Blog

Is ChatGPT or Claude GDPR-Compliant? What Health Practitioners Need to Know

By John Garvi· MSc Computer Science, Nutritionist· July 21, 2026
Photo by Shantanu Kumar on Unsplash

Short answer: the question is framed wrong. ChatGPT and Claude are not compliant or non-compliant as products. The tier you use, the agreement that comes with it, and what you paste into it decide whether your use is defensible.

Understanding the Responsibility: Controller and Special Category Data

As a nutritionist or dietitian, you are the controller of your clients' data. This means you decide how and why their personal data is processed. Health data falls under GDPR's Article 9, which categorizes it as special category data. This requires a higher level of protection due to its sensitive nature. Therefore, the responsibility of ensuring compliance falls heavily on you, the practitioner.

Tier Comparison: ChatGPT and Claude

Service

DPA Available

Trains on Inputs by Default

EU Residency

ChatGPT Free/Plus

No

Yes

No

ChatGPT Team/Enterprise

Yes

No

Yes

OpenAI API

Yes

No

Yes

Claude Consumer

No

Yes

No

Claude for Work/API

Yes

No

No

Usage Postures and Verdicts

  • Consumer tier, no client data: Fine and useful for general tasks.

  • Consumer tier + client data: Indefensible. No DPA and potential data training risks.

  • Business/API tier with executed DPA: Defensible with proper configuration and DPIA (Data Protection Impact Assessment). Suitable for organizations but heavy for solo practices.

Residency: SCCs vs EU-region

Standard Contractual Clauses (SCCs) are often used for data transfers outside the EU. However, if your practice requires EU-region processing for compliance, ensure your service provider offers this option. Azure OpenAI, for instance, provides EU-region processing.

Regulatory Direction

Recent regulatory actions indicate a tightening of controls around AI and data privacy. Italy's temporary ban on consumer ChatGPT in 2023 and the ICO's fine on MediaLab.AI in 2026 highlight the importance of compliance. Additionally, the EU AI Act requires AI tools to disclose their nature to users starting August 2026.

AI Tool Compliance Checklist

  1. Is there a DPA on my tier?

  2. Does the tool train on inputs?

  3. Where is the data processed?

  4. Could this data identify a client?

  5. Have I documented why this use is compliant?

Notrispace: A Workspace Built for Nutrition Practice

Notrispace offers a comprehensive workspace designed specifically for nutritionists and dietitians. It integrates records, notes, bookings, messaging, meal planning, and billing into one system. The AI features, such as drafting notes and flagging lab markers, work within the platform, ensuring client data remains secure. Notrispace is built on UK/EU GDPR principles from day one, making it a reliable choice for practitioners handling sensitive health data.

Remember, if you'd need a client's consent to share it with a stranger, it doesn't go in a consumer chatbot. Always ensure your tools and practices align with GDPR requirements. For more insights on using AI in your practice, check out our article on AI assistants for nutritionists.

Related

Build the full workflow

Run your practice in Notrispace

Is ChatGPT GDPR Compliant?