Everyone’s talking about artificial intelligence—but what actually happens to your data when you use ChatGPT, Copilot, or other AI tools? There are three terms you should know: data protection, feedback loop, and the CLOUD Act. Here’s an overview—clear, practical, and covering the most important laws for Switzerland, Germany, and Austria.
Why This Issue Affects Everyone
You type a question into an AI tool, upload a document, or rate an answer with a „thumbs up.“ What many people don’t know: At that very moment, your data can not only be processed but, under certain circumstances, also used to train the AI model. And depending on where the provider is based, even U.S. authorities may have access to it.
That sounds alarming—but there’s no need to panic once you understand the context. That’s exactly what this article is about.
1. Data Protection: The Rules for Your Data
Data protection addresses a very fundamental issue: Whether and how your personal data may be processed. Personal data refers to any information that can be used to identify you directly or indirectly—such as your name, email address, IP address, and even your chat history with an AI tool.
An Overview of the Most Important Laws
In the EU The General Data Protection Regulation (GDPR) has been in effect since 2018. It establishes principles that serve as a common thread throughout everything: lawfulness, transparency, purpose limitation, data minimization, and integrity. Every instance of data processing requires a legal basis—for example, your consent or a legitimate interest on the part of the provider.
In Germany The Federal Data Protection Act (BDSG) supplements the GDPR, among other things, with stricter rules regarding employee data. In Austria The National Data Protection Act (DSG) governs implementation and oversight by the Austrian Data Protection Authority.
In Switzerland The revised Data Protection Act (revDSG) has been in effect since September 1, 2023. Its content is closely modeled after the GDPR, but it remains a separate Swiss law. The principles are comparable: proportionality, purpose limitation, data security, and transparency.
What does this mean for AI?
As soon as an AI system is trained, tested, or operated using personal data, these laws apply. So if you type into an AI tool, „I, Roger from Zurich, with this email address…“—that constitutes personal data, and data protection laws apply.
Important: Data protection law no longer applies only when data has been anonymized to such an extent that re-identification is practically impossible.
2. The Feedback Loop: When AI Learns from Your Data
The so-called „feedback loop“ describes a process that many users aren’t even aware of: Your inputs—such as prompts, uploaded files, and even ratings like „This answer was helpful“—can be used to further develop the AI model. Technically, this data is incorporated into future training, validation, or fine-tuning cycles.
Is that allowed?
Under the GDPR and the revDSG, training using personal data is permitted only under certain conditions:
- There must be a Legal Basis are present (e.g., your consent or a legitimate interest on the part of the provider following a careful balancing of interests).
- The Purpose must be clearly explained, for example, „Improvement of the model.“.
- The principle of Data Minimization: Whenever possible, data should be pseudonymized or anonymized.
- For data requiring special protection (Health, religion, political views)—in practice, explicit consent is almost always required.
Your Rights: Opt-out and More
As a data subject, you have a whole range of rights under the GDPR and the revised GDPR:
- Right to Information: What data does the provider have? What is it used for?
- Right to erasure: The famous „right to be forgotten.“.
- Right to Object: This is particularly relevant in AI training—you can object to the processing if it is based on a legitimate interest.
- Withdrawal of Consent: You can do this at any time. From that point on, your data may no longer be used.
Practical Tip: Many AI providers offer an option in their settings such as „Use my data to improve the model.“ Here, you can typically opt out of future training. Be sure to do this—especially when dealing with sensitive topics.
3. The U.S. CLOUD Act: When U.S. authorities can access your data
Now things are getting geopolitical. The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) is a U.S. law passed in 2018. It states that U.S. law enforcement agencies can access electronic data held by U.S. service providers—specifically regardless of where this data is stored.
In practical terms, this means: If you use a service from Microsoft, Google, or Amazon, U.S. authorities can theoretically demand access to your data—even if the servers are located in Frankfurt, Vienna, or Zurich.
Why is that a problem?
From the perspective of the EU and Switzerland, such a disclosure constitutes a transfer to a third country, which is subject to strict requirements under the GDPR and the revised Swiss Data Protection Act. This gives rise to a fundamental legal conflict: What U.S. law requires may be prohibited by EU/Swiss law.
Here's an example: If you store patient data in a U.S. cloud service, a U.S. government agency could demand access under the CLOUD Act—even though European and Swiss law would normally require strict conditions to be met for such access.
