We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies to improve it. You can change your choice anytime. Privacy Policy

  • Security
  • Pricing
Book a scoping call
All AI tools
ChatGPT

ChatGPT

OpenAI OpCo, LLC

Medium riskLLM / ChatHow we rate

Short answer

Short answer: ChatGPT is safe for work on the Team or Enterprise tier (no training on your data by default, a DPA, SSO). On the Free or Plus tier, treat it as an uncontrolled consumer tool — don't put client, candidate or personal data into it without a policy and redaction in place.

At a glance

Vendor / legal entity
OpenAI OpCo, LLC
Headquarters
🇺🇸 San Francisco, US
Category
LLM / Chat
Ownership / jurisdiction
US company (San Francisco); a capped-profit entity controlled by the OpenAI non-profit.
Trains on your data?
On by default — opt-out available
Data hosting & residency
Processed primarily in the US. Eligible business customers can store content at rest in Europe; there is no consumer EU-residency option.
Sub-processors
Sub-processor list and DPA are published on the OpenAI Trust Portal (trust.openai.com).
Enterprise tier
ChatGPT Team, Enterprise, Edu and the API exclude your inputs from training by default and add SSO/SAML and a DPA — the Free and Plus consumer tiers do not.
Certifications
SOC 2 Type 2 · ISO/IEC 27001:2022 · ISO/IEC 42001:2023 · CSA STAR · DPA available
Pricing model
Freemium: Free, Plus/Pro subscriptions, and per-seat Team/Enterprise; usage-based API.

Why this rating

Medium risk

The consumer tiers (Free/Plus/Pro) train on your conversations by default — you must opt out — and there is no consumer DPA, which is the classic shadow-AI exposure. That is offset by a strong governed path: ChatGPT Team/Enterprise and the API exclude training by default, offer a DPA, EU data-at-rest, and a broad certification set (SOC 2, ISO 27001/42001, CSA STAR). Medium: safe on the business tiers, risky on the consumer ones.

How we rate

What it is

ChatGPT is OpenAI's chat interface to the GPT models, offered in consumer (Free/Plus/Pro), business (Team/Enterprise/Edu) and developer API tiers. The governance question is the tier: on the consumer tiers, conversations are used to improve models unless you opt out in Data Controls, and there is no signed DPA — so pasting client, candidate or regulated data there is the classic shadow-AI exposure. Team, Enterprise and the API change that materially.

Known incidents & regulatory actions

  • Italy's Garante temporarily blocked ChatGPT over GDPR concerns (no legal basis for training, no age check); access was restored ~4 weeks later, and in 2024 the Garante fined OpenAI €15M.

    2023–2024 · Sources

Legal & compliance examples

How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.

High riskEU AI Act — Annex III(4) high-risk · Art. 5(1)(f) prohibited

Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.

Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.

These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.

Check your EU AI Act risk class →

Frequently asked questions

Does ChatGPT train on your data?

On the Free and Plus tiers, yes by default — you can opt out under Settings › Data Controls. On Team, Enterprise, Edu and the API, your inputs are not used to train models by default.

Is ChatGPT GDPR-compliant?

Enterprise/API with a signed DPA and EU data-at-rest can be operated GDPR-compliantly; the consumer tiers without a DPA and with US processing are hard to justify for personal data. GDPR compliance is your responsibility as controller, not a property of the tool.

Is ChatGPT high-risk under the EU AI Act?

ChatGPT is a general-purpose AI system — its risk class depends on how you use it. Using it to evaluate, rank or decide about people (e.g. screening candidates) is high-risk under Annex III; drafting and research are not.

How do I allow or block ChatGPT at work?

With Qadar AI Shield you can discover who uses ChatGPT, redact personal data before it reaches the tool, and allow-list or block it per group — without blanket-banning a tool your team relies on.

Sources

Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.

  • •Enterprise/API no-training, DPA, certifications
  • •Business data not used for training
  • •Consumer training & opt-out (Data Controls)
  • •EU data residency for business
  • •Italy Garante action (incident)

Govern this tool

Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.

Book a demoSee how Shield Web governs AI

Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.

Subscribe to our newsletter

Product and governance updates — see our privacy policy.

AI security and control for every model your team uses.

Built in Dubai. Designed for teams operating across regions, models, and regulatory environments.

  • Product

    • Shield Web
    • Shield Control
    • Shield Desktop
    • Shield Mobile
    • Pricing
    • Download
  • Solutions

    • For CISOs
    • For Operations
    • For AI Teams
  • Use Cases

    • AI Governance
    • AI Agent Security
    • LLM Access Control
    • Secure AI Deployment
    • Enterprise Operations
    • Financial Services
    • HR & Recruiting
  • Resources

    • Help Center
    • Blog
    • Guides
    • Glossary
    • Changelog
    • Compare
    • FAQ
  • Company

    • About
    • Careers
    • Security & Trust
    • Contact
  • Tools

    • Disclose
    • AI Risk Calculator
    • EU AI Act Checker

© 2026 Qadar AI. All rights reserved.

  • ·Legal
  • ·Privacy
  • ·Terms
  • ·Partner Terms
  • ·GDPR / DPA
  • ·