The key points at a glance
- No special rules: data protection law is technology-neutral and applies directly to AI, according to the FDPIC.
- Transparency: state where and for what you use AI, and where the data comes from.
- Caution with personal data: customer data, health information or HR files don’t belong in public AI tools without a check first.
The FADP applies to AI too
The Federal Data Protection and Information Commissioner (FDPIC) clarified in 2023 and confirmed again in 2025: the Federal Act on Data Protection (FADP), in force since September 2023, applies directly to AI. For businesses, this mainly means:
- Inform: anyone processing personal data with AI must be transparent about the purpose, how it works and where the data comes from (Art. 19 FADP).
- Allow objection: data subjects can object to their data being processed.
- Automated decisions: if an AI decides something important on its own, such as granting credit or a job application, you must disclose this, and the person can request that a human review the decision (Art. 21 FADP).
- Assess risk: if an AI application poses a high risk to those affected, a data protection impact assessment is required beforehand (Art. 22 FADP).
Data abroad
Most well-known AI services run on servers in the USA. Personal data may be sent there if the destination country has an adequate level of protection or suitable safeguards are in place (Art. 16 FADP). Since 15 September 2024, the Swiss-U.S. Data Privacy Framework applies to the USA: data transfers to companies certified under it are permitted without additional contracts.
So check with every provider: are they certified? Is there a business version with a data processing agreement? Is your input used for training, and can this be switched off?
What doesn’t belong in an AI tool
| Data | Example | Public tool |
|---|---|---|
| General knowledge | Structuring a quote, shortening a text | ok |
| Anonymised data | Enquiries without names, addresses or numbers | ok |
| Customer data | Names, emails, contracts, invoices | business only |
| Especially sensitive | Health, religion, criminal matters, HR files | no |
| Trade secrets | Calculations, source code, strategy papers | business only |
The simplest rule for your team: if you wouldn’t write it on a postcard, it doesn’t belong in the free version of an AI tool.
The chatbot on your website
- Recognisable as AI: the bot identifies itself as AI. For visitors from the EU, this has been mandatory since August 2026; more on this under Labelling AI content.
- Data-sparing: don’t ask for data in the chat that you don’t need. Keep chat histories only as long as necessary.
- Load only after a click: many chat widgets load scripts from third-party servers as soon as the page opens. Better: the widget only starts once someone opens it.
- A human as a way out: always offer a direct route to your team.
Checklist
- Draw up a list of all AI tools used in the business, with purpose and provider.
- For each tool, clarify: server location, certification, training on your data, contract.
- A short internal policy: which data may go into which tool.
- Add a section on AI to your privacy policy: which services, for what purpose, in which countries.
- Label your website chatbot as AI and set it up to be data-sparing.
- Check your website itself with our free privacy check.
This article does not replace legal advice for your specific case.
Use AI, protect your data
We build chatbots and AI features that load in a data-sparing way, with hosting in Switzerland on request. Talk to us: book a free intro call.










