ChatGPT in the Company: Trade Secrets, the AI Policy and What Works Technically Instead of a Ban
The question whether employees may use ChatGPT has long been answered in most companies, just not by management. It is answered every day at the desk, with a private account and a customer letter on the clipboard. A ban changes little about that; it only makes sure it happens in secret and nobody asks any more.
This article answers the question the way a managing director should ask it: what does the German Trade Secrets Act require, what do the GDPR and the AI Act require, which version of a chat service tolerates which data, what belongs in a policy that fits on one page, and which technical access makes the ban unnecessary.
In brief: Under § 2 no. 1 of the Trade Secrets Act (GeschGehG) information is only a protected trade secret if its holder has taken reasonable confidentiality measures. Unregulated input into external AI services is the opposite of that. The consumer version of ChatGPT offers no data processing agreement and can use inputs for training; business versions and the programming interface exclude that by default and offer a data processing agreement under Art. 28 GDPR. The solution is therefore not a ban but a company account with four data classes, a one-page policy and documented training that also satisfies Art. 4 of the AI Act.
What happens if nobody regulates it?
The best-known thing that can happen happened at Samsung in 2023: according to media reports, engineers entered internal source code and meeting notes into ChatGPT to save themselves work. The group then prohibited the use of generative AI on company devices. The case is often told as an argument for a ban. It is the opposite: the inputs happened before there was a rule, and the ban came when the code was already with the provider.
In mid-sized companies the case looks less spectacular and is therefore more frequent. The sales representative has the quote for a major customer rephrased, terms included. The HR officer summarises three applications, names included. The accountant asks how an invoice with a particular VAT identification number should be treated. Each of these inputs is meant harmlessly and each is, depending on account and settings, a transfer to a provider outside the EU without a contract.
The IBM report Cost of a Data Breach 2025 puts the average cost of a breach in organisations with high use of unapproved AI tools at 4.63 million US dollars, around 670,000 US dollars more than in organisations without such shadow AI. The figures are calculated across large companies, but the mechanism is the same: what was entered without a rule can afterwards be neither recalled nor explained.
What does the Trade Secrets Act require?
That the holder protects the secret itself before the law does. That is the point that surprises most companies.
§ 2 no. 1 GeschGehG defines a trade secret by three criteria: the information is not generally known and therefore of commercial value, it is the subject of reasonable confidentiality measures by its holder, and there is a legitimate interest in keeping it secret. The middle criterion is a precondition, not a recommendation. Anyone who cannot evidence reasonable measures has, in a dispute, no trade secret but merely information they would have liked to keep secret.
§ 4 GeschGehG then prohibits obtaining, using or disclosing a trade secret without authorisation; §§ 6 to 8 give the holder claims for injunction, removal, destruction, surrender and information, § 10 a claim for damages, and § 23 makes intentional violations a criminal offence. All of that only helps once the first hurdle is cleared. For AI use that means: the policy that regulates what may go into which service is not a compliance exercise but the evidence that establishes protection in the first place.
What counts as a reasonable measure depends on the value of the information and the size of the company. For AI use five building blocks have proven themselves:
| Measure | What it achieves | Effort |
|---|---|---|
| Four data classes mapped to tools | Everyone knows what may go into which tool without asking case by case | One afternoon |
| Written AI policy | Evidences that the company has regulated the handling | One page |
| Technical separation: company access with a data processing agreement, consumer accounts not approved | Makes the rule enforceable instead of merely asserted | One to two weeks |
| Confidentiality clauses in employment contracts that expressly name AI services | Closes the gap between general confidentiality and the specific tool | Legal review |
| Documented training | Also satisfies Art. 4 of the AI Act and evidences that the rule was known | Two hours per year as a rule of thumb; Art. 4 prescribes no duration |
Which version tolerates which data?
The answer is not in the law but in the provider's terms, and it differs considerably by type of access. The following overview applies to ChatGPT according to OpenAI's statements on its Enterprise Privacy, Help Center and Data Processing Addendum pages, checked on 14 September 2026; for other providers the structure is the same, the terms have to be checked afresh before every contract.
| Access | Data processing agreement | Use of inputs for training | Data processing in the EU | Suitable for |
|---|---|---|---|---|
| Consumer version (free or individual subscription) | No | Yes by default, switchable off in the account | No | Public information: rephrasing texts, research, ideas |
| Business versions (ChatGPT Business, ChatGPT Enterprise) | Yes | No by default | Storage in Europe selectable for new Enterprise and Edu workspaces, not on the Business plan | Internal data without personal reference; with contract and storage in Europe also personal data |
| Programming interface with own integration | Yes | No by default | Europe as project region for enterprise customers approved for advanced data controls, otherwise via a European access route to the models | Customer data in own applications, with upstream filtering |
| European provider or own hosting | Yes, under German or EU law | No, where excluded by contract | Yes | Professional secrets under § 203 StGB, particularly sensitive data |
The rightmost column is the data classification every policy needs, and it has four levels:
- Public: what is on the website or in the press release. May go into any tool.
- Internal: what employees know and customers do not: process descriptions, templates, uncritical figures. Only into tools with a data processing agreement and without training use.
- Confidential and personal: customer data, personnel data, quotes, contracts. Only into tools with a contract, training use excluded and data processing in the EU, or via an own integration that removes personal data before handover.
- Secret: calculations, source code, formulas, everything that falls under the Trade Secrets Act, plus professional secrets under § 203 StGB. Only into systems under own control or with providers that sign the obligation under § 203 para. 4 StGB. Where a language model may run for that is set out in the article on LLM hosting under § 203 StGB.
With this table the question "may I enter that?" can be answered without asking in almost all cases. That is the purpose of the exercise: not bans, but decidability at the desk.
What the GDPR and the AI Act additionally require
Three things, and none of them is new.
Art. 28 GDPR: the data processing agreement. As soon as personal data is entered into a tool, the provider is a processor, and without a contract the processing is unlawful. For providers outside the EU the requirements of Art. 44 et seq. GDPR on third-country transfers come on top; the EU-US Data Privacy Framework covers certified US providers but does not replace the contract. The data processing agreement is also the document in which the exclusion of training use is written.
Art. 4 AI Act: the literacy duty. Since 2 February 2025 every deployer must ensure that its staff has sufficient AI literacy. Anyone who lets ChatGPT be used professionally is a deployer. The training that explains the policy fulfils this duty; it must be documented. What the duty requires and what does not threaten is in the article on the AI literacy duty.
Art. 50 para. 4 AI Act: labelling. AI-generated texts must be labelled if they are published to inform the public on matters of public interest and nobody has reviewed them editorially. That does not apply to quotes, emails and internal documents. It can apply to articles on the website; review by a human before publication resolves the question. All cases are in the article on the labelling duty.
What belongs in the AI policy?
One page. Anything longer is not read, and a policy nobody knows is not a reasonable confidentiality measure. The page contains eight points:
- Approved tools, with version and access: which account, which provider, who grants access.
- The four data classes and the mapping of which class may go into which tool. As a table, not as prose.
- Tools not approved, expressly: consumer accounts for classes 2 to 4, browser extensions with access to page content, dictation and translation services without a contract.
- Checking of outputs: every output is checked by a human before being passed on to customers or authorities. Responsibility for the content stays with the person who uses it.
- Labelling towards the outside where Art. 50 of the AI Act requires it, and labelling internally where the company wants it.
- Contact person for doubtful cases, by name. The question "may I do that?" must be answerable in five minutes, otherwise it is not asked.
- Training: who, when, how often; participation is documented.
- Violations: what happens, graded from a reminder to consequences under employment law.
A note on co-determination: a policy that regulates how employees do their work with a tool concerns, according to the decision of the Hamburg Labour Court of 16 January 2024, work conduct and is not in itself subject to co-determination. A company account whose usage logs the employer can inspect, by contrast, is a technical device suitable for monitoring. When the works council co-determines and how logging is built so that it counts transactions rather than people is in the article Works council and AI adoption.
Why the company account replaces the ban
Because a ban does not prevent use but makes it invisible, and because the alternative costs less than a single data breach.
A company account is at first only a contract: business version or programming interface, data processing agreement, training use excluded, data processing in the EU. With that, data classes 1 and 2 are approved immediately, and the largest part of everyday needs is covered: texts, summaries, translations, research.
For class 3 the technology comes in that makes the difference between a rule and its enforcement: an own integration that sits between employees and provider. It removes personal data before handover or replaces it with placeholders, it enforces the data classes technically rather than by trust, and it logs transactions, not people, so that co-determination stays short. Such an interface is sensibly operated within the EU and filters before anything leaves the company.
For class 4 what remains is a system under own control or a provider that signs the obligation under § 203 StGB. That is more expensive, but concerns only the smallest part of the data and the smallest circle of employees.
The result is a rule that can be kept because keeping it is more convenient than circumventing it: the approved tool is reached faster than the private account, it can do more, and it does not ask.
