If you serve customers in Switzerland and the EU, the short answer is: GDPR-compliant operations cover roughly 85 % of revFADP requirements out of the box — but the remaining 15 % decide whether you face criminal penalties or administrative ones. The Swiss revFADP, fully effective since 1 September 2023, deliberately stays close to GDPR but adds two teeth that don't exist in EU law: criminal liability for individuals (not just companies) and a stricter consent regime for profiling. For AI specifically, Switzerland diverges harder still, because there is no Swiss equivalent of the EU AI Act — yet — which creates both a regulatory gap and a competitive opportunity for Swiss-hosted AI services.
This guide compares the revFADP and GDPR for AI use cases head to head, lays out the five concrete differences that change how you build (data subject rights, consent, fines, profiling, DPO obligations), and gives you a decision matrix for the three common SME setups: Swiss-only, Swiss + EU, and EU primary with Swiss exposure. Sources: PwC's revFADP/GDPR comparison, Adnovum's seven-differences breakdown and DLA Piper's Swiss data-protection summary.
The headline answer for 5- to 500-employee SMEs
If your AI tooling is GDPR-compliant and EU-hosted, you are roughly 85 % covered for Switzerland — but you still need to address five revFADP-specific items: (1) criminal liability disclosures in employment contracts of senior decision-makers, (2) explicit consent for high-risk profiling (stricter than GDPR), (3) a Swiss representative if you have no Swiss subsidiary, (4) FDPIC-specific breach notification within 72 hours, and (5) updated DPA templates referencing Swiss law alongside the GDPR.
What does not exist in Switzerland yet: an EU-AI-Act equivalent. The Federal Council's consultation on a Swiss AI law is ongoing as of April 2026 — most observers expect a 2027–2028 effective date. Until then, your AI risk classification, training-data documentation, and bias-audit obligations under EU AI Act Articles 9–15 simply do not have a Swiss counterpart. That's the regulatory gap. It also means: if you sell AI services into Switzerland from Switzerland, you face fewer formal AI obligations than your EU competitors right now — a 12- to 24-month competitive window.
FADP vs GDPR: the side-by-side that matters for AI
The two regimes overlap on intent (protect personal data, give individuals control) and disagree on enforcement (criminal vs administrative penalties), profiling thresholds (Swiss is stricter), and AI specificity (EU has the AI Act layer, Switzerland doesn't yet). The table below covers the dimensions that actually shape your AI build.
| Dimension | EU GDPR | Switzerland revFADP | AI impact |
|---|---|---|---|
| Penalty regime | Administrative fines up to €20m or 4 % global turnover | Criminal fines up to CHF 250,000 against individuals | Senior decision-makers personally exposed in CH |
| Profiling consent | Consent for fully automated decisions only | Explicit consent for high-risk profiling, even if not fully automated | AI scoring tools need explicit CH consent flow |
| Sensitive data | Race, ethnicity, health, biometric identification, sexual orientation | Same + genetic data + biometric data explicitly listed | AI systems using biometrics need stricter Swiss safeguards |
| DPO requirement | Mandatory for public bodies + large-scale processing | Recommended, not mandatory | CH companies can run leaner; cross-border best practice still says appoint one |
| Breach notification | 72 hours to supervisory authority | "As soon as possible" to FDPIC (interpreted ~72h) | Same operational SLA, different routing |
| AI Act layer | EU AI Act Art. 9–15 applies (Aug 2026 high-risk) | No equivalent yet — consultation phase | 12–24 months CH competitive window for AI deployment |
| Adequacy | Switzerland holds GDPR adequacy decision (mutual) | EU recognised, US-DPF Swiss extension required for US transfers | CH ↔ EU AI data flows OK, US AI vendors need Swiss-DPF cover |
Map your AI systems to FADP and GDPR in one go
A 12-minute AI governance assessment shows which Swiss + EU obligations apply to each of your AI systems — and where the revFADP overlay actually changes what you need to build.
Switzerland's missing AI Act equivalent: gap or opportunity?
Switzerland has no in-force AI-specific law as of April 2026, and the Federal Council's consultation suggests a principle-based approach rather than the EU's risk-classification model. For SMEs that operate AI products from Switzerland, this is a real competitive advantage — for the next 12 to 24 months. After that, expect Swiss law to land somewhere between EU AI Act and Council of Europe AI Convention principles, with sector-specific overlays (finance, health, employment).
Practical implication: don't build to the missing Swiss AI law. Build to EU AI Act high-risk requirements as your baseline, even for Swiss-only operations. When the Swiss law lands, it will be GDPR-style adequate to or stricter than the EU benchmark — never weaker. The cost of over-compliance is a lost competitive window. The cost of under-compliance is rebuilding under regulatory pressure with shrinking timelines. Pick the cheaper mistake.
The criminal-liability detail nobody mentions in vendor pitches
Under revFADP Articles 60–61, individuals — not just companies — can face criminal fines up to CHF 250,000 for intentional or grossly negligent breaches. This is the single biggest structural difference from GDPR, where personal liability for executives is almost non-existent. Practical implications: your CISO, DPO and AI-system owner names are now on a list. Their employment contracts in CH need an explicit indemnification clause and a D&O policy that explicitly covers criminal-defence costs (most don't by default). If you're hiring for those roles in Switzerland in 2026, expect candidates to negotiate this — and rightly so.
Implementation: 5 differences that change your build
If your stack is GDPR-mature, these are the five concrete changes the revFADP forces you to make. None of them is expensive in isolation — together they're a half-day of legal work plus contract updates.
1. Add Swiss-law clauses to your existing DPAs
Your existing GDPR DPAs need a Swiss-law overlay clause: This DPA is interpreted in line with revFADP requirements where Swiss data subjects are processed; in case of conflict, the stricter regime applies.
One-page addendum, signed once with each vendor.
2. Appoint a Swiss representative if you have no CH establishment
If you process Swiss data subjects' data and have no Swiss subsidiary, you must appoint a representative in Switzerland under revFADP Art. 14. Service providers exist for CHF 200–600 per month. Same shape as the GDPR Art. 27 representative — different jurisdiction, separate appointment.
3. Tighten profiling consent flows for Swiss users
AI scoring, recommendation systems, and behavioural analytics that process Swiss users need explicit consent — not legitimate interest, not contract necessity — under revFADP. Add a Swiss-specific consent layer in the cookie banner / signup flow that triggers when you detect a Swiss IP or address. Most CMP tools (Usercentrics, OneTrust, Cookiebot) support this geo-routing natively.
4. Update employment contracts of senior data + AI roles
Roles with personal criminal exposure under revFADP (CISO, DPO, AI-system owner, Head of Data) need an indemnification clause + criminal-defence cost coverage in your D&O policy. Standard D&O often excludes criminal proceedings — confirm in writing with your insurer. Cost: CHF 0–2,000 in policy adjustments per role per year.
5. Set up a separate FDPIC breach-notification channel
Your existing GDPR breach SOP routes to the lead supervisory authority. Switzerland's FDPIC is a separate channel: incidents involving Swiss data subjects must be reported to the FDPIC "as soon as possible" (interpreted as 72 hours). Add a step to your incident response runbook: parallel notification, not sequential.
Decision matrix by company setup
Three setups cover ~95 % of SMEs we work with. The right play differs sharply between them — picking the wrong one means either over-spending on representatives and consents you don't legally need, or under-spending and carrying personal liability for senior people.
| Setup | Primary regime | What you must add | What you can skip |
|---|---|---|---|
Swiss-only (no EU customers) | revFADP | FDPIC reporting, criminal-liability D&O coverage, Swiss-law DPA templates | Mandatory DPO, 4 % global-turnover penalty modelling, EU-Rep |
Swiss + EU (most common SME) | Both — stricter wins | All five revFADP-specific items above + GDPR compliance, plus Swiss representative | Almost nothing — this is the most demanding setup |
EU primary, occasional CH exposure | GDPR with revFADP overlay | DPA Swiss addendum, geo-routed consent for CH IPs, FDPIC breach channel | Swiss representative if you process <CHF 250k turnover from CH (low-volume threshold) |
Quick AI readiness check — Swiss + EU specific
Find out which AI compliance obligations actually hit your business in 12 minutes. Includes Swiss-specific items most generic checks miss.
