AI and Data Protection in Switzerland: Duties, Contracts, Security
What this is about: AI use within the Swiss legal framework
Swiss companies have been adopting generative AI at high speed since 2023. ChatGPT, Microsoft Copilot, Claude or proprietary retrieval-augmented-generation solutions regularly process personal data in the process. Three legal regimes are therefore engaged at once: the Swiss DSG (Federal Act on Data Protection / FADP), in force since 1 September 2023, the GDPR where it applies extraterritorially, and Regulation (EU) 2024/1689 (the EU AI Act). As of May 2026, Switzerland has no dedicated AI law. The Federal Council signed the Council of Europe AI Convention on 5 September 2024 and announced a technology-neutral regulatory approach. This article complements our AI Compliance Guide (German-language pillar) with the Swiss application perspective. It answers four questions: which DSG duties apply when foundation models are used? When does the EU AI Act reach Swiss providers? What contracts are needed with OpenAI, Anthropic or Microsoft? And how do you secure LLM applications technically? We address these topics from the perspective of a data protection advisor, an ISO 42001 auditor and a security lens aligned with the OWASP LLM Top 10. The article is aimed at small and medium-sized enterprises (SMEs) and mid-market companies that want to deploy AI productively while remaining compliant.
DSG duties when using generative AI
The DSG has no dedicated AI article. The familiar duties, however, continue to apply unchanged as soon as a model processes personal data. Central are the processing principles under Art. 6 DSG (lawfulness, good faith, purpose limitation, proportionality, accuracy and data security), the duty to inform under Art. 19 DSG and the Records of Processing Activities (ROPA) under Art. 12 DSG. The practical consequence: every LLM use case that processes personal data belongs in the ROPA. The privacy notice must name the model deployed, the engaged processors and any third-country transfers. Particularly sensitive is Art. 21 DSG on automated individual decisions. If the AI system makes a decision without human involvement and this decision has legal effects or significantly affects the data subject, that person must be informed and granted the right to be heard and to have the decision reviewed by a natural person. This typically concerns automated credit decisions, applicant filtering or pricing decisions. Where sensitive personal data is processed or the processing is likely to result in a high risk, a Data Protection Impact Assessment (DPIA) under Art. 22 DSG is required. For common LLM rollouts in HR, legal and sales we recommend a standardised DPIA template and a documented risk assessment per use case.
EU AI Act: extraterritorial reach for Swiss providers
The EU AI Act entered into force on 1 August 2024. The prohibitions under Art. 5 have applied since 2 February 2025, the obligations for general-purpose AI since 2 August 2025, and the high-risk requirements apply from 2 August 2026. Swiss companies fall within scope as soon as they place an AI system on the EU market, operate it in the EU, or where the output is used in the EU. The majority of internationally active Swiss SMEs are therefore affected. From our perspective, three steps are priorities. First: risk classification of every AI use case (prohibited, high-risk, GPAI, limited risk, minimal). Second: review of the AI literacy duty under Art. 4 AI Act, which requires every provider and deployer to ensure sufficient AI literacy among the involved staff. Third: contract adjustments with model providers, since high-risk deployers must be able to demand technical documentation, logs and conformity evidence. A documented AI inventory modelled on a DSG ROPA is the precondition. Without an inventory, neither the risk class nor the EU relevance can be evidenced per use case. Our AI Compliance Guide (German-language pillar) describes the cascade of duties in detail.
Contracts with OpenAI, Anthropic and Microsoft
Whoever uses ChatGPT, Claude or Copilot in a business context is the controller, with the model provider acting as processor. Three contractual building blocks follow. First, a data processing agreement under Art. 9 DSG or Art. 28 GDPR. OpenAI offers a Data Processing Addendum, Anthropic a DPA, and Microsoft the Online Services Terms including Product Terms and DPA. Consumer tiers (such as ChatGPT Free or Plus) do not provide a DPA, which is why these tiers are unsuitable for processing personal data. Second, the question of third-country transfers. From a Swiss perspective the United States does not have a general adequacy level; however, the FDPIC (Federal Data Protection and Information Commissioner) has recognised the Swiss-U.S. Data Privacy Framework for certified companies since 15 September 2024. For non-certified recipients, Standard Contractual Clauses plus a Transfer Impact Assessment are required. Third, the training question: by default, providers may not use inputs from API or business tiers for model training, but they often may from consumer tiers. This default belongs explicitly in the contract and in the internal acceptable-use policy. We recommend maintaining a catalogue of all generative AI tools, with owner, legal basis, DPA status, hosting region and training opt-out.
