"Data leaks? Not my problem. That's on OpenAI." That's the reflex. It is false. Under the GDPR, the moment you chose to paste that document into ChatGPT and hand the data to the tool, you became the one who has to answer for it first, before anyone else does. So who does what here? Here is each party's role.
| Actor | Their role |
|---|---|
| You (who send the document) | Data controller. You decide to use the AI: the main responsibility is yours. |
| The AI provider | Processor. It processes for you under its terms, but that does not relieve you of your responsibility. |
| The data subject | Their rights apply (information, access, erasure). It is up to you to answer for them. |
Note: this is a general explanation, not legal advice. The exact split of responsibilities depends on the contract and context. Have your case validated by your DPO or counsel.
Why the responsibility stays yours
The AI provider? A processor. It acts on your behalf, full stop. But the decision to send the data was yours, as the data controller, which means you are the one who, when the day comes, will have to justify that processing before the data subject and the authority and bear any leak that follows. Nobody else.
The best protection: do not send identity
The simplest way? Remove the target. No identifying data, no leak possible. Once the document leaves pseudonymized, stripped of everything that points to a real person before it ever leaves your machine, there is no breach to manage and no liability to bear on that point. Nothing left.
Safe-Doc does exactly that. It removes identity before the AI, which cuts the risk at the root instead of cleaning up afterwards, processes in the European Union, then purges. Nothing lingers. To go further, see the ChatGPT and GDPR at work guide.
The liability is yours. Reduce it: pseudonymize before the AI.