5 common mistakes companies make at the FADP/GDPR seam
From audit work and onboarding conversations across Swiss + EU SMEs in 2025/2026, the same five mistakes recur. Three of them get caught only in an audit — at which point fixing them is 10× the cost of avoiding them upfront.
— From audit work with Swiss + EU SMEs, 2025–2026The cost of treating revFADP as
GDPR-liteisn't the audit fine. It's the senior data-protection candidate who reads the criminal-liability clause and walks away from your offer.
5 rules for FADP + GDPR for AI
GDPR maturity gives you ~85 % of revFADP. The remaining 15 % is where audits hit — don't skip it.
Build to EU AI Act high-risk requirements, even in Switzerland-only operations. The Swiss law will land at or above EU level.
Personal criminal liability is real. Adjust senior contracts and D&O cover before you make offers in Switzerland.
Confirm Swiss-US DPF extension for any US AI vendor processing Swiss subjects' data. EU-only certification is not enough.
Use the 12–24 month Swiss AI-Act-gap as a deployment window — not as a permanent exemption.
AI Companies Compliance in Switzerland vs GDPR: What Changed in 2025 and 2026
Short answer: Switzerland still has no AI Act, and it will not copy the EU one. On 12 February 2025 the Federal Council chose a sector-by-sector approach: ratify the Council of Europe AI Convention, amend existing laws where needed (data protection first), and add non-binding measures elsewhere (Federal Council release). Switzerland signed the Convention in Strasbourg on 27 March 2025 (Council of Europe); the Federal Department of Justice and Police is drafting the implementing bill, covering transparency, data protection, non-discrimination and supervision, for public consultation by the end of 2026 (Federal Chancellery). Until that bill passes, which realistically means 2028 or later, the only binding cross-sector AI rule for a company in Switzerland is the revised Data Protection Act (FADP, SR 235.1).
For an AI company that serves Swiss and EU customers this creates an asymmetric calendar. In the EU, the AI Act transparency duties under Article 50 apply from 2 August 2026 and the Annex III high-risk obligations, after the Digital Omnibus, from 2 December 2027. In Switzerland nothing AI-specific is dated yet; the Council of Europe Convention itself binds the state, not your company, until Swiss law transposes it. The practical consequence: build your AI governance to the EU standard once, and the Swiss bill will almost certainly ask for a subset of it.
1 September 2023: revised FADP in force
No transition period. Technology-neutral, therefore directly applicable to AI processing of personal data.
9 November 2023: FDPIC statement
The Federal Data Protection and Information Commissioner confirms the FADP applies to manufacturers, providers and users of AI systems, reaffirmed on 8 May 2025.
12 February 2025: Federal Council decision
Ratify the Council of Europe AI Convention, regulate sector by sector, no Swiss copy of the EU AI Act.
27 March 2025: Switzerland signs the Convention
Signature in Strasbourg by Federal Councillor Albert Rösti. Ratification requires the implementing bill.
28 January 2026: FDPIC on generative AI
Data Protection Day statement: generative AI falls under the FADP as soon as personal data is processed; users must be able to recognise they are dealing with AI and how their prompts are used.
End of 2026: consultation draft of the Swiss AI bill
FDJP bill implementing the Convention: transparency, data protection, non-discrimination, supervision. Parliament afterwards; entry into force not before 2028.
