Skip to content
GDPR6 min read

GDPR Article 28: Do You Need a DPA for ChatGPT? (2026)

A data processing agreement (DPA) is the written contract GDPR requires between a controller and any processor handling personal data on its behalf. Consumer AI tiers rarely give you one.

A

AIovert Security & Compliance Team

GDPR, EU AI Act & DORA practitioners writing on AI data protection for EU businesses.

Published 4 July 2026 · Last updated 4 July 2026

The short answer

If an AI vendor processes personal data on your behalf, GDPR Article 28 requires a written data processing agreement (DPA) that binds the processor to specific duties: processing only on your instructions, keeping data confidential and secure, and assisting with data-subject rights. Consumer AI tiers frequently do not offer a compliant DPA, so they are unsuitable for business processing of personal data. Enterprise and API tiers usually do provide one.

What does GDPR Article 28 actually require?

GDPR Article 28 requires the DPA to set out the subject matter, duration, nature and purpose of processing, the type of personal data and categories of data subjects, and the controller's rights. It must also impose the specific processor duties in Article 28(3), including sub-processor controls and deletion or return of data at the end of the service. Without a valid Article 28 agreement, using a tool to process personal data has no lawful footing for the controller–processor relationship.

Why don't consumer tiers meet it?

Consumer AI services are offered under standard terms that do not constitute an Article 28 DPA and may permit the provider to use inputs to improve the service, which is incompatible with processing personal data strictly on the controller's documented instructions. The exposure is not theoretical: according to Cyberhaven, 11% of the data employees paste into ChatGPT is confidential, much of it entered into consumer accounts with no processor agreement at all. That is why putting customer data into ChatGPT can be a GDPR breach.

How do you stay compliant without a DPA?

Because you cannot rely on a DPA for consumer tools, the safer path is to prevent personal data from being entered into them at all, and reserve personal-data workloads for tiers that provide a proper agreement. AIovert is an EU-based, on-device browser DLP tool that classifies and blocks sensitive data before it is entered into consumer AI tools such as ChatGPT, Claude and Gemini, so a missing DPA never becomes an unlawful disclosure. See how to make AI tools GDPR compliant for your company, when a DPIA is required for AI tools, the complete AI DLP guide, and the best GDPR DLP and AI data security tools.

Frequently asked questions

Do we need a DPA if we only use the free version of ChatGPT?

If you enter personal data, you need a compliant Article 28 DPA, and the free tier typically does not provide one. That is why entering personal data into consumer tiers is high-risk and often best blocked technically.

Is the AI vendor a processor or a controller?

Usually a processor when acting on your documented instructions, but this depends on the terms. Some providers may act as an independent controller for certain purposes (like service improvement), which changes your obligations and risk.

What if the vendor uses our data to train models?

Training on your inputs is generally incompatible with processing solely on the controller's instructions, unless specifically agreed and lawful. Business tiers that commit not to train on your data avoid this problem.

Primary sources

Regulatory dates and requirements can change. Verify against the official EU sources above before relying on them. This page is informational and not legal advice.

See AIovert live

Block personal data from reaching AI tools you have no DPA with, on-device, across ChatGPT, Claude and Gemini. Set up in ~15 minutes.