Home / Blog
· Chandra Tungathurthi

ChatGPT and GDPR: The Alternative Is Running Your Own AI

Machine translation of the German original.

Can ChatGPT be used GDPR-compliantly? The honest answer: not the public version, Enterprise only conditionally, and an EU region does not solve jurisdiction. The alternative that became realistic in 2026: running the AI yourself. With comparison table and the case record.

Every company knows the scene by now: the teams want ChatGPT because it takes real work off their hands. The data protection officer says no, because nobody can prove where the inputs end up. Both are right. This post sorts the options honestly and shows the path that became realistic in 2026: running the AI yourself.

Why public ChatGPT is out for company data

Three facts suffice. The Italian data protection authority (Garante) fined OpenAI 15 million euros. A US court ordered OpenAI to preserve ChatGPT logs, explicitly including deleted conversations. And under the CLOUD Act, US providers must hand over data they control, regardless of where the servers stand. Whoever types contracts, customer data or source code into a public US tool has given up control over them. Not maybe. Structurally. The cases are documented as case files on the home page, with sources.

Public ChatGPTPrompt goes to US serversUS law, US access US cloud, EU regionPrompt goes to Frankfurt,provider stays a US companyCLOUD Act still applies Your infrastructurePrompt stays in-houseYour law, your control An EU region moves the geography, not the jurisdiction. Only the third column changes whose law applies.
Where does your prompt go? Three architectures, one decisive difference.

The European alternatives, honestly placed

The usual lists recommend European providers: Mistral with Le Chat from Paris, DeepL from Cologne, German platforms with servers in Germany. That is not bad advice, and for uncritical tasks it is often the fastest step. But thought through cleanly, those lists only swap the landlord: your data still flows to a third party, you still pay per seat or per token, and someone else still decides what the model can do. A European landlord is better than a US landlord. Ownership is a different category. That is what the rest of this post is about.

The options, compared

ChatGPT (public)ChatGPT EnterpriseAzure OpenAI, "EU region"Run your own
Training on your dataPossibleContractually excludedContractually excludedDoes not happen
US jurisdiction (CLOUD Act)YesYesYes, despite the EU regionNo
Where your prompts landUS serversThe provider's serversEU datacenter of a US providerYour infrastructure
Cost modelFree to subscriptionPer seat, foreverPer token, foreverBuild once, then operate
Evidence for your DPO and works councilBarely possibleContract paperworkContract paperworkArchitecture: data never leaves the house

The Enterprise and Azure columns are better than their reputation and worse than their marketing. The contracts are solid, but they change nothing about jurisdiction: Microsoft's own legal director testified under oath in 2025 that EU customer data cannot be guaranteed to stay beyond US reach. An EU region answers where the servers stand. Not whose law applies.

Running your own: no longer a research project

For years the objection was: too expensive, too complex, too weak. All three objections have aged. Small open models deliver reliable results once they are fine-tuned for a concrete task, on hardware a mid-sized company already owns or can buy for the price of a few years of enterprise licenses. The proof is running in your browser right now: the chat bar at the top of this page is a fine-tuned language model computing entirely on your device. Not a byte of your questions leaves it. If that works in a browser tab, it works on a server in your rack.

Typical first use cases with my clients: an internal assistant that answers from your own documents. Document review that reads contracts without contracts leaving the building. Product data enriched and classified automatically (PIM, ETIM). All tasks where a specialist under your control beats a brilliant generalist under someone else's.

Frequently asked questions

Is ChatGPT Enterprise GDPR-compliant?

It is more compliant than the public version: no training on your data, contracts, retention terms. What remains is the structural question: a US provider is subject to US law, whatever the contract says. Whether that is acceptable for your data is a risk decision, not a compliance checkbox.

Isn't Azure OpenAI in an EU region enough?

For some workloads, yes. But an EU region solves geography, not jurisdiction: the CLOUD Act follows the provider, not the datacenter. The clean line: uncritical workloads may go to the cloud; sensitive AI workloads (prompts, documents, logs) belong inside your own perimeter.

What does your own AI cost?

It depends on scope, which is why I do not quote figures on a website. The structure is what matters: instead of paying per seat per month forever, you build once and then operate. Past a certain team size the math tips quickly toward ownership. In a free first consultation we run your numbers concretely.

Break-even self-hosting is cheaper from here on Cloud subscription per seat/token, forever Self-hosted build once, then operate Time → Cost → Build
Schematic: rent grows with usage and time, self-hosting costs a build once and then runs flat. Where the break-even sits depends on team size and workload; that is exactly what we calculate in the first consultation.

How long does the rollout take?

A pilot takes weeks, not quarters: a working system on your data, inside your landscape, with real metrics. Then you decide about scaling up with evidence.

And the EU AI Act?

It tightens transparency and documentation duties. Self-hosting makes exactly those proofs easy: you can show at any time where data is processed, because the answer is: at your place.

The honest next step

If your teams want ChatGPT and your data protection says no, that is not a stalemate. It is a design task. The solution is rarely "ban everything" and rarely "allow everything". It is a line: what may go to the cloud, and what has to be yours. Drawing that line, and building your side of it, is exactly my work.

The twin at the top of this page answers first questions about this, directly on your device. For everything else: the first consultation is free.

Chandra Tungathurthi
Chandra Tungathurthi is an AI consultant and technical architect in Essen, Germany. He builds sovereign enterprise AI for DACH companies: systems that run in the EU or inside the client's own infrastructure. More about him.