ChatGPT Business and Data Protection: What Swiss Employers Need to Regulate
Short answer: ChatGPT Business and data protection
Short answer: Yes, a Swiss company can in principle use ChatGPT Business for personal data and confidential information too. But that does not make every use permissible. What matters is the specific use case, the category of data and whether the requirements of the Swiss Federal Act on Data Protection (FADP) and existing confidentiality obligations are met.
ChatGPT Business is OpenAI's self-serve plan for teams. Until 29 August 2025 it was called “ChatGPT Team”. For customers in Switzerland, the contracting party is OpenAI Ireland Ltd. The OpenAI Services Agreement and the Data Processing Addendum (DPA) apply. Under these, OpenAI processes personal data in customer content as a processor and, by default, does not use inputs and outputs to train its models.
That provides a contractual basis. It does not replace your own assessment. Neither a Business subscription, nor the absence of training, nor a storage location in Europe makes a processing operation lawful by itself.
As a first orientation:
- Generally unproblematic: public information and internal content without personal data and without a confidentiality obligation.
- Only after documented approval: ordinary personal data and confidential business information, limited to defined use cases and kept to a minimum.
- Blocked pending a separate assessment: sensitive personal data (Art. 5 let. c FADP), information covered by professional confidentiality, official secrecy or banking secrecy, and data that a contract prohibits from being passed on.
Many employees already use ChatGPT, often through personal accounts. The company then has no contract with the provider, although it remains responsible for the processing of customer and employee data. Employers should therefore define which access is permitted, which data may be entered and who reviews the results.
This article is for owners, executives and compliance officers of Swiss SMEs. It separates statutory duties from recommended practice, compares ChatGPT Business with personal accounts, Enterprise and the API, and contains a rollout checklist, an example and a text module for the internal policy. Legal position and product information as of 30 September 2026. The article does not replace an assessment of the individual case.
Conditions for personal data and confidential data
The FADP does not prohibit the use of AI services. It is worded in a technology-neutral way and, according to the Federal Data Protection and Information Commissioner (FDPIC), is directly applicable to AI-supported data processing. Anyone who enters personal data into ChatGPT processes that data and discloses it to a service provider. The company remains the controller (Art. 5 let. j FADP). If no personal data is entered, the FADP does not apply to the input. Confidentiality obligations may apply nonetheless.
Statutory duties
| Topic | Statutory duty | What it means for ChatGPT Business |
|---|---|---|
| Processing by processors | Art. 9 FADP, Art. 7 of the Data Protection Ordinance (DPO): processing may be assigned only by contract or by legislation. The provider may process the data only in the manner in which the controller itself is permitted to. No statutory or contractual duty of confidentiality may prohibit the assignment. The controller satisfies itself that the provider is able to guarantee data security. Sub-processors only with prior approval. | The Services Agreement and the DPA must apply to the account that is actually used. The DPA contains a general approval of the listed sub-processors, with a right to object to changes. Personal accounts do not meet this requirement. |
| Disclosure abroad | Art. 16 and 17 FADP, Annex 1 DPO: disclosure only to States with an adequate level of protection or with appropriate guarantees, such as standard data protection clauses recognised by the FDPIC. | Ireland is on the Federal Council's list of States. However, OpenAI lists processing in the USA and other countries. The USA is deemed adequate only for organisations certified under the Swiss-U.S. Data Privacy Framework. In all other cases, guarantees and a documented assessment are needed. |
| Data security | Art. 8 FADP, Art. 1 to 3 DPO: technical and organisational measures appropriate to the risk, including access control. | Sign-in, roles, restrictions on apps and clear instructions are the responsibility of the company, not of the provider. |
| Processing principles | Art. 6 FADP: purpose limitation, proportionality and accuracy. Personal data must be destroyed or anonymised as soon as it is no longer required for the purpose. | Enter only as much personal data as the purpose requires. The Act does not set a fixed period. The company itself defines when chats, files and projects are deleted. |
| Information | Art. 19 FADP: information to data subjects, including the categories of recipients and, where data is disclosed abroad, the State and the guarantees. | Review the privacy notice and the information given to employees and supplement them where necessary. |
| Data protection impact assessment | Art. 22 FADP: required beforehand if the processing is likely to result in a high risk, in particular in the case of large-scale processing of sensitive personal data. | Hardly an issue for marketing copy based on public information. For HR, health or profiling applications, assess beforehand and record the result. |
| Employee data | Art. 328b of the Code of Obligations (CO): processing only to the extent that the data concern the employee's suitability for the job or are necessary for the performance of the employment contract. | HR data is a separate case to assess, see the example below. |
| Confidentiality | Art. 321 of the Swiss Criminal Code (SCC), Art. 47 of the Banking Act (BankA), Art. 69 of the Financial Institutions Act (FinIA), Art. 62 FADP, Art. 162 SCC and contractual obligations. | Separate assessment before any input, see the section on professional confidentiality. |
Violations can be a criminal offence. Under Art. 61 FADP, a fine of up to CHF 250,000 is imposed, on complaint, on anyone who wilfully discloses personal data abroad without satisfying the requirements of Art. 16 and 17 FADP, assigns processing to a processor without satisfying the requirements of Art. 9 para. 1 and 2 FADP, or fails to comply with the minimum requirements for data security. The criminal provisions are directed at the responsible natural persons. The business can be fined in their place only in the cases of Art. 64 para. 2 FADP.
If a company uses a language model in dealings with customers, for example as a chatbot, the FDPIC also requires transparency about the fact that they are communicating with a machine and about how their inputs are used further.
Recommended practice
The following points are not expressly required. They do make it easier to demonstrate that the duties are met.
- Approval per use case instead of blanket approval of the tool.
- An entry in the record of processing activities, even if the company is exempt from the obligation under Art. 12 para. 5 FADP and Art. 24 DPO. The exemption applies to companies with fewer than 250 employees, provided they neither process sensitive personal data on a large scale nor carry out high-risk profiling.
- Leave out names or pseudonymise them where the purpose allows.
- A written usage policy, a short training session and a simple reporting channel for erroneous inputs.
- Regular review of the contract and product documentation, because OpenAI changes features and terms frequently.
What a Business subscription, “no training” and EU storage do not settle
- Business subscription: It provides the contract that Art. 9 FADP requires. Whether the purpose, scope and data category are permissible is for the company to decide.
- “No training”: The commitment concerns a single type of use. The content is still stored, processed by sub-processors and, according to OpenAI, can be viewed by authorised persons, for example to investigate abuse.
- Storage in Europe: OpenAI documents data residency for eligible Enterprise, Edu, Healthcare and API customers, not for ChatGPT Business. Even there it concerns stored content of certain features. Other processing steps can take place outside the region.
Business, personal account, Enterprise and API compared
The following information comes from OpenAI's public documentation, accessed on 30 September 2026. A commitment applies only to the product for which OpenAI makes it. What counts is the contract your company has actually concluded.
| Criterion | Personal account (Free, Go, Plus, Pro) | ChatGPT Business | ChatGPT Enterprise | API platform |
|---|---|---|---|---|
| Contract | Terms of use and privacy policy for individuals. For users in Switzerland, OpenAI Ireland Ltd. is itself the controller. No DPA with the employer. | OpenAI Services Agreement and DPA, concluded online. The contracting party is OpenAI Ireland Ltd., and Irish law applies. | Services Agreement and DPA, concluded through sales with an order form. | Services Agreement and DPA. Billed separately from ChatGPT. |
| Training | Content may be used for training. Can be switched off in the settings. Giving feedback can still share the conversation. | Inputs and outputs are not used for training by default. This also applies to data from connected apps. | No training by default. | No training since 1 March 2023, unless the customer expressly opts in. |
| Retention and deletion | Chats remain stored until the user deletes them. Deletion then follows within 30 days, with exceptions. Temporary chats for up to 30 days. | Deleted or unsaved conversations are removed within 30 days, unless longer retention is required by law or is necessary to protect the services or third parties. No Zero Data Retention in the self-serve plan. | Workspace admins set the retention period. Deleted conversations are removed within 30 days, unless there is a legal retention obligation. | Abuse monitoring logs for up to 30 days by default. Application data, depending on the endpoint, partly until deleted. Zero Data Retention only after approval by OpenAI. |
| Storage location and processing location | No choice. Processing in the USA, among other places. | No data residency documented. According to the sub-processor list, processing in the USA, among other places. | Data residency for stored content in eligible new workspaces, including in the region “Europe (EEA + Switzerland)”. Model inference in the region only as an add-on option. | Data residency as a project configuration for eligible customers and only for supported endpoints. |
| Access by OpenAI | As set out in OpenAI's privacy policy. | Authorised employees for technical support, abuse investigations and legal obligations, and specialised third parties for abuse review. | Authorised employees only to resolve incidents, to recover content with the customer's explicit permission, or where the law requires it. | As for ChatGPT Business. |
| Administration | No central administration by the employer. | Admin console, four fixed roles (Owner, Admin, Analytics Viewer, Member), SSO via SAML or OIDC with domain verification. No SCIM, no custom roles, no Compliance API. Admins can view, export and delete members' conversations. | In addition SCIM, role-based access control, and the Compliance API and logs. | A separate API organisation with projects, distinct from the ChatGPT workspace. |
| Apps and connectors | Users connect apps themselves. Data from apps can be used for training if the setting is active. | Apps are enabled by default. Admins can only switch them on or off for the whole workspace. | New workspaces start with a selection of enabled apps. New apps are generally disabled. Access can be controlled per role. | The customer builds the integrations and is responsible for them. |
Four points from the documentation deserve particular attention:
- Retention in Business is not clearly documented. The ChatGPT Business FAQ states that workspace admins can control the retention period. The overview of commitments on the same page mentions this control only for Enterprise, Healthcare and Edu. Check in your own workspace which setting exists and record the result.
- Deletion commitments come with exceptions. OpenAI itself describes one case: in 2025, an order by a US court temporarily obliged the company to retain deleted content as well. According to OpenAI, this affected the then Team plan among others, but not Enterprise. According to OpenAI, the obligation ended on 26 September 2025.
- The DPA does not anticipate sensitive data. The description of the processing (Schedule 1) states that no transfer of sensitive data is anticipated, unless users unexpectedly enter it in unstructured data. Anyone who plans to process sensitive personal data systematically will find no express basis for this in the standard contract.
- Security attestations do not replace your own assessment. OpenAI states that a SOC 2 Type 2 audit has been completed for ChatGPT Business and makes audit reports available on written request no more than once a year. That helps the controller satisfy itself as required by Art. 9 para. 2 FADP. The risk assessment remains the company's task.
Storage location is not processing location
For ChatGPT Business, the sub-processor list names cloud infrastructure from Microsoft, Google, Oracle, CoreWeave and Amazon Web Services. All are listed with locations in the USA, some additionally in other countries. There are also service providers for support and content moderation, including in the USA, Canada and the Philippines. OpenAI entities in the USA, Ireland, the United Kingdom and Japan provide technical and operational support.
Even for Enterprise with data residency, OpenAI states the following: the commitment concerns stored customer content of certain features. Model inference in the region is an additional option. Steps such as authentication, routing, text extraction from files and analytics can take place outside the region. Whatever goes to third parties through apps, MCP servers or web search is subject to the terms of those third parties.
For the assessment under Art. 16 FADP, the whole chain therefore counts. The DPA provides that OpenAI Ireland transfers data from the EEA and Switzerland to recipients outside the EEA and Switzerland only on the basis of the EU standard contractual clauses or an adequacy decision of the European Commission. The FDPIC recognises the EU standard contractual clauses, provided they are adapted for Switzerland. It also requires the controller to ensure that the law of the recipient State allows the clauses to be complied with. Whether this is the case in your own contractual relationship has to be assessed and documented.
Connected apps, external actions and other data outflows
ChatGPT Business can do more than answer text prompts. Each of the following features is a separate route by which data can leave the company or be changed in other systems:
- Apps (formerly connectors): connections to services such as Google Drive, Slack, Outlook or SharePoint. ChatGPT can read content there and, depending on the app, also write. Data sent to an app is subject to the terms of the respective provider.
- Web search: ChatGPT can use information from the conversation and from apps to formulate search queries.
- Memory: ChatGPT can store information from conversations and apps and reuse it later.
- GPTs, agents and scheduled tasks: they can perform actions through connected accounts, including when triggered by events such as a new email.
- Shared links and public GPTs: content can become accessible to people outside the workspace.
Recommended practice: switch off all apps at the start and approve individual ones only after a separate assessment. Set the permission so that ChatGPT asks before every read and write access, and address shared links in the policy.
Rollout checklist
The checklist walks through the points that should be settled before the first productive use. The column “Approve or block” contains a recommendation. The decision is taken by management and recorded in writing.
| Check item | Evidence | Responsible role | Approve or block |
|---|---|---|---|
| 1. Contracts and processing by processors. Does the OpenAI Services Agreement with the DPA apply to the workspace? | Filed contract versions with their dates, DPA signed via OpenAI's form, entry in the record of processing activities. | Management, data protection lead | Approve if both documents apply to the account. Block any business use through personal accounts. |
| 2. Training. Are inputs and outputs used for training? | Section 4.2 of the Services Agreement, excerpt from the OpenAI documentation with access date, check that no voluntary data sharing is active. | Data protection lead, workspace owner | Approve with the default setting. Block feedback features for conversations containing personal data. |
| 3. Retention and deletion. How long do chats, files, projects and GPT knowledge remain stored? | The company's deletion rule, screenshot of the workspace setting, procedure when employees leave, note on OpenAI's 30-day period and its exceptions. | Data protection lead, workspace owner | Approve once the deletion rule is implemented. Block data whose timely deletion cannot be ensured. |
| 4. Storage location and processing location. Where is content stored and where is it processed? | Current sub-processor list, note that ChatGPT Business does not guarantee data residency, countries entered in the record of processing activities. | Data protection lead | Block data that must remain in Switzerland or the EEA under a contract or by law. |
| 5. Sub-processors and disclosure abroad. Are the guarantees settled for every recipient State? | Transfer assessment under Art. 16 and 17 FADP (list of States, listing under the Swiss-U.S. Data Privacy Framework, standard data protection clauses with the Swiss adaptations), subscription to change notifications, updated privacy notice. | Data protection lead, legal counsel | Approve after a documented assessment. Block as long as the guarantees for a recipient State are unresolved. |
| 6. Access and administration. Who gets into the workspace and who administers it? | SSO with multi-factor authentication through the company's own identity provider, verified domain, list of roles with at least two owners, offboarding process, rule for inviting external domains. | IT lead, workspace owner | Approve personal data only with SSO and multi-factor authentication. Block shared accounts. |
| 7. Apps, external actions, shared links. Which outward connections are active? | Inventory of enabled apps, GPTs and agents, decision per app with contract and transfer assessment, permission settings, rule on shared links. | IT lead, data protection lead | Starting point: all apps disabled. Approve individually. Block write access to customer or HR systems without an individual assessment. |
| 8. Data categories and prohibited uses. Which data may be used for what? | Classification table, list of approved use cases, a data protection impact assessment where the risk is high. | Management, heads of department | Approve per use case. Block sensitive personal data and information protected by secrecy obligations unless separately assessed. |
| 9. Instructions and training. Do employees know the rules? | Usage policy in force, training record, confirmation that the policy has been read. | HR, line managers | Workspace access only after training. |
| 10. Review of results. Who checks outputs before they are used? | Defined review step in the relevant process, spot checks. | Heads of department | Block decisions about individuals that rest solely on an AI output. |
| 11. Incidents. What happens after an erroneous input or a data leak? | Reporting channel, procedure including the assessment under Art. 24 FADP, contact list, incident register. | Data protection lead, IT lead | Approve once the reporting channel is known and has been rehearsed once. |
In small companies, several roles often lie with the same person. What matters is that every task is assigned to a named person. A data protection advisor under Art. 10 FADP (the Fedlex translation says “data protection officer”) is voluntary for private companies.
Example: three use cases in an SME
The following example is invented. “Sample Building Services Ltd” does not exist. The example shows the logic of the assessment and is not an assessment of a real case.
Sample Building Services Ltd employs 60 people and designs heating and plumbing systems for private and business customers. It has opened a ChatGPT Business workspace and wants to approve three applications.
| Application | Data category | Decision in the example |
|---|---|---|
| Marketing copy from published information | Public, no personal data | Approved with the basic rules |
| Pseudonymised support records | Personal data (pseudonymised), confidential | Approved with conditions |
| Identifiable HR records | Personal data, partly sensitive | Blocked pending a separate assessment |
1. Marketing copy from public information
Marketing has newsletter and website copy drafted from product information that has already been published.
- Does the input really contain only public material? Unpublished prices, customer names and reference projects without consent do not belong in it.
- Without personal data, the FADP does not apply to the input. The transfer assessment and the data protection impact assessment are not needed for this application.
- The result is reviewed before publication: technical details, advertising claims, third-party rights in texts and images.
Decision: approved. The basic rules of the usage policy apply.
2. Pseudonymised support records
Customer service wants to have service requests summarised and reply templates drafted. Names, addresses and telephone numbers are replaced by ticket numbers before uploading.
- Pseudonymised data remains personal data. The company holds the mapping and can identify the individuals at any time (Art. 5 let. a FADP). Pseudonymisation lowers the risk. It is not anonymisation, and the FADP continues to apply.
- Free text often contains further pointers to the person, such as the address of the property, an installation number or details of their housing or health situation. It is cleaned before uploading. The mapping table stays outside ChatGPT.
- Check items 1, 4 and 5 of the checklist are completed: contract, processing locations, disclosure abroad.
- The privacy notice names IT and AI service providers as a category of recipients and informs about disclosure abroad.
- Where the company processes data on behalf of business customers, OpenAI becomes a sub-processor. This requires the customer's prior approval (Art. 9 para. 3 FADP). Confidentiality clauses in customer contracts are checked.
- The ticketing or CRM system is not connected through an app as long as no separate assessment has been made for it.
Decision: approved with conditions, recorded in writing and limited to this use case.
3. Identifiable HR records
HR wants to have employment references, warnings and absence analyses produced from the personnel file.
- Art. 328b CO limits which data about employees may be processed at all.
- Personnel files regularly contain sensitive personal data, such as data relating to health (Art. 5 let. c FADP). OpenAI's DPA does not provide for the transfer of sensitive data.
- A data protection impact assessment has to be considered (Art. 22 FADP).
- ChatGPT Business does not offer custom roles. According to OpenAI, workspace admins can view and export members' conversations. HR content would therefore be accessible to people outside the HR department.
- Analyses of performance at work can constitute profiling (Art. 5 let. f FADP). Decisions with a legal consequence or a considerable adverse effect must not be left to the machine alone without fulfilling the duties under Art. 21 FADP.
- Employees would have to be informed about this processing and the recipients of their data (Art. 19 FADP).
Decision: blocked. General drafting assistance without names and without content from the file remains permitted, for example a suggested wording to describe very good performance in customer service. HR writes the reference itself and remains responsible for it. Approval of identifiable HR data can only be considered after a separate assessment, with an impact assessment and a settled solution for the contract and for access.
Usage policy: data classes, prohibitions, text module
A usage policy is not expressly required by law. It is, however, the obvious means of implementing the organisational measures under Art. 7 and 8 FADP. Under employment law, it rests on the employer's right to issue directives and instructions (Art. 321d CO) and on the employees' duty of loyalty and confidentiality (Art. 321a CO).
Minimum content
- Scope: all employees, apprentices and external persons with access to company data, all AI services, all devices.
- Approved tools: list with account type. For business purposes, only the company workspace counts.
- Tools that are not approved: named expressly, with a pointer to the permitted alternative.
- Data classes: which class may go into which tool.
- Input rules: data minimisation, pseudonymisation, prohibitions.
- Review of results: who checks what before a result is used.
- Duty to report: report erroneous inputs and incidents immediately and without hurdles.
Permitted data categories
| Data class | Examples | Rule for ChatGPT Business |
|---|---|---|
| Public | Published website copy, media releases, product sheets. | Permitted. |
| Internal | Process descriptions and drafts without personal data and without a confidentiality obligation. | Permitted in the company workspace. |
| Confidential | Ordinary personal data of customers, suppliers and employees, quotes, contracts, cost calculations. | Only in approved use cases, kept to a minimum and pseudonymised where possible. |
| Strictly confidential | Sensitive personal data, personnel files, information protected by secrecy obligations, data under a contractual ban on disclosure, access credentials. | Blocked. Exception only after a separate assessment and a written decision by management. |
Prohibited uses
- Business content in personal accounts or in AI services that are not approved.
- Decisions on hiring, promotion, dismissal or the conclusion of a contract that rest solely on an AI output.
- Monitoring or behavioural analysis of employees.
- Uploading entire customer, staff or payroll lists.
- Passwords, API keys and source code containing credentials.
- Enabling apps, GPT actions or agents without approval.
Text module for the internal policy
The following excerpt can be adapted and adopted. Replace the details in square brackets.
Use of ChatGPT Business at [company]
- Only the ChatGPT Business workspace of [company] is approved for business purposes. Personal accounts and other AI services must not be used for business content.
- Public and internal information may be entered. Personal data and confidential information may be entered only in the approved use cases listed in the annex, kept to a minimum and pseudonymised where possible.
- The following are not entered: sensitive personal data, content from personnel files, information subject to a statutory or contractual duty of confidentiality, and access credentials.
- Apps, GPT actions, agents and shared links may be used only if [role] has approved them.
- Results are drafts. Anyone who uses a result checks facts, figures, legal statements and third-party rights and remains responsible for the content. Decisions about individuals are never taken solely on the basis of an AI result.
- Chats and files containing personal data are deleted as soon as the purpose has been achieved, at the latest after [period under the deletion rule].
- Erroneous inputs, conspicuous results and security incidents are reported immediately to [reporting point]. Anyone who reports in good faith need not fear any disadvantage.
- [Company] may check usage within the limits of the law, in particular to investigate incidents. There is no monitoring of behaviour.
Reviewing results
Under the Services Agreement, OpenAI provides the services without any warranty as to the accuracy of the content. Responsibility for a result that is used lies with the company. For personal data, there is also the duty to satisfy oneself that the data is accurate (Art. 6 para. 5 FADP). In practice this means: check facts and figures against the source, have legal statements assessed by a specialist, and provide for sign-off by a responsible person where texts are intended for third parties.
Professional confidentiality, monitoring and incidents
Professional confidentiality: always assess separately
For information covered by professional confidentiality, the general approval of ChatGPT Business is not enough. Art. 9 para. 1 let. b FADP permits processing by a processor only if no statutory or contractual duty of confidentiality prohibits it. This concerns in particular:
- Art. 321 SCC: among others, members of the clergy, lawyers, notaries, patent attorneys, auditors subject to a duty of confidentiality under the Code of Obligations, doctors, dentists, pharmacists, psychologists and nurses, as well as their assistants.
- Art. 47 BankA and Art. 69 FinIA: directors and officers, employees and agents of banks and of financial institutions such as portfolio managers or securities firms.
- Art. 62 FADP: professional duty of confidentiality for secret personal data that a person learns while practising a profession that requires knowledge of such data.
- Art. 320 SCC: official secrecy for members of an authority, public officials and their auxiliaries.
Fiduciaries (Treuhänder) are not named in Art. 321 SCC, unless they act as auditors subject to a duty of confidentiality. For them, Art. 62 FADP, contractual confidentiality obligations and any professional rules come into consideration.
Whether engaging a cloud AI provider with processing abroad counts as the permissible engagement of an assistant or constitutes a disclosure depends on the relevant professional law, the consent of the persons entitled, the contract and the technical measures. A Business contract, the absence of training or storage in Europe do not answer this question. With ChatGPT Business, it has to be taken into account that, according to OpenAI, authorised employees and engaged third parties can view content to investigate abuse and that processing takes place in several countries.
Institutions supervised by FINMA additionally observe FINMA Guidance 08/2024 on governance and risk management when using artificial intelligence and the outsourcing requirements that apply to them.
Recommended practice: until the separate assessment is completed and documented, information protected by secrecy obligations does not belong in ChatGPT Business.
Checking usage and employee monitoring
Art. 26 of Ordinance 3 to the Employment Act (ArGV 3) prohibits monitoring and control systems that are intended to monitor the behaviour of employees at the workplace. If such systems are required for other reasons, they must be designed so that they do not impair health and freedom of movement. In addition, there is the protection of personality rights under Art. 328 CO and the limit set by Art. 328b CO.
In ChatGPT Business, according to OpenAI, workspace admins can view and export conversations. The company should therefore disclose in the policy that such access is possible and limit it to specific occasions, such as the investigation of an incident. A four-eyes principle and a log of accesses are advisable. A systematic analysis of how individual employees use the tool would probably count as monitoring of behaviour and would therefore be impermissible.
Anyone who uses AI to assess employees observes Art. 21 FADP. The provision applies where a decision is based exclusively on automated processing and has a legal consequence for the person or a considerable adverse effect on them. The company must then inform the person and, on request, allow them to express their point of view and to request a review by a natural person.
Incidents: erroneous inputs and data leaks
Entering personal data into a service that is not approved can be a breach of data security, because the data becomes accessible to unauthorised persons (Art. 5 let. h FADP). A simple procedure:
- Contain: delete the chat and files, disconnect the affected app connection. In the case of a personal account, instruct the person to delete the content and record this. By its own account, OpenAI removes deleted content within 30 days, with exceptions.
- Establish the facts: which data, how many people, which service and account type, who had access.
- Check the duty to notify: under Art. 24 FADP, the FDPIC must be notified as quickly as possible if the breach is likely to lead to a high risk to personality or fundamental rights. The data subjects must be informed if this is required for their protection or if the FDPIC so requests. The FADP sets no deadline in hours. The content of the notification is governed by Art. 15 DPO. The documentation must be retained for at least two years from the notification.
- Check further duties: contractual duties to inform customers and the consequences for professional confidentiality.
- Incident at the provider: in the DPA, OpenAI undertakes to inform customers of a personal data breach without undue delay. Determine who receives such notices.
- Learn the lessons: adjust the policy, the training and the technical settings.
EU dimension: GDPR and AI Act
For many Swiss SMEs, EU law applies in addition. The GDPR applies where a company offers goods or services to persons in the EU or monitors their behaviour (Art. 3(2) GDPR). A personal data breach must then be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours (Art. 33 GDPR).
The EU AI Act also covers deployers in third countries where the output of the AI system is used in the EU (Art. 2(1)(c)). Since the amendment by Regulation (EU) 2026/1744, in force since 27 July 2026, Art. 4 requires providers and deployers to take measures to support the development of AI literacy of their staff. They do not have to guarantee any specific level of AI literacy. Prohibited practices include emotion recognition in the workplace, except for medical or safety reasons (Art. 5(1)(f)). Training employees is recommended practice even without an EU connection.