ISO/IEC 42001:2023 as a governance framework
ISO/IEC 42001:2023, published in December 2023, is the first international management system standard for artificial intelligence. It follows the familiar high-level structure and is therefore combinable with ISO/IEC 27001. For Swiss companies, 42001 is relevant for two reasons. First, it provides an auditable framework that can evidence due diligence for AI use towards customers, insurers and authorities. Second, it structurally mirrors central requirements of the EU AI Act: risk management, data governance, transparency, human oversight and continuous improvement. Organisations that already operate ISO 27001 can extend the information security management system with the AI-specific controls instead of building parallel structures. In practice, we begin mandates with three building blocks: an AI policy with clear responsibilities, an AI risk register with a scoring logic, and a lifecycle process for models (procurement, testing, release, monitoring, decommissioning). Our experience shows: SMEs benefit even without formal certification, because the structure de-emotionalises discussions with business units. Organisations working in parallel on ISO 27001 will find guidance on integration in our ISO 27001 guide and in our AI Compliance Guide (German-language pillar).
Technical security: OWASP LLM Top 10 in practice
AI applications enlarge a company's attack surface. The OWASP LLM Top 10 (version 2025) systematise the most common threats. From our pentest experience, four risks are particularly relevant for Swiss SMEs. First, prompt injection: inputs from emails, websites or documents override the model's system instructions. Mitigation: separation of data and control channels, tool allowlisting, output filtering. Second, sensitive information disclosure: employees enter customer data or source code into public chats. Mitigation: enterprise tiers with tenant separation, DLP rules on the proxy and a binding acceptable-use policy. Third, insecure output handling: LLM outputs are fed into SQL queries, shell commands or HTML without validation. Mitigation: treat output like user input, use context-aware encoding and parametrisation. Fourth, model extraction and training-data leakage from in-house fine-tuning: using personal data for training risks its reproduction in answers. Mitigation: differential privacy, data minimisation and output audits. We recommend including AI applications in the annual pentest scope and explicitly testing the prompt layer, tool calls and knowledge base. Documented monitoring (token consumption, anomalies, blocked prompts) belongs in every productive AI deployment.
Use-case examples: HR, customer service, internal RAG
Three application areas illustrate how DSG duties can be implemented concretely. In HR, CVs are often pre-filtered automatically. As soon as filtering leads to a rejection without a human in the loop, Art. 21 DSG is triggered: information, right to be heard and human review must be ensured. We recommend designing the filtering as a recommendation and assigning the final decision, with documentation, to a person. In customer service, chatbots increasingly replace first contact. The privacy notice must name the provider, the model, the storage location and the retention period. Inputs containing sensitive personal data (health, religious beliefs) should be technically detected and either blocked or escalated. With internal RAG systems (retrieval-augmented generation on the organisation's own documents) a permissions problem arises: when the model accesses a knowledge base, the answer does not automatically inherit the requesting user's read permissions. An answer may therefore contain content from sources the user is not authorised to see. The solution lies in a permission-aware retrieval architecture: permissions are enforced in the retrieval layer, not first in the prompt. Audit logs, a clear legal basis per source and an impact assessment also belong to productive operation.
Recommendations and next steps
Our recommendation to Swiss SMEs is to build AI compliance pragmatically in three waves. First wave: inventory of all AI applications, clarification of the legal basis and EU relevance, conclusion of DPAs, prohibition of consumer tiers for personal data. Second wave: anchoring in data protection management (ROPA, DPIA template, training under Art. 4 AI Act) and integration into an existing ISMS under ISO/IEC 27001. Third wave: build a lean AI management system under ISO/IEC 42001 with lifecycle, monitoring and an annual pentest of the AI applications. As of May 2026, the Swiss legal situation is technology-neutral; that makes clear internal standards all the more important. Those seeking support will find three matching services with us: Swiss data protection advisor for DSG implementation, external EU Data Protection Officer for GDPR representation and ISMS under ISO 27001 as the basis for 42001. For methodological depth we recommend our AI Compliance Guide (German-language pillar) and for structured staff training the data protection workshop for SMEs. Well-designed AI governance enables innovation without jeopardising customer trust.
