AI, Law & Data Protection
AI Phone Assistants and Data Protection: What Swiss SMEs Need to Know
What data an AI phone assistant processes
An AI phone assistant is software that conducts inbound or outbound calls on its own: it understands spoken language, replies in a synthetic voice and handles tasks such as booking appointments, giving information or routing calls. From a data protection view, the key point is that personal data is generated continuously – the voice itself, the name, the phone number, the request and often further details callers mention in passing.
- Voice recordings and transcripts count as personal data; if voices are used to identify individuals, biometric – and therefore sensitive – personal data arises.
- Health, financial or religious details mentioned in a call are sensitive data and require heightened care.
- Metadata such as caller number, time and duration are personal data too, even without a name.
revDSG/nFADP basics for voice assistants
The relevant law is the revised Data Protection Act (revDSG/nFADP), in force since 1 September 2023; the supervisory authority is the FDPIC (EDÖB). It has no general permit requirement but obliges organisations to process data responsibly. Whoever deploys an AI phone assistant is the 'controller' responsible for upholding the processing principles – whether the technology is built in-house or bought from a provider.
- Purpose limitation: use data only for the stated purpose (e.g. booking), not secretly for training or marketing.
- Data minimisation and proportionality: collect and store only what is truly needed, and define retention periods.
- Privacy by design and by default, plus a record of processing activities; a data protection impact assessment where risk is high.
- Data subject rights: callers can request access, rectification and erasure – processes must be able to fulfil this.
Transparency duty: telling callers it is an AI
Transparency is the most sensitive point with AI phone assistants. Callers must not be deceived: they must be able to tell they are speaking with a machine, not a human. The revDSG requires appropriate information about the processing of personal data. In parallel, Article 50 of the EU AI Act explicitly requires people to be informed when they interact with an AI system, unless this is already obvious. The EU AI Act has extraterritorial effect and can reach Swiss companies addressing people in the EU.
- Opening announcement: state clearly and briefly that an AI assistant is answering, and offer a route to a human.
- Recording: secretly recording non-public conversations is a criminal offence under Art. 179bis SCC – record only with prior notice and a legal basis.
- Privacy notice: document purpose, recipients, retention and any cross-border transfer in an easily findable way.
Data handling: cloud, processors and cross-border transfers
Most AI phone assistants rely on cloud services and language models from external providers. Under the revDSG these are typically processors: using them requires a contract governing purpose, security and the exclusion of unauthorised use, plus oversight of any sub-processors. If data is transferred abroad – for example to a US data centre – an adequate level of protection must be ensured, if necessary via standard contractual clauses and supplementary measures.
- Check where speech is processed and stored – the provider's location and legal jurisdiction matter.
- Contractually exclude the use of call content for model training without a legal basis.
- Technical security: encryption, access controls and defined deletion periods for recordings and transcripts.
Common mistakes and a short practical checklist
Many problems stem not from the technology but from missing transparency and unclear responsibilities. A Swiss SME automating its phone reception with AI should treat it like any other data processing: documented, minimal and traceable. The points below sum up the typical pitfalls.
- Mistake: leaving callers unsure whether they speak with an AI. Better: a clear announcement plus a human option.
- Mistake: recording everything 'just in case'. Better: only what is needed, with retention and a legal basis.
- Mistake: using a provider without a processing agreement. Better: settle the contract, sub-processors and server location.
- Mistake: being unable to serve data subject rights. Better: set up a process for access and erasure.
Frequently asked questions
Do I have to tell callers that an AI phone assistant is answering?
Yes, transparency is central. Callers must not be deceived and must be able to tell they are speaking with an AI. This follows from the revDSG transparency principle and – where the EU is involved – explicitly from Article 50 of the EU AI Act. A clear opening announcement is the simplest solution.
May an AI phone assistant record calls?
Only with prior notice and a legal basis. Secretly recording non-public conversations is a criminal offence in Switzerland under Art. 179bis SCC. Anyone recording must inform callers at the start, state the purpose, limit the storage period and keep recordings secure.
Does the EU AI Act apply to Swiss companies?
It can. The EU AI Act has extraterritorial effect and also covers providers or deployers outside the EU when their AI system targets or affects people in the EU. A Swiss SME with EU customers should therefore plan for the Article 50 transparency duty. This does not replace individual legal advice.
Where is an AI phone assistant's voice data processed?
That depends on the provider and is a core question. Many services process speech in cloud data centres, sometimes abroad. Under the revDSG such providers are usually processors and need a contract; for transfers abroad an adequate level of protection must be ensured. Clarify server location, sub-processors and whether content is used for model training.
What first steps should an SME take before rolling one out?
Define purpose and data types, vet the provider including server location and processing agreement, prepare the transparency announcement and privacy notice, define retention and deletion periods, and set up processes for access and erasure requests. Where risk is high, a data protection impact assessment is advisable. This overview is general and not a substitute for individual legal advice.
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo