{"id":1004944,"date":"2026-03-18T13:33:28","date_gmt":"2026-03-18T12:33:28","guid":{"rendered":"https:\/\/www.iterates.be\/?p=1004944"},"modified":"2026-02-25T12:15:38","modified_gmt":"2026-02-25T11:15:38","slug":"chatgpt-corporate-data-protection-guarantees","status":"publish","type":"post","link":"https:\/\/www.iterates.be\/en\/chatgpt-corporate-data-protection-guarantees\/","title":{"rendered":"ChatGPT: corporate data protection guarantees"},"content":{"rendered":"<div class=\"vgblk-rw-wrapper limit-wrapper\">\n<p>Generative artificial intelligence has taken hold in organisations at a speed that few IT or legal managers anticipated. ChatGPT, OpenAI's flagship tool, is now used in thousands of European companies, often without any formal framework, internal policy or risk analysis. For managers, DPOs and compliance officers, the question is no longer whether their staff use ChatGPT, but how to do so in a legally secure way.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>1. ChatGPT and the RGPD: what does the legal framework actually say?<\/strong><\/h2>\n\n\n\n<p>Before adopting or tolerating the use of ChatGPT in the workplace, it is important to understand the legal framework in which this tool operates. Visit <strong>RGPD and artificial intelligence<\/strong> are not yet perfectly clearly articulated, and this is precisely where the first risks lie.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Data controller or data processor: a strategic blur<\/strong><\/h3>\n\n\n\n<p>When a company uses the OpenAI API, the relationship is relatively clear-cut: OpenAI acts as a processor, and the company as a data controller. But in the case of ChatGPT used directly via the\u2019<a href=\"https:\/\/www.iterates.be\/en\/web-and-mobile-development-trends\/\" title=\"\">web interface<\/a>, the boundary is more blurred. OpenAI may take on the role of co-responsible or even independent controller for certain operations, in particular the training of its models. This ambiguity has direct consequences for the <strong>compliance IA enterprise<\/strong> Who is responsible in the event of a leak or unlawful processing?<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>The positions of the European authorities<\/strong><\/h3>\n\n\n\n<p>Several data protection authorities have already taken action. The Italian authority (Garante) suspended access to ChatGPT in 2023. The French CNIL has conducted investigations. L\u2019<strong>RGPD impact assessment<\/strong> imposed by these authorities reveals real shortcomings: lack of transparency regarding the data collected, absence of a clear legal basis for training, difficulties in exercising people's rights. The <strong>compliance IA Belgium<\/strong> is also on the radar of the Data Protection Authority (DPA), which is keeping a close eye on the practices of local companies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>RGPD, AI Act and new obligations to come<\/strong><\/h3>\n\n\n\n<p>Le <strong>European AI Act<\/strong>, which came into force in 2024, adds a further layer of regulatory complexity. General-purpose generative AI systems, such as ChatGPT, are now subject to transparency and technical documentation obligations. For businesses, this means that the <strong>AI data governance<\/strong> can no longer be left to improvisation: it must be structured, documented and audited.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>2. What are the practical risks for businesses?<\/strong><\/h2>\n\n\n\n<p>The risks associated with\u2019<strong>use of ChatGPT data protection<\/strong> are not theoretical. They occur on a daily basis, often without the organisation being aware of them. Here are the most critical examples.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Sensitive data inserted in prompts<\/strong><\/h3>\n\n\n\n<p>The main vulnerability is behavioural. An employee who submits a customer contract, HR data, financial information or source code in a ChatGPT prompt transfers this information to OpenAI's servers, which are located outside the EU. These <strong>ChatGPT personal data<\/strong> can be used to drive models, unless otherwise configured. The <strong><a href=\"https:\/\/www.iterates.be\/en\/on-premise-and-european-cloud-solutions-for-your-technological-independence\/\" title=\"\">data transfer outside the EU<\/a><\/strong> triggers specific obligations under the RGPD (standard contractual clauses, risk analyses) that are rarely met in practice.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Shadow AI: a major organisational risk<\/strong><\/h3>\n\n\n\n<p>Le <strong>shadow AI company<\/strong> refers to the undeclared, unsupervised and uncontrolled use of AI tools by employees. This is one of the most dangerous blind spots for the <strong>generative AI security<\/strong> Data protection: the organisation does not know what data is shared, with what tools, under what conditions. Without an inventory or policy, it is impossible to guarantee compliance or to react in the event of an incident.