Privacy

GDPR and AI chatbots: where prompts cross the line

Jul 6, 20265 min read

A support agent pastes a customer email into a public chatbot to draft a reply. A recruiter drops a candidate CV into a prompt to summarise it. A lawyer asks an assistant to redline a contract that names real people. Each of these takes seconds, feels harmless, and may be unlawful under GDPR.

The reason is simple, and most teams miss it. The moment personal data leaves your control and reaches a chatbot provider, you have carried out a processing operation. If that provider sits outside the EEA, you have also made an international transfer. Both need a lawful footing. Neither is something you can wave away because the tool was convenient.

This is not a theoretical concern. Regulators have already acted, and the numbers are not small.

The prompt is a processing operation

GDPR governs the processing of personal data. Processing is broad. It covers collection, use, disclosure by transmission, and making data available. When you type a name, an email address, a health detail, or any information about an identifiable person into a chatbot and press send, you are disclosing that data to a third party. That is processing, and you are doing it as a controller.

Every processing operation needs a lawful basis under Article 6. Consent, contract, legitimate interests, and the others are not interchangeable defaults you can assume after the fact. You need to identify the basis before the data moves, and you need to be able to show it.

Data minimisation sits right beside this. Article 5 requires that personal data be adequate, relevant, and limited to what is necessary. A prompt that includes a full customer record to answer a narrow question fails that test. If the chatbot only needs the shape of a problem, it does not need the person attached to it.

If the model does not need to know who the person is to do the task, the person's identity has no business being in the prompt.

The chatbot provider is a third party

It is tempting to treat a chatbot as a tool, like a calculator or a text editor that runs quietly on your side. It is not. A public chatbot is operated by a separate company that receives your input, processes it on its own infrastructure, and may use it in ways set out in its own terms.

That makes the provider a third party in GDPR terms, and often a separate controller or a processor depending on the arrangement. Either way, sending personal data to it is a disclosure. You need a basis for that disclosure, you need to have done your due diligence on the recipient, and you need the contractual terms that GDPR requires when a processor is involved.

The casual, account-level use that happens across most organisations rarely has any of this in place. People sign in with a personal or team login, paste what they need, and move on. There is no record of what was disclosed, no assessment of the recipient, and no basis written down. From a compliance standpoint, that is exposure sitting in plain sight.

When the data leaves the EEA

Chapter V of GDPR restricts transfers of personal data outside the EEA. A transfer needs an adequacy decision, appropriate safeguards such as standard contractual clauses, or a narrow derogation. Many widely used chatbot providers process data on infrastructure outside the EEA. If your prompt reaches them there, you have made a restricted transfer.

This is where the convenience of a public chatbot collides hardest with the law. The transfer rules were written precisely for the situation where personal data crosses a border to a recipient whose legal environment you do not control. Pasting a customer file into a prompt can trigger every one of those rules at once: a disclosure to a third party, on the basis of nothing in particular, across a border without safeguards.

The regulators are not waiting

If this still feels abstract, the enforcement record removes any doubt. As widely reported, in March 2023 Italy's data protection authority, the Garante, temporarily banned ChatGPT over privacy concerns. Access was restored only after OpenAI made changes to address what the regulator raised.

That was not the end of it. As widely reported, in December 2024 the Garante fined OpenAI 15 million euros over data protection issues connected to ChatGPT. The Garante has also taken action against other AI services. The pattern is consistent: European regulators treat the handling of personal data through these tools as regulated activity, and they are prepared to use the full range of their powers, from suspension to substantial fines.

The lesson for a controller is not that chatbots are forbidden. It is that the data you put into them carries the same obligations it carries everywhere else. Regulators have shown they will look, and they will act.

The safe pattern: nothing regulated to transfer

There is a clean way through this, and it does not require banning useful tools. The principle is to make sure that by the time a prompt leaves your control, it contains no personal data at all.

If you remove or mask names, contact details, identifiers, and other personal data before the text reaches the chatbot, then the thing you send is no longer personal data. There is no disclosure of an identifiable person, no lawful basis to scramble for, and no restricted transfer, because there is nothing regulated left to transfer. The model still gets the structure and the substance it needs to be useful. The person stays behind.

This is data minimisation turned into a workflow rather than a wish. Instead of trusting people to judge, prompt by prompt, what is safe to paste, you strip the regulated content out at the boundary, before it can leave. The task gets done. The exposure does not happen.

For DPOs, lawyers, and compliance teams, this reframes the question. You are no longer asking whether each chatbot use was lawful after it happened. You are making the unlawful version impossible to send.

That is the role Velum is built to play: it removes and masks personal data before a prompt ever leaves your control, so the regulated content never reaches a third party or crosses a border. If you want to see where this fits across support, recruitment, legal, and the other places prompts go out every day, see the use cases.

Share this article
XLinkedIn