How Swiss Data Protection Affects AI Services Compared to GDPR: What Changes and What Privacy Law Cannot Cover
Swiss data protection affects AI services through the revised Federal Act on Data Protection (FADP), which applies to processing that has an effect in Switzerland; it is not “GDPR-lite.” Compared with the GDPR, the FADP uses different territorial mechanics, private-sector lawfulness rules, breach thresholds, DPO duties and criminal sanctions. The GDPR sets a 72-hour authority-notification rule where feasible, while the FADP requires notice to the FDPIC as quickly as possible only when a breach is likely to create a high risk. Neither comparison replaces a separate EU AI Act assessment.
A jurisdiction label can hide different processing as easily as identical track lists can hide two performances. The evidence sits in prompts, retrieved files, training settings, support access, retention controls and subprocessor routes. I would not approve the box from its label, especially in this quiet hour before the street moves.
What must an AI service map prove before anyone compares the FADP with the GDPR?
An AI service map must identify each operation, its data subjects, controller and processor, purpose, data categories, locations, recipients, retention and decision effect. “Hosted in Switzerland” proves one location claim at most; it says nothing about inference, abuse review, backups, support or connected tools.
Record the number of users and other data subjects, the number affected by an incident, and each store’s retention. Do not turn a percentage into a headcount. OpenAI’s report on its March 2023 ChatGPT incident said payment information might have been visible for 1.2% of Plus subscribers active during a nine-hour window. It did not publish the absolute number affected. Record that denominator as unknown.
Retention needs endpoint-level care. OpenAI’s current Data Controls documentation says API abuse-monitoring logs are retained for up to 30 days by default, subject to exceptions, while `/v1/conversations` application state remains until deleted. “OpenAI retention: 30 days” is a mislabeled entry. Record the endpoint, account control, deletion event and exception.
FADP Article 12 records include purpose, categories of data subjects and data, recipients and, if possible, retention; foreign disclosures also identify country and safeguard. GDPR Article 30 is a separate obligation. One evidence sheet can serve both if its fields preserve those differences.
When does the Swiss FADP or the GDPR reach an AI service?
FADP Article 3 applies to circumstances with an effect in Switzerland even when initiated abroad. GDPR Article 3 reaches processing in the context of an EU establishment and certain non-EU processing tied to offering goods or services to people in the EU or monitoring their behaviour there. A Zurich server cannot switch off either test.
FADP Article 14 requires a private controller abroad to appoint a Swiss representative only when four cumulative conditions are met: offering goods or services or monitoring behaviour in Switzerland, large scale, regular processing and high risk to personality. The representative is distinct from a processor, DPO or sales office.
Build the scope finding per data flow. A Swiss employer using an EU recruitment model may create a Swiss effect and an EU-establishment connection. A choice-of-law clause cannot erase statutory reach. Roles follow who determines purposes and means for each operation: a vendor can process customer prompts for the customer while controlling its own account-security use.
Is the Swiss FADP a lighter lawful-processing version of the GDPR?
The “GDPR-lite” description is legally unreliable. Overlapping principles do not make the private-sector mechanics interchangeable.
GDPR Article 6 requires a lawful basis: consent, contract necessity, legal obligation, vital interests, public task or legitimate interests subject to balancing. Special-category data also requires an Article 9 condition. “Agreed to the terms” does not establish contract necessity for model training or cure an incompatible purpose.
FADP Article 6 requires lawful, good-faith, proportionate processing for a recognisable purpose and destruction or anonymisation when data is no longer needed. For private processing, Articles 30 and 31 examine unlawful personality-rights breaches and justification by consent, overriding private or public interest, or law. A GDPR Article 6 label skips that Swiss analysis.
When the FADP requires consent, it must be voluntary, specific and informed; sensitive data, private high-risk profiling and federal-body profiling require explicit consent. Ask which purpose the person accepts. Inference, human review, safety monitoring and model improvement are four possible purposes, not one blurred “AI processing” purpose.
FADP Article 9 limits a processor to what the controller may do, requires assurance of data security and requires prior approval for a subprocessor. GDPR Article 28 has its own contract terms. A GDPR data processing addendum cannot prove the Swiss conditions by title.
How do automated decisions and DPIA triggers differ for AI services?
FADP Article 21 covers exclusively automated decisions with a legal consequence or considerable adverse effect. The controller must inform the person and, on request, allow a point of view and human review, subject to contract and explicit-consent exceptions. A genuine human decision can change the classification; a rubber stamp cannot.
