What you can safely share with AI under the Swiss Data Protection Act
By the end of this guide, you know which information can go into which AI tool, and your accounts don’t train the AI on your chats. Time needed: 10 minutes to read, 5 minutes per account to change settings.
The rule in one line: the Swiss Data Protection Act (FADP, in German nDSG) applies to AI. The Federal Data Protection and Information Commissioner (FDPIC) says the law “applies to the use of AI-supported data processing” (FDPIC). When your team pastes a customer’s details into an AI tool, your business is responsible for that data.
Personal data means any information about an identifiable person: a name, an email address, an order history, a photo.
Green, amber, red
| What | Where it can go | |
|---|---|---|
| Green | Public information, your own marketing texts, general questions, anonymised examples (“Customer A ordered 3 units”), your price list. | Any AI tool your business has approved. |
| Amber | Customer names and contact details, order and project details, supplier offers, internal documents that name people. | Only a business account with a contract and no training on your data. Only what the task needs. |
| Red | Sensitive personal data as the law defines it: religious, philosophical, political or trade-union views or activities; health, the private sphere, race or ethnicity; genetic data; biometric data that identifies a person; administrative and criminal proceedings or sanctions; social assistance (FADP, Art. 5). Also: passwords, bank logins, salaries and HR files, anything under professional secrecy or an NDA. | Not in an AI tool, unless you have specific approval and advice. |
When in doubt, remove the names first. Replace them with “Customer A” or “[name]”. Then the text is usually green.
Worked example (hypothetical). You want help answering a complaint.
- Amber: “Frau Anna Meier, Bahnhofstrasse 5, 3600 Thun, order 4711, complains that the sofa arrived damaged on 02.10.2026.”
- Green: “Customer A complains that a sofa arrived damaged. Delivery was last week.”
The AI needs the problem, not the person. Add the name yourself when you send the reply.
Free plans and business plans
| Personal plans (Free and paid) | Business plans | |
|---|---|---|
| Training on your chats | ChatGPT, Claude and Gemini can use your chats to improve their models unless you switch it off (steps below). | ChatGPT Business, Claude Team and Enterprise, Microsoft 365 Copilot and Google Workspace don’t train on your content by default (OpenAI, Claude, Microsoft, Google). |
| Contract | Consumer terms. | Business terms, usually with a contract on how the vendor handles your data. |
| Who controls settings | Each person, separately. | An admin, for the whole team. |
| Use for | Green only. | Green and amber. |
Switch off training on personal accounts
Each person who uses a personal account for work must do this on their own account.
ChatGPT (2 minutes)
-
On the web, click your profile icon.
-
Click Settings, then Data controls.
-
Turn off Improve the model for everyone and click Done.
What you’ll see: a small window with an on/off switch. Done closes it.
The phone app has the same switch under your profile icon, Data controls. New chats then won’t be used for training (OpenAI Help).
Claude (2 minutes)
-
Click your name, then Settings.
-
Click Privacy.
-
Turn off Help improve our AI models.
What you’ll see: the switch on the privacy page. You can also go straight to claude.ai/settings/data-privacy-controls.
The phone app works the same way. New chats are then not used for training, except chats flagged for safety review (Anthropic Privacy Center). Team and Enterprise don’t train by default.
Gemini (2 minutes)
-
Go to gemini.google.com.
-
Click Settings & help, then Activity.
-
At the top, click On, then choose Turn off, or Turn off and delete activity.
With Keep Activity off, Google says your chats “won’t be used to train our AI models, unless you choose to send Google feedback” (Gemini Privacy Hub). Chats are still kept for up to 72 hours (Gemini Help). For Google Workspace work accounts, your admin controls this.
Microsoft Copilot, personal account (2 minutes)
-
On copilot.com, click your profile icon, then your profile name.
-
Click Privacy.
-
Turn off Model training on text and Model training on voice.
What you’ll see: a separate Personalization switch on the same page. Leave it as you like; it isn’t about training.
The apps have the same switches under Privacy (Microsoft Support). With a Microsoft 365 work account you don’t need this: Microsoft says your prompts and responses aren’t used to train its models (Microsoft Learn).
Files in OneDrive, SharePoint or Google Drive
When AI works inside your company’s files, it sees what the person using it can see. Microsoft says Microsoft 365 Copilot only shows data the user can already view (Microsoft Learn). Google says the same for Gemini in Google Workspace (Google Workspace Admin Help).
Before you switch it on (20 minutes): check who can open your HR, payroll and contract folders. Look for files shared with “everyone in the organisation” or “anyone with the link”, and limit them to the people who need them. Otherwise the AI can find them for anyone in the team.
Letting ChatGPT or Claude read your Drive, OneDrive or email. OpenAI says that on Free, Plus, Go and Pro, it “may use information accessed from apps to train our models” (OpenAI Help). Connect company files only on a business plan, or with training switched off.
Don’t rate answers on personal accounts
OpenAI says a thumbs up or down on ChatGPT means the whole conversation “may be used to improve our models, even if you’ve opted out” (OpenAI Help). Google makes the same exception for feedback. Tell your team not to rate answers.
Five-minute team rule
Copy this into your team chat:
AI rule for [company]:
- Use only our approved tool: [tool and plan]. No private accounts for work.
- Green (public, anonymised, our own texts): OK.
