ChatGPT consumer (chatgpt.com Free / Plus) — generally incompatible with regulated workloads
The consumer ChatGPT product at chatgpt.com is designed for individual users, not organizational data processing. The default settings include opt-in to training (OpenAI may use conversations to improve future model versions unless the user opts out via Settings → Data Controls). The consumer terms do not include an enterprise DPA, do not provide a contractual no-training warranty, and do not provide region residency.
For an organization considering using consumer ChatGPT in a regulated workflow (employees pasting customer data into ChatGPT.com, marketing teams using ChatGPT Plus to process EU resident contact lists, etc.), the answer is: generally do not do this for GDPR-covered processing.
The risk surface: every prompt is a potential GDPR violation if it contains personal data. Without a DPA, OpenAI is not contractually bound to GDPR processor obligations. Without a no-training warranty, the personal data could be incorporated into training datasets (the consumer opt-out mitigates this but is per-account and not a contractual flow-down to OpenAI's commitments).
The European Data Protection Board's ChatGPT taskforce report (2024) examined consumer ChatGPT specifically and flagged multiple GDPR-compliance gaps that have been partially addressed by OpenAI but remain a complicated picture. Most EU DPAs have publicly cautioned organizations against using consumer ChatGPT for processing personal data of EU residents.
Practical guidance: prohibit employees from using consumer ChatGPT for any organizational data processing involving EU resident personal data. Provide a workspace-scoped alternative (ChatGPT Team or Enterprise) for legitimate organizational AI use cases.