TL;DR: Using consumer-tier ChatGPT, Claude.ai, or personal Gemini for work is the single most common AI compliance mistake. All three providers have strong enterprise protections, but only at specific paid tiers; the gap between consumer and enterprise data handling is significant.
Most AI governance guides compare ChatGPT, Claude, and Gemini on features. This one compares them on compliance: data training policies, DPA availability, EU data residency, audit logs, and what plan your team actually needs to get meaningful protections.
The most important finding is consistent across all three: the consumer tier and the enterprise tier are not the same product from a data handling perspective. They share a name and a similar interface, but the terms governing what happens to your data are different in ways that matter for any organization with GDPR obligations, client confidentiality requirements, or a security policy that prohibits data leaving defined boundaries.
Understanding the tier structure
Each provider sells multiple products under the same brand name. Before comparing providers, it is worth understanding the tier structure within each one.
OpenAI / ChatGPT:
- ChatGPT Free: consumer product, data may be used for training by default
- ChatGPT Plus: individual subscription, training opt-out available but not default
- ChatGPT Team: small team product, no training on data by default, DPA available
- ChatGPT Enterprise: no training, full DPA, SOC 2, admin controls, audit logs
- OpenAI API: developer access, no training on data by default, DPA available
Anthropic / Claude:
- Claude.ai Free: consumer product, data may be used for training
- Claude.ai Pro: individual subscription, similar terms to Free with some improvements
- Claude for Work (Team/Business): no training on data, DPA available
- Claude for Work (Enterprise): no training, full DPA, admin controls, SSO
- Anthropic API: developer access, no training by default, DPA available
Google / Gemini:
- Gemini (gemini.google.com, personal account): consumer product, standard Google privacy terms
- Gemini Advanced (Google One AI Premium): individual subscription, some improved terms
- Gemini for Google Workspace (paid Workspace): no training on Workspace data, DPA included in Workspace terms
- Gemini Enterprise / Business: full enterprise controls, admin policies
The pattern is consistent. Free and personal subscription tiers have weaker data protections and are designed for consumer use. Team, Business, and Enterprise tiers have the data processing agreements, no-training guarantees, and admin controls that organizations need.
ChatGPT compliance profile
Training on your data:
- Free/Plus: yes, by default. Opt-out available in settings (Settings, then Data controls), but it must be done by each user individually. Not enforceable at an organizational level.
- Team: no training on team data by default. This is a policy-level guarantee, not opt-out dependent.
- Enterprise: no training, no exceptions. Inputs and outputs are not used for model improvement.
Data residency:
- OpenAI processes data in the US (primarily). EU data residency is not available as a standard option. For EU customers, GDPR compliance relies on Standard Contractual Clauses for US-to-EU transfers.
DPA availability:
- Available for ChatGPT Team and Enterprise, and for API customers. Covers GDPR controller-processor relationship and includes SCCs.
- Free and Plus: no DPA available.
SOC 2 Type II: Yes, available for Enterprise customers.
Audit logs: Available at Enterprise tier. Team tier has limited admin visibility but not full audit logs.
EU-specific features: No EU data residency. SCCs provided for transfer compliance. OpenAI has published GDPR documentation and appoints EU representatives.
The key limitation for EU-focused teams: OpenAI cannot offer data residency in the EU as of 2026. If your compliance requirements specify that data must not leave the EU, ChatGPT (at any tier) cannot currently meet that requirement without additional technical and legal mitigations.
For a detailed comparison of the Team and Enterprise tiers specifically, see ChatGPT team vs enterprise compliance 2026.
Claude compliance profile
Training on your data:
- Claude.ai Free/Pro: conversations may be used to improve Anthropic's models. Anthropic's privacy policy allows this for consumer accounts.
- Claude for Work (all tiers): no training on customer data. Anthropic is explicit and consistent on this point. Conversations through Claude for Work plans are not used for model training.
- Anthropic API: no training on API inputs/outputs by default.
Data residency:
- Anthropic processes data in the US. No EU data residency option as of 2026. GDPR compliance relies on SCCs.
DPA availability:
- Available for Claude for Work (Business and Enterprise). Includes GDPR-relevant terms and SCCs.
- Consumer plans: no DPA available.
SOC 2 Type II: Yes.
Audit logs: Available at Enterprise tier. Business tier has team admin controls but audit log depth varies.
EU-specific features: Anthropic has published GDPR compliance documentation and provides SCCs. No EU data centers. If data residency in the EU is a requirement, Claude does not currently satisfy it at the infrastructure level.
One notable characteristic of Anthropic's approach: their Constitutional AI methodology and their published policies on model training tend to be more specific and auditable than some competitors. For a direct comparison of Anthropic and OpenAI on GDPR specifically, see Anthropic vs OpenAI GDPR compliance 2026.
Gemini compliance profile
Training on your data:
- Gemini on personal Google account: processed under Google's standard privacy terms for consumer services. Google's consumer terms allow broad data use.
