Can your staff use ChatGPT at work? A plain guide for Cyprus companies
6 October 2026
I get asked this a lot, usually after someone in the team has already been using ChatGPT for a few months and the owner only just noticed. The honest answer is that staff using ChatGPT at work is not the problem on its own. The problem is what gets typed into it, and which version of it they are using. Here is how I walk clients through this.
Consumer plans and business plans are not the same product
A free ChatGPT account, or a personal ChatGPT Plus subscription, may use what you type in to train the model, by default. That is the setting most people have, because most people never go looking for a setting to change. It is fine for drafting a generic email or brainstorming a blog title. It is not fine for anything that belongs to your company or your customers.
A business plan (ChatGPT Business, or Team/Enterprise tiers) and the API work differently. By default, inputs on these are not used to train the model, and OpenAI offers a Data Processing Agreement under GDPR Article 28 for business customers. That DPA is the thing that actually makes it defensible to put company data anywhere near the tool, because it sets out who is processing the data and under what terms.
So the question "can staff use ChatGPT" is really two questions: which account are they signed into, and what are they typing. Get those two right and most of the risk goes away.
What should never go into a personal account
Customer data of any kind: names, emails, medical or financial details, anything that identifies a real person. If it is personal data under GDPR and it goes into a personal ChatGPT account, you have no contract covering what happens to it next.
Contracts, NDAs, and anything covered by a confidentiality clause. Pasting a supplier contract into ChatGPT to "summarise this" is a common habit, and it is exactly the kind of thing an NDA is written to prevent.
Anything you would not want to see repeated outside the company. That is a rough test, but it works, because it forces the question before the paste happens rather than after.
The traffic-light rule
I use a simple three-colour rule with clients because it is easy to remember under time pressure, which is when most mistakes happen.
Green: public information. Your own website copy, a published price list, a generic question with no company specifics. Fine on any account.
Amber: internal but not sensitive. A draft internal email with no names, a general process question, a first pass at a job description. Fine on a business account, best avoided on a personal one.
Red: customer data, contracts, NDA material, anything confidential. Never paste it into a personal account. On a business account with a signed DPA it is a different conversation, but it still needs a decision, not a habit.
Why a blanket ban usually backfires
The instinct a lot of owners have is to ban ChatGPT outright. I understand the instinct, but in practice it rarely works. Staff who find a tool useful keep using it, just on their own phone, on their own account, where nobody can see what they are typing. A ban does not remove the risk. It just removes your visibility into it.
The better move is to give people a safe way to do what they are already trying to do, with rules that are short enough to actually read.
What to set up instead
A business plan with a signed DPA, so there is a contract covering how your data is processed, and inputs are not used for training by default. This is the single biggest lever: it moves the account itself from indefensible to reasonable.
A one-page staff rule sheet, built around the traffic-light rule above, that says plainly what can and cannot be pasted in, and which account to use for which kind of work. One page people actually read beats a ten-page policy nobody opens.
A note on API keys and access tokens: these should never go into a chat window or a shared document, for the same reason customer data shouldn't. A key pasted into a conversation can end up logged, shared, or searched in ways you did not intend, and once it is out it has to be treated as compromised and rotated. Keep keys in a password manager or secrets store, not in a prompt.
The company stays the data controller either way, whichever account staff use. The EDPB's ChatGPT taskforce work from 2024 looked at exactly this question, and the short version is that using a tool does not transfer your GDPR responsibilities to the tool's provider. Getting the account and the rules right is how you actually meet those responsibilities, not a box to tick afterwards.
If you want a second pair of eyes on what your team is already doing, the safe AI page covers the wider approach I take with clients, and the briefing is the session where I walk a leadership team through exactly this kind of decision. This is general information, not legal advice.
Frequently asked questions
Is ChatGPT banned under GDPR?
No. GDPR does not ban any specific tool. It requires that personal data is processed with a lawful basis, proper safeguards, and a contract where a processor is involved. A business ChatGPT account with a signed DPA can meet that; a personal account used for customer data generally cannot.
What's the difference between ChatGPT Plus and ChatGPT Business for a company?
Plus is a personal subscription and, by default, inputs may be used to train the model. Business plans and the API do not use inputs for training by default and come with a Data Processing Agreement under GDPR Article 28, which is the contract that covers how your company's data is handled.
Does this apply if my company is outside Cyprus?
Yes. I am based in Larnaca, Cyprus, but GDPR applies across the EU, and the account and contract questions here are the same wherever the company is registered.
Behind on AI? Start with a free plan.
A free audit of how you work and a written plan of what to automate. No cost, no commitment. Limited spots.