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Sanctions, reputation and legal liability<\/strong><\/h3>\n\n\n\n<p>Penalties under the RGPD can reach 4 % of annual global turnover. But beyond the fines, it is the contractual liability to customers, the loss of trust and the damage to reputation that are the most immediate risks for SMEs. A company that cannot demonstrate that it is in control of its data flows is exposed to audits, litigation and a weakening of its commercial relations.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Quelles-garanties-propose-OpenAI-aujourdhui-1024x683.jpg\" alt=\"\" class=\"wp-image-1004949\" srcset=\"https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Quelles-garanties-propose-OpenAI-aujourdhui-1024x683.jpg 1024w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Quelles-garanties-propose-OpenAI-aujourdhui-300x200.jpg 300w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Quelles-garanties-propose-OpenAI-aujourdhui-768x512.jpg 768w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Quelles-garanties-propose-OpenAI-aujourdhui-18x12.jpg 18w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Quelles-garanties-propose-OpenAI-aujourdhui.jpg 1279w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">The guarantees offered by OpenAI <\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>3. What guarantees does OpenAI offer today?<\/strong><\/h2>\n\n\n\n<p>OpenAI has gradually strengthened its contractual and technical arrangements to meet European regulatory requirements. These guarantees are real, but they require companies to take an active approach.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Data Processing Addendum (DPA)<\/strong><\/h3>\n\n\n\n<p>L\u2019<strong>OpenAI DPA<\/strong> (Data Processing Addendum) is a contractual agreement which governs the processing of data within the framework of the API. It specifies OpenAI's obligations as a processor, the security measures applied and the conditions of transfer. This document is essential for any company wishing to use OpenAI's services within a framework that complies with the RGPD. But beware: it does not automatically apply to the use of ChatGPT via the general public interface.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Privacy settings and disabling training<\/strong><\/h3>\n\n\n\n<p>OpenAI now allows users and businesses to disable the use of their data for model training. This option, which can be accessed in the account settings or via the API, is a minimum requirement for any organisation concerned about <strong>compliance IA enterprise<\/strong>. It doesn't solve all the problems, but it significantly reduces exposure.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Hosting, data transfer and security<\/strong><\/h3>\n\n\n\n<p>The data processed by OpenAI is hosted in the United States. The legal framework applicable to <strong>data transfers outside the EU<\/strong> is based on standard contractual clauses (SCCs) and, since 2023, on the EU-US Data Privacy Framework. The <strong>generative AI security<\/strong> proposed by OpenAI includes encryption of data in transit and at rest, strict access controls and security certifications (SOC 2). These elements must be documented in your data processing register.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>4. Good practice for correct and controlled use<\/strong><\/h2>\n\n\n\n<p>Compliance cannot be decreed: it must be built methodically, combining an organisational framework, legal analysis and human training.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Implementing an internal AI policy<\/strong><\/h3>\n\n\n\n<p>All organisations must draw up a formal policy for the use of AI tools, specifying which tools are authorised, in which contexts and with which data. This policy should distinguish between professional and personal use, define the categories of data excluded from prompting, and provide for control mechanisms. This is the first line of defence against <strong>shadow AI company<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Carrying out an impact assessment (DPIA)<\/strong><\/h3>\n\n\n\n<p>L\u2019<strong><a href=\"https:\/\/www.iterates.be\/en\/are-you-still-compliant-with-the-rgpd-and-artificial-intelligence-regulations\/\" title=\"\">RGPD impact assessment<\/a><\/strong> (or DPIA Data Protection Impact Assessment) is mandatory whenever processing is likely to result in a high risk to individuals. The use of ChatGPT on customer, HR or financial data generally meets this criterion. The DPIA makes it possible to identify the risks, document them and define the appropriate mitigation measures, an essential step for the <strong>AI data governance<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Training teams in AI data governance<\/strong><\/h3>\n\n\n\n<p>Technology is not enough without human awareness. Training employees in the risks associated with prompts, good information-sharing practices and the obligations of the RGPD is an investment directly linked to reducing legal risk. A trained team is less likely to generate incidents of <strong>generative AI security<\/strong> and better able to identify anomalies.