ChatGPT Business (the plan formerly called ChatGPT Team) can be used in a GDPR-compliant way for many everyday tasks, but only under conditions the plan itself does not enforce: OpenAI excludes Business workspace data from model training by default and offers a data processing agreement, yet EU data residency is not available on this tier, the seat floor is two users, and everything a data protection officer actually checks, from the legal basis to the ban on personal data in prompts, is your job, not OpenAI's. This article walks through the exact checks a German or Austrian DSB applies, where Business passes, where it fails, and which alternatives close the gap without a 150-seat enterprise contract.
The context is the same everywhere: about 42% of German companies know or assume that employees use private AI accounts, while only 26% provide an official one, according to Bitkom. A Business workspace is the cheapest way to replace private accounts with company accounts, which is precisely what the Hamburg data protection commissioner asks for. It is the sensible first step. It is not the finish line.
ChatGPT Free, Plus, Business and Enterprise: what each tier does for data protection
The tiers differ less in model quality than in who controls the data. Free and Plus are consumer contracts: your inputs may be used for training unless every single user opts out, there is no data processing agreement and no admin. Business is the first tier that behaves like a business contract. Enterprise adds the pieces regulated buyers need, at a seat floor most mid-sized companies cannot meet. Prices and minimums below are as reported in 2026; OpenAI does not publish Enterprise terms, and Business pricing was cut in April 2026, so check the current page before you sign.
| Criterion | Free / Plus | Business (ex-Team) | Enterprise |
|---|---|---|---|
| Training on your data | Yes by default, per-user opt-out in settings | Excluded by default | Excluded by default |
| Data processing agreement (Art. 28) | No | Yes, OpenAI standard DPA, self-serve | Yes, negotiable |
| EU data residency | No | reported: Enterprise and API only | Yes, per contract |
| SSO / SAML | No | reported | Yes, plus SCIM |
| Retention control | Per user, 30-day temporary chats | Workspace admin settings | Admin plus compliance API |
| Audit log / compliance API | No | No | Yes |
| Seat minimum | 1 | 2 | About 150, annual (reported) |
| Price | $0 / $20 | About $25 monthly or $20 annual per user after the April 2026 cut (reported) | Quote only, about $45 to 75 per user (reported) |
Reported means: not published by OpenAI on a page we could cite, but consistent across several 2026 pricing analyses. Treat the seat floor and Enterprise price as negotiation anchors, not facts. Everything about training exclusion, the DPA and the Hamburg checklist is documented and linked.
What the data protection officer checks for ChatGPT Business
The checklist below follows the Hamburg data protection commissioner's guidance for LLM chatbots and the DSK orientation on AI and data protection, mapped to what ChatGPT Business can and cannot do. Points one to four are organisational and apply to any tool. Points five to ten are where the tier decides.
The full set of questions an officer asks about any AI tool, with the artefact that answers each one, is in the data protection officer checklist for AI.
Written rules on what may be used for what
The Hamburg checklist starts with compliance rules: which tools, which scenarios, with examples of allowed and forbidden use. Without rules the employer may be liable for what employees do on their own. Our AI policy template is written for this.
Involve the DSB before the first use case, decide on a DPIA
Item two of the checklist: the officer is involved when rules are written and when a use case is first implemented, and a data protection impact assessment is made where the use case warrants it. The DPIA template covers the AI-specific sections.
Company accounts, no private accounts, no private use
Item three, verbatim: if professional use is wanted, professional accounts should be provided, and private use of those accounts is discouraged. A Business workspace satisfies this; a pile of Plus subscriptions on personal e-mail addresses does not.
Strong authentication
Item four: an AI account with chat history is an attractive target. Business supports SSO (reported); turn it on with your identity provider and enforce a second factor.
Sign the data processing agreement
Business is the first tier with a DPA. It is OpenAI's standard text, accepted online, not negotiated. Read it with our AVV checklist for AI chat: sub-processors, transfer mechanism, deletion on termination.
Confirm the training exclusion in writing
Item eight of the checklist is the opt-out. On Business it is the default, which is the single biggest reason to prefer it over Plus. Document it in the DPIA, because the DSB will ask where it is written.
Settle the third-country transfer
Without EU residency, prompts and stored chats are processed in the United States under the Data Privacy Framework and standard contractual clauses. That is a legal basis today, with a transfer impact assessment on file. It is also the point at which most officers in regulated sectors say no.
No personal data in prompts, no personal data in outputs
Items five to seven: where the provider processes data for its own purposes no personal data may be entered, and even with training excluded the guidance asks you to keep prompts free of anything that identifies customers, partners or employees. The checklist example of a problematic prompt is drafting a reference letter for a named role at a named company.
Retention and deletion set by an admin
Set workspace retention and make deletion a policy, not a habit. Business has admin settings for this; it has no compliance API, so exports for an audit are manual.
