By Rafael Luque Ocaña

An employee pastes customer data into a chatbot: is it a personal data breach?

When it is a personal data breach, when it has to be notified and what to do in the first 24 hours, across three scenarios.

This article is for anyone who runs an SME or handles its data protection and has just found out that someone on the team has pasted customer data into an AI chatbot: a list to sort, a customer's email to rewrite, an order sheet to summarise. The question that follows is always the same: is this a personal data breach, and does it have to be notified? The answer depends on the scenario, and the decision comes with a deadline that starts running when the company becomes aware of what happened.

What the definition says

The GDPR defines a personal data breach in Article 4(12): "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed".

The last part is what matters here. A breach does not require anything to be lost or destroyed: it is enough for the data to be disclosed to someone who was not authorised, or for someone unauthorised to access it. Pasting data into a chatbot means disclosing it to the provider that runs the chatbot. The useful question, then, is not "has anything been lost?" but "was that disclosure authorised?".

Three scenarios

First: the company tool, under contract. The company has procured the chatbot, has it in its inventory and has signed with the provider the processing contract Article 28 GDPR requires. That contract stipulates, among other things, that the processor "processes the personal data only on documented instructions from the controller" (Article 28(3)(a)). If the employee uses the tool for a task the company's policy allows, the data reaches a processor under contract, for the intended purpose. In principle there is no unauthorised disclosure, and therefore no breach.

Second: the personal account. The same employee uses a free personal account on another chatbot, with no contract between the company and the provider. The customer data goes to a third party with which there is no processing relationship and no documented instructions. That fits the "unauthorised disclosure of, or access to" in the definition: it can be a personal data breach, and what remains to be decided is how much risk it carries.

Third: the tool under contract, used for something else. The company does have a contract with the provider, but for another use: the chatbot is authorised for drafting marketing copy, and the employee pastes in customers' health data. There is a processor and there is a contract, but that processing falls outside the documented instructions. Whether the data has reached someone who should not have access to it is a question of fact — what the contract allows, what the provider does with what it receives, who can see it — and the answer may be yes. While that is being clarified, it is wise to treat the case as a possible breach.

To notify or not: two different thresholds

If there is a breach, the GDPR separates two decisions, each with its own threshold.

The first is notifying the supervisory authority. Article 33(1) requires this "without undue delay and, where feasible, not later than 72 hours after having become aware of it", "unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons". The clock runs from the moment the company becomes aware, and the exception is that a risk is unlikely, not that there was no harm. If the notification comes after 72 hours, the same paragraph requires it to be accompanied by the reasons for the delay.

The second is communicating it to the people affected. Article 34(1) requires this "when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons". The threshold is higher: a breach may require notifying the authority without requiring the customers to be informed.

Neither is triggered simply because a chatbot is involved. It depends on what data it was, how many people it concerns, what the provider does with it and whether it can be deleted. That is why no single answer fits every case, and why anyone who says this is "always" or "never" notifiable deserves some scepticism.

The first 24 hours

Six actions, in this order:

  1. Contain. Ask the person to stop using the tool with that data and to delete the conversation if the service allows it. It does not fix what has already gone out, but it stops more going out.
  2. Find out what went out. Which data, how many people, which tool, which account and when. Put it in writing from the start.
  3. Read the terms of service. Whether the provider keeps conversations, whether it uses them to train its models, where it processes them and whether there is a processing contract with the company. That is what separates the first scenario from the second.
  4. Tell whoever handles data protection, the data protection officer if you have one, and decide who coordinates.
  5. Document. Article 33(5) requires the controller to "document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken". It applies to all of them, notified or not, and it is what later allows the authority to verify what you did.
  6. Decide, and record why. With all of the above, assess whether a risk is unlikely (Article 33(1)) and whether a high risk is likely (Article 34(1)), and record the decision with its reasons, whichever way it goes. The 72-hour clock does not wait for the investigation to be complete.

What prevents the next case

What separates the first scenario from the second is not decided on the day of the incident: it is decided beforehand. A company that knows which AI tools it uses, under which contract and for what, starts from the first scenario. That is why the inventory is the foundation of everything else, and why a spreadsheet stops working once you need to show since when each tool has been on record.

The other half is training. Article 4 of the AI Act, as worded by Regulation (EU) 2026/1744, says that providers and deployers "shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". It is an obligation of means: the text itself makes clear that it "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Staff knowing which data must not go into a chatbot is a measure of exactly that kind, and our Article 4 checklist helps put those measures in order. The rest of the problem — where the AI nobody has recorded comes from — is covered on the shadow AI page.

And if the provider is going to process personal data on the company's behalf, the processing contract is what turns the second scenario into the first. It is worth reviewing with the questions an AI provider should be able to answer in writing.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Do you have to notify if there was no harm?

Not always, but that is not the question. Article 33(1) GDPR requires notification to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. What decides it is whether a risk is unlikely, not whether there was harm. And whether or not it is notified, the breach is documented (Article 33(5)).

What if the chatbot does not train on the data?

It helps in assessing the risk, but it does not decide whether there was a breach. The definition in Article 4(12) GDPR includes unauthorised disclosure of, or access to, personal data: what matters is whether the data reached a third party without authorisation, and with what safeguards that party processes them. The provider not training on them is a factor in the Article 33(1) assessment, not an exception.

What evidence shows the use was unauthorised?

Whatever you already had before the incident: a use policy stating which tools are authorised and for which data, the inventory where they appear, and the record showing the employee knew the rule. Without those documents, it is hard to establish afterwards which use was permitted.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.