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Comment-Iterates-accompagne-les-PME-belges-vers-une-IA-conforme-et-strategique-1024x682.jpg\" alt=\"\" class=\"wp-image-1004950\" srcset=\"https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Comment-Iterates-accompagne-les-PME-belges-vers-une-IA-conforme-et-strategique-1024x682.jpg 1024w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Comment-Iterates-accompagne-les-PME-belges-vers-une-IA-conforme-et-strategique-300x200.jpg 300w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Comment-Iterates-accompagne-les-PME-belges-vers-une-IA-conforme-et-strategique-768x512.jpg 768w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Comment-Iterates-accompagne-les-PME-belges-vers-une-IA-conforme-et-strategique-18x12.jpg 18w, https:\/\/www.iterates.be\/wp-content\/uploads\/2026\/03\/Comment-Iterates-accompagne-les-PME-belges-vers-une-IA-conforme-et-strategique.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Data protection support<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>5. How Iterates supports Belgian SMEs on the road to compliant and strategic AI<\/strong><\/h2>\n\n\n\n<p>At Iterates, we support Belgian SMEs in implementing an AI strategy that is both effective and rigorously compliant. Our approach combines legal expertise, technical mastery and strategic vision to ensure that AI becomes a lever, not a risk.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>RGPD audit &amp; mapping of AI uses<\/strong><\/h3>\n\n\n\n<p>We start with a complete inventory: what AI tools are used in your organisation, by whom, on what data, in what flows? This mapping enables us to identify areas of <strong>shadow AI company<\/strong>, This is the basis for a comprehensive data protection policy. This is the basis of a <strong>compliance IA Belgium<\/strong> solid and defensible.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Technical support (architecture, security, flow control)<\/strong><\/h3>\n\n\n\n<p>We can help you design a technical architecture that minimises risks: data compartmentalisation, anonymisation of prompts, deployment of on-premise or European cloud solutions, implementation of outbound flow controls. The aim is to guarantee <strong>generative AI security<\/strong> without sacrificing operational efficiency.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Integration of secure AI tools into your IT ecosystem<\/strong><\/h3>\n\n\n\n<p>We select and integrate AI solutions that are tailored to your business needs, respect the <strong>RGPD and artificial intelligence<\/strong>, and compatible with your existing infrastructure. Whether it's sovereign alternatives to ChatGPT, locally deployed models or secure configurations of the OpenAI API, we're with you every step of the way, from strategy to implementation.<\/p>\n\n\n\n<p class=\"has-text-align-center\"><strong><a href=\"https:\/\/www.iterates.be\/en\/contact\/\" title=\"\"><a href=\"https:\/\/cal.com\/rodolphebalay\/it-project-meeting-iterates?duration=60\">Contact Iterates to find out more<\/a><\/a><\/strong><\/p>\n\n\n\n<p><\/p>\n<\/div><!-- .vgblk-rw-wrapper -->","protected":false},"excerpt":{"rendered":"<p>L&#8217;intelligence artificielle g\u00e9n\u00e9rative s&#8217;est impos\u00e9e dans les organisations \u00e0 une vitesse que peu de responsables IT ou juridiques avaient anticip\u00e9e. ChatGPT, l&#8217;outil phare d&#8217;OpenAI, est aujourd&#8217;hui utilis\u00e9 dans des milliers d&#8217;entreprises europ\u00e9ennes souvent sans cadre formel, sans politique interne, et sans analyse des risques. Pour les dirigeants, DPO et responsables de la conformit\u00e9, la question&#8230;<\/p>","protected":false},"author":1,"featured_media":1004948,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1226],"tags":[],"class_list":["post-1004944","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tendances"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/posts\/1004944","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/comments?post=1004944"}],"version-history":[{"count":0,"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/posts\/1004944\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/media\/1004948"}],"wp:attachment":[{"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/media?parent=1004944"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/categories?post=1004944"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.iterates.be\/en\/wp-json\/wp\/v2\/tags?post=1004944"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}