As of: 19 June 2026 · Reading time: 4 min
Key takeaways
- Artificial intelligence, especially in the form of advanced language models such as ChatGPT, revolutionizes the way companies work.
- From the automation of customer service ...
Artificial intelligence, especially in the form of advanced language models such as ChatGPT, revolutionizes the way companies work. From the automation of customer service ...
“Good software is not an accident—it comes from a structured development process with clear quality standards.”
– Björn Groenewold, Managing Director, Groenewold IT Solutions
ChatGPT and Data Protection: This is how the GDPR-compliant use in the company
Introduction: The growing importance of AI chatbots
Short: Executive answer: Artificial intelligence, especially in the form of advanced language models such as ChatGPT, revolutionizes the way companies work.
Executive answer: Artificial intelligence, especially in the form of advanced language models such as ChatGPT, revolutionizes the way companies work.
For ChatGPT and Data Protection: This enables GDPR-compliant use in the…, Data Analytics & Business Intelligence, Cost Calculator: AI Development, Discover solutions sowie AI & Machine Learning help you align implementation, scope and budget before you commit.
Artificial intelligence, especially in the form of advanced language models such as ChatGPT, revolutionizes the way companies work. From the automation of customer service to the creation of content to support in software development – the possibilities of use are diverse and promise considerable efficiency increases. However, with the growing enthusiasm for these technologies, critical issues are also focussed, especially on data protection. The legal implementation of AI solutions is a key challenge for companies within the scope of the General Data Protection Regulation (GDPR). The concern about data protection violations and the uncertain legal situation lead to restraint in many decision-makers.
The legal grey area: ChatGPT and the GDPR
Short: The use of ChatGPT in its standard configuration is in a voltage ratio to several core principles of the GDPR.
The use of ChatGPT in its standard configuration is in a voltage ratio to several core principles of the GDPR.
A main conflict point is the principle of data minimisation, which states that only the personal data necessary for the purpose of processing may be collected.
ChatGPT, on the other hand, has been trained and processed with huge amounts of data without the user having full control of which data is stored and used accurately.
The transparency obligations of the GDPR are also difficult to fulfill because the exact functioning of the algorithms and the data flows for the end user are hardly understandable.
OpenAI, the company behind ChatGPT, has responded to these concerns and now offers a data processing addendum (DPA).
This document is an important building block for GDPR compliance, but does not solve all problems.
In particular when using the free version of ChatGPT, conversations are used for training the model, which represents a processing of personal data for a purpose that is not clearly defined.
Risks when using ChatGPT in the company
Short: The unconsidered input of sensitive information represents the greatest risk.
The unconsidered input of sensitive information represents the greatest risk.
As soon as personal data from customers, employees or confidential business secrets are entered into the chat window, they will withdraw from the company's control.
This can have far-reaching consequences, from data protection violations with high fines to the loss of intellectual property.
Another, often overlooked risk arises from the fact that OpenAI is an American company and is therefore subject to laws such as the CLOUD Act.
Under certain circumstances, this allows US authorities to access data stored by US companies even if the servers are located in Europe.
Solutions for the Datansc
References and further reading
Short: The following independent references complement the topics in this article:
The following independent references complement the topics in this article:
- Bitkom – German digital industry association
- German Federal Office for Information Security (BSI)
- European Commission – Digital strategy
- MDN Web Docs (Mozilla)
- W3C – World Wide Web Consortium
"Mobile apps need clear offline and security models alongside UX—trust collapses without both."
— Björn Groenewold, Managing Director, Groenewold IT Solutions
Frequently Asked Questions (FAQ)
What is this article about: “ChatGPT and Data Protection: This enables GDPR-compliant use in the company”?
This post explores ChatGPT and Data Protection: This enables GDPR-compliant use in the company from the perspective of requirements, typical pitfalls, and sensible next steps.
In short: Artificial intelligence, especially in the form of advanced language models such as ChatGPT, revolutionizes the way companies work. From the automation of customer service ...
Who benefits most from the content described here?
Useful for project leads and product owners in Software development who must choose between standard software, custom development, and integration.
How does this topic fit into an IT or digital strategy?
Technically and organizationally, alignment with experienced partners pays off — from requirements to operations; start with the services overview. For multi-system landscapes, IT consulting and architecture helps align vendors and internal teams.
What are sensible next steps if we need support?
A practical next step: book a consultation and clarify which MVP or pilot fits your team and landscape.
About the author
Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Blog recommendations
Related articles
These posts might also interest you.

ERP introduction: Go-Live and follow-up
The introduction of a new ERP system (Enterprise Resource Planning) is a marathon, not a sprint. Many companies focus intensively on the selection and implementation of the software, ...

ERP introduction: Success measurement and continuous improvement
The introduction of a new ERP system is a decisive step for medium-sized companies to digitize and increase efficiency. But with the Go-Live the project hasn't been...

GDPR updates 2026: What has changed?
The year 2026 marks a turning point in European digital law. A number of new regulations enter into force or achieve decisive implementation phases. For companies, this means...
Free download
Checklist: 10 questions before software development
Key points before you start: budget, timeline, and requirements.
Get the checklist in a consultationRelevant next steps
Related services & solutions
Based on this article's topic, these pages are often the most useful next steps.
Related solutions
Cost calculators
More on Software development and next steps
This article is in the Software development topic. In our blog overview you will find all articles; under category Software development more posts on this subject.
For topics like Software development we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.
If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.

