Trust, Security & Regulation
AI and data privacy for businesses: which data flows where, and how do you stay compliant?
Which personal data flows where when you use AI?
Before setting rules you must understand the data flows. With generative AI, data leaves the company at several points: in the prompt itself (for example a customer email you ask it to summarise), in uploaded files, through connections to your CRM or ticketing system, and through the sub-processors the provider uses in the background. Every one of these channels can carry personal data, often without the employee realising it.
- Prompt content: names, emails, contract details, health or applicant information sent along in the text.
- Uploads: documents, spreadsheets and images, which often hold more personal data than the prompt itself.
- System connections: agents and integrations that autonomously reach into mailbox, CRM or file storage.
- Metadata and logs: IP addresses, user IDs and timestamps that the provider stores to run the service.
- Training use: with consumer accounts inputs may be used to improve the model; with business tiers usually not.
Legal basis: revised FADP, EU AI Act and consent
In Switzerland the revised Federal Act on Data Protection (revFADP/nFADP) has applied since 1 September 2023. It requires a justification for every processing of personal data: consent, performance of a contract, an overriding legitimate interest or a statutory basis. A blanket consent for everything is fragile; narrowly defined purposes are better. When a company engages an AI provider, that provider is usually a processor, which requires a data-processing agreement and technical and organisational measures.
If you affect customers or staff in the EU, the GDPR applies on top, and the EU AI Act reaches extraterritorially: it classifies AI systems by risk and bans some practices outright. Data protection and AI regulation therefore interlock. For sensitive data or large-scale profiling, a Data Protection Impact Assessment (DPIA) may be required before an AI process goes live.
Data minimisation: the most effective lever
The best data protection is not sending data at all. Data minimisation means checking, per use case, which personal data a model genuinely needs to do the job. Often the answer is: none. A draft contract can use placeholders instead of real names, an analysis can run on aggregated rather than individual records. Pseudonymisation and anonymisation cut the risk before data ever leaves the building.
- Purpose limitation: define per use case which fields are needed, and leave out the rest.
- Masking: replace names, customer numbers and addresses with placeholders before prompting.
- Limit retention: enable short storage periods and zero data retention at the provider.
- No special data without sign-off: health, applicant or criminal data only after a clear governance decision.
Choosing a provider: what businesses must check
Not every AI service is fit for personal data. What matters is less the model quality than the contractual and technical setup. A serious provider is transparent about where data is processed, whether it is used for training and how long it is retained. For transfers to the US, the Swiss-U.S. Data Privacy Framework has served as a recognised transfer mechanism since 15 September 2024; otherwise you need Standard Contractual Clauses and a transfer impact assessment.
- Data-processing agreement with clear instruction rights, deletion duties and breach notification.
- Data location and sub-processors disclosed; ideally processing in Switzerland or the EU can be selected.
- Training opt-out and zero data retention guaranteed by contract, not just as a setting.
- Security evidence such as ISO 27001 or SOC 2, encryption and role-based access.
- Auditability: logs and export options to provide evidence to the EDOEB.
Governance: from one-off decisions to rules
AI data protection rarely fails on technology and usually on missing everyday rules. A short, readable AI policy helps: which tools are allowed, which data classes never belong in a prompt, and who decides in case of doubt. A register of AI applications (mirroring the record of processing) creates oversight and meets accountability duties. Training beats bans: staff who understand data flows make better calls than those quietly using shadow AI.
Swiss perspective: data location and sovereignty
For many Swiss companies the argument is not only legal compliance but digital sovereignty. Choosing a provider that processes in Switzerland or the EU reduces transfer risk and eases communication with customers. At the model level, alternatives are emerging such as Apertus, an open language model developed in Switzerland at ETH Zurich and EPFL that aims to advance transparent, locally operable AI. Where data is especially sensitive, open models in your own or a Swiss data centre can be a data-frugal option.
Frequently asked questions
May employees enter customer data into ChatGPT or similar tools?
Only under conditions. Personal data does not belong in free consumer accounts whose inputs may be used for training. It becomes permissible with a business or enterprise tier, a data-processing agreement, training opt-out and a legal basis under the revised FADP. Ideally the data is minimised or masked first.
What is the difference between the revised FADP and the GDPR for AI projects?
The revised FADP is the governing Swiss law; the GDPR is EU law that also reaches Swiss firms once they process people in the EU. Both require a legal basis, transparency and security but differ in details such as fine levels and specific duties. For Swiss law you refer to the revFADP/nFADP, never the GDPR.
When do I need a Data Protection Impact Assessment for an AI application?
A DPIA is needed when a processing is likely to bring a high risk to personality or fundamental rights, for example large-scale profiling, systematic monitoring or processing sensitive data at scale. For automated decisions with legal effects it is often advisable. When in doubt, document the assessment to meet accountability duties.
Are my inputs used to train the AI model?
It depends on the tier. Many free consumer offerings may use inputs to improve the model unless you opt out. Business and enterprise tiers usually exclude this by contract. Check the provider's current terms and have the training opt-out fixed in the data-processing agreement.
Is it compliant if an AI provider processes data in the US?
It can be. Since 15 September 2024 Switzerland recognises the Swiss-U.S. Data Privacy Framework: if the US provider is certified under it, an adequate level of protection applies. Otherwise you need appropriate safeguards such as Standard Contractual Clauses plus a transfer impact assessment. A data location in Switzerland or the EU remains the lowest-risk option.
How do I prevent shadow AI in the company?
Bans alone push usage underground. More effective are approved, secure tools, a clear AI policy and training so staff understand data flows. Offer a compliant default solution that makes daily work easier, and name a contact point for new use cases. Visibility and a simple approval process cut the incentive to quietly use unsafe services.
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo