If you serve customers in Switzerland and the EU, the short answer is: GDPR-compliant operations cover roughly 85 % of revFADP requirements out of the box — but the remaining 15 % decide whether you face criminal penalties or administrative ones. The Swiss revFADP, fully effective since 1 September 2023, deliberately stays close to GDPR but adds two teeth that don't exist in EU law: criminal liability for individuals (not just companies) and a stricter consent regime for profiling. For AI specifically, Switzerland diverges harder still, because there is no Swiss equivalent of the EU AI Act — yet — which creates both a regulatory gap and a competitive opportunity for Swiss-hosted AI services.

This guide compares the revFADP and GDPR for AI use cases head to head, lays out the five concrete differences that change how you build (data subject rights, consent, fines, profiling, DPO obligations), and gives you a decision matrix for the three common SME setups: Swiss-only, Swiss + EU, and EU primary with Swiss exposure. Sources: PwC's revFADP/GDPR comparison, Adnovum's seven-differences breakdown and DLA Piper's Swiss data-protection summary.

85 %of GDPR controls translate directly to revFADP requirements
CHF 250kmax criminal fine for individuals under revFADP (vs €0 personal liability under GDPR)
0Swiss equivalent of EU AI Act in force as of April 2026
Sep 2023revFADP fully effective — no grace period remaining

The headline answer for 5- to 500-employee SMEs

If your AI tooling is GDPR-compliant and EU-hosted, you are roughly 85 % covered for Switzerland — but you still need to address five revFADP-specific items: (1) criminal liability disclosures in employment contracts of senior decision-makers, (2) explicit consent for high-risk profiling (stricter than GDPR), (3) a Swiss representative if you have no Swiss subsidiary, (4) FDPIC-specific breach notification within 72 hours, and (5) updated DPA templates referencing Swiss law alongside the GDPR.

What does not exist in Switzerland yet: an EU-AI-Act equivalent. The Federal Council's consultation on a Swiss AI law is ongoing as of April 2026 — most observers expect a 2027–2028 effective date. Until then, your AI risk classification, training-data documentation, and bias-audit obligations under EU AI Act Articles 9–15 simply do not have a Swiss counterpart. That's the regulatory gap. It also means: if you sell AI services into Switzerland from Switzerland, you face fewer formal AI obligations than your EU competitors right now — a 12- to 24-month competitive window.

FADP vs GDPR: the side-by-side that matters for AI

The two regimes overlap on intent (protect personal data, give individuals control) and disagree on enforcement (criminal vs administrative penalties), profiling thresholds (Swiss is stricter), and AI specificity (EU has the AI Act layer, Switzerland doesn't yet). The table below covers the dimensions that actually shape your AI build.

DimensionEU GDPRSwitzerland revFADPAI impact
Penalty regimeAdministrative fines up to €20m or 4 % global turnover

Criminal fines up to CHF 250,000 against individuals

Senior decision-makers personally exposed in CH
Profiling consentConsent for fully automated decisions only

Explicit consent for high-risk profiling, even if not fully automated

AI scoring tools need explicit CH consent flow
Sensitive dataRace, ethnicity, health, biometric identification, sexual orientation

Same + genetic data + biometric data explicitly listed

AI systems using biometrics need stricter Swiss safeguards
DPO requirementMandatory for public bodies + large-scale processingRecommended, not mandatoryCH companies can run leaner; cross-border best practice still says appoint one
Breach notification72 hours to supervisory authority"As soon as possible" to FDPIC (interpreted ~72h)Same operational SLA, different routing
AI Act layerEU AI Act Art. 9–15 applies (Aug 2026 high-risk)

No equivalent yet — consultation phase

12–24 months CH competitive window for AI deployment
AdequacySwitzerland holds GDPR adequacy decision (mutual)EU recognised, US-DPF Swiss extension required for US transfersCH ↔ EU AI data flows OK, US AI vendors need Swiss-DPF cover

Map your AI systems to FADP and GDPR in one go

A 12-minute AI governance assessment shows which Swiss + EU obligations apply to each of your AI systems — and where the revFADP overlay actually changes what you need to build.

