Skip to content

Switzerland's Federal Data Protection Act and AI

9 min read · updated August 11, 2026

Switzerland has no AI act and, at the time of writing, no draft of one in Parliament. What it has is a revised data protection statute with two provisions that catch most AI deployments squarely, and a criminal liability model that surprises people who arrive from the GDPR.

Switzerland’s position

The revised Federal Act on Data Protection (SR 235.1) entered into force on 1 September 2023, together with its ordinance, replacing the 1992 Act. The official multilingual text is published on Fedlex, the Swiss federal law portal. It was drafted to keep Switzerland’s adequacy position with the EU, so much of it will read as familiar; the differences are in the details, and the details are where AI work lands.

On AI specifically, the Federal Council decided in February 2025 on an approach: ratify the Council of Europe Framework Convention on artificial intelligence, human rights, democracy and the rule of law, and implement it through targeted, sector-specific amendments rather than a comprehensive Swiss AI act, with a consultation draft to follow. That is a stated direction with a timetable measured in years, not an instrument in force, and it should not be described as Swiss AI regulation.

Nothing here is legal advice, and the Swiss AI legislative position is under active development. Confirm the current state of the Framework Convention implementation and of any sectoral amendment with Swiss advice before relying on the absence of an AI statute.

Scope matters before anything else. Article 3 applies the FADP to circumstances that have an effect in Switzerland, even if initiated abroad, and Article 14 requires a controller with no Swiss establishment to designate a representative in Switzerland in defined circumstances involving regular, large-scale processing of Swiss data subjects’ data with a high risk. A foreign AI service with Swiss users is inside the Act, in the same way that the AI Act reaches beyond the Union.

Article 21: automated individual decisions

Article 21 is the provision an automated decision system hits first, and it is built differently from GDPR Article 22. Where the European provision starts from a prohibition subject to exceptions, the Swiss provision starts from a duty to inform.

  • Paragraph 1 requires the controller to inform the data subject about a decision taken exclusively on the basis of automated processing that has a legal consequence for them or significantly affects them.
  • Paragraph 2 gives the data subject, on request, the right to have the decision reviewed by a natural person. The human reviewer is explicit in the Swiss text—a point of difference from Brazil’s Article 20, where the equivalent words were removed before the statute took effect.
  • Paragraph 3 disapplies the duties in defined circumstances, including where the decision is directly connected with the conclusion or performance of a contract and the data subject’s request is granted, and where the data subject has expressly consented to the decision being taken automatically.

The practical consequence is that Switzerland permits fully automated decisions more readily than the GDPR does, and pays for it with a notification duty and a review right that are hard to satisfy retrospectively. Note the shape of the contract exception: it is available where the request is granted. An automated approval is treated differently from an automated refusal, which is a sensible distinction and one the European exemptions do not draw in the same way—compare the Article 22 exemptions.

Article 25, the right of access, adds a related duty: where an automated individual decision within Article 21 has been taken, the information the data subject is entitled to includes information about the logic on which the decision is based. That is the Swiss version of the explanation question, and it has the same unresolved edge as everywhere else— what “the logic” means for a system whose behaviour is not reducible to a stated rule is not settled by the text.

Article 22: impact assessment

Article 22 requires a data protection impact assessment where processing is likely to result in a high risk to the personality or fundamental rights of the data subject, and states that a high risk arises in particular from the use of new technologies, having regard to the nature, scope, circumstances and purpose of the processing. Paragraph 2 identifies extensive processing of sensitive personal data and systematic large-scale monitoring of public areas as high risk in particular.

“New technologies” named in the article itself is the hook that makes an AI deployment a default candidate for assessment rather than an argued one. Article 23 then requires consultation with the Federal Data Protection and Information Commissioner where the assessment shows a high residual risk despite the measures planned, with a carve-out where the controller has consulted its own data protection adviser. The structure should be recognisable from the DPIA triggers for AI under the GDPR, and an assessment written for one can generally be adapted rather than rewritten.

Where the processing happens

Cross-border disclosure is governed by Articles 16 and 17: personal data may be disclosed abroad where the Federal Council has determined the destination state provides adequate protection, and otherwise only where appropriate safeguards apply—standard contractual clauses recognised by the FDPIC, binding corporate rules, or one of the enumerated exceptions.

For an AI deployment this is a question about infrastructure rather than about paperwork. Model inference happens wherever the provider serves it, and providers routinely serve from several regions. The compliance record has to be able to say which country a given request was processed in, and under which safeguard, and that is an answer most systems cannot give after the fact.

The penalty falls on a person

This is the Swiss feature that most often surprises, and it changes how the statute is treated internally. The FADP’s sanctions are criminal fines imposed by the cantonal criminal authorities on natural persons for specified breaches—including breaches of the duty to inform, of the duties around cross-border disclosure, and of the duty to provide information on request—up to CHF 250,000. Companies can be fined only in a limited way, and only where identifying the responsible individual would require disproportionate investigative effort, at a much lower ceiling.

There is no GDPR-style administrative fine on turnover here, and the headline number is small next to European penalties. The exposure is nonetheless of a different kind: a named individual within the organisation, prosecuted, rather than a corporate line item. In practice this makes internal allocation of responsibility a materially more serious exercise in Switzerland than the size of the maximum fine suggests, and it is the reason Swiss organisations tend to document who holds each data protection duty with more care than the same organisation does elsewhere.