GDPR compliance doesn’t automatically cover Switzerland. FADP compliance doesn’t automatically cover the EU. The two laws share core principles, but liability, breach thresholds, lawful basis, representative rules, and AI-specific legislation all diverge. Most AI companies serving both markets end up under both laws at once.
At a Glance
| Issue | Swiss FADP | EU GDPR | Practical read |
|---|---|---|---|
| Territorial trigger | Effects in Switzerland, even if the processing started abroad | EU establishment, or targeting/monitoring EU users | Assess separately — they don’t overlap automatically |
| Default lawful basis | No six-basis requirement; processing is allowed unless it breaches personality rights or processing principles | Every activity needs one of six Art. 6 bases | Lighter starting point in CH, not a blank check |
| Maximum penalty | CHF 250,000, criminal, on the individual | €20M or 4% of global turnover, administrative, on the company | Named people carry the risk in CH; the balance sheet carries it in the EU |
| Breach notification | FDPIC, “as soon as possible,” only if likely high risk | Authority within 72 hours, where the breach is likely to risk rights/freedoms | CH’s threshold is higher, not just its clock looser |
| DPIA trigger | Likely high risk (Art. 22) | Likely high risk (Art. 35) | Similar substance, separate documentation |
| Automated decisions | Inform + right to request human review (Art. 21) | Restriction with narrow exceptions and safeguards (Art. 22) | GDPR restricts the decision itself; FADP leans on transparency |
| Representative | Controllers only, and only if regular, large-scale, high-risk, and CH-targeted (Art. 14) | Most non-EU controllers and processors targeting the EU (Art. 27) | CH’s bar is narrower on both scope and who it catches |
| AI-specific law | None yet; consultation draft due end of 2026 | AI Act, phasing in through 2028 | Swiss-only systems face no AI statute today — but “Swiss-only” is a narrower fact pattern than it sounds |
Does GDPR cover Switzerland?

No, not automatically. Switzerland isn’t an EU or EEA member. GDPR applies to a Swiss AI company only if that company independently meets GDPR’s own scope test.
Switzerland runs its own law: the FADP, in force since September 1, 2023. It tracks GDPR closely because Switzerland needs the EU to keep treating it as adequate — a status the European Commission reviews roughly every four years. Weaken the FADP too much, and adequacy could lapse.
If you touch personal data in Switzerland and the EU, plan on both laws applying at once.
Lawful Basis: The Difference That Actually Changes How You Build
GDPR Article 6 blocks processing by default. Every activity needs one of six lawful bases before it starts — including a training run or a log pipeline.
FADP flips that. Processing is allowed unless it breaches the general principles in Articles 6 and 8 — proportionality, purpose limitation, transparency, good faith — or infringes personality rights, which then requires a specific justification under Article 31.
One real carve-out: no infringement occurs if the person made the data public themselves, without restricting its use. But that carve-out doesn’t suspend the underlying principles. Purpose limitation and proportionality still apply, especially where public data gets repurposed for model training — that’s a new use, not a free pass.
Net effect: Switzerland doesn’t force a GDPR-style basis analysis before you touch a dataset. That’s a real head start for early experimentation, not a general exemption.
Liability: Individuals, Not Just the Company

- FADP: up to CHF 250,000, criminal, on the individual responsible for a willful violation.
- GDPR: up to €20 million or 4% of global turnover, administrative, on the organization.
The FDPIC investigates and can order corrective measures, but can’t issue a fine itself — a Swiss criminal court decides that. A named engineering lead or product owner who willfully misuses training data in Switzerland carries personal exposure. That changes who signs off before a feature ships.
Breach Notification: The Threshold Matters More Than the Clock
FADP: report to the FDPIC “as soon as possible” — only if the breach is likely to create a high risk to personality or fundamental rights.
GDPR: notify within 72 hours, but only where the breach is likely to result in a risk to rights and freedoms — not every breach, automatically.
So the real comparison isn’t “no deadline vs. 72 hours.” It’s a higher bar for reporting at all under Swiss law, against a lower bar plus a hard clock once that lower bar is met. A minor logging incident — a misconfigured endpoint that briefly exposed prompt text internally — can clear GDPR’s threshold while sitting under FADP’s.