Train people and check results
Article 4 of the AI Act has required AI literacy since February 2025, and the checklist asks that outputs be checked before use. Both are yours to organise regardless of tier; see the training duty guide.
Ten points, scored in ten minutes: the free AI governance check
Answers where your rules, DPIA, accounts and training stand today and returns a gap list you can hand to the DSB. Anonymous, EU-hosted.
When ChatGPT Business is enough, and when it is not
Business is enough when the work is generic and the data is not personal: marketing copy, code, translations of public material, meeting preparation without names, brainstorming. It is not enough when the value of the tool comes from your own data, because that data is exactly what the checklist tells you to keep out of it.
Professionals bound by confidentiality face a second law on top of the GDPR; AI for tax firms covers section 203 of the German criminal code and what the provider contract must contain.
Business is enough for
Replacing private Plus accounts with company accounts, today
Teams of 2 to 50 with generic writing, coding and research tasks
Companies whose DSB accepts a US transfer under the Data Privacy Framework with a documented assessment
A first policy, first training and first DPIA before choosing a platform
Business is not enough for
Professional secrecy holders (tax advisors, lawyers, doctors, section 203 of the Criminal Code) without EU residency
HR use: reference letters, applicant screening, performance text land in Annex III of the AI Act
Customer data from CRM, tickets or contracts: the checklist says no personal data goes in
Anything an auditor must reconstruct: there is no compliance API below Enterprise
A works council that asks where logs are stored and who can read them
The trap is the second year. A Business workspace is bought to stop shadow AI, works, and then people start pasting customer e-mails and CVs into it because it is the sanctioned tool. At that point the plan has not changed but your risk has, and the DSB who approved a generic-use tool did not approve a CRM.
Alternatives with EU data residency and no 150-seat minimum
If the officer's objection is the transfer, the fix is residency, and residency below 150 seats means leaving OpenAI's own tiers. Three options are realistic for a company of 10 to 250 people; a longer list is in ChatGPT alternatives for the Mittelstand, and the step-by-step move is in the migration guide.
If Langdock is on your shortlist, read the Langdock alternative guide first: its April 2026 usage limits changed the comparison.
| Option | EU residency | Seat minimum | Models | Permissions on your data | Watch out for |
|---|---|---|---|---|---|
| Teamo AI | Yes, EU | None, 14-day trial | OpenAI, Anthropic, Google, Mistral, Aleph Alpha | Per row, 7 rings, 3 audit logs | Young product, small review base |
| Langdock | Yes, Germany | None | Several | Workspace and folder level | Usage limits since April 2026, Trustpilot 2.2 |
| meinGPT | Yes, Germany | Pilot from about 9,000 euros per quarter (reported) | Several | Workspace level | Pilot fee is the floor |
| ChatGPT Enterprise | Yes, per contract | About 150 (reported) | OpenAI only | Workspace level, compliance API | Annual prepaid, quote only |
The permission column matters more than it looks. A residency-compliant chat tool still shows every user everything the workspace holds. If the reason you want AI is your CRM, your tickets and your contracts, the question is not only where the data sits but who inside the company may see which row. That is the difference between a chat tool and an AI operating system for companies, and it is why ChatGPT Enterprise and Copilot end up in the same box for a data protection officer: both are chat windows with a workspace switch.
Teamo AI: shared knowledge that never leaves Europe
EU-hosted, several model providers behind one interface, per-row permissions on Slack, Teams, Jira, Notion, HubSpot, Pipedrive and your calendar, three audit logs. No seat minimum. 14 days free, no credit card, your team invited in minutes.
Verdict: buy Business to stop shadow AI, not to run the company on it
ChatGPT Business is the right first purchase for a company whose employees already use ChatGPT privately: two seats, training excluded, a DPA, SSO, done in an afternoon. Sign it, write the policy, run the training, and keep personal data out. Then watch what people paste. The day the sanctioned tool becomes the place where customer data lives is the day the tier stops matching the risk, and the DSB's next question will be about residency and permissions, which Business cannot answer at any price below the enterprise contract.
ChatGPT Business and GDPR in five sentences
Business excludes your data from training by default and comes with a DPA and SSO, which makes it the cheapest way to replace private accounts. It has no EU data residency, no compliance API and a two-seat floor. The Hamburg checklist still applies in full: rules, DSB, company accounts, strong login, no personal data in or out, training opt-out. It is enough for generic work and not enough for professional secrecy holders, HR or customer data. For those, an EU-hosted platform with per-row permissions closes the gap without a 150-seat contract.






![European AI for Teams: Why 'EU Region' on US Clouds Is Not Enough [2026]](https://www.teamazing.com/wp-content/uploads/2026/04/EU-AI-Usage.jpg)
![OpenClaw at Work: 5 Reasons Your Security Team Will Say No [2026]](https://www.teamazing.com/wp-content/uploads/2026/03/openclaw-in-companies.jpg)