Skip to content
Vienna, AT

Data protection reference  ·  DACH  ·  interactive

Popular AI tools: what about data protection?

Pick the data class you care about. We’ll show which tiers are contractually workable in DE · AT · CH — and where training or web access breaks the model. Tap any cell for the verdict and reasoning.

Published by kilga.io— AI strategy & governanceCoverage DE · AT (EU GDPR) + CH (revised FADP)Status Jul 2026
How we assess · methodology & DACH notes

This is a contractual data-protection read on mainstream AI offerings for the DACH region — which tier is workable for personal data, confidential data, or professional secrets, and who reserves the right to train on your inputs.

DACH. Germany and Austria fall under the EU GDPR (with §203 StGB / professional-secrecy rules on the “secrets” row); Switzerland under the revised FADP (nDSG) and Art. 321 StGB. Contract with the EU entity where offered and rely on the EU-US Data Privacy Framework or SCCs; for Switzerland, use the Swiss annex to the SCCs. EU-native (Mistral) and German-jurisdiction (Aleph Alpha) providers sidestep the US-transfer question, which is why they score strongly on sovereignty-sensitive rows.

Footnotes: *For web search, the MCA & DPA do not apply — the Microsoft Services Agreement for private customers applies instead. ** When using Bing Search in Azure, Bing grounding terms also apply; the DPA does not cover that data as customer data.

Start with your question

What data are you protecting?
Filter by provider
Find a tool
More filters · highlight, consumer plans
Highlight verdict
Read Meets Measures required Not met Risk decision N/AWEB Web terms riskDEBUG Debug use
Full legend & BYO-key note

How to read a cell — risk map

Minimum requirements generally met. Calm / no fill: suitable for the data class in that row, subject to correct configuration.
Risk-based decision required. Accent ring: verdict carries a reservation spelled out in the cell note / drawer.
Additional measures or restrictions required. Faint rose: only if amendments or configuration steps are in place.
Minimum requirements not met. Deeper rose = higher risk — not suitable (or the provider uses your data for its own purposes).
Not applicable. The row’s question doesn’t apply to this offering.

Badges

WEBWith web access, different contractual terms apply or data is used for the provider’s own purposes — not suitable for personal, confidential or secrecy-protected data.
DEBUGWhen accessing the web, data may be used for debugging — a risk assessment is required.

About “Use via a BYO-key add-in”

Marks tiers that can be driven from a bring-your-own-endpoint Office add-in (Word / Excel / Outlook) via your own LLM API key. Only API-based services qualify — consumer chat apps do not.

Phone layout: Scorecard is the default. Matrix is available as a wide comparison after you unlock it — it needs horizontal scrolling.

*For web search, the MCA & DPA do not apply — the Microsoft Services Agreement for private customers applies instead.

** When using Bing Search in Azure, the Terms of Use for Grounding with Bing Search / Grounding with Bing Custom Search also apply. The DPA does not apply and the entered data is not treated as customer data.

This table is published and maintained by kilga.io. It is for information purposes only and does not constitute legal advice. The suitability-for-use assessment requires a risk assessment by your own organisation plus correct configuration of the tools. Agreements for customers in the DACH region — Germany and Austria (EU GDPR) and Switzerland (revised FADP) — were taken into account; different agreements may apply in other regions. These considerations cover data protection only, not other areas of law such as copyright. Providers change their terms and offers frequently — always confirm against the live documents linked here. Status July 2026; linked Terms/DPA URLs re-verified from the providers’ current pages. The analytical framework builds on a publicly published DACH data-protection analysis of mainstream AI tools.

Compare