# AI Contracts with OpenAI, Anthropic and Microsoft: 5 Clauses for Swiss SMEs

> Author: Chris Jon Graf (AI Strategist & CEO)
> Updated: 2026-09-15
> URL: https://ai-outsourcing.ch/insights/ai-contracts-with-openai-anthropic-and-microsoft-5-clauses-for-swiss-smes

## Summary

Swiss SMEs should focus on five contract clauses before committing to OpenAI, Anthropic or Microsoft: data processing location and DPA, training exclusion, deletion periods, subcontractors and liability caps. Reviewing these gives you a clear path to revDSG compliance and manageable risk.

## Why you should review AI contracts now

Many Swiss SMEs use ChatGPT, Claude or Azure OpenAI Service without ever reading the underlying contract. That is understandable but risky: it is not the model that determines revDSG compliance, liability and data protection, but the small print. Reviewing five central clauses gives you clarity fast.

## The five clauses in detail

### 1. Data processing location and DPA

A valid Data Processing Agreement (DPA) is mandatory under Art. 9 revDSG whenever personal data is passed to an AI provider. With OpenAI, you must actively sign the DPA via the enterprise privacy page — it is not automatically included. Swiss customers contract with OpenAI Ireland Ltd.; data residency in the EU is available for some enterprise customers. Microsoft can keep customer data in Switzerland via the Switzerland North and West regions. Anthropic stores data in the US by default; EU residency is only available through Amazon Bedrock or Google Vertex AI.

> **At a glance**
>
> Always check: Who is your contracting entity? Where is data processed? Is a valid DPA in place?

### 2. Training exclusion

The second decisive clause is whether the provider may use your data to train its models. Anthropic's Commercial Terms state that Customer Content from the Services is not used for training. Microsoft does not use customer data for training without explicit consent. With OpenAI, the training exclusion is set out in the DPA for API and Enterprise — it does not exist in consumer ChatGPT. Always ask for a written training exclusion if personal or confidential data is processed.

### 3. Deletion periods

How long are prompts and outputs stored? OpenAI retains API inputs and outputs for a maximum of 30 days and then deletes them. With Microsoft, you can disable data logging so that prompts and completions are not stored. Anthropic's retention periods are less prominent; ask about them explicitly. The shorter the deletion period, the better for compliance.

**30 days** — Maximum retention for OpenAI API inputs and outputs before deletion

### 4. Subcontractors

Almost all providers use subcontractors, for example for cloud infrastructure. The key question is whether you can object to new subcontractors. OpenAI's DPA gives you 30 days to object to new subcontractors. Microsoft publishes a subprocessor list. Anthropic processes data on AWS or Google Cloud infrastructure by default. Check whether this chain fits your risk profile.

### 5. Liability caps

Liability clauses vary significantly between providers. In practice, they rarely cover indirect damages or data loss in full, and liability is often capped. For SMEs this means: read the liability sections carefully and clarify whether you can live with the caps — or whether you need additional contractual guarantees or insurance for critical applications.

> **Don't forget the CLOUD Act**
>
> All three providers are US companies. Even with data stored in Switzerland or the EU, a US court can demand access under the CLOUD Act. EU data residency reduces the risk but does not eliminate it. If you process particularly sensitive data, address this in the contract.

## How to run the review

The review sounds like lawyers' work, but as a decision-maker you can approach it in a structured way. The important thing is not to rely on marketing slides, but to read the actual documents: DPA, Commercial Terms, product terms.

1. Request the current DPA and Commercial Terms and confirm the contracting entity.
2. Check the data processing location: Switzerland, EU or US?
3. Get the training exclusion in writing.
4. Note the deletion periods for prompts and outputs.
5. Read the subcontractor section and your right to object.
6. Compare the liability caps with your risk.

Completing this review gives you a solid baseline. For a broader governance perspective, [how mid-sized companies make AI a leadership issue](https://www.ki-podcast.ch/ki-im-mittelstand-management-thema-nicht-it-projekt) is a useful next step.

## FAQ

### Does every Swiss SME need a DPA with the AI provider?

Yes, as soon as personal data flows to a provider, Art. 9 revDSG requires a data processing agreement. With OpenAI you must actively activate the DPA; with Microsoft it applies via the product DPA; with Anthropic a Swiss DPA addendum is available.

### Can my data stay in Switzerland with Microsoft?

If you choose the Switzerland North or West regions, you can keep customer data in Switzerland. OpenAI or Anthropic do not directly offer this.

### Can OpenAI use my data for training?

In consumer ChatGPT this is possible. In the API and Enterprise area, the DPA excludes training with your data once activated. Always check this in writing.

### What does the CLOUD Act mean for Swiss SMEs?

Even with EU/CH data residency, US authorities can demand access under the CLOUD Act. Residency reduces the risk but does not eliminate it.

### What is the shortest deletion period?

OpenAI deletes API inputs and outputs after a maximum of 30 days. With Microsoft you can disable logging; with Anthropic you should ask about retention periods explicitly.

## Sources

- [OpenAI Data Processing Addendum](https://openai.com/policies/data-processing-addendum/)
- [ChatGPT / OpenAI DPA Explained (2026) — Janus Compliance](https://www.januscompliance.co.uk/blog/openai-dpa-data-processing-agreement-2026)
- [Anthropic Commercial Terms](https://conductatlas.com/platform/anthropic/anthropic-commercial-terms/)
- [Claude Regional Compliance — Anthropic](https://claude.com/regional-compliance)
- [Microsoft Azure OpenAI Service — Data Privacy](https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/openai/data-privacy)
- [No training on company data: ChatGPT, Claude and Copilot compared — ai-edu.ch](https://ai-edu.ch/en/insights/ki-geschaeftsabos-datenschutz/)
- [AI and Swiss Data Protection — slonge.ch](https://slonge.ch/en/blog/ai-data-protection-switzerland)
