Tool · guide
AI and customer data: the Swiss rules
What you should not put into ChatGPT, Copilot or Gemini — under the revised Swiss data protection act, not the GDPR. And who a fine would actually hit.
No form, no email address. Pass it to everyone who uses AI tools at your company.
Why most guidance only half applies to you
Almost everything written in German about AI and data protection is GDPR material from Germany. But a company in Lachen, Pfäffikon or Rapperswil is governed first by the revised Swiss Data Protection Act, in force since 1 September 2023. It resembles the GDPR in its logic, but differs in exactly the places that worry people — above all on fines.
The key sentence up front: the Data Protection Act applies to AI directly. Switzerland has no separate AI statute, but the moment personal data flows into an AI tool, the ordinary law applies. That is also the position of the Federal Data Protection and Information Commissioner.
1 · It only covers data about natural persons
Unlike the old act, the revised law protects only the data of natural persons. Data about companies as such no longer falls under it. That sounds like a large relief for B2B businesses — but only up to a point: the buyer at your customer is a natural person. Their name, address and your CRM notes about them are personal data. The exemption is narrower than it sounds.
2 · Who a fine actually hits — and who it does not
This is the biggest misunderstanding. Switzerland has no GDPR-style corporate fines running into the millions.
- Fines are imposed on natural persons, not the company — up to CHF 250,000.
- Only intentional conduct is punishable. Negligence is not.
- Most offences require a criminal complaint — someone has to file one.
- The company can only be fined subsidiarily, up to CHF 50,000, and only where identifying the responsible individual would take disproportionate effort.
- The Commissioner cannot fine you. Prosecution sits with the cantons; the Commissioner can file a complaint.
Punishable conduct includes intentionally breaching the duties to inform and to give access, disclosing data abroad without a valid basis, handing data to a processor without meeting the statutory conditions, and disregarding an order of the Commissioner.
This is not an all-clear, it is a sense of proportion: the real risk for an SMB is rarely the fine. It is the reputational damage and the customer conflict when it comes out that customer data ended up somewhere it should not have.
3 · The AI vendor is a processor
When you put personal data into an AI tool, the vendor processes that data on your behalf. The law sets three conditions: the vendor may only process the data in ways you would be permitted to yourself; you must satisfy yourself that it can guarantee data security; and sub-processors require your prior approval.
The first condition is the interesting one. A vendor that uses your inputs to train its own models is processing for its own purpose — no longer purely on your behalf. That is exactly why the choice between a free account and a business account is not a question of comfort but the practical control.
Note that, unlike the GDPR, Swiss law prescribes no catalogue of mandatory clauses for a processing agreement. A written contract is still the usual — and the only evidenceable — route.
4 · Your data leaves the country
Practically every AI tool processes in the United States. For disclosure abroad, the Federal Council maintains a country list. The US has been on it since 15 September 2024 — but only for organisations certified under the Swiss–U.S. Data Privacy Framework. A US vendor without that certification does not benefit.
If the destination is not on the list and the vendor is not certified, you need your own basis — in practice the standard contractual clauses recognised by the Commissioner. Check this per vendor, not in the abstract.
5 · Say so in your privacy notice
You must inform people appropriately when you collect their data: who you are, what you process it for, and which recipients or categories of recipients receive it. If the data goes abroad, you must also name the country and the safeguard you rely on.
There is no dedicated AI clause in the act. The duty is derivative: the AI vendor is a recipient, and it sits abroad. The Commissioner goes further and expects transparency about purpose, functioning and data sources — and about whether inputs are reused to improve the model. That is the supervisory authority’s interpretation, not settled case law.
Free account or business account: the practical difference
The difference between a personal free account and a business account is nowhere defined in law — but in practice it decides whether you can treat the vendor as a processor at all. As of August 2026, per the vendors’ own documentation:
| Vendor | Business account / API | Personal free account |
|---|---|---|
| OpenAI (ChatGPT) | No training on your data unless you explicitly opt in. Processing agreement available. | Data from the consumer services is used for training. |
| Anthropic (Claude) | No training on inputs and outputs from the commercial products. | Only with your permission, on safety review, or if you opt in. |
| Microsoft 365 Copilot | Prompts and responses are not used to train the foundation models. | The consumer product is a different one — not verified here. |
| Google Gemini | For Workspace tiers, check Google’s current statements. | Selected conversations are reviewed by humans and kept up to three years. Google itself says: do not enter confidential information. |
These terms change. Verify them with the vendor before relying on them — and note down when you checked.
The rule of thumb for everyday use
If you would not email a sentence to an external service provider you have no contract with, it does not belong in an AI tool you have no contract with either. Not a legal definition, but it holds up remarkably well in practice.
What to actually do
- Decide which AI tools are permitted in your company at all — and write it down.
- Move those tools onto business accounts. That is the single biggest step.
- Check per vendor whether it is certified under the Swiss–U.S. Data Privacy Framework.
- Add the recipient categories and the disclosure abroad to your privacy notice.
- Tell your team what does not go in: health data, salary data, job applications, complete customer lists.
- Record who decided this and when — that is your diligence, documented.
Two things you probably do not have to do
A record of processing activities is generally not required for companies with fewer than 250 employees (as at 1 January). The exemption falls away if you process sensitive personal data on a large scale or carry out high-risk profiling. For a typical trade business: no obligation — for a practice handling health data it looks different.
A 72-hour breach deadline does not exist in Switzerland. You report “as quickly as possible”, and only where the breach is likely to result in a high risk to the person concerned. The threshold is higher than under the GDPR.
Frequently asked questions
Can we paste a customer email into ChatGPT to draft a reply?
With a business account that does not train on your data, a vendor you have checked, and a privacy notice that covers it: usually defensible. With a personal free account: no. Strip names and contact details where you can — what is not in there cannot leak.
We are purely B2B. Does this even concern us?
Yes. Company data is not protected, but the people at your corporate customers are. Contacts, email addresses and meeting notes are personal data.
What about the EU AI Act?
For a Swiss company using AI internally for Swiss customers it is usually not the issue. It becomes relevant if you provide AI systems yourself or your outputs land with users in the EU. The exact reach is genuinely disputed in borderline cases. Switzerland has no AI act in force; a draft implementing the Council of Europe convention is expected by the end of 2026.
Do we need a data protection impact assessment?
If the processing carries a high risk to the personality of the people concerned, yes. The Commissioner names this explicitly in the AI context. For using a writing tool in day-to-day office work that is usually not the case; for automated decisions about people it very much is.
Not legal advice
This guide is orientation from marketing practice, not legal advice. Status: August 2026. The Federal Council’s country list and the vendors’ terms change; the rules for health, HR and recruitment data are stricter than described here. If sensitive data is involved in your case, talk to a lawyer.
Sources
Swiss Data Protection Act (DSG, SR 235.1) · Data Protection Ordinance (DSV) incl. Annex 1 · Federal SME portal on the revDSG · FDPIC: the Data Protection Act applies to AI · Federal Council on the Swiss–U.S. Data Privacy Framework · FDPIC reporting portals
Let us talk for 20 minutes.
A short conversation first: I want to understand how you work, what you sell and to whom. Then I look inside your account and tell you what I see. No pitch, no sales pressure.
Rather look for yourself first? The free tools need no form.