ChatGPT Business (the plan formerly called ChatGPT Team) can be used in a GDPR-compliant way for many everyday tasks, but only under conditions the plan itself does not enforce: OpenAI excludes Business workspace data from model training by default and offers a data processing agreement, yet EU data residency is not available on this tier, the seat floor is two users, and everything a data protection officer actually checks, from the legal basis to the ban on personal data in prompts, is your job, not OpenAI's. This article walks through the exact checks a German or Austrian DSB applies, where Business passes, where it fails, and which alternatives close the gap without a 150-seat enterprise contract.

The context is the same everywhere: about 42% of German companies know or assume that employees use private AI accounts, while only 26% provide an official one, according to Bitkom. A Business workspace is the cheapest way to replace private accounts with company accounts, which is precisely what the Hamburg data protection commissioner asks for. It is the sensible first step. It is not the finish line.

42%of German companies know or assume employees use private AI tools; only 26% provide an official account (Bitkom)
2seats is the ChatGPT Business minimum, against about 150 for Enterprise (reported)
0EU data residency options on the Business tier: residency is an Enterprise and API feature (reported)
8checklist items in the Hamburg DPA guidance for LLM chatbots, from company accounts to the training opt-out

ChatGPT Free, Plus, Business and Enterprise: what each tier does for data protection

The tiers differ less in model quality than in who controls the data. Free and Plus are consumer contracts: your inputs may be used for training unless every single user opts out, there is no data processing agreement and no admin. Business is the first tier that behaves like a business contract. Enterprise adds the pieces regulated buyers need, at a seat floor most mid-sized companies cannot meet. Prices and minimums below are as reported in 2026; OpenAI does not publish Enterprise terms, and Business pricing was cut in April 2026, so check the current page before you sign.

CriterionFree / PlusBusiness (ex-Team)Enterprise
Training on your dataYes by default, per-user opt-out in settingsExcluded by defaultExcluded by default
Data processing agreement (Art. 28) NoYes, OpenAI standard DPA, self-serveYes, negotiable
EU data residency No reported: Enterprise and API onlyYes, per contract
SSO / SAML No reportedYes, plus SCIM
Retention controlPer user, 30-day temporary chatsWorkspace admin settingsAdmin plus compliance API
Audit log / compliance API No No Yes
Seat minimum12About 150, annual (reported)
Price$0 / $20About $25 monthly or $20 annual per user after the April 2026 cut (reported)Quote only, about $45 to 75 per user (reported)

Reported means: not published by OpenAI on a page we could cite, but consistent across several 2026 pricing analyses. Treat the seat floor and Enterprise price as negotiation anchors, not facts. Everything about training exclusion, the DPA and the Hamburg checklist is documented and linked.

What the data protection officer checks for ChatGPT Business

The checklist below follows the Hamburg data protection commissioner's guidance for LLM chatbots and the DSK orientation on AI and data protection, mapped to what ChatGPT Business can and cannot do. Points one to four are organisational and apply to any tool. Points five to ten are where the tier decides.

The full set of questions an officer asks about any AI tool, with the artefact that answers each one, is in the data protection officer checklist for AI.

1

Written rules on what may be used for what

The Hamburg checklist starts with compliance rules: which tools, which scenarios, with examples of allowed and forbidden use. Without rules the employer may be liable for what employees do on their own. Our AI policy template is written for this.

2

Involve the DSB before the first use case, decide on a DPIA

Item two of the checklist: the officer is involved when rules are written and when a use case is first implemented, and a data protection impact assessment is made where the use case warrants it. The DPIA template covers the AI-specific sections.

3

Company accounts, no private accounts, no private use

Item three, verbatim: if professional use is wanted, professional accounts should be provided, and private use of those accounts is discouraged. A Business workspace satisfies this; a pile of Plus subscriptions on personal e-mail addresses does not.

4

Strong authentication

Item four: an AI account with chat history is an attractive target. Business supports SSO (reported); turn it on with your identity provider and enforce a second factor.

5

Sign the data processing agreement

Business is the first tier with a DPA. It is OpenAI's standard text, accepted online, not negotiated. Read it with our AVV checklist for AI chat: sub-processors, transfer mechanism, deletion on termination.

6

Confirm the training exclusion in writing

Item eight of the checklist is the opt-out. On Business it is the default, which is the single biggest reason to prefer it over Plus. Document it in the DPIA, because the DSB will ask where it is written.

7

Settle the third-country transfer

Without EU residency, prompts and stored chats are processed in the United States under the Data Privacy Framework and standard contractual clauses. That is a legal basis today, with a transfer impact assessment on file. It is also the point at which most officers in regulated sectors say no.

8

No personal data in prompts, no personal data in outputs

Items five to seven: where the provider processes data for its own purposes no personal data may be entered, and even with training excluded the guidance asks you to keep prompts free of anything that identifies customers, partners or employees. The checklist example of a problematic prompt is drafting a reference letter for a named role at a named company.