DPIAs: Same Trigger Logic, Separate Paperwork
Both laws use a high-risk test. FADP Article 22 pushes the check earlier — as soon as project planning — escalating to a full DPIA if that check flags likely high risk. An FAQ chatbot probably stays under the line; a tool scoring creditworthiness or screening job applicants almost certainly clears it.
A GDPR DPIA is a solid foundation for the Swiss version. Treat it as a starting point, not a substitute — Swiss scope and documentation still need their own pass.
Transfers: A Different Gatekeeper
The Federal Council, not the FDPIC, decides which countries count as adequate. As of 2026, that list covers all EU/EEA states plus several others.
Outside that list, EU Standard Contractual Clauses still work — with Swiss-specific amendments, typically a Swiss addendum on governing law and jurisdiction. Pre-2021 SCCs don’t qualify at all.
For US infrastructure: the Federal Council approved its own adequacy decision for the Swiss–US Data Privacy Framework on August 14, 2024, effective September 15, 2024. DPF-certified US vendors can receive Swiss personal data without extra contractual steps.
Sensitive Data and Inference
The revised FADP added genetic and biometric data to its sensitive categories, alongside health, political/religious/union views, the intimate sphere, and criminal records.
AI systems that infer sensitive characteristics — rather than collect them directly — can trigger heightened obligations under both regimes, particularly where the inference relies on or produces sensitive personal data. That’s a case-by-case question about the specific data, inference method, and purpose. Don’t treat every prediction as automatically sensitive; assess it.
Do You Need a Swiss Representative?

Narrower than GDPR’s Article 27 test, and it applies to controllers only — not processors, unlike the EU rule.
FADP Article 14 requires a foreign controller to appoint a Swiss representative only when all four conditions hold together:
- Processing connects to offering goods/services, or monitoring behavior, in Switzerland.
- It’s large-scale.
- It’s regular.
- It poses high risk to personality or fundamental rights.
The FDPIC assesses that “high risk” across a company’s entire Swiss-facing footprint — a different lens than a single-project DPIA. A mid-sized foreign AI vendor can clear GDPR’s broader Article 27 bar while sitting under this one. Check both independently.
Records of Processing
FADP Article 12 requires a written record — data categories, purposes, recipients, retention where possible, security measures, and details of foreign disclosures. Roughly GDPR Article 30’s Swiss counterpart.
There’s an exemption for organizations under 250 employees, but only where processing poses negligible risk. Don’t assume it from headcount alone — assess it against what the processing actually involves. Training pipelines, profiling-adjacent features, and sensitive-data handling tend to push risk above the exemption regardless of company size.
Build the register around the AI lifecycle: model, purpose, data categories by training vs. inference use, retention, subprocessors and location, transfer mechanism, and the automated-decision workflow.
Automated Decisions: Article 21 vs. Article 22

GDPR Article 22 restricts a fully automated decision with legal or similarly significant effects unless a narrow exception applies — contract necessity, legal authorization, explicit consent. Even then, human review and the right to contest are mandatory.
FADP Article 21 takes an inform-and-review approach instead. The affected person must be told the decision was automated and can request human review — but there’s no standalone Swiss right to block the decision outright.
Practically: a hiring-screening or credit-scoring tool needs a genuinely solid basis to run at all for EU users. For Swiss users, the question shifts to whether the transparency and review mechanics actually work.
AI Training Data
- Public data isn’t automatically free to scrape. FADP’s exception is narrower than “findable online” — the person has to have made it public without restricting its use. GDPR scraping still needs a lawful basis.
- Prompts and outputs are personal data the moment they tie to an identifiable person.
- Fine-tuning on production data is a new purpose, not a continuation of the original one — exactly what purpose-limitation rules exist to catch.
- Synthetic data isn’t automatically anonymous. If it traces back to a real person, through memorization or a small source set, identifiability tests can still apply.
- Model memorization matters. If a model can reproduce personal information from training data, deletion and anonymization claims deserve closer scrutiny — document how training-data removal and model updates actually address it.
Evaluating an AI Vendor
Work through this with any third-party model API:
- Where does inference physically run?
- Are prompts and outputs stored, and for how long?
- Do prompts train the vendor’s models — and can that be turned off?
- Who are the subprocessors, and where are they based?
- What transfer mechanism covers data leaving Switzerland or the EU?