Try It Free

Switzerland's missing AI Act equivalent: gap or opportunity?

Switzerland has no in-force AI-specific law as of April 2026, and the Federal Council's consultation suggests a principle-based approach rather than the EU's risk-classification model. For SMEs that operate AI products from Switzerland, this is a real competitive advantage — for the next 12 to 24 months. After that, expect Swiss law to land somewhere between EU AI Act and Council of Europe AI Convention principles, with sector-specific overlays (finance, health, employment).

Practical implication: don't build to the missing Swiss AI law. Build to EU AI Act high-risk requirements as your baseline, even for Swiss-only operations. When the Swiss law lands, it will be GDPR-style adequate to or stricter than the EU benchmark — never weaker. The cost of over-compliance is a lost competitive window. The cost of under-compliance is rebuilding under regulatory pressure with shrinking timelines. Pick the cheaper mistake.

The criminal-liability detail nobody mentions in vendor pitches

Under revFADP Articles 60–61, individuals — not just companies — can face criminal fines up to CHF 250,000 for intentional or grossly negligent breaches. This is the single biggest structural difference from GDPR, where personal liability for executives is almost non-existent. Practical implications: your CISO, DPO and AI-system owner names are now on a list. Their employment contracts in CH need an explicit indemnification clause and a D&O policy that explicitly covers criminal-defence costs (most don't by default). If you're hiring for those roles in Switzerland in 2026, expect candidates to negotiate this — and rightly so.

Implementation: 5 differences that change your build

If your stack is GDPR-mature, these are the five concrete changes the revFADP forces you to make. None of them is expensive in isolation — together they're a half-day of legal work plus contract updates.

1

1. Add Swiss-law clauses to your existing DPAs

Your existing GDPR DPAs need a Swiss-law overlay clause: This DPA is interpreted in line with revFADP requirements where Swiss data subjects are processed; in case of conflict, the stricter regime applies. One-page addendum, signed once with each vendor.

2

2. Appoint a Swiss representative if you have no CH establishment

If you process Swiss data subjects' data and have no Swiss subsidiary, you must appoint a representative in Switzerland under revFADP Art. 14. Service providers exist for CHF 200–600 per month. Same shape as the GDPR Art. 27 representative — different jurisdiction, separate appointment.

3

3. Tighten profiling consent flows for Swiss users

AI scoring, recommendation systems, and behavioural analytics that process Swiss users need explicit consent — not legitimate interest, not contract necessity — under revFADP. Add a Swiss-specific consent layer in the cookie banner / signup flow that triggers when you detect a Swiss IP or address. Most CMP tools (Usercentrics, OneTrust, Cookiebot) support this geo-routing natively.

4

4. Update employment contracts of senior data + AI roles

Roles with personal criminal exposure under revFADP (CISO, DPO, AI-system owner, Head of Data) need an indemnification clause + criminal-defence cost coverage in your D&O policy. Standard D&O often excludes criminal proceedings — confirm in writing with your insurer. Cost: CHF 0–2,000 in policy adjustments per role per year.

5

5. Set up a separate FDPIC breach-notification channel

Your existing GDPR breach SOP routes to the lead supervisory authority. Switzerland's FDPIC is a separate channel: incidents involving Swiss data subjects must be reported to the FDPIC "as soon as possible" (interpreted as 72 hours). Add a step to your incident response runbook: parallel notification, not sequential.

Decision matrix by company setup

Three setups cover ~95 % of SMEs we work with. The right play differs sharply between them — picking the wrong one means either over-spending on representatives and consents you don't legally need, or under-spending and carrying personal liability for senior people.

SetupPrimary regimeWhat you must addWhat you can skip

Swiss-only (no EU customers)

revFADPFDPIC reporting, criminal-liability D&O coverage, Swiss-law DPA templatesMandatory DPO, 4 % global-turnover penalty modelling, EU-Rep

Swiss + EU (most common SME)

Both — stricter winsAll five revFADP-specific items above + GDPR compliance, plus Swiss representativeAlmost nothing — this is the most demanding setup

EU primary, occasional CH exposure

GDPR with revFADP overlayDPA Swiss addendum, geo-routed consent for CH IPs, FDPIC breach channelSwiss representative if you process <CHF 250k turnover from CH (low-volume threshold)

Quick AI readiness check — Swiss + EU specific

Find out which AI compliance obligations actually hit your business in 12 minutes. Includes Swiss-specific items most generic checks miss.

Try It Free

5 common mistakes companies make at the FADP/GDPR seam

From audit work and onboarding conversations across Swiss + EU SMEs in 2025/2026, the same five mistakes recur. Three of them get caught only in an audit — at which point fixing them is 10× the cost of avoiding them upfront.

The cost of treating revFADP as GDPR-lite isn't the audit fine. It's the senior data-protection candidate who reads the criminal-liability clause and walks away from your offer.

— From audit work with Swiss + EU SMEs, 2025–2026

5 rules for FADP + GDPR for AI

GDPR maturity gives you ~85 % of revFADP. The remaining 15 % is where audits hit — don't skip it.

Build to EU AI Act high-risk requirements, even in Switzerland-only operations. The Swiss law will land at or above EU level.

Personal criminal liability is real. Adjust senior contracts and D&O cover before you make offers in Switzerland.

Confirm Swiss-US DPF extension for any US AI vendor processing Swiss subjects' data. EU-only certification is not enough.

Use the 12–24 month Swiss AI-Act-gap as a deployment window — not as a permanent exemption.

AI Companies Compliance in Switzerland vs GDPR: What Changed in 2025 and 2026

Short answer: Switzerland still has no AI Act, and it will not copy the EU one. On 12 February 2025 the Federal Council chose a sector-by-sector approach: ratify the Council of Europe AI Convention, amend existing laws where needed (data protection first), and add non-binding measures elsewhere (Federal Council release). Switzerland signed the Convention in Strasbourg on 27 March 2025 (Council of Europe); the Federal Department of Justice and Police is drafting the implementing bill, covering transparency, data protection, non-discrimination and supervision, for public consultation by the end of 2026 (Federal Chancellery). Until that bill passes, which realistically means 2028 or later, the only binding cross-sector AI rule for a company in Switzerland is the revised Data Protection Act (FADP, SR 235.1).

For an AI company that serves Swiss and EU customers this creates an asymmetric calendar. In the EU, the AI Act transparency duties under Article 50 apply from 2 August 2026 and the Annex III high-risk obligations, after the Digital Omnibus, from 2 December 2027. In Switzerland nothing AI-specific is dated yet; the Council of Europe Convention itself binds the state, not your company, until Swiss law transposes it. The practical consequence: build your AI governance to the EU standard once, and the Swiss bill will almost certainly ask for a subset of it.

1

1 September 2023: revised FADP in force

No transition period. Technology-neutral, therefore directly applicable to AI processing of personal data.

2

9 November 2023: FDPIC statement

The Federal Data Protection and Information Commissioner confirms the FADP applies to manufacturers, providers and users of AI systems, reaffirmed on 8 May 2025.

3

12 February 2025: Federal Council decision

Ratify the Council of Europe AI Convention, regulate sector by sector, no Swiss copy of the EU AI Act.

4

27 March 2025: Switzerland signs the Convention

Signature in Strasbourg by Federal Councillor Albert Rösti. Ratification requires the implementing bill.

5

28 January 2026: FDPIC on generative AI

Data Protection Day statement: generative AI falls under the FADP as soon as personal data is processed; users must be able to recognise they are dealing with AI and how their prompts are used.

6

End of 2026: consultation draft of the Swiss AI bill

FDJP bill implementing the Convention: transparency, data protection, non-discrimination, supervision. Parliament afterwards; entry into force not before 2028.

