ChatGPT Data Protection Switzerland: What SMEs Need to Know
By Marina Nerandzic
March 6, 2026
ChatGPT is the world's most well-known AI tool - and many Swiss SMEs are already using it informally. Employees copy customer data, contract clauses, or internal documents into ChatGPT without thinking about the consequences. This is a data protection risk you should be aware of.
The problem: Data flows to the USA
When you use the regular ChatGPT version (chat.openai.com), your inputs are processed on OpenAI servers in the USA. According to OpenAI's terms of use, your inputs may be used to train the model - unless you've explicitly opted out or use the API.
For a Swiss SME under the FADP (Data Protection Act), this means:
- Personal data (customer names, email addresses, phone numbers) may not be transferred to the USA without a legal basis.
- Particularly sensitive data (health, finances, religion) is absolutely off-limits.
- Confidential business information (contracts, financial figures, strategies) should never be entered into public AI tools.
Alternatives for privacy-conscious SMEs
- Azure OpenAI (Switzerland North): Microsoft offers GPT-4 on Swiss servers. Your data stays in Switzerland and isn't used for training. Requires an Azure subscription.
- Open-source models (Llama, Mistral): Language models you can run on your own servers. Full control, no data leaks, but higher technical effort.
- Swiss Hosted AI agents: Custom solutions on Swiss infrastructure, tailored to your specific requirements.
Immediate measures for your SME
- Introduce an AI policy: Clearly define which data may be entered into which tools. A one-page policy is enough to start.
- Consider ChatGPT Enterprise or Teams: These versions don't process data for training. For smaller teams, this can be a pragmatic solution.
- Isolate sensitive workflows: For processes involving customer data or contracts, use a dedicated Swiss Hosted AI solution.
- Train employees: 30 minutes is enough to communicate the most important do's and don'ts.
Our approach: Sovereign AI
We call it 'sovereign AI' - AI systems where you maintain full control over your data. Swiss Hosted, open source where possible, zero-data-retention during processing. This way, you benefit from AI advantages without data protection compromises.