Skip to content
← Back to blog
GDPRArticle

Customer data in ChatGPT and Claude: prepare the document first

Which details does the model need? A complaint example, the difference between anonymisation and pseudonymisation, and the cost of implementation support.

Author

Syntalith

Published Updated 3 min read

The model needs to help draft a response to a complaint. Does it need the customer's address, bank details and two years of correspondence? A smaller input is often enough: the relevant facts, timing and an approved extract from the returns policy.

Reduce the data before submitting it to the tool. Uploading a complete document and asking the model to anonymise it has already transferred that document to the provider. The company must approve that processing arrangement beforehand. GDPR requires personal data to be limited to what is necessary for the purpose. Article 5 GDPR

Worked example: preparing a complaint response

This is an illustrative workflow, without real customer data. An employee needs a draft about a damaged product and will review it before sending.

Part of the caseNeeded for this draft?Preparation
Name, email and delivery addressUsually noRemove before submission; the employee adds the recipient details later
Description of damageYesKeep product facts and remove unrelated information about individuals
Purchase and complaint datesIf they determine the applicable responseInclude only the necessary date or established time interval
Order numberUsually unnecessary for draftingUse a local case reference if the output must be matched to a record
Returns policyThe relevant sectionProvide the current version and a source reference
The customer's entire correspondence historyNoSelect the messages relevant to this case

An instruction could say: “Draft a response using the case description and policy extract. Identify the clause supporting your suggestion. List any missing fact an employee must check. Do not state that a refund has been approved.”

The expected output is clear: a proposed reply, its source and any unresolved questions. The employee still checks the facts, the policy version and their authority to make the decision.

Removing a name does not establish anonymity

If the company keeps a table linking a case reference to a customer, the information may be pseudonymised and still subject to GDPR. This can reduce exposure without removing data protection obligations. An unusual event, job title or combination of locations and dates may also identify someone.

The European Commission distinguishes data that can be linked back to an individual from irreversibly anonymous information. Covering two fields is not enough to promise anonymity. European Commission guidance

Documents can also contain comments, tracked changes, hidden sheets, metadata and attachments. Inspect the file that will actually be sent. Placing a coloured rectangle over text in a PDF may leave the underlying text retrievable.

When manual preparation becomes a bottleneck

For a few cases, an agreed template and employee review may be sufficient. At higher volumes, an integration can retrieve only the necessary fields, prepare an input and save the result for review. Access to the key linking a case reference to a customer should be restricted and separated from the data sent to the model.

That integration needs representative tests. Include personal data in comments, unexpected formats and messages mentioning a third party. Automated detection can miss details or remove useful information. Uncertain cases need a manual review path; a promise of perfect automatic anonymisation would be inappropriate.

Track correction work, preparation time and instances where unnecessary data enters the model input. A shorter prompt alone does not establish that the workflow is correct.

How Syntalith helps, and what to budget

When employees follow inconsistent practices, AI team training starts at €600 net per day. We can agree exercises covering document preparation and output review, using materials approved for the workshop.

When the data flow itself needs changing, an AI process audit starts at €600 net. Its core deliverables are a process map, architecture, implementation plan and fixed build quote. We agree the preparation and data-control scope for the particular task. Software subscriptions, integration development and legal advice are not automatically included in that fee.

Syntalith combines training with implementation work. Once the manual workflow has been tested, we can quote for automating it. This gives the company an opportunity to assess a smaller solution before commissioning a larger system. Book a free 30-minute process scan and describe the document types without sending customer records.

Sources and service prices checked on 30 September 2026. The company must establish the lawful basis and approved data scope with its responsible owner, involving its DPO or legal adviser where appropriate.

OpenAI Select Partner

Syntalith is an OpenAI Select Partner in the OpenAI Partner Network.

We help your team respond to customers faster and find information in company documents. We choose and set up the right AI tools, then teach your team how to use them.

How to introduce ChatGPT and OpenAI at work
Syntalith is a member of Claude Partner Network, Anthropic's partner program.

Denotes membership in Anthropic's partner program for Claude. Not an endorsement of Syntalith's services by Anthropic.

Free process scan

Start with a free process scan.

  • A 30-minute call with the engineer who would lead the work.
  • A review of the processes that cost you the most time and money.
  • A written summary: a possible direction, missing information and the next step.

The scan chooses one process to assess, and within 2 business days you receive a recommendation, including when a simpler route is the better fit.

€0

30 minutes · written takeaway within 2 business days

Book a free process scan (30 min)

Times are shown in your own time zone. We work with clients across time zones.

Describe the process in the form