Customer data in AI assistants: what's allowed, what's not

Parts of the AI Act already apply, the GDPR in full. What to fix before customer data goes into ChatGPT, Claude or Gemini, and why your subscription matters.

GDPR
AI Act
privacy
ChatGPT
Claude
By the AI Focus team · 7 min read
Share:

At a glance

  • The AI Act partially applies already: since 2 August 2026 a chatbot must disclose it is AI.
  • The GDPR applies in full; the announced relaxation was never voted through.
  • Consumer accounts of ChatGPT, Claude and Gemini may train on your chats; business accounts don't by default.
  • Our take: the real pitfall isn't Brussels, it's which account you use.
Customer data in AI assistants: what's allowed, what's not
In this article

Customer data in AI assistants: what’s allowed, what’s not

“The AI Act has been postponed,” you read everywhere this summer, so AI and privacy start to feel like a problem for later. That is only half true: the postponed part does not affect most SMEs, and the rules that do affect you simply apply. More important still, the biggest risk is not in the law but in the kind of account your people use for ChatGPT, Claude or Gemini. Anyone pasting customer data into a chatbot from a free or personal account already has a problem today. Get the business setup right, and you are free to use AI.

”The AI Act has been postponed” is only half true

On 24 July 2026, the so-called Digital Omnibus on AI appeared in the Official Journal as Regulation (EU) 2026/1744, in force since 27 July 2026. It shifts a sizeable chunk of the AI Act: standalone high-risk systems, such as AI used for recruitment and selection, were due to comply by 2 August 2026 and now get until 2 December 2027; AI embedded in regulated products gets until 2 August 2028. The deadline for watermarking synthetic media also moved, to 2 December 2026, but only for systems that were already on the market before 2 August 2026. Launch something new today and you are bound by it immediately.

Look instead at what did not move. According to the official implementation timeline (updated 31 August 2026), the prohibited practices and the AI literacy obligation, the duty to give your staff a basic understanding of AI, have applied since 2 February 2025. The rules for makers of general-purpose AI models have applied since 2 August 2025, and the Article 50 transparency obligations since 2 August 2026: a chatbot must make clear that you are talking to AI, and AI-generated content must be recognisable as AI-generated. If your website runs a chatbot, that applies today, delay or no delay.

And the GDPR itself? The part of the wider omnibus that was meant to relax it never got voted through; the GDPR applies in full.

The real trap is your account

In practice, the AI Act is rarely where things go wrong. They go wrong with what happens to the text you type in. And that is decided not in Brussels but by your subscription. The three big providers draw a strikingly similar line: personal accounts may train on your chats, business accounts do not by default.

ProviderPersonal accountBusiness account
ChatGPTMay train on your chats; opt out via “Improve the model for everyone”Business, Enterprise and API: no training by default
ClaudeYou choose; opted in: kept for 5 years, opted out: 30 daysTeam, Enterprise and API: no training by default
GeminiWith “Keep Activity” on: possible training and human review, reviewed chats kept up to 3 yearsWorkspace: no training without permission

All sources are the providers themselves, checked on 6 September 2026. OpenAI writes about consumer accounts, verbatim: “we may use your content to train our models”. At Anthropic, since the policy change of 28 August 2025, you choose whether your chats become training material; allow it and the retention period is five years, switch it off and it is thirty days. Team, Enterprise and the API stay out of training by default. And Google itself warns free Gemini users not to enter confidential information: with “Keep Activity” on, chats can be used to improve models and some can be read by human reviewers; once reviewed, they are kept for up to three years, even if you delete them. For Google Workspace, the rule is different again: no model training on customer data without permission.

The honest counterargument: you can switch off training on a personal account too, and a careful user does. True, but that leaves three problems unsolved. A personal account gives you no data processing agreement, the contract that Article 28 of the GDPR requires with any party processing personal data on your behalf. On Gemini, chats seen by reviewers stay on file for up to three years regardless. And above all: you cannot possibly check that every employee has unticked that box, and anyone working from a personal account falls under the consumer regime anyway, not under the business guarantees your company pays for.

Which assistant suits you best on substance is a question we dug into in our comparison of ChatGPT, Claude and Gemini; for privacy the answer is duller: the right subscription matters more than the right model.

What the GDPR requires regardless

As soon as personal data, meaning any information about an identifiable person, heads towards an AI service, the familiar rules kick in; you can read them at gdpr-info.eu. Beyond the Article 28 data processing agreement, Article 35 requires a data protection impact assessment (DPIA), a risk analysis up front, whenever the processing is likely to involve a high risk, such as systematic profiling. Article 22 gives people the right not to be subject to a fully automated decision with significant effects; if you let AI take such decisions, a human must be able to intervene. And a data breach that poses a risk to data subjects must be reported to the supervisory authority within 72 hours under Article 33.

In Belgium, that supervisory authority is the Data Protection Authority, which maintains a theme page and brochures on AI and the GDPR. At European level, the EDPB, the umbrella body of Europe’s privacy regulators, adopted guidelines on web scraping for generative AI on 7 July 2026. Their line: consent is unworkable at that scale, and legitimate interest, subject to a strict test, becomes the main route. The public consultation runs until 30 October 2026.

Where your data sits, and what to sort out tomorrow

With the right subscription in place, one question remains: where does your data physically sit? OpenAI has offered European data residency since 5 February 2025 for the API and new Enterprise and Edu workspaces, and since 16 January 2026, for certain customers, inference residency too, meaning the processing itself also happens in Europe. Google Workspace lets you choose a European storage region on most business plans. Anthropic lags behind: its own privacy page has stated, since the update of 15 June 2026, rather drily, “Note that data is stored in the US”, and European hosting is listed on the compliance page as “Coming 2026”. If you build on Claude, for instance because the API got a lot cheaper for agent work with Fable 5.1, that belongs in your risk assessment.

In concrete terms: put your people on a business subscription or the API, with a data processing agreement, and agree in writing that personal accounts are not for client work. Check whether profiling means you need a DPIA, keep a human in the loop for decisions that really matter, and know that a data breach has to be reported within 72 hours. This is context, not legal advice: for a specific case, the Belgian DPA’s page is a starting point and a specialist the next stop. The core message stands: the law does not forbid you from putting AI on client work, it forbids you from doing it sloppily. And the difference is usually not a lawyer, but a subscription.

Stay on top of AI trends

Get the latest insights on AI in business every week, with exclusive case studies and practical implementation tips.

No spam. Unsubscribe anytime. Privacy guaranteed.