AI and data protection in Switzerland: what companies need to know
Using artificial intelligence is permitted in Switzerland, but not unconditionally. As soon as employees enter personal data into an AI tool, that is processing under the revised Federal Act on Data Protection (revFADP). The company remains the controller – including where the actual computation happens at the AI provider.
Switzerland has no dedicated AI act so far. The framework comes from the revFADP, from the professional and supervisory law of the relevant sector and – for companies with EU exposure – additionally from the GDPR and the EU AI Act.
This article sorts the duties, names the points where AI projects fail in practice, and closes with a checklist for rollout.
Why every AI input is a processing operation
With every prompt, data flows to the provider of the model. If the input or an uploaded document contains names, client data, job applications or health information, the company is processing personal data – with every duty the revFADP attaches to it.
This holds even when nobody uploads a file. A prompt such as "Draft a letter telling Mr Müller we are not extending his probation" contains personal data and, in this case, employment information as well. The threshold sits lower than it is perceived to in day-to-day work.
Then there is the organisational half: many employees use AI privately and carry the habit into the office. Without clear rules this produces shadow AI – usage IT does not know about, and which is therefore neither documented nor secured.
Which regimes apply
Depending on clientele and sector, several regimes apply to Swiss companies side by side. They do not exclude one another; they stack.
| Regime | Applies to | Applicable since |
|---|---|---|
| revFADP (FADP, SR 235.1) | Processing that has an effect in Switzerland | 1 September 2023 |
| GDPR | Processing relating to people in the EU and the EEA | 25 May 2018 |
| EU AI Act | Providers and deployers of AI systems whose output is used in the EU | In force since 1 August 2024, phased in until 2027 |
| Professional and supervisory law | Holders of professional secrets, banks, insurers, healthcare | Applies unchanged, independently of data protection law |
Transfers abroad: the problem with US providers
Most large AI providers are based in the United States. Art. 16 FADP only permits disclosure abroad where the destination state ensures adequate protection or a contractual safeguard is in place. For the US, the Federal Council has recognised the Swiss-U.S. Data Privacy Framework – but it only carries for companies actually certified under it.
Independently of that, the US CLOUD Act of 2018 remains: it obliges providers subject to US law to hand data to authorities on order, regardless of where the servers stand. For confidential client and business data that is a structural risk which contracts cannot fully dissolve.
The most robust answer is keeping data in the EU or Switzerland with a provider that does not use inputs for training and offers a data processing agreement. The key is to ask both questions separately: where do the servers stand, and which law governs the company operating them?
Training on inputs: the point where it tips
What matters in data protection terms is not whether a tool is labelled "AI", but what happens to the inputs. If prompts are used to improve models, the data leaves its original purpose – a conflict with the purpose limitation in Art. 6 FADP and with confidentiality towards clients.
Consumer offerings either allow training by default or make it depend on a setting each individual has to configure. For a company that is not a defensible basis: a setting individual employees can change is not a technical or organisational measure.
What is defensible is a contractual commitment at company level, combined with centrally managed access. Only then can a company evidence to clients, regulators or a court what actually happened to the data.
Data protection impact assessment: when it becomes necessary
Art. 22 FADP requires a data protection impact assessment where processing is likely to entail a high risk to personality or fundamental rights. The act expressly names large-scale processing of sensitive data and systematic monitoring of public areas.
For AI, indicators of high risk include processing sensitive data, results feeding into decisions about individuals, and data flowing to states without adequate protection. Companies that designate and consult a data protection adviser may, under certain conditions, forgo involving the FDPIC.
Three patterns that make AI projects fail
The mistakes repeat, and they are rarely technical.
- The ban without an offer: AI tools are blocked without an official alternative in place. Usage moves to private devices, the risk stays – only now without visibility.
- The pilot without rules: a team trials a tool, the processing is never documented, and the pilot quietly becomes production. Record, contract and privacy policy are permanently behind.
- Provider selection without checking the processing location: a contract is signed because the product convinces. Where data is processed and which law governs the provider only gets clarified when a client asks.
Checklist: rolling out AI in line with data protection
Introducing AI is not purely an IT project but a governance task. These seven steps cover the duties arising from the revFADP.
- Take stock: which AI tools are already in use – officially and unofficially? Without this step every later measure stays incomplete.
- Write the AI policy: which data may go into which tools, what is excluded, who decides on exceptions?
- Select the provider: hosting in the EU or Switzerland, no training on company data, a data processing agreement, a clarified processing location.
- Manage access: roles and permissions centrally instead of private accounts, and reliable revocation when someone leaves.
- Document: add the processing to the record, update the privacy policy, and run an impact assessment where the risk is high.
- Train people on personal data, professional secrecy and hallucinations – using concrete examples from their own working day.
- Make usage evidenceable through audit logs, so that nothing has to be reconstructed later that nobody recorded.
Frequently asked questions
Is ChatGPT compliant with Swiss data protection law?
There is no blanket answer – it depends on the version, the contract and the type of data. For personal data and confidential business data, consumer versions are unsuitable: the processing location cannot be steered, there is no data processing agreement, and the training setting sits with individual users rather than with the company.
Do we need client consent to use AI?
Not necessarily. The revFADP permits processing in principle; a justification only becomes necessary once the processing infringes personality. What matters more in practice is transparency: the privacy policy has to cover the use. Stricter requirements apply to sensitive data and to holders of professional secrets.
Who is liable for data protection breaches caused by AI use?
The company is responsible as the controller. Fines under the revFADP, however, are directed at the responsible natural person – typically management or the internally designated person. A data processing agreement does not shift responsibility; it governs it.
Is anonymising inputs enough?
Anonymisation lowers the risk considerably, but it is harder than it sounds. Removing names is not sufficient when the constellation of facts, the date and the location make a person identifiable. As a sole measure it does not carry; alongside a contract and a clarified processing location it is worthwhile.
Does the EU AI Act apply to Swiss companies?
It does not apply directly through Swiss law, but it can bite where a Swiss company places AI systems on the EU market or the output of an AI system is used in the EU. For many companies in the DACH region it is therefore indirectly relevant – through clients, group policies and tenders.
Do we have to notify the FDPIC about our AI use?
There is no general duty to notify AI use. The FDPIC has to be involved where a data protection impact assessment shows a high residual risk and no data protection adviser was consulted – and in the event of a notifiable breach of data security.
Sources
- Swiss Federal Act on Data Protection (FADP, SR 235.1) · Fedlex – Swiss Federal Chancellery
- Federal Data Protection and Information Commissioner · FDPIC
- Regulation (EU) 2016/679 (GDPR) · EUR-Lex
Related reading
Bring AI into your company securely.
Try Custodos with your team – and see how quickly secure AI becomes productive.
- Try it with the whole team
- Set up in minutes
- Productive from day one
