Blog

Swiss FADP vs EU GDPR for AI services

Usually both apply at once. The differences that change an AI architecture, and the transfer mistake that gets expensive.

Does the Swiss FADP apply to our AI service, or the GDPR? The question comes up in almost every first conversation, and the answer is usually the same: both. Since 2 August 2026 a third set of rules often applies too, and that one is not data protection law at all.

The two laws overlap heavily. Build for the GDPR and you cover most of the FADP along the way. The work sits where they diverge, and there are fewer such places than people expect.

What a FADP-compliant AI system looks like in detail is covered in revDSG-compliant AI architecture. This piece is about the comparison.

Which law applies to our AI service?

The two laws hook onto different things, which is why they do not exclude one another.

The FADP looks at effects. Under Art. 3 para. 1 it “applies to circumstances that have an effect in Switzerland, even if they were initiated abroad”. No seat required, no establishment, no intent.

The GDPR asks whether you have an establishment in the EU, or whether the service targets people there or monitors their behaviour.

Your AI serviceFADPGDPR
Swiss customers only, operated in Switzerlandyesno
Swiss company, EU customers as wellyesyes
EU company processing data of people in Switzerlandyesyes
Swiss company on EU infrastructure, Swiss customers onlyyesusually no

That last row surprises people. A server in Frankfurt does not turn a Swiss service into a GDPR case; what counts is who the offer is aimed at. Art. 16 FADP still governs that transfer, though, and we will get to it.

The difference the others follow from

The GDPR forbids any processing for which you cannot name one of the six legal bases in Art. 6. Ship an AI feature and you need to know which one applies before you do.

The FADP has no such catalogue for private controllers. Art. 6 FADP sets out principles instead: lawfulness, good faith, proportionality, purpose limitation, recognisability, accuracy. Processing turns unlawful by way of personality protection. Art. 30 FADP finds a breach of personality rights where data are processed contrary to the principles of Art. 6 and 8, contrary to the express wishes of the data subject, or where sensitive data go to third parties. And under Art. 31 such a breach is unlawful only if consent, an overriding interest or the law does not justify it.

In practice: under the GDPR every purpose carries a legal-basis field, filled before rollout. Swiss law has no such field. What you have to show there is that the purpose was specific and recognisable and the processing stayed proportionate.

That asymmetry is worth exploiting. Build for the GDPR and the Swiss side of this comes free. The other direction hurts: a system designed only against Swiss law never collected the legal bases, and retrofitting them is archaeology.

One exception is worth remembering. Art. 6 para. 7 FADP requires express consent in Switzerland too, for sensitive personal data and for high-risk profiling. An AI system that scores people lands there faster than the word suggests.

Six more differences

TopicSwiss FADPEU GDPRConsequence in the system
Automated individual decisionArt. 21: inform, human review on requestArt. 22: prohibited in principlereview path vs. clearance up front
Sensitive data categoriesArt. 5 lit. c, six categoriesArt. 9 and Art. 10 kept apartclassifications do not line up
Impact assessmentArt. 22, waived where certifiedArt. 35, no such waivercertification saves effort here only
ProcessorsArt. 9, no mandated contentArt. 28(3), minimum contentan EU-style contract covers both
Breach notificationArt. 24, “as soon as possible”Art. 33, 72 hoursone chain, paced to the EU deadline
Sanctionup to CHF 250,000 against the individualup to EUR 20m or 4 % against the firmchanges who signs off

Two of those rows deserve more than a cell. And one difference is missing from the table entirely, because it does not fit into a row: disclosure abroad.

Art. 21 FADP is not a copy of Art. 22 GDPR

Both provisions deal with decisions a machine takes on its own, but with opposite signs.

Art. 22 GDPR gives the data subject the right not to be subject to such a decision. In substance a prohibition: to decide automatically you need an exception first, whether contractual necessity, a legal basis or explicit consent.

Art. 21 FADP prohibits nothing. It requires you to inform the person where a decision is based exclusively on automated processing and carries a legal consequence or a considerable adverse effect. On request they can state their position and demand that a human review it.

Those are two different jobs. On the Swiss side you build a review path: a marker that this decision was automated, a channel for the request, and someone who genuinely reassesses. On the EU side you first establish whether you may decide automatically at all. The review path is the expensive half, because behind it sits a responsibility rather than a button.

The transfer mistake that costs up to CHF 250,000

This is where AI services come undone most often, since nearly all of them hand data to a US provider.

Art. 16 FADP permits disclosure abroad where the Federal Council has found the destination adequate. For the USA it has: on 14 August 2024 it recognised the Swiss-U.S. Data Privacy Framework and amended Annex 1 of the Data Protection Ordinance with effect from 15 September 2024. Since then personal data may go to US companies certified under that framework without further safeguards.

Everything hangs on that word. It is not the USA that is adequate, it is certified companies. And the Data Privacy Framework has three separate parts: the EU-U.S. DPF, the UK Extension and the Swiss-U.S. DPF. Companies certify for each one individually, so a provider on the EU list is not automatically on the Swiss one.

The check takes two minutes and belongs in procurement:

  1. Look the provider up at dataprivacyframework.gov, using the legal entity name from the contract rather than the brand.
  2. Check the status. “Inactive” means the certification lapsed, and adequacy went with it.
  3. Check that the Swiss-U.S. framework is listed. If it only says “EU-U.S.”, the Swiss data flow needs a route under Art. 16 para. 2 FADP, usually the standard contractual clauses recognised by the Commissioner.

Skip that and you are not risking proceedings against the company. Art. 61 lit. a FADP puts disclosure abroad in breach of Art. 16 under a fine of up to CHF 250,000, against the individual responsible.

