Skip to Content

Generative AI and data protection: what can a Swiss SME send to ChatGPT?

Client data, HR, contracts or tax: practical rules for benefiting from AI without turning a prompt into a confidentiality incident.
January 30, 2026 by
JBP
| No comments yet

ChatGPT can summarize a contract, rephrase a delicate email or extract the key points of a file in seconds. The temptation to send the entire document is therefore strong. This is precisely where the tool’s usefulness meets data protection, confidentiality and sometimes professional secrecy.

For a Swiss SME, the answer is neither “everything is prohibited” nor “everything is allowed once model training is disabled.” Using generative AI is data processing and, where an external service is involved, generally a form of IT outsourcing. The company remains responsible for the tool selected, the data sent and the settings chosen.

The practical rule fits in one sentence: send only necessary information, within an approved contractual environment, after removing everything the AI does not need.

At a glance

  • A prompt, attached file or image containing information about a person constitutes processing of personal data.
  • Disabling training reduces one risk, but does not eliminate processing, possible retention or the SME’s other obligations.
  • A personal account should not be used to process identifiable client, HR, tax, medical or legal files.
  • ChatGPT Business, Enterprise or the API provide a stronger professional framework, but do not make every submission lawful.
  • Genuine anonymization, minimization and an internal policy are the most immediately useful protections.

The first reflex: treat a prompt as a disclosure of data

The Federal Act on Data Protection (FADP) applies in a technology-neutral way. The FDPIC has reiterated this for artificial intelligence systems: as soon as AI processes personal data, the FADP applies. On January 28, 2026, it again emphasized the importance of transparency, particularly regarding possible uses of data entered in prompts.

Personal data means any information relating to an identified or identifiable natural person. A name is therefore not essential. A combination such as “our 58-year-old finance director in Vevey, absent for six months” may be enough to recognize someone. Information published on LinkedIn or in the commercial register also remains personal data; its public nature does not automatically remove purpose limitation, proportionality or a confidentiality obligation.

“Not used to train the model” does not mean “no data is processed”

Model training, conversation retention, security checks, administrative access within a workspace and any connected third-party services must be distinguished. These are different questions. A setting that disables training does not therefore turn a personal account into a digital safe.

Environment Training Practical meaning for an SME
Personal ChatGPT account Content may contribute to model improvement unless the relevant setting is disabled. Reserve for public, fictional or genuinely anonymized content. It is not the appropriate environment for an identifiable business file.
Temporary Chat Not used for training and absent from history; a copy may nevertheless be retained for up to 30 days for safety purposes. Useful for reducing persistence, but insufficient on its own to authorize sensitive or secrecy-protected data.
ChatGPT Business Business data is not used to train models by default. A more suitable framework for an SME, provided the contract, DPA, subprocessors, access rights and internal uses are approved.
ChatGPT Enterprise or API No training on inputs and outputs by default; additional controls depend on the offering and configuration. Preferable for structured integrations or stronger requirements, after analyzing flows, retention and data residency.

OpenAI also states that business data is encrypted at rest and in transit. Its Data Processing Addendum, applicable from January 1, 2026, includes obligations on confidentiality, security, subprocessor management and assistance. These safeguards matter, but do not replace the analysis the SME must perform for its own use.

Green, amber or red: a simple framework

Level Examples Recommended approach
Green Already public text, fictional scenario, generic procedure, aggregated statistics, template without real names. Use is generally possible, with human review of the result and respect for copyright.
Amber Internal contract, redacted client email, non-public commercial figures, pseudonymized document, limited accounting extract. Only in an approved professional environment, after minimization, contractual review and access checks.
Red Named tax return, salary certificate, medical file, identity document, bank details, password, disciplinary file, litigation strategy, critical trade secret. Do not send through a standard service. Use requires specific approval of the case, contract and security and, depending on the risk, an impact assessment.

Anonymizing does not mean replacing a name with “Client A”

Anonymization must make reidentification reasonably impossible. If the company keeps a table linking “Client A” to Ms Dupont, or the facts described are enough to identify her, the data is only pseudonymized. It remains subject to the FADP.

The right approach removes direct identifiers as well as unnecessary indirect ones: exact dates, a unique role, municipality, distinctive amounts, file numbers, metadata and signatures. A structural analysis can often be requested without sending the file: providing the relevant contract clauses is better than uploading all 47 pages and every appendix “just in case.”

Six legal checks before sending data

1. Purpose and proportionality

The SME must have a defined purpose and send only what is necessary to achieve it. Asking for stylistic improvements to a letter does not justify sending the recipient’s name, address, social insurance number, medical history and entire file.

2. Transparency and control of data

The company’s privacy notice must describe purposes, categories of recipients and, where applicable, disclosures abroad sufficiently clearly. Using an AI tool must not create hidden processing that a client or employee could not reasonably anticipate.

3. Compliant outsourcing

Under Article 9 FADP, processing may be delegated to a processor where a contract or the law provides for it, the processing does not exceed what the company itself would be authorized to do, and no statutory or contractual duty of secrecy prohibits it. The SME must also ensure the provider guarantees data security and governs its own subprocessors.

