take three ChatGPT uses from this week. For each, write data, purpose, tool, and basis, or write do not paste. Move personal data out of public chat before the next rewrite. Ask counsel only where the note still has [missing], not as a substitute for stopping. Share the note with the person who owns privacy. That is how GDPR and ChatGPT at work stay a practice, not a slogan on a vendor page.