14 July 2026
Which AI tools are companies allowed to provide to employees from a data protection and confidentiality perspective? Our popular overview has grown larger and more detailed. Anthropic has been added, while well-known players have unfortunately still not fully done their homework. For part 31 of our AI blog series, we have once again analyzed the most popular offerings.
This overview can be found here.
Since our last update 15 months ago, the AI tools offered by the previously featured providers have grown significantly. We have now added Anthropic, the most important new player alongside OpenAI, Microsoft, and Google. Additionally, we have supplemented the overview with offerings from DeepL and several providers from our home market. While this list is not exhaustive, we anticipate inquiries about the omission of European offerings like Mistral. The reason is simple: we simply do not encounter them in the many companies we advise on these matters. Chinese providers of language models are also missing from the list because, although companies use their offerings, they do not use them as a service. Instead, companies deploy these (sometimes very powerful) open-source models on their own infrastructure or that of national providers. From a data protection perspective, this is the most secure option and is also easy to manage with the right hardware; however, many companies still shy away from investing in the necessary infrastructure (typically CHF 20k or more).
The AI tools previously listed surprisingly show no change in the overall assessment of the results: There are solutions that are suitable for corporate use. However, this still does not apply to all AI tools or all company data. As the range of services on offer continues to grow, the relevant contractual terms are constantly changing, and provider-specific – or even AI-tool-specific – issues regularly arise, assessing compliance remains a real challenge from the customer’s perspective. Most companies find this completely overwhelming. At the same time, intense pressure from the business side to deploy specific tools drives companies to use legally deficient solutions.
Microsoft continues to spark intense discussion, as their "Copilot" for Microsoft 365 and Azure OpenAI Services still lack a legally compliant solution for internet search (so-called web grounding). We do not understand why Microsoft cannot offer a truly data protection-compliant solution here, unlike competitors such as Google.
Furthermore, no cloud provider has satisfactorily resolved the issue of concluding agreements that meet professional secrecy requirements while also allowing an opt-out for abuse monitoring. In our view, human abuse monitoring by providers poses a problem in this context, as they monitor data, for example, to verify compliance with agreements or to report incidents to authorities if necessary. A purely automated safeguard that uses solely technical measures to prevent the AI from responding to certain requests or filtering certain outputs does not, in our view, pose a problem with regard to professional secrecy (or data protection). It is part of the service provided by the provider to the customer, including so that the customer does not have to implement its own measures (e.g., filters) to ensure compliant use of AI, and is covered by the provider’s agreement and control. If something "gets caught" in the filter, nothing happens - in both senses of the word. As long as the provider does not access the data in plain text or process it further for other purposes, we believe that abuse monitoring implemented in this manner is acceptable. The situation is different with manual abuse monitoring, where an employee of the provider reviews the content on the provider’s behalf. The customer has no influence over which specific person reviews the data and how, how that person evaluates the data, or what follow-up measures (e.g., account suspension, reporting to authorities) the provider takes. Typically, this does not constitute an auxiliary activity subject to the customer's instructions. If a company cannot opt out of human abuse monitoring with Hyperscalers, local providers offer a viable alternative; although their open-source models cannot match the full functionality and power of major cloud providers, they nevertheless present a competitive offering.
When we subsequently speak about admissibility under data protection law, we do so from the perspective of the EU General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (Swiss DPA) in the case of international cloud providers, and the Swiss DPA in the case of Swiss providers. The remarks on professional and official secrecy refer to the legal situation in Switzerland. Further explanations on this can be found here; these apply to both professional and official secrecy.
In the public sector, however, the legal situation currently plays only a subordinate role. For public administrations, procuring AI services from cloud providers is currently politically taboo, at least for bodies unable to "fly under the radar." This situation is driven primarily by hardliners among the cantonal data protection authorities who, with what we consider to be legally questionable claims regarding the U.S. CLOUD Act, for example, spread the view that cloud use is illegal for official secrecy data and that the risk-based approach does not apply—which is incorrect. Unfortunately, this has caused considerable uncertainty. We assume it will take another year or two before these authorities realize that this blocking attitude actually undermines data protection. In addition to the topic of foreign government access (Foreign Lawful Access), digital sovereignty also shapes the public sector discussion. Conversely, the private sector discusses these issues much more objectively (see here for the whole picture).