GDPR Article 22 gives a right against solely automated decisions producing legal or similarly significant effects. Exceptions include contract necessity, authorising law and explicit consent, with human intervention and contest rights in specified cases. The reviewer needs authority, information, time and a real ability to change the outcome.
FADP Article 22 requires a prior DPIA when processing is likely to create a high risk to personality or fundamental rights. Nature, extent, circumstances, purpose and new technology matter; the Act names large-scale sensitive-data processing and systematic large-scale monitoring of public areas. High residual risk triggers FDPIC consultation unless a qualifying private-controller DPO is consulted under Article 23.
GDPR Article 35 also uses likely high risk and calls out extensive automated evaluation supporting significant decisions, large-scale special-category or criminal-data processing, and large-scale systematic public-area monitoring. Supervisory-authority lists still matter. A vendor DPIA cannot decide the customer’s different purpose, data and deployment.
The EU AI Act asks a different classification question. It regulates systems and operator roles through prohibited practices, high-risk classification, provider and deployer duties, transparency and general-purpose AI rules. A privacy DPIA cannot discharge its Article 9 risk-management or Article 26 deployer duties. FADP/GDPR high risk concerns personal-data effects; AI Act high risk follows Article 6 system and use classifications.
Which breach threshold and notification clock applies under each regime?
Under GDPR Article 33, a controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to risk people’s rights and freedoms. A late notification must give reasons. Article 33 also asks, where possible, for the categories and approximate number of data subjects and records concerned. The processor tells the controller without undue delay.
FADP Article 24 has no fixed 72-hour number. The controller notifies the FDPIC as quickly as possible when a data security breach is likely to lead to a high risk to personality or fundamental rights; the processor informs the controller as quickly as possible. The FDPIC’s 2025 breach guidelines centre on that “likely high risk” test. The absence of a Swiss numeric deadline does not create waiting room: assessment, containment and escalation time must still be documented.
The authority thresholds are not the same. GDPR supervisory notification starts at risk, with an exception where risk is unlikely. Swiss FDPIC notification starts at likely high risk. Communication to people is another track: GDPR Article 34 uses likely high risk and “without undue delay,” while FADP Article 24 requires informing data subjects when needed for their protection or when the FDPIC requests it.
Use the incident export as the count source. If the system can establish only accounts, devices or records, say which unit was measured; a record count is not a person count. The 2023 OpenAI post’s 1.2% figure and nine-hour window show why a percentage, population and exposure event should remain separate fields. The notification decision should preserve unknowns rather than manufacture an exact person count.
Who needs a DPO or adviser, and who can receive the fine?
GDPR Article 37 does not require every organisation to appoint a DPO. Appointment is mandatory when processing is by a public authority or body, except courts acting judicially; when core activities require regular and systematic large-scale monitoring; or when core activities consist of large-scale processing of special-category data or criminal-conviction and offence data. Union or Member State law can add requirements.
For Swiss private controllers, FADP Article 10 says they may appoint a data protection officer; the FDPIC describes private appointment as voluntary. Federal bodies must appoint one. A qualifying private controller’s officer must be independent, free of incompatible duties, expert, publicly contactable and notified to the FDPIC if the controller wants the consultation benefit for a DPIA with high residual risk. This role is also called a data protection adviser in Swiss materials. It is not the Article 14 Swiss representative.
The headline fine needs its addressee and condition attached. Under FADP Articles 60 and 61, listed wilful offences by private persons can carry a criminal fine of up to CHF 250,000, often on complaint. Article 61 includes wilful unlawful disclosure abroad, improper processor assignment and failure to meet minimum data-security requirements. This is not a universal tariff for every FADP error.
The often-repeated CHF 50,000 figure comes from a separate attribution rule. FADP Article 64(2) says that when a fine no higher than CHF 50,000 is under consideration and identifying the perpetrator would require measures disproportionate to the potential penalty, the authority may stop pursuing those persons and order the business to pay instead. Quoting CHF 50,000 as “the maximum Swiss privacy fine” mislabels both the amount and the defendant.
GDPR Article 83 uses administrative fines against controllers and processors, with an upper tier of €20 million or 4% of total worldwide annual turnover, whichever is higher, for specified infringements. It remains a ceiling applied through case-specific factors, not an automatic invoice. Procurement should therefore ask who owns each control and escalation under each regime, rather than comparing two naked maximums.
Does Swiss hosting settle cross-border AI data protection?
Swiss hosting settles only the location it actually covers. FADP Article 16 permits disclosure abroad when the Federal Council recognises adequate protection or when an accepted safeguard applies, including specified contractual clauses, recognised standard clauses or approved binding corporate rules. The FDPIC’s transfer guidance also tells controllers using contractual safeguards to examine whether destination-country law lets the recipient comply and whether technical measures are needed.
For GDPR flows into Switzerland, the European Commission currently lists Switzerland as providing adequate protection, allowing covered EU-to-Switzerland transfers without an additional Chapter V safeguard. Onward access from Switzerland to another country is a new disclosure question. Remote support, safety review, model inference, prompt caching, subprocessors and tool calls can each create another route.
Switzerland does have local cloud infrastructure: Microsoft Azure’s official geography page lists Switzerland North and Switzerland West regions. Availability of a named model, endpoint and processing feature still has to be verified in the vendor’s regional product sheet. A Swiss invoice, company address or storage selection does not prove that every copy and human access path stays in Switzerland.
What evidence record should procurement require before approving the AI service?
Approve a versioned evidence record, not a vendor adjective. This six-step sequence keeps the legal finding attached to the service configuration that produced it.
- Freeze the source sheet. Record product version, endpoints, model, connected tools, purposes, data categories, data-subject populations, sample inputs, output uses and the source document for every field.
- Assign roles per purpose. Name controller, joint controller or processor for inference, security, support, analytics and model improvement separately; attach the applicable processor and subprocessor terms.
- Map reach and routes. Apply FADP Article 3 and GDPR Article 3 to each population and establishment, then record every processing country, remote-access country, onward recipient, adequacy basis or safeguard.
- Test decisions and high risk. Document whether output drives a legal or considerably/significantly adverse result, whether human review is genuine, and why an FADP Article 22 or GDPR Article 35 DPIA is required or ruled out. Run the EU AI Act classification beside it.
- Pin down time and incident numbers. Replace “standard retention” with days or a deletion event for each store. Define awareness and escalation timestamps, count affected people separately from accounts and records, and preserve unknown quantities.
- Sign the residual finding. Record controls, unresolved risks, DPO or adviser input, prior consultation where required, owner, approval date and the exact configuration approved. A model, endpoint, training setting or transfer-route change reopens the relevant finding.
That record gives legal, security and procurement teams one source reel while preserving separate slates. It also makes confident vendor claims testable: “no training” must point to a setting and contract; “30-day retention” to an endpoint table; “Swiss hosted” to a processing and access map; “human oversight” to a person with authority to intervene.
FAQ
What is the Swiss equivalent of GDPR?
Switzerland’s federal counterpart is the revised Federal Act on Data Protection, in force since 1 September 2023 and supervised by the FDPIC. It protects personal data of natural persons and applies to effects in Switzerland. It is not a Swiss version of the GDPR; cantonal rules can also govern cantonal public bodies.
Is AI GDPR compliant?
An AI product has no universal GDPR-compliant status. Compliance depends on the specific controller, purpose, lawful basis, data, transparency, retention, security, transfers and use of automated decisions. A vendor’s compliant platform can still be deployed unlawfully when a customer uploads incompatible data or uses output for an unassessed significant decision.
Does Switzerland have AI data centers?
Yes. Switzerland has cloud data-centre regions capable of supporting AI workloads; Microsoft Azure lists Switzerland North and Switzerland West. Local infrastructure does not prove end-to-end Swiss processing. Confirm the model and endpoint’s regional availability, inference location, storage, support access, subprocessors, backups and connected tools in the vendor’s current service documentation.
What country has the strongest data privacy laws?
There is no objective single-country winner because privacy strength depends on scope, rights, regulator powers, remedies, sector rules and enforcement. The GDPR is an EU regulation rather than one country’s law; Switzerland uses the FADP. For an AI procurement, territorial reach and the actual data flow matter more than a league-table label.
When does an AI service need a Swiss DPIA?
FADP Article 22 requires a DPIA before processing likely to create a high risk to personality or fundamental rights. Nature, extent, circumstances, purpose and new technology matter. The Act specifically identifies large-scale sensitive-data processing and systematic large-scale monitoring of public areas; the customer’s deployment can trigger the assessment even if the vendor assessed its platform.
Which breach threshold triggers notification under each regime?
GDPR Article 33 requires authority notice within 72 hours where feasible unless risk to rights and freedoms is unlikely. FADP Article 24 requires notice to the FDPIC as quickly as possible when high risk to personality or fundamental rights is likely. Notices to affected people follow separate, higher or protective-need tests.