4. Bonus: The EU AI Act—New Rules Specifically for AI
Since 2024, Regulation (EU) 2024/1689—known as the AI Act—has established the EU’s first AI-specific regulation. It is important to understand that the AI Act does not replace the GDPR, but rather supplements it.
Article 10 is particularly relevant to AI training, as it sets out requirements for training, validation, and test data—namely, quality, representativeness, and governance. Strict obligations apply to high-risk AI, and for large foundational models (General Purpose AI), there are transparency requirements regarding training data.
What does all this mean for you in practice?
Here are the key recommendations for action:
Check the following for every AI tool: Where is the provider located? What data is stored? Is it used for training? Is there an opt-out option?
For sensitive data: Choose providers in the EU or Switzerland that have no or limited exposure to the CLOUD Act and offer clear options to ensure your data isn't used for training purposes.
If you use AI yourself: Document the legal basis and the purpose. Whether it’s the GDPR or the revDSG—without a clear legal basis, it becomes legally problematic.
This article provides a general overview and is not a substitute for legal advice. For company-specific questions, we recommend consulting a specialist in data protection law.
Sources and Additional Information
ADVANT NCTM. (n.d.). The European Commission’s Template on Training Data Transparency: Initial Guidelines for the AI Act. https://www.advant-nctm.com/en/news/the-european-commissions-template-on-training-data-transparency-first-guidelines-for-the-ai-act
AI Act Info. (n.d.). Article 10: Data and Data Governance. https://aiactinfo.eu/article/article-10-data-and-data-governance
Datalynx. (n.d.). Six Principles on the CLOUD Act from Microsoft. https://datalynx.ch/en/insights/it-support/six-principles-on-the-cloud-act-from-microsoft/
DLA Piper. (n.d.). Data Protection Laws Around the World: Austria. https://www.dlapperdataprotection.com/index.html?t=about&c=AT
European Data Protection Board [EDPB]. (2024). EDPB Opinion on AI Models: GDPR Principles Support Responsible AI. https://www.edpb.europa.eu/news/news/2024/edpb-opinion-ai-models-gdpr-principles-support-responsible-ai_en
Eurojust. (n.d.). Cloud Act. https://www.eurojust.europa.eu/publication/cloud-act
University of Applied Sciences Northwestern Switzerland [FHNW]. (n.d.). Data Protection Seminar. https://www.fhnw.ch/de/weiterbildung/wirtschaft/seminar-datenschutz
GDPR Local. (n.d.). GDPR & Machine Learning. https://gdprlocal.com/gdpr-machine-learning/
heydata. (n.d.). How to Train AI Models Using Personal Data Without Violating the GDPR. https://heydata.eu/en/magazine/how-to-train-ai-models-with-personal-data-without-violating-gdpr/
Kiteworks. (n.d.). German Federal Data Protection Act (BDSG). https://www.kiteworks.com/risk-compliance-glossary/german-federal-data-protection-act-bdsg/
LEXR. (n.d.). From Concept to Implementation: The Legal Framework for AI Training Explained. https://www.lexr.com/de-ch/blog/von-der-idee-zur-umsetzung-rechtsgrundlagen-fur-ki-training-erklaert/
Petrie-Flom Center, Harvard Law School. (February 24, 2025). Europe Tightens Data Protection Rules for AI Models—and It’s a Big Deal for Healthcare and the Life Sciences. https://petrieflom.law.harvard.edu/2025/02/24/europe-tightens-data-protection-rules-for-ai-models-and-its-a-big-deal-for-healthcare-and-life-sciences/
Secure Privacy. (n.d.). Guide to German Data Privacy Laws: BDSG, TTDSG, GDPR. https://secureprivacy.ai/blog/german-data-privacy-laws-guide-bdsg-ttdsg-gdpr
Skadden, Arps, Slate, Meagher & Flom LLP. (2025). CNIL Clarifies the GDPR Basis for AI Training. https://www.skadden.com/insights/publications/2025/06/cnil-clarifies-gdpr-basis-for-ai-training
SRD Attorneys at Law. (n.d.). Privacy & AI Under the GDPR. https://www.srd-rechtsanwaelte.de/en/blog/privacy-ai-gdpr