Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant?

No tool is GDPR-compliant on its own; compliance depends on how you use it. What the business versions of all four offer is what compliance needs from a supplier: a data processing agreement, no training on your content by default, retention controls and, on some plans, control over where data is stored. The free and personal versions lack most of that.

So the useful question isn't "is ChatGPT GDPR-compliant?" but "can I use this plan of this tool in a way that meets my GDPR duties?" For business plans the answer is usually yes, provided you also do your part: a lawful basis, an honest privacy notice, sensible retention, a risk assessment for high-risk uses, and staff who use company accounts. For personal plans used with clients' data, the answer is usually no, however good the vendor's security. If you have customers in the EU, or otherwise fall under the GDPR, the comparison below shows what each vendor contributes and what's left to you.

Follow me on Instagram@sagnikteaches

Why "GDPR-compliant" isn't a feature you can buy

The GDPR places most duties on the controller, which is you: deciding why data is used, telling people about it, keeping it no longer than needed, and answering their requests. A supplier can help by acting as your processor under a contract, keeping data secure and not using it for its own purposes. It can't make your use lawful for you.

Connect on LinkedInSagnik Bhattacharya

That's why a "GDPR compliant" badge on a vendor's website proves less than it seems. A pharmacy owner might read that claim on an AI vendor's homepage and relax, while a locum drafts patient letters in a personal free account the badge has nothing to do with. The badge describes the vendor's business product under its business contract. What matters is which plan your staff are actually using, under which terms, for which data. The eight GDPR steps for a small business using AI sets out your side of the arrangement.

Subscribe on YouTube@codingliquids

The four side by side, on what a business needs

Everything below comes from each vendor's own trust, legal and help pages as of September 2026, and applies to their business plans unless stated.

ChatGPT (OpenAI)Claude (Anthropic)Gemini (Google Workspace)Copilot (Microsoft)
Data processing agreementFor Business, Enterprise and the APIBuilt into the Commercial Terms, with standard contractual clausesCloud Data Processing AddendumProducts and Services Data Protection Addendum
Training on your contentNot by default on business plansNot by default on commercial plansNot outside your domain without permission; not reviewed by peoplePrompts, responses and organisational data not used to train foundation models
Personal plansTraining on until switched off; no DPATraining is a sign-up choice; no DPAKeep Activity and human review on personal accountsConsumer app has training settings and personalised ads
Retention controlsAdmin-set on Enterprise and Edu; deleted chats removed within 30 daysCustom retention on Enterprise, 30-day minimumGemini app chats auto-deleted after 3, 18 or 36 months (18 by default)Retention policies through Microsoft Purview
Where data livesData residency for eligible Enterprise, Edu and API customers; storage-region choice for new Business workspacesNo EU processing option listed for its APIData regions for storage from Business Standard; in-region processing on Enterprise PlusAn EU Data Boundary service for EU customers, with exceptions
Certifications mentionedSOC 2 Type 2, ISO/IEC 27001, 27017, 27018, 27701SOC 2 Type II, ISO 27001, ISO/IEC 42001SOC 1/2/3, ISO 27001, 27701, 27017, 27018, 42001 and othersISO 27001, ISO 42001 and others

On paper the four are closer than their marketing suggests. The differences that matter in practice are in the fine print on where data lives, and in what falls outside each vendor's commitments.

ChatGPT: good defaults on Business, residency mainly above it

OpenAI will execute a DPA for ChatGPT Business, ChatGPT Enterprise and the API, and business data isn't used for training by default. Its business products have been through independent SOC 2 Type 2 examination. On personal plans, "Improve the model for everyone" under Data Controls is on by default for Free, Plus and Pro, and there's no DPA.

Where data lives is more nuanced. Eligible Enterprise, Edu and API customers can choose data residency, keeping content stored at rest in a chosen region, and eligible Enterprise and Edu customers can add inference residency, so processing happens in-region too. ChatGPT Business now lets you pick a storage region at checkout, but OpenAI's help page is clear that this covers storage, not where requests are processed, and that a copy of prompts and responses is kept in OpenAI's primary region for a limited time for abuse monitoring. For most small businesses that's acceptable with the DPA's transfer terms; if a client contract demands processing in a particular place, it isn't. How ChatGPT's plans differ on client data covers the training side in more detail.

