ChatGPT
OpenAI OpCo, LLC
Short answer
Short answer: ChatGPT is safe for work on the Team or Enterprise tier (no training on your data by default, a DPA, SSO). On the Free or Plus tier, treat it as an uncontrolled consumer tool — don't put client, candidate or personal data into it without a policy and redaction in place.
At a glance
- Vendor / legal entity
- OpenAI OpCo, LLC
- Headquarters
- 🇺🇸 San Francisco, US
- Category
- LLM / Chat
- Ownership / jurisdiction
- US company (San Francisco); a capped-profit entity controlled by the OpenAI non-profit.
- Trains on your data?
- On by default — opt-out available
- Data hosting & residency
- Processed primarily in the US. Eligible business customers can store content at rest in Europe; there is no consumer EU-residency option.
- Sub-processors
- Sub-processor list and DPA are published on the OpenAI Trust Portal (trust.openai.com).
- Enterprise tier
- ChatGPT Team, Enterprise, Edu and the API exclude your inputs from training by default and add SSO/SAML and a DPA — the Free and Plus consumer tiers do not.
- Certifications
- SOC 2 Type 2 · ISO/IEC 27001:2022 · ISO/IEC 42001:2023 · CSA STAR · DPA available
- Pricing model
- Freemium: Free, Plus/Pro subscriptions, and per-seat Team/Enterprise; usage-based API.
Why this rating
The consumer tiers (Free/Plus/Pro) train on your conversations by default — you must opt out — and there is no consumer DPA, which is the classic shadow-AI exposure. That is offset by a strong governed path: ChatGPT Team/Enterprise and the API exclude training by default, offer a DPA, EU data-at-rest, and a broad certification set (SOC 2, ISO 27001/42001, CSA STAR). Medium: safe on the business tiers, risky on the consumer ones.
What it is
ChatGPT is OpenAI's chat interface to the GPT models, offered in consumer (Free/Plus/Pro), business (Team/Enterprise/Edu) and developer API tiers. The governance question is the tier: on the consumer tiers, conversations are used to improve models unless you opt out in Data Controls, and there is no signed DPA — so pasting client, candidate or regulated data there is the classic shadow-AI exposure. Team, Enterprise and the API change that materially.
Known incidents & regulatory actions
Italy's Garante temporarily blocked ChatGPT over GDPR concerns (no legal basis for training, no age check); access was restored ~4 weeks later, and in 2024 the Garante fined OpenAI €15M.
2023–2024 · Sources
Legal & compliance examples
How the same tool can be a safe helper or a high-risk deployment — the difference is what it decides about a person. Examples authored with Qadar AI's governance findings.
Don't: Screen candidate CVs and auto-reject applicants, or infer a candidate's emotions in a video interview.
Fine: Draft a job description, summarise public market research, or brainstorm interview topics — with no automated decision about a person.
These examples are general information, not legal advice, and are pending a legal review. Your obligations depend on your exact use, tools, and set-up.
Frequently asked questions
Does ChatGPT train on your data?
On the Free and Plus tiers, yes by default — you can opt out under Settings › Data Controls. On Team, Enterprise, Edu and the API, your inputs are not used to train models by default.
Is ChatGPT GDPR-compliant?
Enterprise/API with a signed DPA and EU data-at-rest can be operated GDPR-compliantly; the consumer tiers without a DPA and with US processing are hard to justify for personal data. GDPR compliance is your responsibility as controller, not a property of the tool.
Is ChatGPT high-risk under the EU AI Act?
ChatGPT is a general-purpose AI system — its risk class depends on how you use it. Using it to evaluate, rank or decide about people (e.g. screening candidates) is high-risk under Annex III; drafting and research are not.
How do I allow or block ChatGPT at work?
With Qadar AI Shield you can discover who uses ChatGPT, redact personal data before it reaches the tool, and allow-list or block it per group — without blanket-banning a tool your team relies on.
Sources
Every fact and the risk rating on this page trace to a primary source — the vendor's own trust center, privacy policy, DPA, or a regulator. Verify current terms before relying on them.
Govern this tool
Qadar AI Shield turns these risk facts into enforcement — discover who uses the tool, redact personal data before it reaches it, and allow-list or block it per team.
Risk levels are Qadar AI's curated assessment from cited primary sources — a curated assessment, not a certification, and not legal advice. Verify a tool's current terms before relying on them.