Skip to content
Vienna, AT
Projects

Popular AI Tools: What About Data Protection?

Cover image for Popular AI Tools: What About Data Protection?
July 24, 2026
Every governance conversation I have about AI eventually lands on the same question, asked a dozen different ways: "can we actually use tool X with data type Y in Germany / Austria / Switzerland?" The honest answer is almost always "it depends on the tier, the DPA, and whether it touches the web," which is true and completely useless if you're trying to make a decision this week. Providers publish their terms, DPAs, and training policies across a dozen different documents each, phrased by lawyers for lawyers. Nobody actually reads all of it before picking a tool. Try the interactive tool → An interactive reference: pick the kind of data you're protecting (personal data, confidential data, professional secrets, or just "will this train the vendor's model on my inputs"), and it ranks and color-codes roughly 35 tool tiers, free and paid, consumer and business, across OpenAI, Microsoft, Anthropic, Google, xAI, Mistral, Perplexity, GitHub, Aleph Alpha, and DeepL, against what's contractually workable in DE/AT (GDPR) and CH (the revised FADP). Every verdict opens into a drawer with the actual reasoning: which DPA applies, what the risk reservation is, whether web access changes the terms, and a direct link to the governing document. Two things mattered more than the visual polish:
  • The reasoning has to be inspectable, not just the verdict. A traffic-light matrix that just says "yes/no" isn't decision-useful in governance work. The moment someone asks "why not," you need the actual clause. Every cell links straight to its source.
  • State has to be shareable. Filters, pinned comparisons, and the open drawer all round-trip through the URL, so a specific view (Anthropic, professional secrets, business tier) is a link you can send in Slack instead of a screen-share.
The tricky part wasn't the interaction design, it was staying honest about the difference between "meets the requirement," "workable with measures," and "technically permitted but I wouldn't recommend it." Most of these tools don't have a clean yes/no answer, and collapsing that into a simpler UI would have made the tool actively misleading. The BYO-key add-in row exists for exactly one reason: it's the row people ask about most once they've internalized that the consumer tier is off the table for company data. Bringing it into this site was its own small exercise in restraint: the interaction logic already worked, so the job was integration, matching the site's existing type and color system, wiring it into proper routing and metadata, and leaving the actual legal analysis untouched, not rewriting something that didn't need rewriting.
  • ~35 tool tiers assessed across ten providers, covering consumer, business, and API tiers
  • Six data-protection questions per tool: personal data, confidential data, professional secrets, the provider's own training use, general company use, and BYO-key add-in eligibility
  • Every verdict is sourced, governing terms and DPA links included, not just an internal opinion
  • Built as a live reference, not a one-time slide deck