Claude: strong defaults, fewer residency options

Anthropic's DPA, including standard contractual clauses for transfers, is automatically part of its Commercial Terms, so accepting those terms for Claude Team, Enterprise or the API means accepting the DPA. Its privacy centre is explicit that consumer products such as Claude Free and Pro aren't covered. Commercial content isn't used for training by default, and deleted chats leave Anthropic's back-end storage within 30 days. Enterprise owners can set custom retention, with a 30-day minimum. Anthropic holds SOC 2 Type II, ISO 27001 and ISO/IEC 42001 certification, the last being the AI management system standard.

The gap is location. Anthropic's data residency documentation for its API lists a global default and a single regional option, and that option isn't in the EU. Its documentation doesn't describe an EU processing option for the Claude apps either, so ask Anthropic directly if you need one. For most small businesses using Claude Team under the DPA that's workable; for those whose clients require processing in the EU, it's a deciding factor. One more detail matters for API users: since June 2026, prompts and outputs on Anthropic's most capable models are kept for 30 days even for zero-data-retention customers, although Anthropic added a route to apply for zero retention again in September 2026.

Gemini: the answer depends on your Workspace edition

In Google Workspace, Gemini and Gemini Notebook fall under the Cloud Data Processing Addendum. Google's privacy hub for Workspace says your content isn't used for any other customers, isn't reviewed by people, and isn't used to train generative AI models outside your domain without permission, and that the Gemini app's chats and uploaded files get the same protection. Admins can set Gemini app conversations to auto-delete after 3, 18 or 36 months; the default is 18. Google lists a long run of certifications for Gemini, including ISO/IEC 42001.

Location depends on edition. Data regions for storage at rest, with an EU option, are available from Business Standard upwards but not on Business Starter. In-region processing, and data regions for the Gemini app itself, need Enterprise Plus or Frontline Plus. A small business on Business Standard can therefore keep stored Workspace data in the EU while Gemini processes requests elsewhere, under the addendum's transfer terms. Personal Google accounts are a different world: with Keep Activity on, chats can be read by human reviewers and kept for up to three years. Whether Gemini is safe for confidential business data looks at Workspace in more depth.

Copilot: the EU Data Boundary, with two carve-outs

Microsoft covers Copilot and Copilot Chat, used by organisations, under its Data Protection Addendum and Product Terms, acting as processor. Prompts, responses and data accessed through Microsoft Graph aren't used to train foundation models, and Microsoft says Copilot services have opted out of the human-review abuse monitoring available elsewhere in Azure. Admins can apply Purview retention policies, and users can delete their own Copilot activity history.

For EU customers, Microsoft describes Copilot as an EU Data Boundary service, with EU traffic kept within the boundary. There are two exceptions to know. Models provided by Anthropic, which Copilot can use as a subprocessor, are currently excluded from the EU Data Boundary. And web searches Copilot sends to Bing sit outside both the boundary and the DPA, with Microsoft acting as an independent controller for them. Microsoft publishes the details on its enterprise data protection page. The practical rules: check whether your admin has enabled Anthropic models, and keep client names out of questions that need the web. Whether Microsoft 365 Copilot keeps business data private covers the settings.

Transfers outside the EU, in plain terms

All four vendors may process some data outside the EU, which is why "where data lives" gets so much attention. The GDPR doesn't forbid that. It requires a safeguard for the transfer, most commonly standard contractual clauses: model contract terms that bind the recipient to protect the data. For AI vendors, those safeguards sit in the DPA, not on the marketing page. Anthropic's privacy centre, for instance, states that its DPA incorporates standard contractual clauses, and Microsoft's EU Data Boundary is designed to keep EU customers' data in the EU in the first place.

What you need to do is modest: keep a copy of each DPA, know which transfer mechanism it relies on, and mention in your privacy notice that providers may process data outside the EU with appropriate safeguards. If a particular client insists on EU-only processing, or you process sensitive data at scale, take the transfer question to your data-protection adviser before choosing a tool.

