Bring-your-own-AI is a GDPR problem first
Somewhere in your company today, someone pasted work into an AI account you don’t control. Not maliciously — the personal account was already open, and the enterprise one has a login. If that paste contained personal data — a customer complaint, a candidate’s CV, a colleague’s performance notes — your organization just processed personal data through a vendor with which it has no agreement, no retention control, and no oversight. The EU AI Act applies without prejudice to the GDPR: whatever your AI Act posture, this is a GDPR problem, and it is yours.
What a personal account actually does with the data
Take OpenAI as the worked example, from their own enterprise privacy documentation — the pattern is similar at other vendors, and worth checking per vendor.
On personal ChatGPT accounts, conversations are used to train models by default — users control this “within settings”, which means your data protection posture depends on a checkbox in an employee’s private account. Deleted chats are scheduled for permanent deletion within 30 days — “unless we are required to retain it for legal or security reasons”. And a personal account is exactly that: personal. OpenAI executes Data Processing Addenda for business products and the API — there is no DPA between your company and the vendor covering what your employee pastes into their private account. Under Article 28 GDPR, processing personal data through a processor without a contract is not a paperwork gap — it’s processing without a lawful setup.
“Deleted” met a court order
If that sounds theoretical, 2025 provided the concrete case. In the New York Times’ copyright lawsuit against OpenAI, a US court in May 2025 ordered OpenAI to preserve consumer ChatGPT and API output data — including chats users had deleted. In OpenAI’s own words, the order covered ChatGPT Free, Plus, Pro, and Team subscriptions and API use without a zero-data-retention agreement. ChatGPT Enterprise was clarified as excluded on 27 May 2025; Edu and zero-data-retention API customers were also out of scope.
The order’s obligations ended on 26 September 2025 — but OpenAI still securely stores user data from the April–September 2025 window, under legal hold, accessible to a small audited legal and security team, because the plaintiffs continue to demand it. European conversations were not exempt while the order ran; OpenAI notes it is “no longer” required to retain EEA conversations going forward.
Read that back slowly: for four months, whether a European employee’s deleted prompts sat in a US litigation hold was decided by which subscription tier they happened to be on. No security failure, no breach — just civil procedure meeting retained logs.
“Not trained on your data” is not “not processed”
The standard fix — “roll out an enterprise account” — is right, and incomplete. Business tiers genuinely change the deal: no training on your data by default, admin-controlled retention, an executable DPA. But look at what remains, again per OpenAI’s own documentation: prompts are still processed and stored (deleted conversations purge within 30 days, “unless we are legally required to retain them”); business data runs through automated classifiers; and access by “authorized employees” and “specialized third-party contractors” is reserved for engineering support, abuse review, and legal compliance.
None of that is scandalous — it is what operating a service looks like. But it means an enterprise rollout is where your GDPR work starts, not ends: execute the DPA, configure retention, assess the transfer, decide which data classes may enter at all. And if anyone waves away model risk with “it’s anonymized”, the EDPB’s Opinion 28/2024 sets a deliberately high bar for calling an AI model anonymous.
The tier table
The 2025 preservation order, mapped against OpenAI’s account types:
| Account | Trains on your content by default | Deleted-chat handling | DPA available | Covered by the 2025 order |
|---|---|---|---|---|
| Personal (Free/Plus/Pro) | Yes, unless the user opts out | Purged within 30 days unless legal/security retention | No | Yes |
| Team (now Business) | No | Purged within 30 days unless legally required | Yes | Yes |
| Enterprise / Edu | No | Admin-set retention; purge within 30 days of deletion unless legally required | Yes | No |
| API (standard) | No | Logs removed after up to 30 days unless legally required | Yes | Yes, without ZDR |
| API (zero data retention) | No | Not logged | Yes | No |
One column decided everything. Your employees choose their column every morning.
Why this is a literacy problem, not just a procurement one
You can buy the right tier and still lose: no filter reads judgment, and the data that matters most — the customer story, the colleague situation, the unreleased plan — is exactly what people paste when they want the model’s help. The durable control is people who know which data goes into which tier, and why. That is what the AI Act’s literacy obligation looks like in practice (what Article 4 asks after the 2026 amendments), and it is simultaneously a GDPR organizational measure — one program serving both regulations. From August 2026, it is also what national authorities supervise.
Our readiness program teaches exactly these decisions per role — what your support team, HR, and engineers may paste where, under your policy, with evidence you can show when someone asks. Book a walkthrough and bring your AI usage policy — or the draft of one.
Ulern builds readiness and evidence. This post explains the risk in plain terms — it is not legal advice, and vendor policies summarized here should be checked against the linked originals.