AI Act × DSG × GDPR, Where Three Regimes Overlap

6 min readLast updated By Dr Iur Dr Econ Nino Jibuti

Introduction

Three regimes hit every AI application in a Swiss company that processes personal data and has EU exposure: DSG, GDPR and the EU AI Act. They partly regulate the same (transparency, risk assessment, human oversight), partly complementary topics (data protection vs product conformity), and partly related topics with different thresholds (lawful basis vs high-risk classification). Anyone running three separate compliance programmes doubles the workload and creates contradictions. Anyone who knows the mapping builds an integrated programme and reduces redundancy to a minimum.

This article delivers the article-level interface analysis:

  • Scope: when do which regimes apply in parallel
  • Transparency: Art. 19 DSG, Art. 13/14 GDPR, Art. 13 and 50 AI Act
  • DPIA vs FRIA: Art. 22 DSG, Art. 35 GDPR, Art. 27 AI Act
  • Automated individual decisions: Art. 21 DSG, Art. 22 GDPR, Art. 14 AI Act
  • Data governance: Art. 6 DSG, Art. 5 GDPR, Art. 10 AI Act
  • Enforcement and sanctions
  • Practical integration into a single governance system

Bottom line up front: about 60 percent of AI Act duties have a direct anchor in DSG or GDPR. Anyone with mature data protection compliance can become AI Act compliant with manageable additional effort, anyone who has not taken DSG seriously will be doubly burdened by the AI Act.

Scope

DSG: territorial and personal under Art. 3, any processing of personal data with effects in Switzerland, regardless of where the controller is established. GDPR: territorial under Art. 3, establishment in the Union (paragraph 1) or "targeting" persons in the Union (paragraph 2). EU AI Act: territorial under Art. 2, providers placing AI on the Union market, deployers in the Union, as well as providers and deployers in third countries whose output is used in the Union.

In practice many Swiss companies fall under all three regimes: DSG always (where personal data is processed), GDPR with EU establishment, EU marketing or processing of persons in the EU, AI Act with AI marketing in the EU or output use in the EU. The mapping must be done per processing activity, not in the abstract: an HR AI with only Swiss employees falls under the DSG and, if the company does not market the supplier in the EU, possibly not under the AI Act. An HR AI in the same company with German applicants falls under all three.

Transparency and information

DSG Art. 19 requires the controller to inform data subjects of the processing, in particular identity, purpose, recipients, third-country transfer. Where profiling or automated individual decisions occur, the logic and the essential effects must be communicated (Art. 19(2)(d)). GDPR Art. 13/14 is more detailed (legal basis, legitimate interests, retention, right to complain) but substantively compatible.

EU AI Act Art. 13 requires the provider of a high-risk system to make available transparent information and user instructions to the deployer, no direct anchor to the data subject, but indirectly: the deployer can only inform GDPR/DSG-compliantly if the provider supplied the necessary data. Art. 50 AI Act adds direct duties to persons: chatbots must disclose their AI nature, deepfakes must be labelled, emotion recognition deployers must inform the affected person. Practical consequence: the company's privacy notice must also include the AI Act transparency under Art. 50, a single document for three regimes.

DPIA vs FRIA

DSG Art. 22 requires a data protection impact assessment where high risk is likely, in particular for large-scale processing of sensitive personal data or systematic extensive monitoring. GDPR Art. 35 requires a DPIA in case of "likely high risk", with detailed content requirements (description, necessity, risks, measures). EU AI Act Art. 27 requires a fundamental rights impact assessment (FRIA) for certain high-risk deployers (public bodies, private providers of public services, banks/insurers for Annex III no. 5).

The three instruments substantially overlap. Art. 27(4) AI Act explicitly allows integration with an existing DPIA. In practice, a single template that consolidates DPIA, DSFA and FRIA contents works well: description of processing, legal basis, necessity and proportionality, risks (data protection AND fundamental rights broadly), technical and organisational measures, residual risk, DPO consultation. Additional fields for FRIA: description of deployment context, frequency and duration of use, affected categories of persons, specific harm risks to fundamental rights, oversight measures, response plan. An integrated DPIA+DSFA+FRIA typically runs 15–25 pages, not 3×8 separately.

Automated individual decisions

DSG Art. 21 and GDPR Art. 22 regulate automated individual decisions with legal effects or significant impact. Both require information, the right to human intervention, expression of view and contestation. Differences: GDPR Art. 22 generally prohibits fully automated decisions (with three exceptions: contractual necessity, statutory basis, explicit consent). DSG Art. 21 permits them in general but ties information and intervention rights to them.

EU AI Act Art. 14 requires human oversight by trained natural persons for high-risk systems, persons who supervise the system, question its results and can intervene where necessary. Unlike GDPR Art. 22, Art. 14 AI Act is process-related (continuous oversight), not decision-related (right to review on individual case). Practical consequence: for a high-risk AI with automated individual decisions, both mechanisms must coexist, continuous oversight (Art. 14) AND individual review right (Art. 21 DSG / Art. 22 GDPR). The workflow design must enable both.

Data governance and data quality

DSG Art. 6 requires accuracy; Art. 7 privacy by design. GDPR Art. 5 lists six principles including "accuracy" (paragraph 1(d)) and "integrity and confidentiality" (paragraph 1(f)). EU AI Act Art. 10 (for high-risk AI) is significantly more detailed: training, validation and test datasets must be relevant, representative, as free as possible of errors and bias, and complete; data management and governance practices must address data provenance, processing operations, assumptions and gaps; bias tests and corrections must be documented.

Practical consequence: anyone working DSG-compliantly typically has a data catalogue and a record of processing. For AI Act Art. 10, an additional data governance plan per AI model must document the training-data provenance traceably. For foundation-model use via API (OpenAI, Anthropic, Google), training-data governance sits with the GPAI provider; the Swiss user can rely on the provider's transparency documentation (GPAI Code of Practice). For fine-tuning with own data, a shared responsibility arises, the fine-tuning dataset must be independently documented.

Supervision and sanctions

DSG: FDPIC as supervisory authority with investigation, supervision and ordering powers; criminal offences (Art. 60–66) with fines up to CHF 250,000 against responsible natural persons (not the company). GDPR: national supervisory authorities (in Swiss-relevant constellations typically BfDI Germany, CNIL France, Garante Italy); fines up to EUR 20 million or 4 percent of worldwide turnover (Art. 83(5)). EU AI Act: national market surveillance authorities + AI Office; fines up to EUR 35 million / 7 percent (Art. 5 prohibitions, Art. 99(3)), up to EUR 15 million / 3 percent (other duties, paragraph 4), up to EUR 7.5 million / 1 percent (false information, paragraph 5).

Practical relevance: an AI incident involving personal data can simultaneously breach all three regimes, e.g. a credit scoring AI without customer information, without DPIA, without human review right, with poor training data. Supervisors increasingly coordinate; the AI Office in 2025 established a formal cooperation framework with national data protection authorities (Art. 74(8)). Anyone operating in the EU should expect cross-investigation as soon as a case becomes public.

How SIDD supports you

SIDD builds integrated compliance programmes mapping DSG, GDPR and AI Act in one governance system. We combine DPIA, DSFA and FRIA templates, integrate AI Act duties into the record of processing under Art. 12 DSG, harmonise the privacy notice around Art. 50 AI Act, and align supplier contracts so that a single contract addendum satisfies the processing agreement duties plus the AI Act supplier duties. We avoid parallel silos, that saves 30–40 percent effort compared to separate programmes.

More on our services at Swiss data protection adviser (DSG) and GDPR DPO (for EU establishments). Further reading: EU AI Act Swiss guide, phases and deadlines, AI regulation in Switzerland. To request a concrete interface analysis for your AI systems, use our quote form or contact us via the contact form.

Need help putting this into practice? SIDD operates the matching service.
See service →

AI Act × DSG × GDPR, Where Three Regimes Overlap

INSIGHT

Artificial Intelligence
24 May 2026
Dr. Dr. Nino Jibuti
How the AI Act, FADP and GDPR interact: scope, transparency, DPIA and FRIA, automated individual decisions, data governance and supervision.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.