Privacy & Sovereignty
What does AI data sovereignty mean for Swiss businesses?
What AI data sovereignty is – and is not
Data sovereignty is an organisation's lasting control over its data: who can access it, where it resides and which law applies. AI raises the stakes, because prompts, documents, customer data and sometimes whole knowledge bases are handed to a model – often a cloud service located abroad.
It matters to separate related terms. Data residency only fixes the geographic storage location. Data localisation requires that data never leave a country. Sovereignty goes further: it also covers legal reach – for instance whether a foreign authority can compel disclosure even when the server sits in Zurich.
- Data residency: where does the data physically sit?
- Data localisation: may the data leave the country at all?
- Data sovereignty: who holds legal and technical control and access?
Why data sovereignty matters for Swiss businesses
- revFADP/nFADP: the revised Data Protection Act requires adequate protection when data is disclosed abroad; transfers to states without an adequate level of protection need additional safeguards.
- Professional and official secrecy: doctors, lawyers and fiduciaries (Art. 321 Swiss Criminal Code) and banks are bound by special confidentiality duties – an uncontrolled AI data leak can be a criminal offence.
- US CLOUD Act: US providers can under certain conditions be compelled to hand over data even when it physically resides in Europe.
- EU AI Act (extraterritorial): also applies to Swiss providers whose AI outputs are used in the EU, adding transparency and risk-management duties.
- Trust and competition: customers, hospitals and public bodies increasingly demand provable data hosting in Switzerland or the EU – sovereignty becomes a selling point.
- FDPIC (EDÖB): the supervisory authority expects documented processing and risk assessments, such as a record of processing and, for high risk, a data protection impact assessment.
Your options at a glance
There is no universally 'right' model – the fit depends on data class, budget and in-house know-how. These five approaches span the spectrum from full outsourcing to complete self-control.
- Swiss cloud / Swiss hosting: AI services from providers with Swiss data centres (e.g. Infomaniak, Exoscale, Swisscom). Upside: data and law stay in Switzerland. Check: which models are available and whether sub-processors abroad are involved.
- Sovereign/EU cloud: offerings with guaranteed EU data residency and partial shielding from third-country access. A good compromise between performance and control.
- Hyperscaler with a Swiss region: AWS, Azure and Google Cloud run Zurich regions. Data sits in Switzerland, but residual CLOUD Act risk and group structure still need weighing.
- Local/on-premise models: open-source LLMs in your own data centre or on your own hardware. Maximum control, no data leaving the house – at the cost of operations, hardware and maintenance.
- Hybrid: sensitive data local, non-critical tasks in the cloud. Often the most pragmatic route in practice.
Local and open-source models as a sovereign foundation
For maximum sovereignty, run models yourself. Open language models can run on your own infrastructure so that no data leaves the building. Apertus adds a fully open language model developed in Switzerland by ETH Zurich, EPFL and the CSCS supercomputing centre, offering transparency over training data and weights.
The price is effort: GPU hardware or a sovereign Swiss compute cluster, plus expertise for operations, fine-tuning and security. For many SMEs a hosted open-source model at a Swiss provider is the better middle path – open weights, but without running your own servers.
A practical decision framework
- Classify data: which data is especially sensitive (health, finance, secrecy-bound professions)?
- Clarify the legal frame: revFADP, professional secrecy, EU AI Act and sector rules (FINMA, healthcare).
- Assess the access model: not just storage location, but who can legally compel access.
- Vet the provider: data-centre location, group headquarters, sub-processors, contracts and certifications.
- Shape contracts: data-processing agreement, standard contractual clauses, deletion concepts and no use of your data for model training.
- Protect technically: encryption, pseudonymisation, confidential computing and access controls.
- Document: keep a record of processing and, for high risk, run a data protection impact assessment.
Common misconceptions
- 'Server in Switzerland = sovereign': not necessarily – the provider's group headquarters and applicable law count too.
- 'Open source solves everything': only if you run it yourself or at a sovereign provider; an open model via a foreign API still leaves you dependent.
- 'revFADP = GDPR': similar but distinct; Switzerland is governed by the revFADP/nFADP, not the GDPR.
- 'Small firms are not affected': professional secrecy and customer expectations apply regardless of size.
Frequently asked questions
What is the difference between data residency and data sovereignty?
Data residency only describes where data is physically stored. Data sovereignty adds legal control: who can compel access and which law governs the data and the provider. A server in Switzerland satisfies residency but does not by itself guarantee full sovereignty.
Can Swiss businesses use ChatGPT or Claude?
Yes, provided data protection is preserved. For especially sensitive or secrecy-bound data you need proper contractual bases (data-processing terms, no use for training), preferably EU/Swiss processing and ideally pseudonymisation. Without such safeguards, sensitive content should not be entered into public services.
Is a Swiss data centre enough to escape the CLOUD Act?
Not necessarily. The US CLOUD Act can compel companies with a US nexus to disclose data regardless of storage location. To exclude this residual risk, choose a provider governed solely by Swiss or EU law, or use encryption where only your own company holds the keys.
Is a local open-source model realistic for an SME?
For scoped tasks, yes. Smaller open models already run on capable standard or GPU hardware. For high quality and many users, hardware and operating demands rise sharply, though. Often a hosted open-source model at a Swiss provider is the more pragmatic start, with a later option to move fully in-house.
What is Apertus?
Apertus is a fully open, multilingual language model from Switzerland, developed by ETH Zurich, EPFL and the national supercomputing centre CSCS. Its weights and details about the training data are disclosed, among other things. That makes it attractive for sovereign scenarios where transparency and local operation matter.
Do I need a data protection impact assessment for AI?
Under the revFADP, a data protection impact assessment is required when processing entails a high risk to personality or fundamental rights. AI applications handling large-scale or especially sensitive personal data often qualify. The assessment documents risks and measures and should be in place before go-live.
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo