
The question "Which data can go into ChatGPT?" arrives too late in most companies. It gets asked after the quote, the customer email thread and half the meeting minutes have long been pasted in. Not out of malice, but because the tool is useful and nobody ever said what the rules are.
A typical case from our work: A head of sales wants to polish the language of a quote and copies it into ChatGPT. All of it, with the customer name, the contact person, prices and the discount structure. To him, this was a writing problem. That he had just transmitted customer data and his own pricing calculation to a third party never crossed his mind, and honestly: why would it? Nobody had ever told him where the line runs.
We see this pattern in almost every conversation about AI adoption. Management is still debating whether to allow ChatGPT. The workforce answered that question long ago, on private accounts, with company data. The debate about whether is settled, it just never happened in the meeting room. What remains is the question that matters: which data may go in and which may not.
And that question can be answered, with three lists that fit on a single A4 page. You do not need a tool list for it. Step by step.
Which data can go into ChatGPT?
Public information can go into any AI tool. Internal working documents can go into a company account whose contract excludes training on your inputs and governs data processing. Personal data of customers or employees and genuine trade secrets belong only in environments you control contractually and technically. They never belong in private free accounts.
That is the short answer. It has a catch, and the catch is the point of this article: The answer assumes you know which of your data is public, internal or confidential. Exactly this decision is missing in many SMEs. ChatGPT did not create this gap, it just makes it expensively visible for the first time.
Why the tool list does not work
The first reflex in many companies is a tool list. ChatGPT allowed, another tool blocked, a third one under review. That feels like control and is not.
For two reasons. First, the list ages faster than you can maintain it. New tools appear all the time, the existing ones add new features, and AI now sits inside software that is on no list at all, from the mail client to the CRM. Second, the list answers the wrong question. Whether a tool is approved says nothing about what may go into it. The quote with the customer name is just as wrong in the approved tool as in the blocked one.
The reverse sorting is more stable: not by tools, but by data. Three categories are enough.
- Green, can go anywhere: everything that is already public today or could be without any problem. Website copy, published prices, generic drafts without names and without customer references. The rule of thumb: Whatever you would send to a journalist without hesitating is green. Anyone may work with this, in a private account too.
- Orange, company account only: internal working content without personal data. Process descriptions, concept drafts, code without credentials, anonymized figures. Allowed, but only in the environment covered by a contract with the provider.
- Red, not at all: personal data of customers and employees, anything under NDA, trade secrets, credentials, pricing calculations. What sits here goes into no external AI tool until someone with decision-making authority defines a vetted exception.
The most common objection to the red list is: "Then we will just anonymize it." The idea is right, the execution is underestimated on a regular basis. Deleting the customer name is rarely enough. If the quote names the industry, the location and the project volume, every reader from your region knows who it is. Anonymizing means making the case unrecognizable, not just emptying the name field. Done properly, it legitimately moves content from red to orange. Done half-heartedly, it keeps the same data in there and adds a clear conscience that switches off the caution.
If you have ever set up a data classification, you will recognize the principle: It is the same exercise, just with a concrete trigger. In our experience, the AI question is the best trigger this exercise has ever had. Classification used to be a paper topic, now it decides daily what flows into someone else's data center.
Personal data: the law already applies
A widespread misconception goes: As long as Switzerland has no AI act, the legal situation is open. The opposite is true.
The Swiss Federal Data Protection and Information Commissioner has stated it: The Data Protection Act is worded in a technology-neutral way and is directly applicable to AI-based data processing. Whoever puts personal data into an AI tool is processing personal data, with all the duties the FADP knows: transparency about purpose and data sources, proportionality, the access rights of the persons concerned.
A dedicated AI act will change little about that. In February 2025 the Federal Council decided to adopt the Council of Europe's AI convention and sharpen sector-specific rules instead of building a horizontal AI act along EU lines. Translated, that means: There is no new base rule coming that you could wait for. The rule that applies to your customer data has applied since September 2023.
In practice this means: As soon as personal data moves into an AI tool, the provider processes it on your behalf. That requires a contract governing it, and an answer to the question of which country the data flows to. With a private free account you have neither. There is no data processing agreement between your company and the provider, because your company is not even a contracting party. The employee is, as a consumer. The same applies internally: An applicant's CV or the payroll list has no place in an AI tool without a proper contractual basis.
The account decides more than the tool
Which brings us to the part missing from most discussions. "ChatGPT" is not a single thing. Behind the same product name sit different contractual relationships, and the difference is not in the technology, it is in the fine print.
A private free account is a consumer relationship. The provider owes something to the individual user, and nothing to your company. A business subscription is a commercial contract, with data processing terms, typically with the assurance that inputs are not used for training, and with administrative controls over who may do what.
Before you release an AI tool for the team, you therefore need exactly two answers from the contract, not from the marketing: Is our input used for training? And where does the data reside? If you cannot find or cannot understand these two answers, that is not a detail problem, that is the answer. Then the tool is not ready for orange or red content.
The company account brings something else the consumer relationship lacks: visibility. You see who uses the tool, you can suspend accounts when someone leaves, and you can set retention periods for chat histories. That sounds like administration, but it is the difference between "we assume the team uses AI" and "we know it and we have it governed". You can say the second sentence to a customer's face when their security questionnaire asks about your AI practices. The first one, better not.
The consequence is uncomfortable for everyone hoping for a ban: A ban without an alternative creates exactly the situation you want to prevent. The work does not disappear, it shifts to private accounts and private devices, where you have neither contract nor insight. The company account is therefore not a comfort question. It is the protective measure with the biggest lever. If you run M365, you already know this logic from the Copilot rollout: The order of steps decides, not the product.
One page is enough to start
Let's be honest: Most of what circulates on this topic is oversized. You do not need an AI competence center or a 20-page rulebook to answer the ChatGPT question. You need one page with the three lists, with five concrete examples from your own business per list. So not "confidential information", but concrete: "our margin per order", "anything with a customer name in it".
How you introduce the page decides its effect. As an attachment to an all-staff email it dies unread. What works: fifteen minutes in the next team meeting, with your own examples, and with the honest sentence that this is not about control, it is about nobody sending customer data to a provider by accident. The workforce is usually relieved. Most of them knew the gray zone existed and would have liked to know earlier what the rules are.
Add two decisions: a company account, so the orange list has a legal place to live, and one person who decides edge cases, so that "don't know" does not automatically mean "go ahead". Why this is not a legal obligation and still cannot wait is something we wrote up in our piece on the AI policy. And if you want to approach the exercise in a structured way, from data ordering to the directive, that is the core of our AI governance work. An initial conversation is enough to see how big the exercise is in your company. It is usually smaller than feared.
The test for your company is simple. Ask three people from different departments what would sit on your red list. If you get three different answers, you do not have an AI question, you have an ordering question, and now a good reason to settle it.
What would sit on your red list?




