Skip to main content

    ChatGPT and social work case notes: is it a GDPR breach?

    Published 18 September 2026 · 8 minute read · General information, not legal advice

    Short answer: if the note contains personal data, and it almost always does, pasting it into a personal ChatGPT account is very likely to break UK data protection law. Not because AI is banned, but because you have handed a child’s or a resident’s details to a company with no contract, no lawful basis you can point to, and no control over what happens next.

    This guide explains what actually happens to the text, why the regulators and professional bodies treat it as a problem, and what a defensible alternative looks like. It is general information, not legal advice.

    What happens to the text you paste

    OpenAI is unusually clear about this. For its consumer products, the ones most care workers sign up to on their own phone, it says:

    “When you use our services for individuals such as ChatGPT and Codex, we may use your content to train our models.”
    OpenAI help centre, How your data is used to improve model performance [1]

    There is an opt-out in the settings, and a Temporary Chat mode that is not used for training. Business products are different: OpenAI states that by default it does not train on inputs or outputs from ChatGPT Business, ChatGPT Enterprise or the API. But a care worker pasting a note into the free app on their phone is not on a business plan, has usually not changed a setting, and has no agreement with OpenAI at all.

    Training is only part of it. Even with training switched off, the text has left your organisation, been stored on a third party’s systems, and been processed for a purpose the person it describes was never told about. That is the data protection problem, and it exists whichever AI service is on the other end.

    Why it is a data protection problem

    Four things go wrong at once when a case note goes into a chatbot.

    • It is personal data, and usually special category data. Health, disability and safeguarding information sit in the most protected class under Article 9 of the UK GDPR, which needs a specific condition on top of an ordinary lawful basis.
    • There is no processor contract. UK GDPR Article 28 requires a written contract with anyone processing personal data on your behalf. A consumer AI account gives you a terms page, not a controller-processor agreement.
    • It may be an international transfer. Many AI services process data outside the UK. Transfers need a lawful mechanism and, under the ICO’s guidance, a risk assessment.
    • Nobody assessed the risk. The ICO’s AI guidance says that using AI will usually involve processing "likely to result in a high risk to individuals’ rights and freedoms", which triggers the legal requirement for a data protection impact assessment.
    “the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA.”
    ICO, Guidance on AI and data protection [2]

    The ICO also draws the line that matters for the rest of this guide: anonymous information is outside data protection law entirely, and personal data is not.

    “Anonymisation is the way in which you turn personal data into anonymous information, so that it then falls outside the scope of data protection law.”
    ICO, Introduction to anonymisation [3]

    What the sector bodies say

    None of the bodies below say "do not use AI". All of them say the same three things: do not put personal data into generic tools, keep a human responsible for the output, and assess the risks before you start.

    The British Association of Social Workers published the first practice guidance on generative AI in social work in March 2025. As Community Care reported, it advised practitioners to:

    “avoid entering sensitive personal information into generic tools without the explicit and informed consent of the person concerned.”
    BASW guidance, reported by Community Care, 11 April 2025 [4]

    The same report noted that "accountability ultimately sat with the social worker using the tool" and that "data protection assessments should also be undertaken before introducing AI products within services".

    The Department for Education’s National Workload Action Group looked specifically at AI in children’s social care case recording in September 2025. It was positive about the potential and blunt about the risks:

    “The lack of transparency of AI models raises concerns about what happens to information once it is fed to an AI application”
    DfE / Research in Practice, AI in case recording, September 2025 [5]

    The Care Quality Commission set out its expectations for providers using AI in May 2026. It does not assess or approve individual tools, but it expects a data protection impact assessment, trained staff, human oversight and transparency with the people who use services. Ofsted takes a similar line: inspectors "can consider the impact that the use of AI has on the outcomes and experiences of children" and may ask leaders how they make sure AI use supports children’s best interests. Both are covered in detail in our guide to what regulators expect.

    What the penalties look like

    The maximum penalty for the most serious breaches under the Data Protection Act 2018 is £17.5 million or 4% of annual worldwide turnover, whichever is higher. In practice the ICO uses its full range of powers, from reprimands and enforcement notices upwards, and the consequences that hurt a care provider first are usually the ones that are not fines at all: a reportable breach, a safeguarding review, a regulator asking questions at the next inspection, and a family finding out.

    It is also worth being honest about the reverse risk. Staff use these tools because the writing load is real. A policy that just says "no" tends to push the behaviour out of sight rather than stop it, which is exactly the situation the DfE report describes: "fragmented approaches and lack of oversight and support pose risks".

    What to do instead

    The workable answer is to take the personal data out before the text goes anywhere. If the AI only ever sees an anonymised version, most of the problems above disappear at the same time: there is no personal data in the transfer, nothing for the model to learn, and nothing to breach.

    The ICO’s guidance on pseudonymisation describes the mechanism precisely. Replacing identifiers with placeholders and keeping the key separately means the data is still personal data in your hands, and may be anonymous in the hands of a recipient who cannot re-identify anyone:

    “If you share pseudonymised data (but not the additional information) with another organisation, it may be anonymous information in their hands”
    ICO, Pseudonymisation [6]

    Doing that by hand on every note is slow and error-prone, which is why it does not happen. Caredact does it automatically: paste the note, and names, addresses, NHS numbers, references and care-specific identifiers are detected and replaced with labelled placeholders. A person checks the highlights and marks anything the detector missed, the AI works on the checked version, and the export puts the real details back. The placeholder map is never sent to the AI, and it is deleted when the document is finished or reaches its retention date. The practical steps are in our guide to anonymising case notes.

    • Write the policy so it names an approved route rather than only a prohibition. Our free AI policy template is built that way.
    • Do the DPIA once, for the approved tool, instead of pretending the unapproved ones are not being used. There is a DPIA template pre-filled for AI in social care.
    • Get a Data Processing Agreement with whatever you approve. If a vendor cannot offer one, that is your answer.
    • Keep a person in the loop and keep a record of what was sent.

    Questions

    Is it fine if the care worker uses a paid ChatGPT Plus account?

    No. Plus is a consumer product. OpenAI’s statement that it may use content for training applies to services for individuals, and a personal account gives your organisation no processor contract at all. Business plans change the training default, but they do not remove the need for a contract, a lawful basis, a DPIA and a decision about where the data goes.

    What if the note has no surname in it?

    A first name plus a school, a street or a diagnosis is still personal data if someone could reasonably identify the person. The ICO’s test is whether identification is reasonably likely, not whether a full name is present.

    Does anonymising the note fix everything?

    It removes the personal data from the transfer, which is the biggest problem. You still need a policy, a human checking the output for accuracy, and a tool you have assessed and contracted with. Caredact is designed to satisfy those parts too, but it is a control, not a substitute for governance.

    Sources

    1. [1]OpenAI, How your data is used to improve model performance (help centre)
    2. [2]ICO, Guidance on AI and data protection: accountability and governance implications
    3. [3]ICO, Introduction to anonymisation
    4. [4]Community Care, First practice guidance for AI in social work warns of bias and data privacy risks (11 April 2025), reporting BASW’s Generative AI and Social Work Practice Guidance
    5. [5]Department for Education / Research in Practice, Artificial Intelligence (AI) in case recording: National Workload Action Group supplementary report (September 2025)
    6. [6]ICO, Pseudonymisation
    7. [7]Data Protection Act 2018, section 157 (maximum amount of penalty)
    8. [8]CQC, Artificial intelligence in health and social care: CQC’s role, expectations and plans (21 May 2026)
    9. [9]Ofsted, How Ofsted looks at AI during inspection and regulation (27 June 2025, updated 21 October 2025)