Language models are powerful, but they work with data. Anyone entering personal information carries responsibility.

Why data protection is central here

The revised Swiss Data Protection Act and the EU GDPR are based on the same principles: purpose limitation, data minimisation, transparency and the rights of data subjects. These principles also apply when data flows into an AI tool.

What makes personal data special

Personal data is anything relating to an identified or identifiable person, including names in emails, notes or customer enquiries. Important: anyone using an AI tool remains responsible for the data; the provider becomes a processor and requires a contract.

Three everyday rules

  • Minimise: only enter what is truly necessary, omit or anonymise names and addresses where possible.
  • Set rules: a list of approved tools with clear limits, data types, retention, location.
  • Inform: let data subjects know when their data is processed with AI.

Control instead of prohibition

A blanket ban helps no one. Clear guard rails are better: approval processes, review duties, an incident reporting channel and training for everyone working with AI.

Data protection is not an obstacle to AI, it is the condition for using it with a clear conscience.

Conclusion

Anyone using AI makes decisions about data every day. With a few clear rules, the benefit stays large and the risk small.

Sources & further reading

© 2026 Teccore GmbH. This article is protected by copyright. External sources are linked and cited; quotations with proper attribution are welcome.

Related articles