At OpenAI, nothing has fundamentally changed contractually since the last update of our table. However, we have made our table somewhat more detailed and now point out fur-ther risks that are relevant for companies:
Of course, we have also contacted OpenAI to explore among other things whether we could use their AI tools in compliance with professional secrecy. However, we received either no response or unhelpful answers from an automated bot. OpenAI therefore appears to have no interest in providing a satisfactory solution for its customers. Consequently, we believe OpenAI is unsuitable for professional and official secrecy holders, and there are also other reservations.
Microsoft has maintained its Copilot naming since our last blog post. Copilot continues to be available in numerous versions. Today, disabling Copilot is more difficult than keeping it active, which partly explains its widespread corporate adoption. For this overview, we have "only" analyzed selected variants within the Office ecosystem—specifically, the Microsoft 365 Copilot Chat integrated into many Microsoft 365 offerings and the paid add-on version, Microsoft 365 Copilot—excluding, and not Copilot in tools like Copilot Studio or GitHub.
While Microsoft's consumer offerings remain not recommended for businesses (see Blog 2), the situation with Microsoft 365 Copilot Chat (automatically included in many Microsoft 365 setups for business customers) and Microsoft 365 Copilot (as an add-on license) has not changed significantly.
What options do companies have? They can disable web search for all users, though this drastically reduces the tool's utility. Alternatively, the paid Microsoft 365 Copilot license allows users to deactivate web search individually. However, Microsoft hides this setting in a context menu, making it user-unfriendly. Furthermore, the distinction between "web" and "work" modes in the paid license confuses users. Many assume "work" mode automat-ically disables the problematic web search, which is incorrect. Based on our current understanding, web search can still occur in "work" mode unless an administrator disables it globally or the user deactivates it on an individual basis.
Many companies prohibit employees from entering personal data or confidential information into Copilot. Legally, this resembles querying an internet search engine, where providers are not data processors and typically do not guarantee confidentiality. However, search engine users control their exact search terms, and they access the service independently rather than through an employer-provided tool. With tools like Copilot, users cannot control—and often do not even know—which parts of their query the tool passes to the search engine, which impairs the level of data protection. While many queries remain unaffected, our tests confirm that web searches can transmit sensitive information to this insufficiently protected environment. We hope that Microsoft will resolve these deficiencies in its widely used tool.
Copilot illustrates how carefully cloud solution users must configure their services. For example, to resolve performance issues and to the annoyance of many data protection officers, Microsoft recently introduced "Flex Routing," a function that processes AI responses in data centers worldwide rather than exclusively in Europe to achieve better load balancing. While not objectionable under data protection law, from our point of view, it would not be acceptable for professional secrets, for example. Crucially, these processing activities outside the "EU Data Boundary" bypass contractual regulations under the label of a "service" and, according to reports, were sometimes activated by default. This reinforces our recommendation to review cloud service configurations regularly.
When using Azure OpenAI Services under a business agreement, the standard business terms generally apply, permitting internal company use. However, Microsoft applies the same exception detailed above when using Bing Search: In this case as well, the Microsoft DPA ceases to apply, and the system no longer treats entered or generated data as customer data under the MCA, leaving it without sufficient confidentiality protection. We refer to our previous explanations on this point. In the case of an API interface, whether web access is routed through the model is controlled by the application using the interface when it calls the language model. While the company can thus restrict web search usage, enabling it allows the model alone to formulate the search query from the user request and the provided context.
With Microsoft, you may use Copilot and Azure OpenAI Services with professional and official secrecy data, provided you conclude the necessary addenda, deactivate abuse monitoring, and do not use Bing Search with data subject to professional or official secrecy. On a positive note, small and medium-sized enterprises can also easily obtain these contract addenda. For further details, please refer to the explanations in the previous blogs (Blog 2, Blog 25). Additionally, when purchasing Microsoft services via a Cloud Solution Provider (CSP), companies must note that the addenda necessary for professional and official secrecy (as well as other contract addenda) are not concluded through a formal process. Therefore, companies should apply our workaround for the missing signature on Microsoft Cloud contracts. Less positive is that Microsoft currently limits the OpenAI Services abuse monitoring opt-out to customers managed directly by Microsoft. However, Microsoft is in the process of testing and hopefully introducing a new process to grant this opt-out to certain professional groups, such as law firms, even if they "only" purchase their Microsoft services via a CSP rather than directly from Microsoft.
It is also worth noting that the Microsoft DPA now applies a 30-day notification period for engaging new AI sub-processors, replacing Microsoft's customary six-month period. However, Microsoft allows customers to deactivate the use of any such sub-processor for at least six months following the announcement.
