Can you put customer data into AI systems?

The question usually gets asked too late — after the first data has already been entered. This piece sets out the legal position, names the three points that have to be settled before first use, and supplies the questions to put to the provider.

A cluster of glowing particles enclosed by a translucent shell
Note This piece provides orientation and does not replace legal advice. What applies to your particular case depends on your data, your purpose and your provider — and should be checked once by someone who carries liability for it.

In short

  • Personal data may go into an AI system where a data processing agreement exists, the place of processing is settled, and use for training is contractually excluded.
  • A setting in the account is not enough. What counts is the contractual commitment — settings can be changed, including by accident.
  • Free access and consumer accounts are fundamentally unsuitable for customer data, whatever the provider.
  • The most common breach is not a deliberate management decision but the employee pasting in a customer's text to have it rephrased.

Few topics create as much uncertainty in companies — and as few concrete rules. In practice it usually goes like this: someone uses an AI tool for daily work, at some point pastes in a customer enquiry, and nobody ever decided whether that is allowed.

The good news: the legal position is clearer than the state of the debate suggests. It comes down to three questions.

Glowing particles enclosed by a translucent shell, others drifting past outside
The line does not run between permitted and forbidden, but between settled and unsettled.

The three questions

What has to be settled before the first input

1. Is there a data processing agreement?
Anyone having personal data processed by a service provider needs a contract for it — in the EU under Article 28 GDPR, in Switzerland under the revised Data Protection Act. Without that contract the processing is unlawful, however secure the provider's technology may be.
2. Where is the data processed?
Within the EU or Switzerland this is unproblematic. Processing in third countries requires a sound basis — an adequacy decision or standard contractual clauses, for instance. Check what the provider commits to, and whether it offers a processing location in Europe.
3. Is use for training excluded?
The point at which business and consumer access differ most clearly. What matters is not a switch in the settings but a contractual commitment. A switch can be flipped — by a person, by accident, on a product change.

Worth knowing

The GDPR applies to Swiss companies too, as soon as they process data of people in the EU — customers, prospects or newsletter recipients from the EU area. Being based in Switzerland does not on its own exempt you.

Conversely, the revised Swiss Data Protection Act applies to processing with a Swiss connection. Many companies therefore have to satisfy both — which in practice usually means working to the stricter standard.

What counts as personal data in the first place

This is where the most common misjudgement sits. Personal data is not only the name in a field, but anything that makes a person identifiable.

Unambiguously personal

Names, email addresses, phone numbers, postal addresses, customer numbers in combination with a name, photographs.

Handling: only within a settled framework

Frequently overlooked

A customer enquiry verbatim. A meeting note. A quote with a company name and contact person. A complaint email pasted in to be rephrased.

Handling: the same as above — this is regularly underestimated

Usually unproblematic

Aggregated figures with no individual reference. Publicly available market data. Your own texts without personal reference.

Handling: at your own discretion

Specially protected

Health data, information on religion, trade union membership, sex life, biometric data. Considerably stricter requirements apply here.

Handling: not without case-by-case legal review

What to ask the provider

Two geometric surfaces meet along a precise seam of light
The contract is the actual joint. Without it nothing fits together, however good the technology.

These six questions can be sent by email and should be answered in writing. Anyone evading one of them has answered it.

Enquiry to the provider
1. Do you provide a data processing agreement under Art. 28 GDPR?
   Please send us your template.

2. In which countries is the data processed and stored? Do you
   offer processing exclusively within the EU?

3. Is the use of our inputs for training models contractually
   excluded – not merely via an account setting?

4. How long are inputs and outputs retained, and how can we
   request deletion?

5. Which sub-processors do you use, and how are we informed of
   changes?

6. How do you support us with access and deletion requests from
   data subjects?
Question three is the decisive one. "We do not use your data for training" in a marketing statement is a different thing from the same statement in the contract.

The rule that actually works

From practice

Most breaches do not arise from a deliberate management decision but in the course of the working day: someone has a difficult customer email in front of them and pastes it in to have a reply drafted. That is understandable, efficient — and, depending on the framework, unlawful.

What works in practice is not training on legal bases but one single clear rule everyone can remember. Ours is: anything containing a name goes only into the approved system. Everything else is unrestricted.

That formulation is legally incomplete — there is personal data without names. But it gets followed, and that is worth more than a correct rule nobody remembers.

Tip Where an approved system is available, the number of breaches drops far more sharply than through any instruction. The reason is simple: most people do not circumvent a rule out of defiance, but because they want to get their work done and see no permitted route.

Anonymising as a middle way

Where no approved system is available, the personal reference can often be removed before the text is entered. "Mr Meier from Schmidt Construction is complaining about the late delivery on 12 June" becomes "a customer is complaining about a late delivery".

Two caveats come with that. First: if enough particulars remain, the person becomes identifiable again — locations, industry descriptions and dates in combination are often sufficient. Second: whatever is essential to the task must not fall away, or the result is worthless.

As a rule of thumb: for help with phrasing, anonymising works well. For anything that needs the specific case it does not — and there, no route avoids a properly settled system.

In closing

The question is answerable, and it is answerable before anything happens. Settle three points, sign a contract, approve one system, and phrase a rule people can remember — that is an afternoon's work and one invoice from a lawyer.

What it costs not to do it is harder to quantify. The fine is one thing. The other is the customer asking what happened to their data, and having no sound answer to give.

Common questions

Can you enter customer data into ChatGPT?

Only with a data processing agreement, a settled place of processing and contractually excluded use for training. For free access and consumer accounts those conditions are generally not met. For business offerings they can be checked — and that belongs before the first input.

Does the GDPR apply to Swiss companies?

Yes, as soon as data of people in the EU is processed. Being based in Switzerland does not on its own exempt you. The revised Swiss Data Protection Act applies in addition. Many companies have to satisfy both and therefore work to the stricter standard.

Is switching off training in the settings enough?

No. A setting can be changed — by a person, by accident, or on a product change. What counts is the contractual commitment. Flipping the switch alone leaves you without a sound basis.

What counts as personal data?

Anything that makes a person identifiable — not only the name. That includes customer enquiries verbatim, meeting notes and quotes with a named contact. Those are precisely the cases most often overlooked in daily work.

Does anonymising the text beforehand help?

For phrasing tasks, yes. What matters is that the person really is no longer identifiable afterwards — location, industry and date in combination often restore the connection. For tasks that need the specific case, anonymising is no substitute for a settled framework.

What is the most workable rule for a team?

One that can be remembered: anything containing a name goes only into the approved system. Legally incomplete, but followed in daily work — and that has more effect than a correct rule nobody recalls. More important than the rule, though, is that an approved system exists at all.

Marketing that sets itself up

The Studio Engine beta is live. Claim your spot and help shape it from the start.

Join the beta →
← Back to overview