All articles
Data protection

The revised FADP and AI: working data-protection-compliant with AI tools

The revFADP does not ban AI, it demands control and evidence. Legal basis, data processing agreements, transfers abroad, and handling shadow AI in the team.

The revised Swiss Federal Act on Data Protection (revFADP) does not ban AI. It requires you to keep control over personal data and to be able to evidence, at any time, what happens to it. This applies to any AI that processes such data.

In short: legal basis, purpose limitation, a data processing agreement, and a verifiable record. Meet these four points and you can use AI compliantly.

What does the revFADP require for AI use?

The revFADP has been in force since 1 September 2023 and follows the same principles as the GDPR. For AI, three core requirements arise: a legal basis and clear purpose for every processing, controllable disclosure to third parties and abroad, and traceable documentation of which data flowed into which system. The statute is documented on Fedlex, and the requirements are explained by the FDPIC.

Do I need a data processing agreement?

Usually yes. As soon as an external service processes personal data on your behalf, you need a data processing agreement covering purpose, data categories, measures, and sub-processors. The more clearly a platform documents where data resides and who accesses it, the easier this evidence is to provide. If the data resides in your own data center, the question of a transfer abroad does not arise in the first place.

Transferring data abroad

A transfer abroad is only permitted if an adequate level of data protection exists. This is exactly where many cloud AI offerings fail, because the data is in practice exposed to the reach of a foreign jurisdiction. Processing in Switzerland or on-premise solves the problem at the root. More on our page on GDPR-compliant AI.

Stopping shadow AI in the team

When no approved solution is available, staff use private AI tools and upload personal data into third-party systems. This shadow AI is a bigger risk than controlled use. The most effective countermeasure is not a ban, but an approved, sovereign alternative plus a clear internal policy defining which data may reach which system.

Template: We provide an AI policy for your company as a downloadable template.

Common questions

Is private ChatGPT use at work a problem?

If personal data or trade secrets are entered, yes. Without a contract and control, the legal basis and the evidence are missing.

Is a server location in Switzerland enough?

Not on its own. What also matters is which law the operator answers to and whether your data is used for training.

How do I evidence traceability?

With an audit trail that logs every processing step with model, time, and cost. AIgent has this built in.