Is ChatGPT GDPR-safe? What Danish companies must do
21 July 2026

Is ChatGPT GDPR-safe for business use? Here are the three requirements you have to meet, what the AI Act demands from August 2026 — and what was postponed.
Short answer: free ChatGPT and ChatGPT Plus are generally not lawful for personal data in a Danish company, because there is no data processing agreement in place and because the content can be used to train the model. The business products that do come with a data processing agreement and don't train on your data — ChatGPT Enterprise and Team, Claude for Work, Gemini in Google Workspace and the corresponding APIs — can be used lawfully, but only if you have your own house in order on legal basis, contracts and documentation. The tool does not do that part for you.
That distinction is what settles the question in practice. Below: the three requirements, the new AI Act timeline, and what to actually do on Monday morning.
The three requirements
1. A legal basis for the processing. You have to be able to point to why you may process the data at all — usually legitimate interest or performance of a contract. "We wanted to try AI" is not a legal basis. If special-category data is involved, such as health information, the bar rises sharply.
2. A data processing agreement with the vendor. The moment you send personal data into an AI tool, the vendor is a processor. Without an agreement the processing is unlawful — and this is exactly where the consumer tiers fail. The agreement also has to cover transfers outside the EU/EEA if the model runs there.
3. Your data must not be used for training. Business products switch training off by default; consumer products do not. Verify it in the contract, not in the marketing material, and write down what you verified.
On top of those come the usual GDPR duties: data minimisation (send only what the task requires), informing data subjects, keeping a record of processing activities, and a data protection impact assessment where the processing is risky.
The cheapest risk reduction there is: keep personal data out of the prompt where you can. A case note without a name and a civil registration number is often just as useful to the model — and a completely different legal starting point.
What does the AI Act require from August 2026?
The picture changed during 2026, and a fair amount of the guidance still online is out of date.
Applies from 2 August 2026: the transparency obligations in Article 50 of the AI Act. Among other things, people must be told when they are talking to an AI system rather than a human; AI-generated audio, image and video must be machine-readably marked as synthetic; and deepfakes must be disclosed as such. Breaches can cost up to EUR 15 million or 3% of global turnover. If you run a customer-facing chatbot that doesn't clearly say it is one, start there.
Postponed: the high-risk requirements. Under the Digital Omnibus package, given final approval by the Council in late June 2026, the deadline for standalone high-risk systems under Annex III — recruitment, creditworthiness, education, access to essential services and similar — moved from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moved to 2 August 2028.
The delay is not a pause. It buys room for the documentation, but systems that will be high-risk still are — and GDPR applies unchanged in the meantime.
What is the Danish DPA looking at?
Datatilsynet, the Danish data protection authority, has flagged artificial intelligence and automated decision-making as a supervisory priority for 2026, focusing on transparency, data minimisation and lawfulness. Datatilsynet and the Danish Agency for Digital Government also run a regulatory sandbox for AI where companies and public bodies can get free guidance on GDPR and risk classification under the AI Act. If you're building something close to the high-risk line, that's an obvious place to start.
What to do in practice
- Map what's already in use. You have staff using AI today. Ask before you ban — a prohibition without a lawful alternative just moves the usage out of sight.
- Give them one approved tool. A business subscription with a data processing agreement costs less than the first inspection case.
- Write a short, readable policy. One page: what may go in, what may not, who to ask. Ten pages won't be read.
- Document as you go. Record of processing, legal basis, data processing agreement, and an impact assessment where relevant. That takes hours if you do it along the way — and weeks if you do it afterwards.
At Indee we build solutions on your own server, so data stays with you, and where we use an external model it runs through EU-hosted endpoints under a data processing agreement. The documentation for your record of processing ships with the solution, not as an invoice afterwards. It's the same approach we use in Validi, which handles health data every day.
Frequently asked questions
Can we use free ChatGPT for work?
For tasks with no personal data and no confidential company information: yes. For anything else: generally no. The free tier and Plus lack a data processing agreement, and the content can be used to train the model. If staff need AI on real work data, you need a business product with a data processing agreement and training switched off.
Is choosing a European AI vendor enough?
No. EU hosting settles the transfer question, but not legal basis, data minimisation, transparency or documentation. Conversely, a US vendor can be used lawfully if the contractual and transfer basis are in place. Location is one criterion among several — not a free pass.
Will our AI solution count as a high-risk system?
Only if it's used in one of the areas the AI Act singles out — including recruitment, creditworthiness, education, law enforcement and access to essential services. An internal assistant that drafts text for a human to approve is normally not high-risk. If you're unsure, risk classification is one of the first things we settle in a workshop — and it costs nothing to consider too early.
Need to get AI and GDPR straight before you build further? Book a no-obligation conversation with Indee — or see what an engagement costs in our breakdown of AI implementation prices.