We have added the Anthropic Claude models to this edition of the overview, including vari-ous consumer plans and the three business plans: "Team", "Enterprise", and "API". As with other providers, Anthropic's consumer plans are unsuitable for corporate use. Conversely, the business plans include a data processing addendum (Anthropic DPA), a confidentiali-ty obligation, and an assurance that Anthropic will not use data for training or service im-provement. Consequently, we believe corporate use is generally permissible, subject to the following considerations:
We have now included DeepL in our overview, covering both the DeepL Free and DeepL Pro versions. Unsurprisingly, we do not recommend the free version for corporate use, as DeepL may use the entered data for its own purposes. Translating texts that contain personal or confidential data requires a DeepL Pro subscription.
We are unaware of any standard addenda for DeepL regarding professional and official secrecy data. Without a special agreement, it must be assumed that DeepL processes data in US and other non-European data centers. However, our experience shows that clients with sufficient contract volume can negotiate contract adjustments, including provisions for professional and official secrecy data.
The entire overview can be found here.
Google has released new offerings, including various versions of Google Gemini Enterprise and renamed some existing offerings. Free versions for business customers (such as the free Google Gemini Enterprise – Business Edition) and for consumers are unsuitable for corporate use since they are either obtained under a consumer contract or Google uses the data for its own purposes. Generally suitable for companies are offerings that are part of the Google Cloud Platform (GCP) and are thus obtained under the "Google Cloud Platform Terms of Service" (GCP Terms). It should be noted in this context that certain offerings for companies are not obtained under the GCP Terms, but under various other contracts, each of which must be examined in detail.
Also for the services purchased under the GCP Terms, not every service is suitable for every use case. Specifically, when using web grounding (web search) via Gemini, certain variations allow Google to store data for debugging. However, unlike Microsoft, Google offers "Web Grounding for Enterprise" when accessing Gemini models via API, whereby no storage for debugging takes place and use with professional and official secrecy data is possible, provided that the further requirements for this are met (see the following explanations on professional and official secrecy). To the best of our knowledge, Google is currently the only provider to do this. This demonstrates once again that the hyperscalers' service-specific terms must be examined in detail in each case.
Google's offerings can be used via the web or as an app (use via the UI) (such as Google Gemini Enterprise) or integrated into Google Workspace. In addition, they are available as an API service, allowing the AI models to be used in one's own systems (such as with "Red Ink"). As explained below, it is important to note that not all offerings are actually suitable for corporate use, even if the name of the service suggests otherwise.
In case of use via the UI as well as with Google Workspace, the following points should be noted:
When using API Services, several aspects should be noted:
If special addenda for professional and official secrecy have been concluded, abuse monitoring is deactivated, and web grounding is not used (or, if available, only Web Grounding for Enterprise is used), the processing of professional and official secrecy data is generally possible. As a further measure, data storage within one's own country and, for data processing abroad, Zero Data Retention (no storage of queries to the AI) should be provided. The latter, i.e., Zero Data Retention, requires that caching be deactivated. Furthermore, we recommend setting up "Access Approval", i.e., access by Google employees generally only takes place with the customer's approval (the equivalent of Microsoft’s "Customer Lockbox"). The remaining probability of Foreign Lawful Access must be assessed separately. For both Google and Microsoft, the trend away from nationally defined processing locations continues: while the top models could originally still be obtained in Switzerland, they were subsequently only offered in selected data centers in other EU countries. In the meantime, Google sometimes only offers its models in such a way that they run somewhere in the EU in order to better distribute the load.
Obtaining the special addenda for professional and official secrecy is more difficult with Google than with Microsoft (where any CSP reseller can provide them). Although customers can conclude the "ordinary" Google Cloud Platform agreement online, the secrecy addendum requires an offline billing contract, i.e., a manually brokered agreement that Google typically reserves for larger clients. For smaller institutions like law firms, securing such a contract usually requires specific contacts and can take several months. Fortunately, we have already successfully brokered several of these contracts (see here). We hope that this manual, informal process can be automated or accelerated in the future. Currently, however, it is unfortunately the case that professional and official secrecy holders can only obtain corresponding AI contracts from hyperscalers through arduous workarounds.
AWS - the third major provider, does not yet offer an official solution for smaller institutions, but we are in discussions with them to find a resolution. Unfortunately, such initiatives typically take months or years, which in most cases is due to corporate bureaucracy rather than business or legal issues.
The entire overview can be found here.
All three major hyperscalers, Microsoft, AWS and Google allow their customers to use Anthropic's models. These then either run on the hyperscalers' data centers, or Anthropic is engaged by the hyperscaler as a sub-processor (for example, in the case of Microsoft Copilot).
At Microsoft, for example, this approach is currently being used with Copilot, where customers are given the option to use Anthropic models as an alternative to the GPT models for Copilot. At present, the data is processed by Anthropic on systems located in the United States. This does not raise any data protection concerns, as Microsoft is obligated under its Microsoft DPA to ensure the necessary protection of the data and to impose the corresponding obligations on its sub-processors. The fact that Anthropic is not certified under the Data Privacy Framework (DPF) does not change this; Microsoft is contractually obligated—and required under the DPF—to properly integrate Anthropic into its contractual framework. However, this option is out of the question for professional and official secrecy data. That said, we have heard that Anthropic plans to run its models in data centers in Europe by the end of the year.
For certain offerings, hyperscalers host Anthropic models as virtual copies within their own data centers. This setup allows customers to procure these models under the hyperscalers' own contracts, which are better suited for sensitive applications and—with the necessary addenda—legally viable for professional and official secrecy data; in some cases even within Europe (though at relatively high prices). While we have not examined AWS and Microsoft Azure in detail, Google establishes the contractual relationship directly with the customer, even though the customer must agree to "comply" with the Anthropic Terms of Service when activating model access. We assume Anthropic requires this of hyperscalers to ensure that their models are used as specified by Anthropic. According to Anthropic’s statements in its Service Specific Terms, at least in the case of Google, Anthropic has no access to the customer’s Google Cloud Platform environment or to the inputs and outputs processed there. Anthropic therefore does not view or monitor the customer’s data or its processing when its models are obtained through Google—in such cases, this is done solely (but at least) by Google as part of its abuse monitoring. According to our understanding, this exclusion does not apply to so-called Covered Models, where Anthropic retains access to customer data even through a hyperscaler (e.g., for abuse monitoring) and thereby commits to the Anthropic DPA. Furthermore, because certain Anthropic services support specific functions like web search, organizations must verify in each individual case which data protection assurances the providers actually make (and, above all, which they do not).
We have now also included the first Swiss providers in our overview who state that they meet the requirements regarding professional and official secrecy. We analyzed the providers' online contracts as a basis. For professional and official secrecy data, we offer a standardized contract addendum that should be required of Swiss providers. This addendum supplements the data processing addendum and the general terms and conditions, and you can obtain it here free of charge.
The entire overview can be found here.
As a law firm, we have deliberately chosen not to use the commonly available tools—in particular ChatGPT and Copilot—because these products either do not provide the necessary protection for our data (ChatGPT) or fail to meet our standards in terms of functionality and performance (Copilot). We use "Red Ink", a Swiss product we developed ourselves, which enables the use of all common models—including on-premises—and is integrated into Microsoft Office, among other platforms, where it offers significantly more than other products (more information here). We use Google’s Gemini models under a Google contract that includes professional and official secrecy addenda, an abuse monitoring opt-out, and zero data retention, hosted in data centers within the EU—including unrestricted web search. Besides, we have adopted Microsoft Azure OpenAI Services as a "second source" with the latest GPT models, likewise under an agreement compliant with professional and official secrecy requirements and featuring an abuse monitoring opt-out (though without web search in that instance). We also offer our employees access to Perplexity, OpenAI (directly), and Anthropic, though not for sensitive data. By accessing the AI directly via an API on a pay-as-you-go basis, we keep costs significantly lower than other companies and can also better control access. However, we have also tested our solution with powerful open-source models (on systems from the Swiss provider onprem.ai) and were pleasantly surprised by the high speed and quality that can now be achieved when the models are properly configured and deployed on suitable systems.
Beyond language model access, organizations must consider the data security and data protection compliance of the software itself (especially in agentic operating mode) and the risks associated with accessing external data sources. We will comment on this separately, as it currently represents a common blind spot in AI integration. This is because the issue mentioned above regarding Copilot’s web search essentially arises with any AI system that accesses third-party data sources (e.g., MCP servers or connectors). Uncontrolled collection of data also raises data protection issues. In other words, it is no longer sufficient to focus solely on the data-protection-compliant use of AI services—the entire ecosystem must be taken into account.
This article is part of a series on the responsible use of AI in companies:
We support you with all legal and ethical issues relating to the use of artificial intelligence. We don't just talk about AI, we also use it ourselves. You can find more of our resources and publications on this topic here.