Thoughts

AI and Data Protection in Switzerland: What Actually Matters

Every second AI conversation we have in Switzerland stalls on the same sentence: but what about data protection?

It is the right instinct pointed at the wrong size of problem. Data protection stops very few AI projects on the merits. It stops many of them through fog: nobody in the room knows exactly what is allowed, so the safe answer becomes no, indefinitely.

This article is the de-fogging we do at the start of client projects, written down. The usual disclaimer applies: we are engineers who work alongside lawyers, not a law firm. For the genuinely hard cases, ask one.

Start with what the Swiss FADP actually cares about: personal data. Information about identifiable people. A surprising amount of business data that companies are nervous about is not personal data at all: product specifications, internal manuals, anonymised process metrics, most supplier documents.

Which leads to the four questions that settle most cases in practice.

Checklist of four questions: is personal data in scope, is it sensitive under the FADP, is there a processor agreement with every provider, can you draw where the data flows

If there is no personal data in scope, most of the anxiety dissolves immediately. Your product documentation does not have privacy rights. Confidentiality still matters, contracts still matter, but you are no longer in FADP territory.

If there is personal data, the next question is whether any of it is sensitive in the legal sense: health information, religious or political views, financial profiles used for creditworthiness. Sensitive data raises the bar sharply. Ordinary contact data in an email thread does not.

Then the question that does the most practical work: is there a processor agreement with every provider that touches the data? The Auftragsverarbeitungsvertrag is the unglamorous document that makes most cloud AI use legitimate. Serious providers offer one as standard. A provider who cannot is answering your question for you.

And finally: can you draw where the data flows, on one page, without guessing? Not because the law demands the drawing, but because every hard conversation, with a regulator, a client or your own board, becomes easy if you have it and impossible if you do not.

Now to the question behind the question: where may the data live?

Three cards comparing Swiss on-premise hosting, Swiss or EU cloud where most projects land, and US cloud which is workable with checks on transfers and contracts

The honest ordering surprises people. Swiss on-prem is the strictest option and the right one for a narrow set of cases, mostly banks and health data. It is chosen far more often than it is needed, usually as an expensive form of reassurance.

Swiss or EU cloud with a proper processor agreement is where most projects land, including for regulated SMEs. The FADP does not require data to stay in Switzerland. It requires adequate protection, and the EU qualifies.

US providers are workable for many cases too, with more checking: transfer mechanisms, certification under the Swiss-US framework, and a sober look at what the data actually contains. Workable is not the same as automatic.

Three practical moves that make all of this easier, whatever you choose.

Minimise before you send. The cheapest data protection is not sending the data. Strip names and identifiers where the task allows it. An AI that classifies invoices rarely needs to know whose salary is on one.

Prefer providers with a no-training guarantee. The serious business offerings commit in writing that your data does not train their models. This single contract line resolves half the board-level worry.

Write the one-pager. Which data, which systems, which providers, which countries, which agreements. Two hours of work. It converts data protection from a mood into a checklist, and it is the first thing we build with every client.

The pattern worth naming: in our projects, data protection has almost never been the reason not to use AI. It has been the reason to use it deliberately: minimised data, contracted providers, flows you can draw. Companies that do this ship. Companies that treat the FADP as a general-purpose no are not protecting data. They are protecting hesitation.

Frequently asked questions

Is it legal for Swiss companies to use AI tools like ChatGPT or Claude?

Yes, with conditions. For data without personal information, the FADP is not the obstacle at all. For personal data, you need a processor agreement with the provider, a legitimate purpose, and appropriate care with sensitive categories. The business versions of the major AI tools offer these agreements as standard.

Does business data have to stay in Switzerland for AI?

No. The FADP requires adequate protection, not Swiss borders. EU hosting qualifies directly, and US providers can qualify through the Swiss-US Data Privacy Framework and contractual safeguards. Swiss-only hosting is genuinely required in narrower cases than most companies assume, mainly specific regulated workloads.

What is a processor agreement and do we need one for AI?

A processor agreement, in German Auftragsverarbeitungsvertrag, is the contract that binds a provider processing personal data on your behalf: what they may do with it, how they protect it, and that they delete it. If personal data flows to any AI provider, you need one. Serious providers have it ready to sign.

Can AI providers train their models on our company data?

Only if you let them. The business and enterprise tiers of the major providers contractually commit that customer data is not used for training. This is one of the main reasons to use business tiers instead of free consumer versions, and it is worth verifying in the contract rather than the marketing page.

What should a Swiss SME do first about AI and data protection?

Write the one-page data flow: which data, which systems, which providers, which countries, which agreements. Then minimise what leaves your systems and sign processor agreements where personal data flows. That is a week of calm work, and it replaces indefinite hesitation with a defensible setup.

Dejan Georgiev

Stuck between wanting AI and worrying about data?

I read every email myself and reply personally. Tell me what data is involved and I will tell you honestly whether it is a real problem or fog.

Dejan Georgiev

Founder of Uliasti

dejan.georgiev@uliasti.com
Uliasti mark
Dejan Georgiev, co-founder of UliastiRuth Georgiev, co-founder of Uliasti
Talk directly with our founders

Not sure where AI fits in your business? Let's talk, no slides.

Book a free 30-minute call and we'll tell you honestly where AI and software will pay off, or check your AI readiness first.

Lake at dawn.
We are a dynamic creative studio
We are a dynamic creative studio
best in design and digital solutions
best in design and digital solutions
we craft exceptional products
we craft exceptional products
led by a passionate and expert
led by a passionate and expert
with a creative mindset.
with a creative mindset.
Dejan Georgiev
CEO of Uliasti
(
Uliasti Studio
Uliasti Studio
Uliasti Studio
)
Where AI
&
Strategy
Drive
Moves
Flow
Inspire
hello@uliasti.com