AI and privacy in Switzerland: what business owners need to know

You are probably already using AI in your business. A chatbot that answers customer questions. A tool that pre-sorts job applications. A system that flags suspicious insurance claims. What you might not know: Switzerland's data protection law already covers all of this, and it has since September 2023. There is no separate "AI law" coming. The rules are here.
We help Swiss companies build AI systems that work within these rules. This guide covers what you actually need to do, without the legal jargon.
Switzerland does not have an AI law (and that's the point)
The EU passed the AI Act in 2024. It classifies AI systems by risk level and imposes specific obligations depending on the category. Switzerland took a different approach. The Federal Council mandated a review of AI regulatory approaches in November 2023, and concluded in February 2025 that sector-specific regulation is sufficient. No standalone Swiss AI Act is planned[1].
What does that mean for you? The law that matters most is the Federal Act on Data Protection (nFADP/nDSG), in force since 1 September 2023. It replaced the old 1992 law. There was no transition period. It applies right now, to every company processing personal data of people in Switzerland, regardless of whether a human or an AI does the processing.
The FDPIC (Switzerland's data protection commissioner) first stated in November 2023 that the nFADP is technology-neutral and applies directly to AI-supported data processing, and expanded on this position in a May 2025 update[2]. If your AI system touches personal data, the same rules apply as if a human employee were handling that data.
There is no "AI exception" in Swiss law. The nFADP applies to all data processing, whether done by a person, a spreadsheet formula, or a large language model. If it processes personal data, it falls under the law.
The one article you need to understand: Article 21
Most of the nFADP is straightforward data protection: inform people what data you collect, why, and where it goes. But one article was written specifically with automation in mind.
Article 21 covers "automated individual decisions." It applies when two conditions are met:
- The decision is fully automated. No human reviews or approves it before it takes effect.
- It produces a legal effect OR significantly affects the person. Credit denied, insurance claim rejected, job application screened out. Either a legal consequence or a significant personal impact is enough to trigger the rule. Minor personalization (like product recommendations) does not count.
When both conditions apply, you must inform the person that an automated decision was made, and you must give them the right to request a human review[3].
Here is the good news: most AI use cases in Swiss SMEs do not trigger Article 21. A chatbot answering support questions is not making legal decisions. An AI summarizing meeting notes is not significantly affecting anyone. But the moment your AI decides who gets a loan, who gets hired, or whose claim gets denied, Article 21 kicks in.
A common mistake we see: companies use AI to "pre-sort" job applications and assume it does not count as an automated decision because a human makes the final call. That is correct only if the human genuinely reviews each application. If the AI filters out 80% of candidates and a recruiter only sees the remaining 20%, the AI made the real decision. Article 21 applies.
What the regulator expects from your AI systems
The FDPIC published detailed guidance on what companies must do when deploying AI. The requirements boil down to four things[2]:
Transparency. You must disclose the purpose, how the system works, and what data sources it uses. If someone is talking to a chatbot, they need to know it is a machine. If your system learns from user interactions, you need to say so.
Purpose limitation. You collected customer data for billing? You cannot feed it into an AI model for marketing without consent. The data can only be used for the purpose it was originally collected for, or a purpose the person would reasonably expect.
Data protection impact assessment. If your AI system processes sensitive data (health, biometrics, financial) or makes decisions that significantly affect people, you need a formal impact assessment before deploying. This is not optional. It is a legal requirement under Article 22 nFADP.
Rights of affected persons. People have the right to know what data you hold about them, to request corrections, and to object to automated processing. Your system needs to support these requests. That means you need to know which data went into which decision, and you need a process for handling requests.
Three real scenarios and what they require
We have helped build AI systems for clients across several industries. Here is what the law requires for three common use cases.
Scenario 1: Customer support chatbot. Your chatbot answers questions using your product documentation and the customer's account data. It does not make decisions about the customer's account. It just provides information. What you need: a clear notice that the customer is talking to an AI (derived from the nFADP's transparency principles and confirmed by the FDPIC in their 2023 and 2025 guidance), and a privacy policy update explaining that account data is processed by an AI system. Article 21 does not apply here because no automated decision is being made.
Scenario 2: AI-assisted hiring. Your system scores resumes and ranks candidates before a recruiter reviews them. If the recruiter genuinely evaluates all candidates, this is a decision support tool and Article 21 does not apply. But if the AI eliminates candidates before any human sees them, it is making an automated individual decision with significant effect. You need: informed consent from applicants, the right to request human review, and a data protection impact assessment. You also need to document how the scoring model works well enough to explain it if someone asks.
Scenario 3: Insurance claim assessment. An AI reviews documents and recommends approval or rejection of claims. If a claims officer reviews every recommendation, this is decision support. If the AI auto-approves claims below a certain amount, it is making automated decisions. FINMA issued specific guidance in December 2024 requiring financial institutions to have clear governance and risk management for AI systems, including model explainability and bias monitoring[4]. You need everything from Article 21 plus FINMA's sector-specific requirements.
The FDPIC is watching (and publishing)
The Swiss regulator is not just writing guidelines. In February 2026, the FDPIC joined 60 other national data protection authorities in a joint statement on AI-generated images[5]. The statement demands safeguards against misuse, transparency about AI capabilities, accessible removal mechanisms for harmful content, and specific protections for children.
This matters because it signals where enforcement is heading. The FDPIC is coordinating internationally. It is building expertise on AI-specific issues. And it has already confirmed that it considers existing law sufficient to act, meaning it does not need new legislation to investigate and sanction AI-related privacy violations.
One more thing to keep in mind: unlike the EU's GDPR, the nFADP holds individuals personally liable. Fines of up to CHF 250,000 can be imposed on the responsible person within the organization, not on the company itself[3]. That means the managing director, the data protection officer, or whoever made the decision to deploy the AI system. This is not an abstract corporate risk. It is a personal one.
Under the nFADP, fines are directed at the responsible individual, not the company. Up to CHF 250,000. This is unusual compared to the EU, where fines hit the organization. Make sure someone in your company is explicitly responsible for AI compliance, and that this person actually knows the rules.
Your pre-deployment checklist
Before you put an AI system into production that processes personal data, run through this list.
What about the EU AI Act?
If you serve customers in the EU, you may also need to comply with the EU AI Act. The two frameworks are different but not contradictory. The EU AI Act classifies systems by risk level (minimal, limited, high, unacceptable) and imposes obligations based on that classification. The nFADP focuses on data protection regardless of risk category.
In practice, if you comply with both the nFADP and standard GDPR requirements, you are already covering most of what the EU AI Act requires for limited and high-risk systems. The main additions from the AI Act are conformity assessments for high-risk systems (like hiring tools or credit scoring), mandatory registration in the EU database for high-risk AI, and specific rules around AI-generated content disclosure.
Switzerland signed the Council of Europe's Framework Convention on AI and Human Rights on 27 March 2025[7]. And this is not some distant future commitment. In February 2025, the Federal Council tasked the FDJP with drafting a bill that implements the Convention into Swiss law. The deadline: a consultation draft by end of 2026[6]. The new law will cover transparency, non-discrimination, data protection, and oversight of AI systems. It is not an "AI Act" in the EU sense, but it will add binding requirements on top of what the nFADP already demands.
This means the regulatory floor is about to rise. Companies that build their AI systems with transparency and documentation from the start will not need to retrofit anything when the new rules arrive. Companies that skip compliance now will face a double catch-up: the nFADP requirements they should already be meeting, plus the new obligations coming in 2027 or 2028.
If you serve only Swiss customers and your AI does not make automated decisions about individuals, your compliance burden is manageable: update your privacy policy, add an AI disclosure, and make sure your data stays where it should. Do not over-engineer compliance for risks you do not have.
Swiss data protection law is not designed to prevent you from using AI. It is designed to make sure people know when AI is making decisions about them and can push back if something goes wrong. Most of the requirements are things you would want to do anyway: be transparent, document your systems, and give people a way to ask questions.
If you are building an AI system and want to make sure it meets Swiss requirements before it goes live, reach out. We have done this for clients in finance, insurance, and healthcare, and the compliance work is easier when it is built in from the start rather than bolted on after launch.
Sources
- [1]Swiss Federal Council (2023). Federal Council examining regulatory approaches to AI. Press release, November 22, 2023. Study mandate to DETEC for AI regulatory overview
- [2]FDPIC (2025). Current data protection legislation is directly applicable to AI. Published May 2025, updated April 2026. Core guidance on AI obligations under nFADP
- [3]Swiss Confederation (2023). Federal Act on Data Protection (nFADP/nDSG). Art. 21 (automated individual decisions), Art. 22 (impact assessments), Art. 60-66 (penalties)
- [4]FINMA (2024). FINMA guidance on governance and risk management when using artificial intelligence. Guidance 08/2024, published December 18, 2024
- [5]FDPIC et al. (2026). Joint statement on AI-generated images and the protection of privacy. Published February 23, 2026. Signed by 61 national data protection authorities
- [6]Federal Chancellery of Switzerland (2025). Regulation of AI. Federal Council decision of February 12, 2025. Consultation draft for AI bill due by end of 2026
- [7]Swiss Federal Council (2025). Switzerland signs Council of Europe Convention on Artificial Intelligence. Signed by Federal Councillor Albert Rösti on 27 March 2025 in Strasbourg