9

Retention and deletion set by an admin

Set workspace retention and make deletion a policy, not a habit. Business has admin settings for this; it has no compliance API, so exports for an audit are manual.

10

Train people and check results

Article 4 of the AI Act has required AI literacy since February 2025, and the checklist asks that outputs be checked before use. Both are yours to organise regardless of tier; see the training duty guide.

Ten points, scored in ten minutes: the free AI governance check

Answers where your rules, DPIA, accounts and training stand today and returns a gap list you can hand to the DSB. Anonymous, EU-hosted.

Run the governance check

When ChatGPT Business is enough, and when it is not

Business is enough when the work is generic and the data is not personal: marketing copy, code, translations of public material, meeting preparation without names, brainstorming. It is not enough when the value of the tool comes from your own data, because that data is exactly what the checklist tells you to keep out of it.

Professionals bound by confidentiality face a second law on top of the GDPR; AI for tax firms covers section 203 of the German criminal code and what the provider contract must contain.

Business is enough for

  • Replacing private Plus accounts with company accounts, today

  • Teams of 2 to 50 with generic writing, coding and research tasks

  • Companies whose DSB accepts a US transfer under the Data Privacy Framework with a documented assessment

  • A first policy, first training and first DPIA before choosing a platform

Business is not enough for

  • Professional secrecy holders (tax advisors, lawyers, doctors, section 203 of the Criminal Code) without EU residency

  • HR use: reference letters, applicant screening, performance text land in Annex III of the AI Act

  • Customer data from CRM, tickets or contracts: the checklist says no personal data goes in

  • Anything an auditor must reconstruct: there is no compliance API below Enterprise

  • A works council that asks where logs are stored and who can read them

The trap is the second year. A Business workspace is bought to stop shadow AI, works, and then people start pasting customer e-mails and CVs into it because it is the sanctioned tool. At that point the plan has not changed but your risk has, and the DSB who approved a generic-use tool did not approve a CRM.

Alternatives with EU data residency and no 150-seat minimum

If the officer's objection is the transfer, the fix is residency, and residency below 150 seats means leaving OpenAI's own tiers. Three options are realistic for a company of 10 to 250 people; a longer list is in ChatGPT alternatives for the Mittelstand, and the step-by-step move is in the migration guide.

If Langdock is on your shortlist, read the Langdock alternative guide first: its April 2026 usage limits changed the comparison.

OptionEU residencySeat minimumModelsPermissions on your dataWatch out for
Teamo AIYes, EUNone, 14-day trialOpenAI, Anthropic, Google, Mistral, Aleph AlphaPer row, 7 rings, 3 audit logsYoung product, small review base
LangdockYes, GermanyNoneSeveralWorkspace and folder levelUsage limits since April 2026, Trustpilot 2.2
meinGPTYes, GermanyPilot from about 9,000 euros per quarter (reported)SeveralWorkspace levelPilot fee is the floor
ChatGPT EnterpriseYes, per contractAbout 150 (reported)OpenAI onlyWorkspace level, compliance APIAnnual prepaid, quote only

The permission column matters more than it looks. A residency-compliant chat tool still shows every user everything the workspace holds. If the reason you want AI is your CRM, your tickets and your contracts, the question is not only where the data sits but who inside the company may see which row. That is the difference between a chat tool and an AI operating system for companies, and it is why ChatGPT Enterprise and Copilot end up in the same box for a data protection officer: both are chat windows with a workspace switch.

Teamo AI: shared knowledge that never leaves Europe

EU-hosted, several model providers behind one interface, per-row permissions on Slack, Teams, Jira, Notion, HubSpot, Pipedrive and your calendar, three audit logs. No seat minimum. 14 days free, no credit card, your team invited in minutes.

Start the free trial, no credit card

Verdict: buy Business to stop shadow AI, not to run the company on it

ChatGPT Business is the right first purchase for a company whose employees already use ChatGPT privately: two seats, training excluded, a DPA, SSO, done in an afternoon. Sign it, write the policy, run the training, and keep personal data out. Then watch what people paste. The day the sanctioned tool becomes the place where customer data lives is the day the tier stops matching the risk, and the DSB's next question will be about residency and permissions, which Business cannot answer at any price below the enterprise contract.

ChatGPT Business and GDPR in five sentences

Business excludes your data from training by default and comes with a DPA and SSO, which makes it the cheapest way to replace private accounts. It has no EU data residency, no compliance API and a two-seat floor. The Hamburg checklist still applies in full: rules, DSB, company accounts, strong login, no personal data in or out, training opt-out. It is enough for generic work and not enough for professional secrecy holders, HR or customer data. For those, an EU-hosted platform with per-row permissions closes the gap without a 150-seat contract.