Implement in three weeks
Week 1: classes and policy. The four data classes are gone through with the departments; each department names its typical inputs, and the mapping emerges from real examples rather than definitions. The policy is written on one page and presented to the data protection officer.
Week 2: access and contract. The business version or programming interface is procured, the data processing agreement concluded, training use excluded, EU processing set. Consumer accounts are not blocked but made superfluous. If class 3 is needed, the integration with filtering begins.
Week 3: training and information. Two hours of training as a guide value, on real inputs from week 1, with an attendance list. Information of the works council if a company account with logs is introduced; information of the workforce in any case. From then on the policy applies, and from then on it is a reasonable confidentiality measure.
Frequently asked questions
May employees use ChatGPT for work? Yes, if it is settled which data may go into which version. Customer data, personnel data and trade secrets have no place in the consumer version, because there is no data processing agreement and inputs can be used for training by default. A company account with a data processing agreement and training use excluded tolerates far more. On top, since February 2025 Article 4 of the AI Act requires staff to be trained.
Do we lose protection as a trade secret if employees enter data into ChatGPT? That is the real risk. Under § 2 no. 1 of the German Trade Secrets Act (GeschGehG) a trade secret is only protected if its holder has taken reasonable confidentiality measures. Anyone who neither regulates nor controls input into external AI services hands the other side the argument in later proceedings that the measures were not reasonable. A policy with an approved list, a technical separation and documented training are such measures.
Does the provider train on our inputs? In the consumer version of ChatGPT, according to the provider, yes by default, switchable off in the account settings. In the business versions and via the programming interface, no by default. Check the terms at the time of contracting and record the result in the AI inventory; providers' rules change.
Do we need a data processing agreement with the AI provider? As soon as personal data is entered, yes, under Article 28 GDPR. Providers offer one for business versions and programming interfaces, not for consumer accounts. A consumer account into which customer data is copied is therefore not a borderline case but a breach.
What belongs in the AI policy? On one page: the approved tools with version, the four data classes and which of them may go into which tool, the duty to check every output before passing it on, labelling towards the outside, a contact person for doubtful cases, training and what happens on violations. Everything else belongs in the training, not in the policy.
Does the works council have to co-determine on ChatGPT? For private accounts without employer access, according to the decision of the Hamburg Labour Court of 16 January 2024, no. For a company account whose usage logs the employer can inspect, the system is suitable for monitoring and § 87 para. 1 no. 6 BetrVG applies. Logging can be built so that it counts transactions rather than people; that shortens the agreement considerably.
Conclusion
The Trade Secrets Act only protects those who protect themselves, and the GDPR only permits what is regulated by contract. Neither speaks against ChatGPT in the company but against the unregulated state in which it runs in most businesses today. Four data classes, one page of policy, a company account with a contract and two hours of training are the whole difference between a risk nobody sees and a tool everyone may use.
What a filtered company access looks like technically and how it connects to existing systems is on the page on AI process automation; what the managing director answers for in the adoption as a whole is in the guide Introducing AI in a mid-sized company.
This is not legal advice. Whether specific measures are reasonable within the meaning of the Trade Secrets Act and how confidentiality clauses should be drafted is for a lawyer to determine; providers' terms are to be checked at the time of contracting.
Sources
- § 2 GeschGehG - Definitions - Gesetze im Internet
- § 4 GeschGehG - Prohibited acts - Gesetze im Internet
- § 23 GeschGehG - Violation of trade secrets - Gesetze im Internet
- Art. 28 GDPR - Processor - gdpr-info.eu
- Article 4 AI Act: AI literacy - artificialintelligenceact.eu
- Enterprise privacy at OpenAI - OpenAI
- Data Processing Addendum - OpenAI
- Samsung Bans ChatGPT, Google Bard, Other Generative AI Use by Staff After Leak - Bloomberg
- Cost of a Data Breach Report 2025 - IBM
- First ruling on works council rights when AI is used (Hamburg Labour Court, 24 BVGa 1/24) - Bird & Bird
AI process automation with a legal framework
One bounded process first, with a data processing agreement, EU hosting and the technical documentation the works council and the data protection officer want to see.
More Articles
AI Automation for SMEs: A Guide to Boosting Efficiency in 2025
36 percent of German firms cannot fully fill open positions, according to the DIHK. Which processes can be automated first, how to recognise them, and why most projects fail.
WhatsApp Business API & AI: How Companies Generate More Revenue
WhatsApp reaches customers more reliably than email. But without documented consent under Section 7 UWG, every promotional message is a legal risk. What has to be settled first.