Check before approval, support, sources
Check before approval
This short list is suitable for every new use case. If a question remains open, the application is considered blocked.
- ☐ The use case and the purpose are described in writing.
- ☐ The data class is determined: public, internal, confidential or strictly confidential.
- ☐ Personal data is limited to what is necessary or pseudonymised. The mapping stays within the company.
- ☐ No sensitive personal data and no information that is protected by secrecy obligations or restricted by contract is involved.
- ☐ Use takes place exclusively in the company workspace. The Services Agreement and the DPA are on file.
- ☐ The transfer assessment and the sub-processor list are up to date. The privacy notice covers the disclosure.
- ☐ The need for a data protection impact assessment has been examined and the result recorded.
- ☐ Apps, actions and shared links are defined for this use case.
- ☐ The deletion rule and the person responsible are determined.
- ☐ The review step for results is defined. There is no automated decision about individuals.
- ☐ The employees involved are trained and know the reporting channel.
- ☐ The decision (approved, approved with conditions or blocked) is dated and signed by management.
How SIDD supports you
SIDD develops the usage policy for generative AI together with your HR, legal and IT teams, tailored to your business model, industry and risk appetite. We deliver a modular template, adapted to your providers, your data classification and the size of your company, along with training materials, awareness materials and an incident procedure. For banks and fiduciaries, we add the procedure for professional confidentiality.
You can find out more about our services under data protection advisory and, for raising employee awareness, under IT security workshops and data protection workshops. To discuss an initial assessment of where your employees already use AI today and which risks this entails, use the contact form. For the implementation, you can request a quote.
Sources
All sources accessed on 30 September 2026. The English versions of Swiss legislation on Fedlex are translations without legal force.
Swiss law and supervision
- Federal Act on Data Protection (FADP), SR 235.1, status as of 7 July 2025
- Data Protection Ordinance (DPO), SR 235.11, status as of 1 December 2025, with the list of States in Annex 1
- Swiss Criminal Code (SCC), SR 311.0, Art. 162, 320 and 321
- Code of Obligations (CO), SR 220, Art. 321a, 321d, 328 and 328b
- Ordinance 3 to the Employment Act (ArGV 3), SR 822.113, Art. 26 (German text, no English version on Fedlex)
- Banking Act (BankA), SR 952.0, Art. 47 (German text, no English version on Fedlex)
- Financial Institutions Act (FinIA), SR 954.1, Art. 69
- FDPIC: AI and data protection
- FDPIC: Update “Current data protection legislation is directly applicable to AI”, 8 May 2025
- FDPIC: Cross-border transfer of personal data
- FINMA: Guidance 08/2024 on governance and risk management when using artificial intelligence, 18 December 2024
EU law
- Regulation (EU) 2016/679 (GDPR)
- Regulation (EU) 2024/1689 (AI Act)
- Regulation (EU) 2026/1744 amending the AI Act, OJ L of 24 July 2026
OpenAI documentation
- Enterprise privacy at OpenAI, as of 8 January 2026
- OpenAI Services Agreement, effective 1 January 2026
- Data Processing Addendum, effective 1 January 2026
- Sub-processor list
- ChatGPT Business, Overview
- Setting up single sign-on for ChatGPT Business
- Data residency and inference residency for ChatGPT
- Apps in ChatGPT
- Admin controls, security, and compliance for plugins and apps
- Chat and file retention policies in ChatGPT
- How your data is used to improve model performance
- Data controls in the OpenAI platform (API)
- Privacy policy for the EEA, Switzerland and the United Kingdom
- How we’re responding to The New York Times’ data demands
This article is general information and not legal advice. OpenAI changes products, plans and contract terms frequently. Before making a decision, check the linked documents in their current version.
