Why this lesson exists. When connecting the model to live customer data. That makes a question you might have been avoiding unavoidable: what does the AI provider do with what you give it? The whole answer turns on one distinction, and this lesson is about that distinction alone. The mechanics of switching settings come in Lesson 10.
By the end of this lesson you will be able to tell whether a given AI account is fit for work use, because you will have seen the difference play out and then judged three cases yourself.
This lesson is practical guidance, not legal advice. If you handle sensitive personal data at scale, involve a data-protection professional.
A freelance HR consultant does excellent work for a mid-sized employer. To speed things up, she uses her personal ChatGPT account, the free one she signed up for a year ago, to draft grievance-outcome letters. She pastes in the case notes: names, the allegations, the medical context behind one absence.
Nothing goes visibly wrong. But three things are true that she has not thought about. First, the free personal account uses conversations to train the provider's models unless she has switched that off, and she has not. Second, there is no contract between her and the provider that makes them responsible for handling that data lawfully; personal accounts do not come with one. Third, when the client's data-protection officer asks, as part of a routine supplier review, "do you use AI on our data, and under what terms?", she has no good answer. The client ends the engagement, politely, not because anything leaked but because she could not show it had not.
Six months later she has a £25-a-month business account. Same tool, same drafts. Now the answer to the DPO's question is: "Yes, [tool], business plan, data not used for training, covered by their data processing agreement, hosted in the EU." The engagement she lost would have been kept for the price of a nice lunch.
GDPR (and UK GDPR, which is essentially the same) is not about AI. It is about personal data: anything that identifies or relates to a living person. The moment you paste a customer's details into a chat tool, you are processing personal data through a third-party supplier, and the same rules apply as for any supplier: know what data goes where, what they do with it, and whether a contract covers it.
Every major AI provider sells two very different kinds of product, and this is where people go wrong.
Consumer products (ChatGPT Free, Plus and Pro; Claude Free, Pro and Max; the Gemini app on a personal Google account; Le Chat Free; Copilot on a personal Microsoft account) are for individuals. Several use your conversations to train their models by default, and you have to switch that off yourself (some don't even allow that on personal plans). They generally come with no data processing agreement (DPA), which is the contract that makes the provider legally responsible for handling your data properly.
Business products like ChatGPT Business and Enterprise; Claude for Work and the Anthropic API; Gemini in Google Workspace; Le Chat Team and Enterprise; Microsoft 365 Copilot; and the API versions of most of them, do not train on your data by default, do come with a DPA, and let an administrator control settings for the whole company. However, don't assume, always confirm this by looking at the plan details or for some providers like OpenAI require you to submit a request for this.
Which is why the rule is short: if you use AI for work, use a business account. The price difference is small when you consider the difference in your legal position. It's the difference between "we can show it is handled properly" and "we hope".
Two further habits sit alongside it, because the cheapest compliance is not sharing personal data at all. Strip names and identifying details from prompts unless the task needs them ("draft a reply to a customer unhappy about a late delivery" works without the customer's details). And never paste passwords, bank details or health information into any AI tool, on any plan.
Data leaving the UK or EU is permitted under specific arrangements, and the large US providers have those in place for their business products. For clients who are sensitive about this (public sector, education, healthcare, finance, anyone who sends supplier-security questionnaires), a provider headquartered in the EU removes the question entirely. Mistral, based in France, stores data in the EU by default, is subject to GDPR as its home law, and has a simple, documented opt-out. That does not make it automatically "more compliant" than a US provider with a proper DPA and EU residency, but it does make the conversation shorter, and its models are strong enough for most everyday business work.
It is worth noting that a US company providing EU residency in government and public offices in the EU is often seen as not true EU data residency. The reason is that in 2018, the US passed the CLOUD Act, which allows the US government to access any data hosted by US companies. This means that if the US government wanted to see your company or organisations private records, all they need to do is access it through one of the US companies you've shared that data with. Keep this in mind when deciding which provider to use, especially if you work with any public government office in the UK or EU.
##