Rules & risk
Läs på svenska →Is it legal to use ChatGPT with customer data? GDPR and the EU AI Act in 2026
BY FARSHAD · CLEARFORM · 4 MIN READ · UPDATED 2026-08-28
In short
Yes, with conditions. Using AI on personal data is lawful under GDPR if you have a legal basis, a data processing agreement with the provider, and controls on what staff paste in. Since 2 August 2026 the EU AI Act also requires you to tell people when they are talking to AI or seeing AI-generated content.
Two separate rulebooks, often confused
GDPR governs the personal data going into and out of the tool. The EU AI Act governs the AI system itself — what it may be used for and what you must disclose. A business can be perfectly GDPR-compliant and still breach the AI Act, and vice versa. They need answering separately.
| QUESTION | WHICH RULEBOOK | WHAT IT DEMANDS |
|---|---|---|
| Can I paste a customer's details into this tool? | GDPR | Legal basis, data processing agreement, minimisation |
| Must I tell visitors the chat is a bot? | EU AI Act, Art. 50 | Yes — disclosure, in force since 2 Aug 2026 |
| Can I use AI to screen job applicants? | Both | High-risk category; obligations deferred to Dec 2027, but GDPR applies now |
| Must I label AI-generated images and text? | EU AI Act, Art. 50 | Synthetic content must be marked as such |
What GDPR questions must you answer before using AI?
The practical failure mode in small businesses is almost never the contract — it's an employee pasting a customer list into a free consumer account at 16:45 on a Friday. Policy without a sanctioned, easy alternative just moves the behaviour into the shadows.
- Legal basis: usually legitimate interest for internal productivity, consent where the output affects the individual
- Processor agreement: a DPA with the AI provider, on a business or enterprise plan — consumer tiers generally don't offer one
- Training opt-out: confirm in writing that your inputs are not used to train the model
- Location: where processing happens, and which transfer mechanism covers it if outside the EU/EEA
- Minimisation: strip names, personal ID numbers and contact details unless they're genuinely needed for the task
- Retention: how long prompts are stored by the provider, and whether you can delete them
What changed on 2 August 2026?
The EU AI Act's general application date and its Article 50 transparency duties took effect on 2 August 2026, and were not postponed. In practice, for a normal SME this means two things: anyone interacting with your chatbot must be able to tell it's a machine, and AI-generated or AI-manipulated content must be marked as such.
Separately, an omnibus amendment adopted in July 2026 deferred the obligations for stand-alone high-risk systems — recruitment, credit scoring, education, critical infrastructure — to 2 December 2027, and for AI inside already-regulated products to August 2028. That's breathing room for the high-risk categories, not a general delay. Prohibited practices, AI literacy duties and transparency all remain in force on the original schedule.
A workable policy for a company without a legal department
- Pick one sanctioned tool on a business plan with a DPA and training opt-out, and pay for it
- Write a one-page rule: what may be pasted, what may never be, who to ask when unsure
- Never paste personal ID numbers, health data, or anything about a named private individual
- Keep a short list of where AI is used in the business — you'll need it for any due diligence anyway
- Label the chatbot and any AI-generated content publicly
- A human signs off on anything that affects a person's money, job or care
Frequently asked questions
01Can I use the free version of ChatGPT for work?
For non-personal data — drafting generic text, brainstorming, explaining a concept — it's usually fine. For anything containing customer or employee data, you need a plan that offers a data processing agreement, which the free tier generally doesn't.
02Do I have to tell customers I use AI?
You must tell them when they're interacting with an AI system rather than a person, and label synthetic content — that's Article 50, in force since 2 August 2026. You don't have to announce every internal use of AI, though your privacy notice should reflect how personal data is processed.
03Does an AI chatbot on my website make me high-risk?
Normally no. A customer-service chatbot is a transparency-obligation system, not a high-risk one. High-risk covers uses like hiring decisions, credit scoring and education access, where obligations now start in December 2027.
04What are the penalties?
The AI Act's penalty tiers run into the tens of millions of euros or a percentage of global turnover for the most serious breaches, and GDPR fines sit alongside them. For a small business the realistic risk is a complaint and a supervisory inquiry — which is still expensive in time and reputation.
05Is this legal advice?
No. This is a practical summary to help you ask the right questions. For anything consequential — automated decisions about people, health or financial data — get it reviewed by a lawyer.
Get a free read on where AI fits — and where it shouldn't
Start freeSOURCES: SOFTWARE IMPROVEMENT GROUP — EU AI ACT SUMMARY, AUGUST 2026 UPDATE · DATAGUARD — EU AI ACT COMPLIANCE TIMELINE
Keep reading