4. Disclosure abroad

Identify the entities involved and processing locations, then check the mechanism applicable to the transfer. Since September 15, 2024, US companies certified under the Swiss–US framework benefit from adequacy recognition. Otherwise, appropriate safeguards may be necessary. Having a DPA does not remove the need to check its scope, subprocessors and the configuration actually purchased.

5. Security and impact assessment

Access must be restricted, accounts individual, authentication strengthened and settings centrally managed. Where planned processing may create a high risk to personality or fundamental rights, particularly with large-scale sensitive data, a data protection impact assessment may be mandatory.

6. Secrets, third-party rights and sector rules

The FADP is only one layer of the issue. A file may contain a trade secret, be subject to a confidentiality clause or fall under professional or sector-specific secrecy. An “ordinary” accounting and fiduciary firm does not automatically benefit from every form of professional secrecy under criminal law, but remains bound by its contracts, duty of care and clients’ trade secrets. For lawyers, doctors, auditors, banks or insurers, additional rules may prohibit or heavily restrict outsourcing.

An internal procedure in eight steps

  1. Inventory uses: writing, translation, contract analysis, HR, customer support, code and marketing.
  2. Classify data: public, internal, confidential, personal, sensitive or protected by secrecy.
  3. Define authorized cases: tool, account, data type and approval level.
  4. Approve the provider: contract, DPA, purposes, retention, subprocessors, processing locations, security and deletion arrangements.
  5. Minimize before sending: remove unnecessary pages, fields and metadata; anonymize where possible.
  6. Secure access: named accounts, multifactor authentication, prompt access removal and connector restrictions.
  7. Require human review: AI can invent a rule, change a figure or produce persuasive but false reasoning.
  8. Plan for incidents: reporting channel, preservation of useful evidence, risk assessment and possible notification to the FDPIC.

Four practical examples

Need Poor reflex Safer approach
Respond to a client complaintPaste the entire email chain with names, addresses and attachments.Summarize the facts, replace unnecessary people and amounts, then request a response structure.
Check a salary certificateUpload the complete named certificate to a personal account.Use a checklist without data or a fictional example; handle the real case in an approved environment with minimized data.
Analyze a CVSend the entire file and ask “should we hire this person?”Define objective professional criteria, remove the photo and unnecessary private data, and retain a human decision.
Summarize a contractSend the signed contract with appendices, bank details and technical secrets.Extract relevant clauses, mask the parties and request a limited analysis; have the legal issues reviewed.

The opposing view: “the client consented”

Consent is neither always necessary nor a blanket exemption. Under Swiss law, private-sector processing that respects FADP principles does not automatically rely on consent. Conversely, where consent is relied upon, it must be freely given and informed; it does not remedy inadequate security, disproportionate disclosure or a breach of secrecy. In employment relationships, whether consent is truly free may also be questioned because of the relationship of subordination.

The counterargument would therefore be simple: the person accepted a vaguely described use but was not informed that an entire file would be sent to an AI service, possibly processed by several subprocessors. The SME must be able to demonstrate governance stronger than a ticked box.

How Delta Conseil SA can support you

Delta Conseil SA can help an SME inventory AI uses, classify data, formalize an internal policy, review processes and introduce proportionate controls. Where a matter requires specialized legal analysis, in-depth technical security or examination of professional secrecy, we coordinate the appropriate specialist’s involvement.

Caution

Compliance depends on the exact service, subscription, settings, connectors, contract and nature of the data. Providers’ features and terms change. Before sensitive use, check the configuration actually available in the workspace, not just a marketing page.

Frequently asked questions

Can I paste a client’s email into ChatGPT?

Sometimes, yes, but not automatically. Remove unnecessary identifiers and information, check the content’s confidentiality and use an approved professional environment. For simple rephrasing, an anonymized scenario is often enough.

Is ChatGPT Business sufficient for personal data?

It offers a more suitable framework because business data is not used for training by default and a DPA is available. The SME must nevertheless check purpose, proportionality, transfers, security, access and secrecy obligations.

Does Temporary Chat allow a tax file to be sent?

No, not by itself. The absence of history and training does not eliminate processing or temporary retention. A named tax file often combines personal data, financial data and contractual confidentiality.

Are initials enough to anonymize?

Rarely. If a person can be recognized through initials, context or a lookup table, the data remains personal. At best, it is pseudonymization.

Who is responsible for an AI-generated error?

The company using the result remains responsible for its decisions and services. OpenAI’s business terms also remind the customer to assess outputs for accuracy and suitability. Documented human review is therefore essential for legal, tax, HR or financial matters.

Official sources

Last legal review: January 30, 2026.

Disclaimer

This publication is provided for information only and does not constitute individualized legal, tax, accounting or financial advice. Each situation must be assessed in light of its specific circumstances and the law applicable at the time of the decision.

For further information, please consult our Legal notice and disclaimer.

Sign in to leave a comment