ChatGPT in business has stopped being a novelty and become a daily tool in law firms, marketing departments and back offices. The tool is not the problem. The problem is that it gets adopted without anyone deciding first what may be typed into it and what may not — and in a company that processes personal data, that decision is not an internal preference. It is an obligation you have to be able to evidence.
In this article we will discuss...
What changed in 2026
Regulation (EU) 2024/1689, the AI Act, entered into force on 1 August 2024 but applies in stages. Prohibited practices and AI literacy obligations have been enforceable since 2 February 2025. General-purpose AI model obligations since 2 August 2025. The general regime and the transparency duties of Article 50 since 2 August 2026.
One important qualification before you plan anything: the digital omnibus on AI, Regulation (EU) 2026/1744, adopted on 8 July 2026 and in force since 27 July, has pushed back the timetable for high-risk systems. Annex III systems move to 2 December 2027 and Annex I systems to 2 August 2028. Transparency stays in 2026, with a grace period for marking AI-generated content that ends on 2 December 2026.
In other words: whoever operates a high-risk AI system has gained some room. Whoever simply uses ChatGPT to draft, summarise or analyse has gained nothing. That use is governed by the GDPR, and the GDPR has applied since 2018.
What the Spanish authority says
The Spanish Data Protection Agency has published unusually practical material. Alongside its guidance on bringing AI-based processing into line with the GDPR and its requirements for auditing such processing, in November 2025 it published its own internal AI use policy — the first in the Spanish public sector. It is useful precisely because it does not theorise: it shows what a real usage policy looks like.
In January 2026 it published a ten-point checklist under the title Be careful what you confide: do not enter identifying, health, financial or contractual data; do not upload images of third parties or of minors; follow your organisation’s internal policy; and do not share employee or client data. In February 2026 it added guidance on agentic AI insisting on three things — allocate controller and processor roles properly, run a data protection impact assessment where the risk requires it, and keep meaningful human oversight.
The European position: a model is not anonymous by default
On 17 December 2024 the European Data Protection Board adopted Opinion 28/2024 on AI models and personal data. Three points are worth keeping.
- A model trained on personal data cannot be presumed anonymous. It must be assessed case by case, and both direct extraction and retrieval through queries must be shown to be insignificant possibilities.
- Legitimate interest can serve as a legal basis, but it requires the three-step test and a genuine balancing exercise that accounts for the scale of processing, the opacity of the model and people’s reasonable expectations.
- If the model was trained on unlawfully processed data and still retains personal data, the organisation deploying it must verify that point as part of its own accountability.
What regulators have already done
The Italian authority fined OpenAI 15 million euros in December 2024 for the absence of a legal basis for training, transparency failures, no age verification and failure to notify a breach. The Court of Rome annulled the fine in March 2026 on jurisdictional grounds between authorities, not on the substance. In May 2025 the same authority fined the company behind Replika 5 million euros, and in January 2025 it blocked DeepSeek in Italy.
The lesson for a company is straightforward: enforcement is currently aimed at providers, but the criteria applied to providers are the same ones that will be applied to you when the complaint comes from an employee or a client.
What you need signed and checked
In practice, the difference between using ChatGPT well or badly comes down almost entirely to the plan you contracted and the paperwork behind it.
- Data processing agreement. Business plans allow you to sign the Article 28 GDPR agreement. Free and personal accounts are not designed for that.
- Training on your data. On business plans and the API, business data is not used for training by default. On free and individual paid accounts the starting configuration is usually the opposite and has to be switched off manually.
- Retention. It varies by plan, from customer-controlled retention to conversations deleted after thirty days. Know the period of the plan you actually use, not the one you assume you use.
- International transfers. Identify where data is hosted and processed, and under what safeguard it travels.
- Sub-processors. Know who they are and what authorisation regime applies.
The five recurring mistakes
- Pasting client, employee or candidate data into a free personal account.
- Uploading contracts or internal files without having checked the retention regime.
- Using the model’s output in a decision affecting a person without real human oversight.
- Not disclosing in the privacy policy that AI tools are used in the processing.
- Having no written internal policy, so every employee decides for themselves what to share.
The fourth and fifth are the expensive ones, because they turn occasional use into undocumented systematic processing.
Where to start
Inventory which AI tools are genuinely in use, who uses them and under which account. A short, workable internal usage policy. An update to the record of processing activities and to the privacy policy. A processing agreement with the provider. And an impact assessment where the processing calls for one.
That sequence is exactly the work we do at Auratech Legal within new technology and advertising law: reviewing the contract with the AI provider, drafting the internal usage policy and putting on paper who answers for what.
