Trust, Security & Regulation
The Revised FADP and AI: What Must Swiss Businesses Consider?
The revised FADP in brief: scope, reach and fines
The revised FADP replaced the 1992 act and moved Switzerland closer to the European protection level without being identical to the GDPR. It now protects only the data of natural persons; data of legal entities is no longer covered. For AI the key point is: as soon as a model or tool processes personal data, the duties apply, regardless of whether the provider sits in Zurich, Dublin or California.
- Extraterritorial effect: the revFADP also covers processing abroad that has an impact in Switzerland.
- Supervision: the FDPIC (Federal Data Protection and Information Commissioner) oversees compliance and can open investigations.
- Penalties: fines up to CHF 250,000 generally target the responsible natural persons, not primarily the company - unlike the GDPR.
Sensitive personal data and AI
The revised FADP defines sensitive personal data, whose processing triggers stricter requirements - such as explicit consent or a data protection impact assessment. These categories appear often in AI projects: health chatbots, biometric face or voice recognition, HR screening or credit-scoring models. Anyone feeding such data into an AI system must clarify the legal basis and safeguards beforehand.
- Covered categories: religious, ideological, political or trade-union views and activities; health, intimate sphere, racial or ethnic origin.
- Genetic data and biometric data that uniquely identify a person - highly relevant for AI-based recognition systems.
- Data on administrative and criminal proceedings or sanctions, and on social assistance measures.
Core duties when deploying AI
- Respect the principles: lawfulness, good faith, proportionality, purpose limitation, transparency and data accuracy - including for training and input data.
- Duty to inform: data subjects must be informed clearly about the collection of personal data and the use of AI.
- Data protection impact assessment (DPIA) where processing is likely high-risk - new technologies, extensive processing of sensitive data or systematic monitoring; if a high residual risk remains, the FDPIC must be consulted.
- Maintain a record of processing activities; SMEs with fewer than 250 employees and low-risk processing are partially exempt.
- Build privacy by design and privacy-friendly default settings into AI systems from the start.
- Ensure data security and report data breaches to the FDPIC as soon as possible where there is a high risk to data subjects.
Automated individual decisions and high-risk profiling
If an AI system makes a decision based solely on automated processing that has a legal effect or significantly affects the person - for example loan refusal, automated candidate selection or premium tiering - the company must inform the data subject. They may request that a natural person review the decision and state their view. Exceptions apply, among others, where the decision relates to a contract and the request is granted, or where consent has been given.
- High-risk profiling - an extensive assessment of key personality traits - can require explicit consent.
- Document when a human reviews the AI decision (human-in-the-loop) and how data subjects can object.
Cross-border transfers: using AI providers correctly
Many AI services run on servers outside Switzerland. A transfer abroad is allowed if the destination country is on the Federal Council's adequacy list. Where an adequate level of protection is missing, appropriate safeguards are needed - standard contractual clauses, binding corporate rules or, within narrow limits, consent. For US providers, the applicable framework (Swiss-US Data Privacy Framework) should additionally be checked.
- Review data processing agreements: the AI provider processes data only on instruction and with adequate security.
- Consider sovereign alternatives: Swiss or EU hosting and open models such as Apertus (ETH Zurich, EPFL, CSCS) can reduce cross-border transfers.
The revised FADP, GDPR and EU AI Act: how they interact
Swiss businesses are subject to the revised FADP but may additionally fall under the GDPR if they target people in the EU. The EU AI Act regulates AI as a product by risk class and is also extraterritorial - it can apply where AI outputs are used in the EU. The three regimes complement each other: the revised FADP addresses data protection, the EU AI Act the safety and governance of the AI system.
- Object of protection: revised FADP - data of natural persons; EU AI Act - safety and fundamental rights around the AI system.
- Penalty logic: revised FADP - fines against responsible individuals up to CHF 250,000; GDPR - corporate fines up to a percentage of turnover.
- In practice: a joint governance framework covers data protection and AI risk more efficiently than separate projects.
Practical checklist for Swiss businesses
- Inventory all AI tools and the personal data they process, including prompts and uploaded documents.
- Set an internal AI usage policy: what may be entered and what may not (sensitive data, trade secrets)?
- Update your privacy notice, record of processing activities and data processing agreements to reflect AI use.
- Run a DPIA early for risky AI initiatives and define a human-in-the-loop for automated decisions.
- Note: this article is general orientation and does not replace individual legal advice.
Frequently asked questions
Does the revised FADP also apply to ChatGPT and other AI tools from abroad?
Yes. As soon as you process personal data of people in Switzerland, the revised FADP applies regardless of where the provider is based. Using a foreign AI tool additionally triggers the rules on cross-border transfers and the need for a data processing agreement.
What is the difference between the revised FADP and the GDPR?
Both pursue similar goals but differ in the details. The revised FADP protects only natural persons and mainly sanctions responsible individuals with fines up to CHF 250,000. The GDPR provides for high corporate fines. If you target EU customers, you can be subject to both regimes.
When do I need a data protection impact assessment for an AI project?
Whenever the processing is likely to entail a high risk to personality or fundamental rights - for example new technologies, extensive processing of sensitive data or systematic monitoring. If a high residual risk remains despite safeguards, the FDPIC must be consulted.
May I enter health or other sensitive data into an AI tool?
Only with a clear legal basis and appropriate safeguards. Sensitive personal data such as health or biometric data demand heightened care, often explicit consent and a DPIA. Without these foundations, such data should not be entered into public AI tools.
How high are the fines for breaching the revised FADP?
Fines can reach CHF 250,000 and generally target the responsible natural persons rather than the company itself. Certain intentional breaches are prosecuted, for example of information or due-diligence duties. Proceedings are conducted by cantonal authorities.
Must I inform customers when an AI makes decisions?
Yes, where a decision is made solely automatically and has legal effect or significantly affects the person. You must inform the data subject, who may request human review and the opportunity to state their view. Certain exceptions, such as contract performance or consent, may apply.
Key terms in the glossary
Practical AI for your business
From idea to implementation – we show you what is concretely possible in your case.
Request a demo