Using AI at work sounds simple, until a client asks how your chatbot handles their data. That question sits right at the center of AI under Swiss law and GDPR, and a lot of companies don’t have a clean answer yet. Switzerland doesn’t have a dedicated AI law. Instead, AI tools fall under existing data protection rules — mainly the Swiss Federal Act on Data Protection (FADP) and, for many companies, the EU’s GDPR too. If your business uses AI and touches personal data, both laws matter. This guide walks through what each law actually requires, where the two overlap, where they differ, and what steps to take now. Why AI Regulation in Switzerland Looks Different From the EU The EU built a dedicated AI Act with risk categories, specific rules for “high-risk” systems, and its own enforcement structure. Switzerland took a different path. There is no Swiss AI Act yet. Instead, Swiss regulators apply the existing, technology-neutral FADP to AI systems. In other words, the law doesn’t ask “is this AI?” It asks “does this process personal data?” If yes, the FADP applies — whether the tool is a spreadsheet macro or a large language model, according to the Federal Data Protection and Information Commissioner (FDPIC). Switzerland Is Watching, Not Ignoring, AI This doesn’t mean Switzerland is hands-off. Switzerland signed the Council of Europe’s Framework Convention on Artificial Intelligence and Human Rights on 27 March 2025. Ratification is still pending, and a domestic consultation proposal on AI-specific rules is expected by the end of 2026. The FDPIC has also signalled that dedicated guidance on AI in the business context is coming, though no firm date has been confirmed. Companies should treat today’s rules as a floor, not a ceiling — more specific obligations may follow. The FADP: Switzerland’s Core Data Protection Law The revised FADP took effect on 1 September 2023, with no transition period. It replaced Switzerland’s older 1992 data protection law and moved Swiss rules closer to the GDPR, while keeping some distinctly Swiss features. What the FADP Actually Covers The FADP protects personal data belonging to natural persons — real people, not companies or associations. That’s a change from the old law, which also covered legal entities. If your AI system processes customer names, employee records, health data, or behavioral data tied to an individual, the FADP applies. The law is deliberately technology-neutral. It doesn’t list “AI” as a special category. Instead, it sets general principles: purpose limitation, transparency, data minimization, security, and accountability. An AI tool has to follow the same rules as any other system that touches personal data. Key Obligations for Companies Using AI A few FADP requirements matter most when AI is involved: Transparency. Your privacy notice should explain which AI tools process personal data and why. If a decision is automated, that needs to be disclosed too. Data protection impact assessments (DPIA). Under Article 22, a DPIA is required when processing is likely to carry a high risk to someone’s personality or fundamental rights. This can include AI used for extensive profiling or automated decision-making. Prohibited uses. Some AI applications don’t fit within the FADP at all. The FDPIC has specifically flagged real-time mass facial recognition and “social scoring” — comprehensive tracking and rating of people’s behavior — as incompatible with Swiss privacy protections. Accountability. Companies, not just the AI vendor, stay responsible for how personal data is used. Fines: A Detail Worth Getting Right This is where many articles get sloppy, so here’s the precise picture. Under Articles 60–64 of the FADP, fines of up to CHF 250,000 can apply — but only for intentional violations, and the fine generally falls on the individual responsible (often a director, manager, or data protection lead), not on the company as a legal entity. Negligent breaches carry no criminal fine under the FADP. A company itself can only be fined directly, and only up to CHF 50,000, if identifying the responsible individual would take disproportionate investigative effort. This person-focused approach is unusual — GDPR, by contrast, fines the organization. Breach Reporting Under the FADP Unlike GDPR’s fixed 72-hour breach notification window, the FADP requires reporting “as quickly as possible” once a breach is likely to result in high risk, without setting an exact deadline. “No fixed deadline” doesn’t mean “no urgency” — regulators still expect prompt action once a high-risk breach is identified. How GDPR Fits Into the Picture Switzerland isn’t in the EU, so GDPR doesn’t apply automatically just because a company is Swiss. However, GDPR reaches beyond EU borders when certain conditions are met, under its own Article 3 territorial scope rules. When GDPR Applies to a Swiss Company A Swiss company can fall under GDPR if it: Has an establishment (like a branch or subsidiary) in the EU Offers goods or services to people located in the EU Monitors the behavior of people in the EU So a Swiss company selling only within Switzerland may never trigger GDPR. But a Swiss AI startup selling a product to German or French customers almost certainly will. FADP vs. GDPR: The Main Differences The two laws share a lot of DNA, but they aren’t identical. A few practical differences, confirmed by PwC Switzerland’s comparison of the two frameworks: Consent. GDPR often requires an active opt-in for many processing activities. The FADP generally works on an opt-out model — people must be informed and given the right to object — though sensitive data and profiling can still require explicit consent. DPO requirement. GDPR often requires a formal Data Protection Officer. Under the FADP, appointing a data protection advisor is recommended but not mandatory for private companies. Enforcement style. GDPR fines organizations, often as a percentage of global turnover. The FADP fines responsible individuals, capped at CHF 250,000. Being GDPR-compliant doesn’t equal FADP-compliant. The frameworks overlap heavily, but a GDPR program still needs Swiss-specific additions to fully satisfy the FADP, and vice versa. The EU AI Act: A Third Layer for Some Companies If your AI system is used in, or offered to, the EU market, the EU AI Act may apply as a separate layer on top of GDPR and the FADP. It doesn’t replace data protection law — it adds product-style rules based on how risky the AI system is considered to be. This matters because a system can trigger AI Act obligations even if it processes no personal data at all, since the Act regulates AI systems more broadly, not just personal data processing. A Swiss company selling an AI hiring tool into Germany, for example, may need to check all three frameworks separately: FADP, GDPR, and the EU AI Act. This layered approach is genuinely new territory for most SMEs, and it’s an area where getting qualified legal advice pays for itself. Practical Steps Swiss Companies Can Take Now Compliance sounds abstract until you break it into concrete actions. Here’s where most companies should start. 1. Map Where AI Touches Personal Data List every AI tool in use — chatbots, hiring software, analytics, recommendation engines — and note whether it processes information about real people. If your team is experimenting with AI assistants or connectors as part of daily workflows, that inventory should include those tools too — see our guide on using a Claude custom connector for web design as one example of how AI tools plug into existing systems and data. 2. Update Privacy Notices and Disclosures Make sure your privacy policy names the AI tools you use, describes what they do, and explains any automated decision-making in plain language. Vague statements like “we may use AI” won’t satisfy transparency requirements. 3. Review Vendor Contracts Ask AI vendors direct questions: Where is data processed? Is it used to train the vendor’s models? What safeguards apply to cross-border transfers? Get answers in writing, not just marketing claims. 4. Run Impact Assessments Where Needed If an AI system profiles people, scores them, or makes automated decisions with real consequences — loan approvals, hiring, insurance pricing — a DPIA is likely required under the FADP, and a similar assessment is likely required under GDPR too. 5. Tighten Data Security Practices Both laws require “appropriate” technical and organizational security measures — what counts as appropriate depends on the risk. If your team isn’t sure where your current security setup falls short, our beginner’s guide to cybersecurity is a reasonable starting point before bringing in a specialist. 6. Assign Clear Ownership Someone in the company should own AI and data protection compliance, even without a legal mandate to appoint a formal officer. Having no owner is the fastest way to end up with gaps nobody notices — and given that FADP fines land on individuals, “nobody’s job” is a genuinely risky position to be in. FAQ Does Switzerland have its own AI law like the EU AI Act? Not yet. Switzerland currently regulates AI through the existing, technology-neutral FADP rather than a dedicated AI statute. Switzerland signed the Council of Europe’s AI Convention in March 2025, and a domestic proposal is expected for consultation by the end of 2026, but nothing binding and AI-specific is in force today. Do Swiss companies need to comply with GDPR? Only if certain conditions apply — for example, having an EU establishment, offering goods or services to people in the EU, or monitoring EU residents’ behavior. A Swiss company operating only within Switzerland generally isn’t subject to GDPR. Is being GDPR-compliant enough to satisfy Swiss law? Not automatically. GDPR compliance gives you a strong starting point, but the FADP has different requirements, like its opt-out consent model and lighter DPO rules. Most companies need a Swiss-specific review layered on top of a GDPR program. What happens if an AI tool’s use violates the FADP? Intentional violations can carry fines of up to CHF 250,000 — and notably, this liability usually falls on the responsible individual, such as a manager or data protection lead, rather than the company as an entity. Companies themselves face this fine only in limited circumstances. Beyond fines, businesses risk FDPIC investigations, binding corrective orders, and reputational damage. Can AI systems be banned outright under Swiss law? Yes, in specific cases. The FDPIC has named real-time mass facial recognition and comprehensive “social scoring” — ongoing surveillance-style tracking and rating of individuals — as incompatible with the FADP’s protection of privacy and personal autonomy. Conclusion AI under Swiss law and GDPR isn’t one single rulebook — it’s a set of overlapping frameworks that depend on what your AI does, where your customers are, and what kind of data is involved. The FADP applies to any Swiss company processing personal data through AI, GDPR kicks in once you touch the EU market, and the EU AI Act may add another layer on top. None of this requires panic, but it does require attention. Start with an honest inventory of where AI meets personal data in your business, tighten your privacy disclosures, and check your vendor contracts. If your AI use is more than basic, it’s worth a conversation with a Swiss data protection lawyer to confirm your specific obligations — this article is a starting map, not a substitute for legal advice, and the rules in this space are still moving. Disclaimer: This article is for general information only and is not legal advice. Data protection and AI regulation are evolving in both Switzerland and the EU. Confirm your specific obligations with a qualified lawyer before making compliance decisions. Post navigation This Is a System Generated Email: What It Means What Is a Productivity Recipe and How Does It Work?