A worked choice for a hearing-aid shop

A hearing-aid shop with two branches and seven staff, in this illustrative case, runs Google Workspace Business Standard, at about $14 a user a month on an annual plan. Some customers live in the EU, and the shop holds audiology records, which are health data. The owner compares three routes for everyday admin (emails, rotas, supplier queries):

OptionExtra monthly costData termsLocation
Gemini in WorkspaceNone: included in Business StandardCloud Data Processing Addendum; no training outside the domainStored data can be kept in the EU; processing may happen elsewhere
ChatGPT Business, 7 seats$175 monthly or $140 billed annuallyDPA; no training by defaultStorage region chosen at checkout; processing not covered
Claude Team, 7 seats$175 monthly or $140 billed annuallyDPA in the Commercial Terms; no training by defaultNo EU processing option

The shop chooses Gemini in Workspace: it costs nothing extra, sits under the contract the shop already has with Google, and lets stored data stay in the EU. Two rules come with it: audiology records never go into any general AI assistant, and staff use only their Workspace accounts, never personal Google or ChatGPT logins. If the shop later wants AI to work with the audiology records themselves, that use gets a risk assessment first; whether you need a DPIA before using AI tools explains how to run one.

The gap no vendor can close: staff on personal accounts

Every protection in the comparison table disappears the moment someone uses a personal account. The gap can be wider than owners expect. In one illustrative case, a six-person osteopathy clinic asks each member of staff, without blame, which AI tools they've used for work in the past month. The answers: two use ChatGPT Free, one uses Claude Free, one uses the Gemini app on a personal Google account, and two use nothing. Three of the four users admit they've pasted patient letters or appointment notes at some point to "tidy the wording".

None of those accounts had a DPA, and on at least two of them training was switched on. The clinic's fix took a week: it chose one business tool (Gemini, because the clinic already ran Workspace), switched it on for everyone's work account, asked staff to delete work chats from personal accounts and switch training off there, and added one line to the staff rules: patient information goes only into the approved work tool, and only when the task genuinely needs it. The cost was nothing extra. The awkward conversation took ten minutes, and it mattered more than any vendor's certificate.

Five questions that decide compliance for your business

  1. Which suite do you already run? If it's Microsoft 365 or Google Workspace, the assistant inside it is usually the path of least contractual effort, because it sits under an agreement you already have.
  2. Does any client contract specify where data must be stored or processed? If so, compare the "where data lives" row carefully, and ask the vendor in writing.
  3. Will health or other special-category data be involved? Then plan choice is the start, not the end: expect a DPIA and adviser input.
  4. How many people will use it? ChatGPT Business and Claude Team need at least two seats, which changes the sums for a sole trader.
  5. What are staff using today? If the honest answer includes personal accounts, fixing that matters more than which vendor you pick.

What stays with you, whichever tool you choose

Even with the best business plan and a signed DPA, these remain your responsibility: a lawful basis for each use, a privacy notice that mentions AI tools, retention that matches your needs, a DPIA where a use is high-risk, a process for access and deletion requests that includes AI chats, and staff who know what may be pasted where. The vendors' certifications, such as SOC 2 and ISO 27001, are good evidence about their security; what SOC 2 and ISO 27001 actually tell you explains how to read them. They're evidence for choosing a supplier, not a substitute for your own compliance.

The short version: all four are capable of being used in a GDPR-compliant way on their business plans, none of them is compliant in a staff member's personal account, and the decision between them usually comes down to the suite you run and where your clients need their data to live.

Further reads

Sources: OpenAI's enterprise privacy and business data pages and help centre on data residency, storage and data controls; Anthropic's privacy centre (DPA, retention), consumer terms update, certifications page and data residency documentation; Google's Generative AI in Google Workspace Privacy Hub, data regions help and Gemini app data regions announcement; Microsoft Learn on enterprise data protection and data, privacy and security for Microsoft Copilot (all checked September 2026). General information, not legal advice.

Want help choosing an AI tool your GDPR duties can live with?

On a 1:1 call we'll look at the suite you run, the personal data your team handles and your clients' expectations, and pick the tool, plan and settings that fit.

Book a 1:1 call with me