- Amber (customer names, orders, offers): only in [approved tool], only what the task needs.
- Red (health, salaries, HR files, passwords, bank logins, anything under secrecy): never.
- Unsure? Remove names first, or ask [name].
For Swiss businesses
- Data sent to the US. Since 15 September 2024, Switzerland accepts US companies certified under the Swiss-US Data Privacy Framework as safe destinations (Federal Council). Check that your AI vendor is certified, or that its contract covers data from Switzerland.
- Know where your data is stored. From each vendor’s own pages:
| Tool | Where your data is stored |
|---|---|
| Microsoft 365, account set up in Switzerland | Microsoft stores email, SharePoint, OneDrive (work), Teams and Microsoft 365 Copilot data in Switzerland (Microsoft Learn). Switzerland is also inside Microsoft’s EU Data Boundary (Microsoft Learn). |
| Google Workspace | On Business Standard and Plus, your admin can choose to store data, including Gemini chats, in the US or Europe. There is no Swiss option (Google Workspace Admin Help). Choosing where data is processed needs Enterprise Plus or Frontline Plus (Google Workspace Admin Help). |
| ChatGPT | New Enterprise and Edu customers can choose Europe (EEA and Switzerland). Business can’t choose (OpenAI Help). |
| Claude | Anthropic says “data is stored in the US” (Anthropic Privacy Center). |
Not sure where yours is? Ask whoever manages your Microsoft 365 or Google Workspace account. They can see it under Data location (Microsoft) or Data regions (Google) (Microsoft Learn, Google Workspace Admin Help).
- A Swiss-hosted option exists. Infomaniak, a Geneva company, says its Euria assistant is “hosted exclusively in Switzerland” and that your data is “neither saved nor used to train AI” (Infomaniak).
- Tell people when a machine answers. The FDPIC says people have a right to know whether they are corresponding with a machine (FDPIC). Say so if an AI answers your customers directly.
- Update your privacy notice. If you use AI on customer data, your privacy notice should say so, including if data goes abroad. You can ask the AI to draft the new paragraph, then have it checked.
Sources
- FDPIC, AI and data protection: https://www.edoeb.admin.ch/en/ai-and-data-protection
- Federal Act on Data Protection (SR 235.1): https://www.fedlex.admin.ch/eli/cc/2022/491/en
- Federal Council, Swiss-US Data Privacy Framework: https://www.admin.ch/en/nsb?id=102054
- OpenAI, Data controls FAQ: https://help.openai.com/en/articles/7730893-data-controls-faq
- OpenAI, How your data is used to improve model performance: https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance
- OpenAI, ChatGPT Business overview: https://help.openai.com/en/articles/8792828-chatgpt-business-overview
- Anthropic Privacy Center, model improvement settings: https://privacy.claude.com/en/articles/12109829-how-do-i-change-my-model-improvement-privacy-settings
- Anthropic, Plans and pricing: https://claude.com/pricing
- Google, Gemini Apps activity: https://support.google.com/gemini/answer/13278892
- Google, Gemini Apps Privacy Hub: https://support.google.com/gemini/answer/13594961
- Google, Generative AI in Google Workspace Privacy Hub: https://knowledge.workspace.google.com/admin/generative-ai/generative-ai-in-google-workspace-privacy-hub
- Microsoft Support, Microsoft Copilot privacy controls: https://support.microsoft.com/topic/microsoft-copilot-privacy-controls-8e479f27-6eb6-48c5-8d6a-c134062e2be6
- Microsoft Learn, Microsoft 365 Copilot privacy: https://learn.microsoft.com/en-us/copilot/microsoft-365/microsoft-365-copilot-privacy
- Microsoft Learn, What is the EU Data Boundary: https://learn.microsoft.com/privacy/eudb/eu-data-boundary-learn
- Microsoft Learn, Data residency commitments in the Product Terms: https://learn.microsoft.com/en-us/microsoft-365/enterprise/m365-dr-product-terms-dr?view=o365-worldwide
- Google Workspace Admin Help, Data covered by data regions: https://knowledge.workspace.google.com/admin/compliance/data-covered-by-data-regions?hl=en
- Google Workspace Admin Help, Compare data region features across editions: https://knowledge.workspace.google.com/admin/compliance/compare-data-region-features-across-google-workspace-editions
- OpenAI, Connected apps in ChatGPT: https://help.openai.com/en/articles/11487775-connected-apps-in-chatgpt
- Microsoft Learn, Location of data in Microsoft Teams: https://learn.microsoft.com/microsoftteams/privacy/location-of-data-in-teams
- Google Workspace Admin Help, Choose a geographic location for your data: https://knowledge.workspace.google.com/admin/compliance/choose-a-geographic-location-for-your-data
- OpenAI, Data residency: https://help.openai.com/en/articles/9903489
- Anthropic Privacy Center, Where are your servers located: https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers
- Infomaniak, Euria: https://www.infomaniak.com/en/euria
Legal note: This article is general information, not legal advice. Laws change and every business is different, so always get advice from a qualified lawyer or your fiduciary (Treuhänder) before you act on it.
Next: Check AI answers before you use them: the 2-minute check
One practical issue every Friday
Every Friday: three AI stories that matter for Swiss businesses, and what to do about them. Free, in English, German, French or Italian.