Using ChatGPT at Work: GDPR Rules for Swedish Firms
By CodexierPublished 6 min read
Most Swedish companies already use ChatGPT, Copilot or Gemini somewhere, usually without a decision ever being taken. GDPR does not forbid that. What it regulates is the personal data that ends up in the prompt, and who is responsible for it once it leaves your systems. This guide gives you a rule staff can follow in ten seconds and the paperwork that keeps you on the right side of IMY.
Why pasting customer data is the real risk
GDPR attaches to the data, not to the software. When an employee pastes a customer's name, personal number, email thread or health detail into a chat window, the company has just transferred personal data to a third party. On a consumer plan that third party may store the text, use it for training and process it outside the EU. None of that is covered by any agreement, so the transfer has no legal basis. The same text typed into an enterprise plan with a data processing agreement and EU processing is an ordinary, documentable processing activity. The difference is the contract, not the model.
Consumer, team and enterprise plans compared
The vendors have moved most of the compliance work into their paid business tiers. Read the current terms for the tool you use, but the pattern is consistent across ChatGPT, Copilot and Gemini:
| Question | Consumer / free plan | Team plan | Enterprise plan |
|---|---|---|---|
| Data processing agreement available | No | Yes, usually a standard DPA | Yes, negotiable |
| Prompts used for model training | Often yes unless you opt out | No by default | No |
| EU data residency option | No | Sometimes | Usually |
| Admin control over accounts and retention | None | Basic | Full, with audit logs |
| Suitable for personal data in prompts | No | With a DPA and a written policy | Yes, within your policy |
Terms change several times a year. Save a PDF of the DPA and the data-use terms you accepted, with the date, so you can show what applied when.
A traffic-light rule for staff
Policies that require a legal reading before every prompt are ignored. A three-colour rule is not. Put it on one page, with examples from your own business:
Green: use freely
Public information, generic drafts, code without secrets, translations of your own marketing text, brainstorming. No names, no customer details, no credentials.
Yellow: only in the company plan
Internal documents, pricing logic, anonymised customer cases, meeting notes with names removed. Allowed in the business account with a DPA, never in a private account.
Red: never paste
Personal numbers, health or financial details, HR matters, anything under NDA, passwords and API keys, unredacted support tickets. If it is needed, anonymise first or use an internal tool built for it.
Data processing agreements and transfers
Two documents decide whether the yellow category is actually allowed. The first is the data processing agreement under Article 28, which makes the vendor your processor and binds it to your instructions. The second is the transfer mechanism, because the major vendors are US companies. Check these points before you approve a tool:
- A signed or click-accepted DPA that names the vendor as processor and lists sub-processors.
- The transfer basis for data leaving the EU: certification under the EU-US Data Privacy Framework, or standard contractual clauses plus a transfer impact assessment.
- Retention: how long prompts and outputs are stored, and whether an admin can set it shorter.
- Training: an explicit statement that your content is not used to train models.
- Deletion on termination and the process for responding to a data subject request that involves prompt history.
If the vendor cannot give you these, the tool stays in the green category only. Many teams get most of the value from AI without pasting anything personal, and the AI integration audit exists partly to map which tasks can be done that way.
What to document for IMY
IMY does not expect a small company to run a legal department, but it does expect accountability: a written decision, a named owner and evidence that staff were told. This is the minimum file we recommend keeping:
- The one-page traffic-light policy, dated, with the tools it covers.
- A row in your record of processing activities for AI-assisted drafting and support, including purpose, categories of data and the vendor as processor.
- The DPA and data-use terms as accepted, saved as PDFs.
- A short training note: who was trained, when, and where the policy lives.
- A review date, at most yearly, because the vendors change their terms often.
When you do not need help with this: if your team uses AI only for green-category work and you have a business plan with a DPA, an afternoon with this checklist is enough. You do not need a consultant. Where an audit earns its fee is when AI is being wired into customer-facing processes, when several tools overlap, or when you cannot say today which accounts your staff are actually using. Then a mapped inventory is worth more than another policy. If that is your situation, book a short call and we will tell you honestly which it is. The related question of whether the EU AI Act adds obligations for a small deployer is covered in our AI Act guide.
Frequently asked questions
Is it illegal to use ChatGPT at work in Sweden?
No. GDPR regulates personal data, not software. Using an AI tool for drafting, coding or research with no personal data involved needs no special basis. The problems begin when staff paste customer or employee data into a plan that has no data processing agreement, no control over retention and possible training on the content.
Do we need a data processing agreement with the AI vendor?
Yes, as soon as personal data goes into the tool. The DPA makes the vendor your processor under Article 28. Consumer plans do not offer one, which is why they belong in the green category only. Business and enterprise plans normally include a standard DPA you accept in the admin console; save a copy with the date.
Can employees use their private ChatGPT accounts for work?
It is the worst of both worlds: the company is still the controller for what is pasted in, but it has no agreement, no admin control and no way to delete the history when the person leaves. Move everyone to a company plan, or restrict private accounts to green-category work in writing.
Not sure which of your AI tools are actually covered?
Fifteen minutes on a call: you list the tools your team uses, we tell you which need a DPA, which are fine as they are and whether a full audit is worth it.
Book a free 15-minute call