Can I upload client data to ChatGPT? What GDPR actually says
The short answer. Usually not as-is. The moment a document contains client personal data, uploading it to ChatGPT is processing under GDPR. You remain responsible, even on a paid plan. It is only allowed if you have a legal basis, apply data minimisation and can account for the processing. The practical route: remove or replace all identifying data first. Then you are no longer uploading client data, you are uploading a safe document. That takes under a minute with ShareSafe.ai.
Why this is not a formality
Three reasons "just quickly into ChatGPT" becomes your problem, not OpenAI's:
- You are the controller. Your client gave their data to you, not to an American AI company. When something leaks or someone complains, the regulator looks at you.
- Data minimisation is a hard requirement. Article 5 GDPR: process no more data than necessary. For a summary or analysis, ChatGPT does not need the real names and amounts. Sending them is by definition more than necessary.
- Your professional duty or contract may be stricter than GDPR. Many advisory agreements, NDAs and professional rules prohibit sharing client information with third parties. An AI vendor is a third party.
"But I have ChatGPT Team, so OpenAI doesn't train on my data"
True, and that matters. But not training is a different subject than not sending. On a Team plan you still transmit the raw client data to OpenAI's servers. Your client's question is not "was it trained on?" but "why was my data there at all?". Minimising what you send answers both. More on this: [ChatGPT Team and confidential documents].
When is it allowed?
A quick decision line:
- No personal data in the document? Then GDPR does not apply and you are bound only by your contracts.
- Personal data, but pseudonymised and you hold the key? Then nothing directly identifiable reaches the AI vendor and you satisfy minimisation. This is the workable route for daily use.
- Raw personal data with explicit consent and a processor arrangement? Legally possible, practically heavy: consent must be specific and revocable, and you must be able to account for the whole chain.
The middle route is the right one for almost every advisory practice. Not because a lawyer says so, but because it is the only route that is both fast and explainable.
The safe route
- Drop the client document into ShareSafe.ai. No account, EU processing, nothing kept after the run.
- Review what was detected: names, companies, amounts, IBANs and addresses become consistent placeholders.
- Download the safe file and your Identity Key. The safe file goes to ChatGPT; the key translates the answer back. The key never leaves your control.
FAQ
- Is pseudonymisation enough for GDPR?
- Pseudonymisation is a safeguard recognised by GDPR itself (Article 4(5) and Article 32). While you hold the key it remains personal data processing on your side, but what you send to the AI vendor no longer contains directly identifying data. That is exactly what minimisation asks for.
- Should this go into my processing register?
- If you process client documents with AI structurally: yes, record the workflow. A fixed, documented route with pseudonymisation is easy to describe there.
- Does this apply to Claude, Gemini and Copilot too?
- Yes. GDPR looks at what you send, not at which brand receives it. The safe route is the same for every AI.
- My client says it's fine. Allowed then?
- Client approval helps, but minimisation still applies, and a company's approval does not automatically cover the individuals in the document (employees, counterparties). Making it safe remains the stronger route.
ShareSafe.ai is part of VaultLM. Raw files stay in the EU. Minimal retention. You hold the key. Try it with your own document →