What the Revised FADP Requires of AI Today: The FDPIC Position, Article by Article

The FDPIC has said the same thing three times, in November 2023, May 2025 and January 2026: the FADP is technology-neutral and applies to AI in full (FDPIC, AI and data protection). There is no AI carve-out and no AI-specific add-on. What that means in practice maps onto four articles, and every one of them has a GDPR twin that is stricter, looser or simply different.

DutySwiss revFADP (FDPIC reading)EU GDPR + AI ActWhat an AI company does
Privacy by design and by defaultArt. 7: build informational self-determination in from development onwardGDPR Art. 25, near-identicalOne design review covers both
Transparency about AIArt. 19: purpose, functioning and data sources of the AI must be disclosed; people must know they talk to a machine and whether prompts train the modelGDPR Art. 13/14 plus AI Act Art. 50 (from 2 Aug 2026): chatbot disclosure, labelling of generated contentWrite the EU Art. 50 notice once; it satisfies the Swiss reading
Automated individual decisionsArt. 21: inform, and grant the right to be heard and to human review; only for decisions with legal effect or significant impactGDPR Art. 22 starts from a prohibition with exceptions; AI Act adds Art. 86 right to explanation for high-risk systems (Dec 2027)Design the human-review path to GDPR; Switzerland is the easier case
Data protection impact assessmentArt. 22: mandatory for high-risk AI processing; FDPIC consultation if the risk stays highGDPR Art. 35/36; the AI Act adds a fundamental-rights impact assessment for some deployersOne DPIA template, two regulator names in the header
Prohibited usesNo list, but the FDPIC names real-time facial recognition and social scoring as incompatible with the FADPAI Act Art. 5 list, in force since 2 Feb 2025, fines up to 7 % of turnoverApply the EU list in both markets
Who is liableIndividuals: criminal fines up to CHF 250,000 (Art. 60 to 63)Companies: administrative fines up to 4 % (GDPR) or 7 % (AI Act) of global turnoverName a responsible person in Switzerland and document decisions

Swiss-specific trap for generative AI: the FDPIC's January 2026 statement expects users to be told whether their prompts are used to improve the model. A consumer ChatGPT account used for customer data fails that test; an enterprise or API contract with training excluded, or a multi-LLM platform that fixes this per tenant, passes it. Check the contract clause before you check the model.

AI Service Compliance Requirements Under Swiss Data Protection Law and GDPR: The Four Operational Differences

If your AI service touches both Swiss and EU residents, which is the normal case for SaaS, recruiting platforms, HR tools and customer-support AI, four operational divergences decide the extra work.

1. Processing inventory. GDPR Art. 30 demands a record of processing activities from any controller offering AI services, regardless of size. The FADP exempts companies under 250 employees unless the processing is high-risk, and high-risk is where most AI lands. Keep the GDPR record; it satisfies both.

2. Cross-border transfers. Switzerland has held EU adequacy since 2000 (confirmed in the 2024 review), and the EU is on the Swiss adequacy list, so CH-EU flows need no extra instrument. Transfers to the US differ: the EU relies on the Data Privacy Framework, Switzerland on the Swiss-US DPF since 15 September 2024. A US model provider therefore needs to be certified under both frameworks, or you fall back to standard contractual clauses with the Swiss annex.

3. Representative. An EU company serving Swiss residents needs a representative in Switzerland only if it processes extensively, regularly and with high risk (Art. 14 FADP). A Swiss company serving EU residents needs an EU representative under GDPR Art. 27 far sooner. Many Swiss AI start-ups miss the second one.

4. Sanctions land on people, not companies. Under Art. 60 to 63 FADP the criminal fine of up to CHF 250,000 targets the individual who decided, typically the managing director or the person in charge of the AI product. Under GDPR and the AI Act the company pays. That single difference changes who signs off your DPIA in Switzerland: make it the person who would be fined.

Score your AI setup against FADP, GDPR and the AI Act

Free eight-minute AI governance assessment: data location, DPIA coverage, transparency notices, human-review path and audit trail, scored for both regimes. Teamo AI itself runs multi-LLM, EU-hosted, with per-row permissions and three independent audit logs, so the evidence the FDPIC or an EU authority asks for already exists.

Start the free assessment