Deleting Customer Data from ChatGPT, Claude and Gemini Under GDPR
If a customer asks you to delete their data and your team has pasted it into ChatGPT, Claude or Gemini, you can delete the chats, and ChatGPT and Claude remove deleted chats from their systems within 30 days. You cannot pull the data back out of a model that has already been trained on it, and personal plans run under consumer terms, not a contract that lets you instruct the provider. The job is to find the chats, delete them, record what you did and tell the customer the truth. This guide covers the steps under GDPR and UK GDPR.
This is general information, not legal advice. If the data is sensitive or the customer is already unhappy, speak to a data protection adviser.
Why this is your problem, not the chatbot's
The customer gave their data to you. Under GDPR that makes you the controller, and the duty to erase sits with you, wherever your team has since put the data.
Two rules matter here:
- Article 17, the right to erasure. When a valid request arrives, you must erase the person's data without undue delay. Article 12 gives you one month to respond. The right has limits: you can keep records the law requires you to keep, such as invoices.
- Article 19, the duty to tell recipients. If you disclosed the data to anyone else, you must tell each recipient about the erasure, unless that is impossible or involves disproportionate effort. If the customer asks who received their data, you have to tell them.
A member of staff who pastes a customer's email thread into a chatbot has sent that customer's data to another company. That company is now on the list.
What deleting does on each chatbot
This is the position for personal accounts as of October 2026.
| ChatGPT | Claude | Gemini | |
|---|---|---|---|
| When you delete a chat | Removed from the account at once and permanently deleted within 30 days, unless OpenAI must keep it for legal or security reasons | Removed from chat history at once and deleted from back-end systems within 30 days | Removed from your activity. Chats already picked for human review are kept for up to three years |
| Does deleting undo training? | OpenAI does not say it does | No. A deleted chat is not used for future training, but stays in models already trained | Google does not say it does |
| Also check | Files saved to the Library are separate and have to be deleted as well | Whether model improvement was on. If it was, the chat may already be in a model trained before you deleted it | With Keep Activity off, chats are still held for up to 72 hours |
For what each provider keeps before you delete anything, see How to Mask PII in ChatGPT, Claude, and Gemini.
What you cannot do
You cannot untrain a model. If the chat was used for training before you deleted it, the model keeps what it learned. Anthropic says so directly: deleted data remains in models that have already been trained. A report commissioned by the European Data Protection Board describes erasure from a model as reversing what the model has memorised, and the methods for doing that are still research.
You cannot instruct the provider on a personal plan. Business plans come with a data processing agreement, which makes the provider your processor and gives you a contractual right to have data deleted. Personal plans run under each provider's consumer terms instead. You are one user asking a large company to delete something.
You cannot guarantee the provider's own deletion. In May 2025 a US court ordered OpenAI to preserve output logs it would otherwise have deleted, including chats users had asked it to delete. The order was lifted in October 2025, though OpenAI had to keep what it had already preserved. It showed that a provider's 30-day promise can be overridden from outside.
You may not be able to find it. Chats sit in individual accounts, often personal ones. There is no search across your team's chat histories.
What to do when the request arrives
- Log the date. You have one month to respond.
- Ask where the data went. Include AI chatbots in the question. Have each person search their chat history for the customer's name, email and order or account number.
- Delete those chats. Delete uploaded files as well. Note what was deleted, by whom and when.
- Check the training setting on each account. Note whether it was on when the data was pasted, then turn it off.
- Decide whether it is also a data breach. An unauthorised disclosure of personal data counts as one. If staff used a tool you had not approved, assess the risk to the customer. A breach that is likely to put people at risk has to be reported to your regulator within 72 hours of you becoming aware of it.
- Reply to the customer. Say what you deleted, what you could not, and which providers received their data if they ask.
- Keep a record. If a regulator asks later, the record is your evidence that you took the request seriously.
What to say to the customer
Plain and specific works better than vague reassurance. Something like:
We have deleted your data from our systems. Some of your details were also entered into an AI assistant by a member of our team. We have deleted those conversations, and the provider states it removes deleted conversations from its systems within 30 days. We cannot confirm whether that information was used to train the provider's models before deletion. We have changed how our team uses these tools so this does not happen again.
A customer can also go to the provider directly. OpenAI, for example, accepts requests through its privacy portal from people who want information about them removed from ChatGPT's responses, whether or not they have an account.
How to stop it happening again
Move work use onto a business plan. You get a data processing agreement and no training on your data by default, and some plans add admin control over retention. It costs more per person and needs someone to set it up.
Write a short policy, but do not rely on it. "Do not paste customer data into AI tools" is easy to write and widely ignored. Our GDPR guide for DPOs covers the options in more depth.
Mask customer data before it is sent. If the customer's name went to the chatbot as [PERSON_A], the provider holds a placeholder and there is far less to chase when an erasure request arrives. PiiBlocker is a free Chrome extension that does this on ChatGPT, Claude, Gemini, Perplexity, Grok, DeepSeek and Kimi. It masks card numbers, Social Security numbers and API keys automatically, and flags names, emails and addresses for one-click masking. Detection runs in the browser, and the link between each placeholder and the real value is encrypted and expires after four hours.
Masking is not a guarantee. No detector catches everything, and the text around a masked name can still point to a person. For the steps, see how to mask personal data before pasting into ChatGPT.
Frequently asked questions
Does deleting the chat satisfy a GDPR erasure request? It deals with the stored copy. It does not reach a model already trained on the data, and you still have to delete the data from your own systems and reply to the customer within one month.
Do I have to tell the customer their data went into ChatGPT, Claude or Gemini? If they ask who received their data, yes. GDPR requires you to tell a person which recipients you disclosed their data to when they request it.
Can OpenAI, Anthropic or Google remove someone's data from a trained model? Not in any practical way today. They can delete stored conversations and stop using them for future training. What a model has already learned stays in that model.
Is pasting customer data into a personal chatbot account a data breach? It can be. An unauthorised disclosure of personal data meets the definition. Whether you have to report it depends on the risk to the people affected, so assess it and record your decision.
Does this apply to UK businesses? Yes. UK GDPR has the same right to erasure, the same one-month deadline and the same duty to tell recipients.
Sources
- GDPR Article 17 and Article 19, accessed October 11, 2026
- OpenAI: Chat and File Retention Policies in ChatGPT, accessed October 11, 2026
- OpenAI: Right to be forgotten and personal data removal from ChatGPT, accessed October 11, 2026
- Anthropic: How long do you store my data?, accessed October 11, 2026
- Google: Gemini Apps Privacy Hub, accessed October 11, 2026
- European Data Protection Board: Effective implementation of data subjects' rights in AI systems, accessed October 11, 2026
- Malwarebytes: OpenAI forced to preserve ChatGPT chats, June 6, 2025
- Engadget: OpenAI no longer has to preserve all of its ChatGPT data, with some exceptions, October 11, 2025
- Anthropic: How do I view and sign your Data Processing Addendum (DPA)?, accessed October 11, 2026
- Google: Use Gemini Apps with a work or school Google Account, accessed October 11, 2026
- OpenAI: Services Agreement, accessed October 11, 2026
PiiBlocker is a free Chrome extension that masks personal data before it reaches AI chatbots. The free version runs in your browser and makes no network calls. Install from the Chrome Web Store.