The short answer
Do not upload personal data about research participants to a consumer AI account. That includes interview transcripts, survey responses with identifiers and health information. Use an AI tool your institution has approved, ideally one that processes data in the EU under a data processing agreement and does not train on your content, and pseudonymise data first.
Non-personal material, such as published papers, your own draft text or fully anonymised data, carries far less risk, though you should still think about unpublished results and confidentiality.
What GDPR requires
GDPR applies whenever you process personal data, meaning information about an identifiable person. Interview transcripts almost always qualify, and pseudonymised data still counts as personal data.
Sending that data to an AI provider is processing, so you need a lawful basis, and the provider acts as your processor. That requires a data processing agreement under Article 28. Health, ethnicity, religion, politics and other special categories need an exception under Article 9, such as the research exception with safeguards under Article 89. If the provider processes data outside the EU, the transfer rules in Chapter V apply as well.
A consumer chatbot account, signed up with a personal email, gives you none of this. There is no agreement between your university and the provider, and you usually cannot control where data goes or how long it is kept.
Consumer and business AI accounts are different
The big AI providers treat consumer and business accounts differently. Check the current terms yourself, because they change.
- OpenAI: consumer ChatGPT conversations may be used to improve models unless you switch this off in the data controls. Business, Enterprise, Edu and API data are not used for training by default. In 2025 OpenAI introduced data residency in Europe for some business products.
- Anthropic: since 2025, users of the consumer Claude plans choose whether their chats may be used for training. Claude for Work, Claude for Education and the API are excluded.
- Google: with Keep Activity switched on, Gemini chats can be used to improve Google services, including training AI models, and a subset is read by human reviewers. Work and school accounts may have different terms.
Data transfers to the United States
Many AI services process data in the US. Transfers to US companies certified under the EU-US Data Privacy Framework are currently allowed. The EU General Court upheld the framework in September 2025, but an appeal to the Court of Justice is pending, so its future is not certain. Earlier transfer frameworks were struck down twice. Many universities therefore prefer providers that process data inside the EU.
What regulators and universities say
The European Data Protection Board’s Opinion 28/2024 on AI models makes clear that data protection law applies fully to AI, and the European Commission’s living guidelines on generative AI in research ask researchers not to give third parties’ personal data to external generative AI systems unless the person has consented and the purpose is clear, and not to upload unpublished or sensitive work without assurances that it will not be reused.
Universities are translating this into concrete rules. KU Leuven treats personal data as always at least confidential, requires strictly confidential personal data to be pseudonymised first, and does not allow free consumer tools for professional work. The University of Helsinki tells researchers not to use sensitive or confidential data or unpublished results as input, and requires a data protection impact assessment when personal data is processed.
Does the EU AI Act change anything for researchers?
Less than many people think. The AI Act excludes AI systems developed and put into service solely for scientific research. That exemption covers research AI systems themselves. It does not exempt researchers who use a general tool like ChatGPT, and it does not change GDPR, which still applies in full to the data you enter.
A checklist for using AI with research data
- Check your institution’s AI guidance and list of approved tools.
- Check your ethics approval and consent forms. Do they allow AI processing?
- Use an institutional or business account, never a personal consumer account, for anything involving participants.
- Prefer tools that process data in the EU, sign a data processing agreement and do not train on your content.
- Pseudonymise before uploading, and upload only what the task needs.
- Do not upload other people’s unpublished work, such as manuscripts you are reviewing.
- Record what you uploaded, to which tool and why, for your data management plan.
How Kahubi is set up for research data
Kahubi is operated by Avidemic AB in Sweden. AI processing, transcription and web search run with European providers, your content is never used to train models, and the subprocessors are listed publicly on our compliance page. That gives you clear answers to the questions your data protection officer will ask.
Sources
- Regulation (EU) 2016/679 (General Data Protection Regulation). EUR-Lex.
- European Data Protection Board (2024). Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models.
- European Commission (2026). Living guidelines on the responsible use of generative AI in research, third version.
- Anthropic (2025). Updates to our consumer terms and privacy policy.
- OpenAI. Data controls FAQ.
- OpenAI. Business data privacy, security and compliance.
- OpenAI (2025). Introducing data residency in Europe.
- Google. Gemini Apps Privacy Hub.
- KU Leuven. Generative AI: principles for responsible use.
- University of Helsinki. Use of generative artificial intelligence in research.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 2.
Last updated 2026-10-09.