- Can the vendor support access, deletion, and rectification requests?
- Can vendor support staff read raw prompts?
Retention length, human review access, and training-reuse policy are exactly the three factors that separate vendors in practice — the same checklist consumer-facing platforms get judged on applies just as directly to enterprise model APIs.
A concrete path worth mapping: Swiss SaaS → customer prompt → US-hosted model API → logging → support dashboard → backup. Each hop needs its own answer: FADP transfer mechanism, GDPR transfer mechanism if EU data is involved, a data processing agreement with the vendor, and — separately — an AI Act role analysis if the system touches the EU market.
Does Switzerland Have Its Own AI Act?

Not yet. AI systems run under existing, technology-neutral rules — led by the FADP, plus sector law where it applies. A consultation draft for Swiss AI legislation is expected by the end of 2026.
Switzerland signed the Council of Europe’s Framework Convention on AI in March 2025 and plans to ratify it through domestic amendments. The FDPIC has confirmed the FADP applies directly to AI-supported processing — a general-purpose law doing the work, not a legal vacuum.
The EU side runs on a firmer schedule, per the AI Act’s implementation timeline:
- February 2025 — prohibited practices and AI-literacy duties.
- August 2025 — general-purpose AI model obligations.
- August 2026 — general application, including Article 50 transparency duties.
- December 2027 — high-risk (Annex III) requirements, deferred from 2026 by the Digital Omnibus.
- August 2028 — high-risk AI embedded in regulated products.
A Swiss-only company faces no AI-specific statute today. But the AI Act’s own scope rule, Article 2(1)(c), reaches further than “established in the EU”: it also covers providers and deployers based in a third country where the system’s output is used in the Union. A Swiss company whose output reaches EU users can fall inside that provision directly — this isn’t a loose inference; it’s a named trigger in the statute.
Provider, Deployer, or Neither
The AI Act and FADP/GDPR aren’t assessing the same thing, and “AI company” isn’t one legal role under the Act.
- Provider — builds or places the system/model on the market. Carries the heaviest documentation and risk-management duties.
- Deployer — uses the system in its own operations. Lighter duties: human oversight, monitoring, and — for public-sector high-risk use — a fundamental-rights impact assessment.
- GPAI model provider — a separate category for foundation models, with its own transparency and copyright-summary obligations, heavier still if the model presents systemic risk.
A company can be a provider for one system and a deployer for another. The Swiss privacy analysis (FADP) and the EU AI Act analysis run on separate tracks — the same processing can require both, independently.
Structuring Compliance
- One inventory, three lenses. FADP: is Swiss-effect personal data involved? GDPR: is EU personal data or EU territorial scope involved? AI Act: is the system in scope, and under which role? Share the technical inventory; keep the three legal assessments separate.
- Adapt the DPIA, starting from the GDPR version, adding Swiss scope and residual risk explicitly.
- Name a decision-maker for high-risk AI launches — individual FADP liability makes this a real, not symbolic, requirement.
- Build the records register around the AI lifecycle, and note the legal-basis analysis for EU-facing processing even where FADP itself doesn’t require one.
- Keep transfer mapping separate from the GDPR one — SCCs need Swiss amendments, not a copy-paste.
If You Already Have GDPR Compliance
| GDPR piece you already have | Swiss action needed |
|---|---|
| Art. 6 lawful-basis mapping | Reassess — don’t assume the six-basis model transfers over |
| GDPR DPIA | Adapt for Swiss scope and risk standard |
| Art. 22 automated-decision process | Map separately against FADP Art. 21 |
| Art. 27 EU representative analysis | Test FADP Art. 14 independently — narrower, controller-only |
| Art. 30 records | Check FADP Art. 12 and the 250-employee exemption on its own terms |
| EU SCCs | Add a Swiss addendum where transfers leave the adequacy list |
| GDPR breach workflow | Layer in FADP’s higher high-risk threshold |
| Corporate accountability structure | Name the individual exposed under FADP |
| — | AI Act role/classification stays a separate analysis regardless |
Choosing Where to Build First
Switzerland’s lighter default lawful-basis model, higher breach threshold, and lack of an AI-specific statute make it a genuinely different regulatory profile — not a compliance shortcut. Individual liability still carries real weight, and Swiss AI legislation is already in drafting.
