{"id":1851,"date":"2026-09-08T09:00:00","date_gmt":"2026-09-08T07:00:00","guid":{"rendered":"https:\/\/pletzenauer.com\/?p=1851"},"modified":"2026-07-27T17:48:54","modified_gmt":"2026-07-27T15:48:54","slug":"ai-gdpr-vendor-comparison","status":"publish","type":"post","link":"https:\/\/pletzenauer.com\/en\/2026\/09\/08\/ai-gdpr-vendor-comparison\/","title":{"rendered":"GDPR in the AI comparison: Claude, ChatGPT, Gemini, Copilot"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>The short answer:<\/strong> all four major vendors refrain from training on your content by default on their business plans. The difference that matters for data protection therefore lies not between vendors but between <em>plans<\/em> \u2014 and your biggest exposure is the personal accounts your staff use on the side. Three questions decide it: is our data used for training? From which plan onwards is it not? And who is liable under the data processing agreement?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Last checked: September 2026. All statements come from the respective vendors&#8217; own documentation and were verified on the day of publication. This is a practitioner&#8217;s assessment from consulting work in Austria, <strong>not legal advice<\/strong> \u2014 the binding evaluation of your specific case belongs with your data protection officer or a law firm.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Disclosure:<\/strong> I earn my living advising on and training people in Claude. Which is why this article sticks strictly to what the vendors themselves document \u2014 no claim without a source in their own documentation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The short version<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Business plans do not train on your content<\/strong> \u2014 Claude, ChatGPT, Microsoft and Google alike.<\/li>\n<li><strong>Consumer plans at Claude and ChatGPT do train by default<\/strong>, with an opt-out. That is the core of the problem.<\/li>\n<li><strong>Shadow AI is your real exposure:<\/strong> employees using personal free accounts with company data.<\/li>\n<li><strong>Data residency is usually an Enterprise feature<\/strong>, not part of the affordable business plans.<\/li>\n<li><strong>Four things no vendor solves for you:<\/strong> policy, roles, prompt hygiene and control over shadow usage.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">The three questions that count<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Data protection marketing is well executed at all four vendors and tells you little. What you actually need to know boils down to three questions:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Is our data used for training?<\/strong> By default, not &#8220;after appropriate configuration&#8221;.<\/li>\n<li><strong>From which plan onwards is it not?<\/strong> This is the question that decides the risk in practice.<\/li>\n<li><strong>Who is our contracting party, and what does the DPA say?<\/strong> Including location, retention and subprocessors.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">The overview<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th><\/th><th>Claude<\/th><th>ChatGPT<\/th><th>M365 Copilot<\/th><th>Google Gemini<\/th><\/tr><\/thead><tbody>\n<tr><td>Training on <strong>consumer plan<\/strong><\/td><td>yes, opt-out available<\/td><td>yes, opt-out available<\/td><td>\u2014<\/td><td>\u2014<\/td><\/tr>\n<tr><td>Training on <strong>business plan<\/strong><\/td><td>no (default)<\/td><td>no (default)<\/td><td>no<\/td><td>no<\/td><\/tr>\n<tr><td>Data processing agreement<\/td><td>for Team\/Enterprise<\/td><td>for Business\/Enterprise<\/td><td>part of M365 agreements<\/td><td>part of Workspace agreements<\/td><\/tr>\n<tr><td>Data residency<\/td><td>Enterprise: custom retention controls<\/td><td>Enterprise: 10 regions<\/td><td>EU Data Boundary, advanced residency<\/td><td>via Workspace settings<\/td><\/tr>\n<tr><td>Logging<\/td><td>audit logs (Enterprise)<\/td><td>compliance API (Enterprise)<\/td><td>prompts are logged<\/td><td>admin console<\/td><\/tr>\n<tr><td>EU contracting entity<\/td><td>Anthropic Ireland Limited<\/td><td>OpenAI Ireland<\/td><td>Microsoft Ireland<\/td><td>Google Ireland<\/td><\/tr>\n<\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft and Google have a dash in the first two rows because there are no &#8220;consumer plans&#8221; there in the sense meant here \u2014 Copilot and Gemini are obtained as business products through your existing licence. That is, if you like, a structural data protection advantage of those two: there is no cheap side door for employees to wander through by accident.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The core: the plan decides, not the vendor<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic lists an opt-out for training on the consumer plans Free, Pro and Max \u2014 meaning training is on by default unless you object. For the commercial products Team, Enterprise and API the position is: &#8220;By default, we will not use your inputs or outputs from our commercial products to train our models.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">OpenAI likewise shows &#8220;content is used to train our models \u2014 opt-out available&#8221; in the consumer plan comparison. For ChatGPT Business, by contrast, the commitment is explicit: your business data is not used for training.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From which follows the real insight of this article: <strong>your data protection exposure does not sit in the management decision but in the workforce.<\/strong> The managing director who selects Claude Team after careful review has not solved the problem while three employees continue using their personal free accounts for proposals and draft contracts. That shadow usage is the case I encounter most often \u2014 and it costs nothing in licence fees but potentially a great deal of everything else.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The specifics per vendor<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Claude<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No training by default on the commercial products. The practically important exception is the feedback button: pressing thumbs up or down transmits the <em>entire<\/em> conversation, which may then be stored in secured systems for up to five years after being decoupled from the user ID. Administrators can disable this feature organisation-wide \u2014 and in environments with sensitive data I would do exactly that before the first person uses it. Enterprise additionally brings SCIM, audit logs, configurable retention and role-based access. For EU services, Anthropic&#8217;s own website footer names Anthropic Ireland Limited as the provider.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">ChatGPT<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Business brings SAML SSO, multi-factor authentication and the commitment that business data is not used for training. The important difference from Enterprise: <strong>data residency across ten regions, SCIM, Enterprise Key Management, role-based access controls and custom retention policies are Enterprise features<\/strong>, not part of the Business plan. If your auditors insist on data residency, Business is not the answer.