AI Is Not a Legal Void in Switzerland: What the nFADP Really Says
No, AI does not escape Swiss law. Here is what the nFADP actually says, and what it changes for your business today.
Many business owners assume that in Switzerland, using AI at work falls outside any specific regulation. That assumption is wrong, and it matters to know this before a problem comes up, not after.
The nFADP (new Federal Act on Data Protection) came into force on September 1, 2023. It never mentions the words "artificial intelligence." It does not need to: the law is technology neutral, meaning it applies to any processing of personal data regardless of the tool used to do it. The Federal Data Protection and Information Commissioner (FDPIC) has confirmed this explicitly: the moment an AI tool processes personal data, the nFADP applies in full.
The day an employee pastes a client email into ChatGPT, the company is already within the scope of the law.
Personal data is not just a social security number or a medical file. It is a name in an email, a customer number, an address, a support conversation, an HR comment. In practice, the moment an employee pastes a client email into ChatGPT to draft a reply, the company is already within the scope of the law.
The good news is that the nFADP does not ban the use of AI. It requires accountability. A small or medium business can use ChatGPT, Claude, or an internal tool, as long as it knows what data it is sharing, with whom, and where it is hosted. The question is never "is AI allowed," it is "which data, for which purpose, on which tool."
Concretely, this comes down to three things:
- First, your privacy policy needs to clearly state whether you use AI to process customer data, not a generic text copied five years ago.
- Second, you need to know, in writing, which AI tools are used across your company, for what, and where the data ends up, which already assumes you know what your teams actually use, not just what you officially approved.
- Third, if AI makes decisions that directly affect a person (screening applications, scoring customers), a formal risk assessment becomes mandatory.
Few business owners have the time to check these three points on their own, let alone know which one applies to their specific situation. This is exactly the kind of grey area that gets expensive once discovered too late.
The real risk for a small business is not AI itself. It is using it without knowing what it sends out, where that data ends up, and without being able to give a simple answer if a client asks the question one day.
Not sure where your business stands on these three points? We can walk through it together in a few minutes, no strings attached: reach out at bonjour@atelier-aa.ai.
Frequently asked
Automation, websites, and strategy: you do all three?
Yes. One studio to scope, build, and wire AI in. We start where it pays off most and keep it coherent from end to end.
Where do we start if we've never touched AI?
With a one-hour review. We identify two or three repetitive, high-volume tasks, estimate the time saved, and deploy the first automation before going further.
We already have a site and a CRM. Do you plug into those?
Yes. We work with the tools you already have rather than replacing them. The AI plugs into what's there: email, quotes, follow-ups, document extraction.