Teams planning eventual EU expansion should build documentation to the stricter GDPR/AI Act standard from day one. Retrofitting AI Act-grade documentation onto a system built for a lighter bar almost always costs more than building once and scoping down for Switzerland, where the extra rigor genuinely isn’t required.
FAQs
Q. Does Switzerland adhere to GDPR?
No. Switzerland does not automatically follow the EU General Data Protection Regulation (GDPR) because it is not an EU or EEA member. However, GDPR can still apply to a Swiss AI company if the company targets people in the EU, offers them goods or services, or monitors their behavior. Switzerland separately regulates personal data under the Federal Act on Data Protection (FADP).
Q. Does GDPR apply to AI companies?
Yes. GDPR applies to AI companies when their AI systems process personal data and the processing falls within GDPR’s territorial scope. AI companies may need to meet GDPR requirements for lawful basis, transparency, data-subject rights, data protection impact assessments, international transfers, and certain automated decisions. The EU AI Act adds separate AI-specific obligations and does not replace GDPR.
Q. What is the Swiss equivalent of GDPR?
Switzerland’s closest equivalent to GDPR is the revised Federal Act on Data Protection (FADP), which has applied since September 1, 2023. The FADP shares many GDPR principles but differs in important areas, including lawful basis, individual criminal liability, data-breach notification thresholds, automated decisions, and representative requirements.
Q. Do AI companies need a DPIA under Swiss data protection law?
Not automatically. Under Article 22 of the Swiss FADP, a data protection impact assessment (DPIA) is required when planned processing is likely to create a high risk to personality or fundamental rights. High-risk AI uses can include large-scale profiling, sensitive-data processing, or automated decisions with significant effects. Using AI alone does not automatically trigger a Swiss DPIA.
Q. Does a foreign AI company need a Swiss representative?
Only in specific circumstances. Under Article 14 of the FADP, a foreign controller generally needs a Swiss representative when its processing targets people in Switzerland, is regular and large-scale, and presents a high risk to personality or fundamental rights. Unlike GDPR Article 27, the Swiss requirement applies to controllers and not processors.
Q. Can Swiss AI companies use US-based AI APIs?
Yes, Swiss AI companies can use US-based AI APIs if personal-data transfers comply with Swiss cross-border transfer rules. A US provider certified under the Swiss–US Data Privacy Framework may receive Swiss personal data under Switzerland’s adequacy decision. Other transfers may require appropriate safeguards, such as EU Standard Contractual Clauses with the necessary Swiss adaptations.
Q. Does AI training automatically require a DPIA under the Swiss FADP?
No. AI model training does not automatically require a DPIA under the Swiss FADP. The legal trigger is whether the planned processing is likely to create a high risk to personality or fundamental rights. The scale of the dataset, use of sensitive personal data, profiling, model purpose, and potential effects on individuals can all affect that assessment.
Q. Can one DPIA cover both GDPR and the Swiss FADP?
A single risk assessment can provide a shared starting point, but it should not automatically be treated as sufficient for both laws. GDPR and the Swiss FADP use similar high-risk concepts, yet the scope, documentation, and legal analysis may differ. AI companies processing data in both Switzerland and the EU should review the assessment separately against each law.
Q. Does Switzerland have its own AI Act?
No, Switzerland does not currently have a dedicated AI Act equivalent to the EU AI Act. AI systems in Switzerland are currently governed primarily through existing technology-neutral laws, including the Federal Act on Data Protection (FADP), as well as applicable sector-specific rules. Swiss AI legislation is expected to move forward through a consultation process planned for the end of 2026.
Q. Is the Swiss FADP stricter than GDPR for AI companies?
Neither law is universally stricter. The Swiss FADP can be stricter for individual accountability because certain willful violations can create personal criminal liability. GDPR is generally stricter on requirements for a lawful basis, data-breach notification, and restrictions on certain fully automated decisions. AI companies operating in both Switzerland and the EU should assess compliance with each law separately.
Related: AI Transformation Is a Governance Problem (Not Tech) — 2026 Truth
| Disclaimer: This article is for general information only and does not constitute legal advice. Swiss and EU AI and data-protection rules can change, and whether the FADP or GDPR applies depends on the specific circumstances of each business. Always verify the current requirements and seek qualified legal advice for compliance decisions. |
