ChatGPT
AI assistant by OpenAI for conversation, analysis, and content creation
About ChatGPT
ChatGPT is OpenAI's flagship conversational AI product, built on the GPT-4o and o1 model families. It supports a broad range of use cases including long-form writing, summarisation, code generation, image analysis, document review, and agentic task execution via its GPT Store and plugin ecosystem. The free tier provides access to GPT-4o mini, while Plus ($20/month) and Pro ($200/month) plans unlock full GPT-4o, o1, and advanced tools such as DALL-E image generation and deep research capabilities. For enterprise customers, ChatGPT Enterprise and the Business plan ($25/user/month) offer enhanced privacy controls, including a guarantee that conversations are not used to train OpenAI models by default. Enterprise deployments can also select data residency regions spanning the US, EU, UK, Canada, Japan, South Korea, Singapore, India, Australia, and the UAE, giving multinational organisations meaningful data sovereignty options. On the compliance front, OpenAI has achieved SOC 2 Type II, ISO/IEC 27001, 27017, 27018, and 27701 certifications, and is GDPR-compliant under Standard Contractual Clauses. ChatGPT Enterprise supports SSO, audit logs, and custom data retention controls, making it viable for regulated industries including legal, financial services, and healthcare when paired with appropriate contractual controls. Key considerations for compliance-focused buyers include the fact that free and Plus-tier conversations may be used to improve OpenAI models unless users opt out, the US-based legal jurisdiction means data can be subject to US law including the CLOUD Act, and not all model inference happens within the customer's chosen residency region. Organisations with strict sovereignty requirements should evaluate ChatGPT Enterprise or API usage with explicit DPAs and the appropriate regional endpoint configuration.
TrustKit Score Breakdown
?64% ModeratePricing
FreemiumFree tierQuick Facts
Frequently Asked Questions
Is ChatGPT GDPR compliant?
ChatGPT has a TrustKit compliance score of 64% (Moderate). Data Residency: Enterprise/Business customers can choose from 10+ regional data residency options including EU and UK. Legal Jurisdiction: US Delaware corporation, subject to CLOUD Act; DPAs available for GDPR.
Where does ChatGPT store data?
ChatGPT hosts data in: US, EU, UK, JP, and more (Azure). Enterprise/Business customers can choose from 10+ regional data residency options including EU and UK
Does ChatGPT train on user data?
ChatGPT: Opt-out available (Business/Enterprise). Free/Plus tiers may train on data; Business and Enterprise tiers exclude data from training by default
What certifications does ChatGPT hold?
ChatGPT holds: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, ISO 27701. SOC 2 Type II, ISO 27001/17/18/701 certified