What the Revised FADP Requires of AI Today: The FDPIC Position, Article by Article
The FDPIC has said the same thing three times, in November 2023, May 2025 and January 2026: the FADP is technology-neutral and applies to AI in full (FDPIC, AI and data protection). There is no AI carve-out and no AI-specific add-on. What that means in practice maps onto four articles, and every one of them has a GDPR twin that is stricter, looser or simply different.
| Duty | Swiss revFADP (FDPIC reading) | EU GDPR + AI Act | What an AI company does |
|---|---|---|---|
| Privacy by design and by default | Art. 7: build informational self-determination in from development onward | GDPR Art. 25, near-identical | One design review covers both |
| Transparency about AI | Art. 19: purpose, functioning and data sources of the AI must be disclosed; people must know they talk to a machine and whether prompts train the model | GDPR Art. 13/14 plus AI Act Art. 50 (from 2 Aug 2026): chatbot disclosure, labelling of generated content | Write the EU Art. 50 notice once; it satisfies the Swiss reading |
| Automated individual decisions | Art. 21: inform, and grant the right to be heard and to human review; only for decisions with legal effect or significant impact | GDPR Art. 22 starts from a prohibition with exceptions; AI Act adds Art. 86 right to explanation for high-risk systems (Dec 2027) | Design the human-review path to GDPR; Switzerland is the easier case |
| Data protection impact assessment | Art. 22: mandatory for high-risk AI processing; FDPIC consultation if the risk stays high | GDPR Art. 35/36; the AI Act adds a fundamental-rights impact assessment for some deployers | One DPIA template, two regulator names in the header |
| Prohibited uses | No list, but the FDPIC names real-time facial recognition and social scoring as incompatible with the FADP | AI Act Art. 5 list, in force since 2 Feb 2025, fines up to 7 % of turnover | Apply the EU list in both markets |
| Who is liable | Individuals: criminal fines up to CHF 250,000 (Art. 60 to 63) | Companies: administrative fines up to 4 % (GDPR) or 7 % (AI Act) of global turnover | Name a responsible person in Switzerland and document decisions |
Swiss-specific trap for generative AI: the FDPIC's January 2026 statement expects users to be told whether their prompts are used to improve the model. A consumer ChatGPT account used for customer data fails that test; an enterprise or API contract with training excluded, or a multi-LLM platform that fixes this per tenant, passes it. Check the contract clause before you check the model.
AI Service Compliance Requirements Under Swiss Data Protection Law and GDPR: The Four Operational Differences
If your AI service touches both Swiss and EU residents, which is the normal case for SaaS, recruiting platforms, HR tools and customer-support AI, four operational divergences decide the extra work.
1. Processing inventory. GDPR Art. 30 demands a record of processing activities from any controller offering AI services, regardless of size. The FADP exempts companies under 250 employees unless the processing is high-risk, and high-risk is where most AI lands. Keep the GDPR record; it satisfies both.
2. Cross-border transfers. Switzerland has held EU adequacy since 2000 (confirmed in the 2024 review), and the EU is on the Swiss adequacy list, so CH-EU flows need no extra instrument. Transfers to the US differ: the EU relies on the Data Privacy Framework, Switzerland on the Swiss-US DPF since 15 September 2024. A US model provider therefore needs to be certified under both frameworks, or you fall back to standard contractual clauses with the Swiss annex.
3. Representative. An EU company serving Swiss residents needs a representative in Switzerland only if it processes extensively, regularly and with high risk (Art. 14 FADP). A Swiss company serving EU residents needs an EU representative under GDPR Art. 27 far sooner. Many Swiss AI start-ups miss the second one.
4. Sanctions land on people, not companies. Under Art. 60 to 63 FADP the criminal fine of up to CHF 250,000 targets the individual who decided, typically the managing director or the person in charge of the AI product. Under GDPR and the AI Act the company pays. That single difference changes who signs off your DPIA in Switzerland: make it the person who would be fined.
Score your AI setup against FADP, GDPR and the AI Act
Free eight-minute AI governance assessment: data location, DPIA coverage, transparency notices, human-review path and audit trail, scored for both regimes. Teamo AI itself runs multi-LLM, EU-hosted, with per-row permissions and three independent audit logs, so the evidence the FDPIC or an EU authority asks for already exists.





![GDPR & EU AI Act: The Compliance Checklist for AI Team Assistants [2026]](https://www.teamazing.com/wp-content/uploads/2026/03/ai-governance-in-companies.jpg)
![Employee AI Trust: The Line Between Development and Surveillance [2026]](https://www.teamazing.com/wp-content/uploads/2026/04/employee-ai-trust-confidentiality.jpg)
