Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

System in use

ChatGPT is already in use

The body that sets the task decides on purpose and means and is therefore the controller under Art. 4(7) GDPR, even where the account is private. Without a contract under Art. 28(3) GDPR there is no instruction, no list of sub-processors and no assistance with data subject rights. A governed access supplies all three and makes the use documentable in the first place.

A language model in use without approval

Two departments have been working with a language model for months. The accounts run on private addresses, the tasks are the employer’s, and the prompts contain customers’ names. There is no approval, and there is no ban either.

A private account does not change who the controller is

Who the controller is follows from Art. 4(7) GDPR and from the decision on purposes and means. The purpose is set by the task, and the task comes from the employer.

That leaves an uncomfortable position. The controllership sits with the employer, the data sit in an account the employer cannot reach, and the demonstration under Art. 5(2) GDPR is owed for processing it does not know about.

Without a contract three things are missing, and all three are needed

What is missing without a contract with the provider can be named precisely, because Art. 28 GDPR lists it.

Three arrangements a private access does not bring with it

Being bound by instructions

Under Art. 28(3)(a) GDPR a processor processes only on documented instructions. A consumer account knows no instructions but terms of use, and the provider determines their content.

Authorisation of sub-processors

Under Art. 28(2) GDPR every further processor requires authorisation. Without a contract there is no list, and so the question under Chapter V of the Regulation cannot be answered either.

Assistance with data subject rights

Under Art. 28(3)(e) GDPR the processor has to assist with requests from data subjects. Without that commitment, information under Art. 15 GDPR remains owed and cannot be provided.

The governed access is the stricter arrangement

What a governed access changes is usually misread as a permission. The comparison, though, is not access against nothing but access against a use nobody knows about.

Two situations, the same controllership

Private accountMerkmalCorporate access
With the employerArt. 4(7) GDPR. It follows the task and not the account.ControllershipWith the employer
NoneContract with the providerUnder Art. 28(3) GDPRWith instructions, a list of sub-processors and a duty to assist.
Only by instructionLimiting inputsTechnically possibleThrough settings on the use of inputs and through the choice of which functions are enabled.
Not possibleWithout knowledge there is no entry under Art. 30(1) GDPR and no demonstration under Art. 5(2) GDPR.Demonstration and recordPossible

The first column is not the more restrained arrangement but the one in which none of what the statute requires can be done. That is why an approval is the stricter decision here.

How we support you in using ChatGPT

First the need is surveyed, without sanction, because without it the choice of edition is a guess. Then a corporate access is procured, with the contract under Art. 28(3) GDPR and with the settings on the use of inputs. Last comes the entry in the record, and only then is the use documented. The order matters, because an access procured without a surveyed need enables the wrong functions.

Frequently asked questions

Is use through a private account prohibited?

No prohibition follows directly from the statute. The processing is lawful only where a legal basis exists and the provider's role is settled. Without a contract under Art. 28(3) GDPR that settlement is missing, and the demonstration under Art. 5(2) GDPR cannot be made.

What happens on an access request?

The right under Art. 15 GDPR runs against the controller, that is, against the employer. Where the prompts sit in a private account, the employer has no access to them and no contractual assistance under Art. 28(3)(e) GDPR. The information is nonetheless owed.

Is it enough to forbid entering personal data?

As a measure yes, as a demonstration no. An instruction without technical safeguards and without a log cannot be evidenced, and Art. 5(2) GDPR requires the demonstration. Through a corporate access, inputs can at least in part be limited and logged.

Does a governed access not cost more than a ban?

In licences yes, in demonstrability no. Without an access the use continues but cannot be documented, and the controllership remains. The comparison is therefore not access against nothing, but access against unknown use.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.