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Microsoft 365 Copilot<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Under the heading Enterprise Data Protection, Microsoft commits that prompts and responses stay within the Microsoft 365 service boundary and are not used to train the language models, with support for GDPR, ISO\/IEC 27018, the EU Data Boundary and Advanced Data Residency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One point you should know and actively communicate: <strong>prompts and responses are logged and subject to your retention policies.<\/strong> From a compliance perspective that is an advantage \u2014 it is auditable who asked what. From an employee perspective it is a piece of information that belongs on the table before the rollout, not after. Where a works council exists, it is a topic in any case.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Google Gemini<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Workspace business plans there is no training on your content. The practical advantage lies in the contractual landscape: if you have already reviewed and approved Workspace, using the included Gemini features is a considerably smaller step than introducing an additional vendor. Anyone booking the extended add-on should review its feature and data scope separately.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The four things no vendor solves for you<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is the part consulting conversations like to skip, because it is uncomfortable. No plan in the world replaces these four points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. A policy.<\/strong> One page, not twenty. What may go in, what may not, which account is permitted, who to ask when unsure. A policy nobody reads is not a policy; it is filing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. Roles and permissions.<\/strong> Who may use which account, who administers it, who removes it when someone leaves? That last point is the one regularly forgotten in small businesses \u2014 and an active AI account belonging to a departed employee is exactly the kind of finding that makes an audit unpleasant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Prompt hygiene.<\/strong> No complete personnel files, no credentials, no unredacted client data until that has been explicitly reviewed. This is not a technical question but a question of habit \u2014 and habits come from training, not from prohibitions in a document.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Control over shadow usage.<\/strong> The most important point and the only one that genuinely costs money: business accounts for everyone who needs one. Economise here and you push data processing into personal accounts over which you have neither knowledge nor control. That is more expensive than any licence.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A workable sequence<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Take stock:<\/strong> who already uses what, and with which account? Ask without threatening sanctions, or you will not get honest answers.<\/li>\n<li><strong>Buy the business plan<\/strong> for everyone using AI in a work context.<\/li>\n<li><strong>Check and document training and feedback settings<\/strong> \u2014 including a screenshot, so the review is traceable later.<\/li>\n<li><strong>Conclude the data processing agreement<\/strong> and have it countersigned by your data protection officer.<\/li>\n<li><strong>Write the policy<\/strong> and explain it in a training session rather than distributing it by email.<\/li>\n<li><strong>Prohibit personal accounts for company data<\/strong> \u2014 credible only once step 2 is done.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">For more depth on Claude in a business context, see <a href=\"https:\/\/pletzenauer.com\/en\/2026\/06\/10\/claude-desktop-gdpr-compliance\/\">Data protection and GDPR in practice<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently asked questions<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Is switching off training on the consumer plan enough?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Technically it reduces the risk; organisationally it is not a solution. You would then have a setting each person must apply and maintain individually, with no central way to verify it \u2014 and no data processing agreement. For business use the route runs through the business plan.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Which vendor is best from a GDPR perspective?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">At business plan level there is little between the four \u2014 all commit to not training on your content, all offer the usual contractual documents. Differences only emerge with specific requirements: if you need data residency in a particular region, the field narrows and usually gets more expensive. Anyone naming a clear winner without knowing your requirements is guessing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Do we need a data protection impact assessment?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">That depends on which data you process and at what scale \u2014 and that is precisely a question for your data protection officer, not a blog article. Prepare for the conversation by writing down the concrete use cases and data categories. It shortens things considerably.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What about the works council?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Where one exists, involve it early \u2014 particularly where prompts are logged, as documented at Microsoft. A rollout planned around co-determination rights costs more time than one that involves the works council from the start. That is not legal advice but a practical observation from projects.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">How often should we review this?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Once a year as routine, plus whenever a vendor changes its terms. Anthropic changed the training default for consumer plans in 2025 \u2014 changes like that do not arrive as a letter to the management board but as a notice inside the application.<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>No business plan trains on your content. The difference lies in the plan, not the vendor \u2014 and your biggest exposure is personal accounts.<\/p>\n","protected":false},"author":1,"featured_media":1995,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-1851","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-automatisierung"],"_links":{"self":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts\/1851","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/comments?post=1851"}],"version-history":[{"count":1,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts\/1851\/revisions"}],"predecessor-version":[{"id":1960,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/posts\/1851\/revisions\/1960"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/media\/1995"}],"wp:attachment":[{"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/media?parent=1851"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/categories?post=1851"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pletzenauer.com\/en\/wp-json\/wp\/v2\/tags?post=1851"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}