Using AI Under GDPR, HIPAA and PCI DSS: What Data You Can Send
Updated · EraseAI
Data protection law doesn't stop at the AI chat box. When someone pastes personal, health or payment data into an AI tool, your organization is sharing it with a third party, and the usual rules apply. This guide gives a practical overview; it is not legal advice.
GDPR (EU and UK)
- You need a lawful basis to process personal data in an AI tool, and the use must match the purpose the data was collected for.
- The AI provider is usually a processor, so you need a data processing agreement. Consumer accounts generally don't offer one.
- International transfers need safeguards when the provider processes data outside the EU or UK.
- Data minimization applies: send only what the task needs. Redacting identifiers before sending is the simplest way to comply.
- Regulators are active: Italy's data protection authority fined OpenAI €15 million in 2024.
HIPAA (US healthcare)
- Protected health information (PHI) may only go to a vendor that has signed a business associate agreement (BAA).
- Most consumer AI tools don't sign BAAs. Some enterprise and API offerings do, under specific configurations.
- De-identifying data under HIPAA's Safe Harbor or Expert Determination methods takes it outside HIPAA's scope.
PCI DSS (payment cards)
- Full card numbers (PANs) must not be stored or sent outside your cardholder data environment.
- An AI tool that receives a card number becomes part of your PCI scope, which almost no AI tool is set up for. Never paste card numbers into AI.
Other rules to know
- EU AI Act: sets obligations by risk level for AI systems and general-purpose models, phased in from 2025.
- Sector rules: financial regulators, legal professional rules on client confidentiality and public-sector data rules may be stricter than general privacy law.
- Contracts: many client contracts restrict sharing their data with third parties, including AI providers.
Safeguards regulators expect
- An inventory of AI tools and what data they receive.
- Business plans with processing agreements for approved tools.
- A written acceptable use policy.
- Technical controls that stop restricted data being sent, such as PII redaction at the point of use.
- Records of what was blocked or redacted, to show the controls work.
Check every message before it reaches AI
EraseAI stops API keys, passwords, card numbers and personal data in ChatGPT, Claude and Gemini. Free in Chrome, no account needed.
Frequently asked questions
Is using ChatGPT GDPR compliant?
It can be, with a business plan that includes a data processing agreement, a lawful basis, transfer safeguards and data minimization. Pasting customer personal data into a personal ChatGPT account is very unlikely to be compliant.
Can I put patient information into AI?
Only into a tool covered by a business associate agreement and configured as required, or after the data has been de-identified. Otherwise, no.