Which is the second big difference from the GDPR. Art. 83 GDPR targets the undertaking, with up to EUR 20 million or four per cent of worldwide turnover. Art. 60 to 63 FADP target the natural person, several of them only on complaint. The company steps in only exceptionally, up to CHF 50,000, where identifying the individual would be disproportionate (Art. 64 para. 2 FADP). When the fine lands personally, someone wants that model swap signed and filed. Which is why a FADP-ready system keeps an approval record.

Which AI providers in Switzerland are subject to the GDPR

People ask for this as a list. No such list can exist, because the answer attaches to the offering rather than the provider. The test has three questions, and one yes is enough:

  1. An establishment in the EU, with the processing carried out in its context? Art. 3(1) GDPR.
  2. Is the offering aimed at people in the EU? Indicators: prices in euros, EU language versions, an EU domain, EU payment methods.
  3. Does the service monitor the behaviour of people in the EU? For AI products this matters most, because usage analytics and personalisation fall under it.

A Swiss provider serving only Swiss corporate customers is out of scope. The first contract under which data of employees in the EU gets processed changes that.

It runs the other way for you as a customer: a provider that does not meet the GDPR may still be fine under the FADP, and one advertising GDPR compliance has said nothing about the Swiss-U.S. DPF.

The EU AI Act, in force since 2 August 2026

The AI Act is product law, not data protection law, and it reaches Swiss companies through market access. It catches you if you place an AI system on the EU market, and equally if the system runs here but its output is used there.

The timetable shifted in 2026, though not everywhere. Regulation (EU) 2026/1744 governs, published on 24 July 2026 and in force since 27 July:

ObligationApplies from
Prohibited practices, AI literacy2 February 2025
General-purpose AI models2 August 2025
Transparency obligations under Art. 502 August 2026
Marking under Art. 50(2), existing systems2 December 2026
High-risk under Annex III2 December 2027
High-risk under Annex I2 August 2028

Only the high-risk categories moved. Art. 50 has applied since 2 August unchanged, and it hits exactly what many teams are building: anyone talking to a chatbot has to be able to tell, and synthetic content needs machine-readable marking. Read over the summer that the AI Act had been postponed and you kept the wrong half.

There is no Swiss AI act, by the way, and none is coming this year. On 12 February 2025 the Federal Council decided to adopt the Council of Europe’s AI Convention into Swiss law and to make the necessary changes sector by sector. A consultation draft is due by the end of 2026. Until then the FADP is the benchmark.

What follows for the architecture

Three decisions come out differently once you know the differences.

Where inference runs. As soon as a prompt contains personal data, handing it to the model is a disclosure abroad unless the model runs here. Art. 16 and Art. 61 FADP meet at that point. What sovereign inference costs and where it actually breaks is covered in Sovereign AI inference in Switzerland.

Jurisdiction as an operational value. Every outbound connection of an agent system needs a recorded jurisdiction, or you cannot say afterwards where the data went. At AIgent that is a start-up condition: an endpoint without a jurisdiction entry does not come up. Cheaper than any investigation after the fact.

The review path. It has to exist before the first automated decision, because you cannot retrofit it into a history.

The same framework applies to coding agents on a different contractual footing, see Using coding agents in line with data protection.

What we advise against

  • “We will just do GDPR, it is stricter.” True for the legal basis, false for transfers abroad. The Swiss-U.S. DPF is its own certification.
  • Believing a Swiss data centre settles it. It settles Art. 16 FADP and nothing else.
  • The consent reflex. Consent is one of three grounds of justification, and a withdrawal takes away the basis for processing already running.
  • Waiting for the Swiss AI act. The AI Act applies to EU market access now.

Frequently asked questions

What is the most important difference between the Swiss FADP and the GDPR?

The GDPR forbids processing without a legal basis under Art. 6. For private controllers the FADP has no such catalogue: processing is permissible as long as it observes the principles of Art. 6 FADP and is not an unlawful breach of personality rights under Art. 30 and 31. The second major difference is the sanction, which in Switzerland hits the acting individual.

Do the FADP and the GDPR apply at the same time?

Usually yes. The FADP covers anything that has an effect in Switzerland. The GDPR applies on top once there is an establishment in the EU or the offering targets people there.

May personal data from Switzerland go to OpenAI or another US provider?

Yes, where the company is certified under the Swiss-U.S. Data Privacy Framework. Certification under the EU-U.S. DPF is not enough; they are separate frameworks. Without it you need safeguards under Art. 16 para. 2 FADP, usually standard contractual clauses.

Do we need a data protection impact assessment for an AI system?

Under Art. 22 FADP, whenever the processing may entail a high risk to personality rights or fundamental rights, which the Act says arises particularly with new technologies from the nature, scope, circumstances and purpose. Large-scale processing of sensitive data is presumed high risk. Unlike the GDPR, Art. 22 para. 5 FADP waives the assessment where a system certified under Art. 13 is used or a code of conduct under Art. 11 is followed.

Does the EU AI Act apply to a Swiss company?

Once the system is placed on the EU market or its output is used there, yes. Art. 50 has applied since 2 August 2026. The high-risk obligations were deferred by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III and 2 August 2028 for Annex I. A purely domestic Swiss service is out of scope.


If you are deciding where your inference runs and what evidence you need for it: we build systems like this and review existing ones. Talk to us.

Sources: FADP (SR 235.1) · Data Protection Ordinance (SR 235.11) · Commissioner on the criminal provisions · Commissioner on the Swiss-U.S. Data Privacy Framework · Regulation (EU) 2026/1744 · OFCOM on Swiss AI regulation

A conversation, not a newsletter

Let's talk about your system

If this article describes something you recognise, a conversation is the shortest route to an answer.

Let's talk