- Gemini for Google Workspace: data is not used to train Google AI models. This is covered by Google's Workspace data processing commitments, which are part of the standard Workspace agreement.
Data residency:
- This is Google's clearest advantage. Google Workspace offers data residency in the EU. Workspace customers can configure their tenant to store and process covered data (including Gemini interactions) in EU data centers. This is a genuine EU data residency option, not just SCCs.
DPA availability:
- Google Workspace includes a data processing amendment as part of standard Workspace terms. All paid Workspace customers have DPA coverage, including for Gemini features.
SOC 2 Type II: Yes.
Audit logs: Available through Google Workspace Admin console. Activity logs for Gemini interactions available at Enterprise tiers.
EU-specific features: EU data residency available. SCCs for transfers that do occur outside the EU. Google has extensive GDPR compliance documentation and EU-specific data protection commitments through Workspace.
For teams in the EU with data residency requirements, Gemini for Google Workspace is currently the strongest option among the three major AI assistants. The data residency feature is meaningful and verifiable through the Workspace admin console.
Side-by-side comparison
| Criterion | ChatGPT Enterprise | Claude for Work Enterprise | Gemini for Workspace |
|---|---|---|---|
| Trains on your data? | No | No | No |
| Consumer tier trains on data? | Yes (default) | Yes (may) | Yes (consumer terms) |
| EU data residency? | No | No | Yes (Workspace) |
| DPA included? | Yes | Yes | Yes (Workspace terms) |
| SOC 2 Type II? | Yes | Yes | Yes |
| GDPR SCCs provided? | Yes | Yes | Yes |
| Audit logs? | Yes | Yes (Enterprise) | Yes (Workspace Admin) |
| Admin policy controls? | Yes | Yes | Yes (Admin console) |
| Minimum plan for DPA | Team | Business | Paid Workspace |
| EU representative? | Yes | Yes | Yes |
The consumer account risk in practice
Here is the scenario that plays out regularly in organizations without AI governance policies:
An employee signs up for Claude.ai on a free account because they want to try it. They use it to draft a client proposal, refine a legal document, or analyze a spreadsheet of customer data. They think nothing of it; it looks like the same tool their company uses in the official team account.
It is not. The free Claude.ai account operates under consumer terms. The company's DPA with Anthropic for Claude for Work covers accounts provisioned through that agreement, not personal accounts the employee created independently.
The same pattern applies to ChatGPT (where a personal Plus account is materially different from a company Team account) and to Gemini (where a personal Google account is entirely separate from the company's Workspace environment).
The fix is not difficult, but it requires active policy and enforcement. Your AI tool register should specify which account type is approved for each tool. Your shadow AI governance controls should be able to detect when employees are using personal accounts for work purposes.
Decision framework for small teams
If you have EU data subjects and need data residency in the EU: Gemini for Google Workspace is your clearest path. Microsoft 365 Copilot with EU Data Boundary enrollment is the other option. Neither ChatGPT nor Claude currently offers EU data residency.
If you want the strongest no-training guarantee with the simplest setup: All three providers are equivalent at their enterprise tiers. Choose based on workflow integration: which tools does your team already use?
If price is the primary constraint: ChatGPT Team and Claude for Work Business are both accessible for small teams. Both include DPAs and no-training guarantees. Google Workspace requires a broader Workspace commitment.
If your team writes code and uses AI for development: Look at how Claude and ChatGPT perform on coding tasks for your specific use cases. The governance protections are similar at enterprise tiers, so the feature comparison becomes the deciding factor. For developer-specific AI governance, the AI coding tools governance policy covers GitHub Copilot and other developer tools.
If you process sensitive data types (health information, legal documents, financial records): All three providers' enterprise tiers can support this with proper configuration. None of them sign HIPAA Business Associate Agreements for their standard AI assistant products; that typically requires specific agreements and products outside the standard assistant line.
One thing all three have in common: none of them maintain identical compliance posture across their full product suite. The enterprise assistant (ChatGPT Enterprise, Claude for Work Enterprise, Gemini for Google Workspace) typically has the strongest protections. A consumer or team-tier account, even with the same brand name, has different terms and should not be assumed to inherit enterprise protections. Always verify the DPA, training opt-out status, and EU data residency against the specific product and tier your organization is actually using, not the brand's enterprise marketing page.
For a focused comparison on privacy-first API options (useful for developers building on these models), see Privacy-first AI API no training GDPR CCPA.
Related reading
- Claude vs ChatGPT compliance small teams
- GDPR-compliant AI assistants comparison 2026
- AI vendor DPA tracker 2026
- AI data privacy for small teams GDPR CCPA
- Shadow AI governance tools visibility tech teams
- Microsoft Copilot data governance for small teams: what you actually n
- Notion AI vs Microsoft Copilot compliance comparison
- ChatGPT Memory Upgrade (Dreaming V3): What It Means for Business Privacy
- CEO's AI Tool Approval Checklist: 10 Questions Before You Say Yes
