Compliance7 min read

AI and Data Protection in Switzerland: the revised FADP (revFADP)

In Switzerland the revised FADP has governed data protection since 1 September 2023. For AI it means sharing fewer personal data, overseen by the FDPIC.

By Alexis de ONYRI
Worried about your data? Anonymize it before AI

In Switzerland, AI and data protection are governed by the revised Federal Act on Data Protection (revFADP). It has been in force since 1 September 2023. The FDPIC is the supervisory authority. When you paste text into an AI tool, you often process personal data. Then the revFADP applies — even if the AI provider sits abroad.

The revFADP has applied since 2023

The revFADP replaced the old law from 1992. It strengthens the rights of the people concerned. And it binds AI projects too, as soon as personal data is involved.

  • In force since 1 September 2023.
  • The FDPIC is the supervisory authority.
  • It covers private firms and federal bodies.
  • It protects the data of natural persons.
  • It moves closer to the GDPR but stays a separate law.

Your main duties

The law rests on clear principles. You must process data fairly and proportionately. And you need a purpose that is fixed from the start.

  • Respect good faith, proportionality and purpose limitation.
  • Inform the people concerned in a transparent way.
  • Ensure adequate data security.
  • Keep a record of processing activities.
  • Run a data protection impact assessment for high risk.

revFADP and GDPR together

Many Swiss firms serve customers in the EU. Then the GDPR can also apply. The European regulation reaches across the border.

  • The revFADP applies to processing linked to Switzerland.
  • The GDPR can reach Swiss firms with EU data subjects.
  • Both demand data minimisation and security.
  • Both require an impact assessment for high risk.
  • When in doubt, check both frameworks.

Put the sanctions in context

Here the two laws differ clearly. The revFADP has no large corporate fines like the GDPR. Instead, the penalty targets responsible individuals.

  • According to the FADP, fines can reach CHF 250,000.
  • They target responsible natural persons.
  • The GDPR provides fines against companies.
  • These can reach EUR 20 million or 4% of turnover.
  • So data protection is a matter for management too.

Cut the AI risk in practice

The best protection is simple: share less. Give the AI only what the task truly needs. That keeps your exposure small. According to OpenAI, the company does not train on the business data of its API and enterprise customers — but check the current documentation.

  1. 1Ask whether real personal data is needed.
  2. 2Remove or replace names, numbers and addresses.
  3. 3Use pseudonyms instead of plain text.
  4. 4Sign a data processing agreement with the AI provider.
  5. 5Document the purpose and legal basis.
AspectrevFADP (Switzerland)GDPR (EU)
Entry into force1 September 202325 May 2018
Supervisory authorityFDPICnational authorities / EDPB
Sanctionsfines up to CHF 250,000 against responsible persons (per the FADP)fines up to EUR 20m or 4% of turnover against companies
Impact assessmentfor high riskfor high risk (Art. 35)
Breach notificationto the FDPICto the authority (72h)
Reachprocessing linked to Switzerlandcan also reach Swiss firms with EU data subjects

Tools help you reduce the amount of data. ONYRI Sanitize detects sensitive data in your text and replaces it with reversible tokens. The mapping table stays in the browser and is never sent to the server. After the AI replies, the real values are restored. To be honest: this is pseudonymisation, not anonymisation. Pseudonymised data stays personal data (GDPR recital 26). A tool replaces neither a data processing agreement (DPA) nor a legal basis. It lowers exposure, it does not remove it.

Bottom line: the revFADP puts Swiss firms under duty when they use AI. Share fewer personal data and you lower your risk. Data minimisation is the easiest first step.

Frequently asked questions

Since when does the revFADP apply in Switzerland?
The revised Federal Act on Data Protection has been in force since 1 September 2023. It replaced the old law from 1992 and strengthens the rights of the people concerned. The FDPIC is the supervisory authority.
Does the GDPR also apply to Swiss firms?
It can. If you process data of people in the EU, the GDPR may apply on top of the revFADP. The European regulation reaches across the border. When in doubt, check both frameworks.
How high are the sanctions under the revFADP?
According to the FADP, fines can reach CHF 250,000. They target responsible natural persons, not the company as under the GDPR. So data protection is a matter for management too.
Does an anonymisation tool make my AI use FADP-compliant?
No. A tool like ONYRI lowers exposure, but it replaces neither a legal basis nor a DPA. Pseudonymised data stays personal data. It is one building block of data minimisation, not a guarantee.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next