The revised Swiss Data Protection Act has applied since 1 September 2023 and is drafted in technology-neutral terms. It therefore covers AI-assisted data processing directly, without Switzerland needing a dedicated AI statute. For legal teams the question shifts away from the legal position and towards procurement: which tool meets the requirements, and how can that be verified?
The Federal Data Protection and Information Commissioner (FDPIC) confirmed this direct applicability in updated guidance dated 8 May 2025.
What the DSG requires of AI applications
Four obligations apply to any organisation running AI over personal data. All four are in the statute, and all four can be tested against a specific tool.
Access rights and automated individual decisions
Art. 25 revDSG governs the right of access, and para. 2 lit. f contains the provision most directly relevant to AI: the data subject is entitled to know whether an automated individual decision has been taken, and the logic on which it is based. Anyone deploying a tool that decides without a human in the loop has to be able to explain that logic.
In legal practice this usually resolves itself, because contract review and research produce proposals while the decision stays with the lawyer. That division of labour is exactly what needs documenting, otherwise the distinction cannot be evidenced in a dispute.
Data protection by design and by default
Art. 7 revDSG requires processing to be arranged technically and organisationally so that data protection rules are observed, and to do so from the planning stage onward. Para. 3 additionally requires default settings that limit processing to the minimum necessary for the purpose.
For bought-in tools that means the assessment belongs before procurement, not before rollout. Introducing a tool first and assessing it afterwards inverts the order the statute sets out.
Impact assessment where new technologies are used
Art. 22 revDSG requires a data protection impact assessment where processing may entail a high risk to personality rights or fundamental rights. What matters for AI projects is para. 2: high risk arises "in particular where new technologies are used".
The DPIA obligation for AI is therefore not a question of interpretation but built into the text. The provision names large-scale processing of sensitive personal data and systematic surveillance of public areas. Standard contract analysis without profiling sits below that threshold; large-scale analysis of HR or health data does not.
Notification of data security breaches
Under Art. 24 revDSG the controller notifies the FDPIC of a data security breach "as soon as possible", and only where a high risk is likely. Unlike the GDPR, the Swiss act sets no 72-hour deadline and applies a higher notification threshold.
The AI provider is a processor
This classification is regularly overlooked when tools are compared, yet it determines whether deployment is permissible at all. Feeding documents into an AI tool transfers processing to a third party. Art. 9 revDSG therefore applies: the data may only be processed as the organisation itself would be permitted to process it, and the controller must satisfy itself that the provider can ensure data security.
For law firms an additional barrier applies that has no GDPR counterpart. Art. 9 para. 1 lit. b revDSG permits transfer only where no statutory or contractual duty of confidentiality prohibits it. Attorney-client privilege under Art. 13 BGFA and Art. 321 of the Swiss Criminal Code is such a duty, and Art. 321 no. 1 extends it to auxiliary persons. Procurement therefore has to establish whether the provider's staff are contractually bound in that capacity.
What to examine in the provider contract itself is covered in the article on reviewing data processing agreements.
What to establish before procurement
Four questions determine whether an AI tool meets the requirements. Every provider can be asked them, and the answers are verifiable.
Where does inference run?
What governs is not where the application is hosted but where data is processed for model computation. Those two locations frequently differ. If the inference region sits outside Switzerland, Art. 16 revDSG applies: either a Federal Council adequacy decision or appropriate safeguards are needed.
What happens to the inputs?
The question is whether inputs are retained beyond the individual request, and whether they are used for training or fine-tuning. How seriously the FDPIC takes this is shown by its preliminary investigation into X and the Grok model: X introduced an opt-out for the use of public posts in AI training on 16 July 2024, and on 20 March 2025 the FDPIC closed the investigation, finding that the DSG requirements were met. An effective opt-out therefore suffices, but it requires transparency about the practice.
Is there human review?
Several model providers run abuse monitoring, where inputs are buffered and reviewed by people on suspicion. For client data that is the critical point, because such review collides with professional secrecy. The question is whether an opt-out is in place.
How is processing on behalf arranged?
Providers engage sub-processors of their own, for models and infrastructure. Art. 9 para. 3 revDSG requires prior authorisation for that, and the list of those sub-processors should be current and open to inspection.
DSG versus GDPR: what matters for AI tools
The two regimes are closely related but diverge at points that bear directly on tool selection.
Topic | Swiss DSG | EU GDPR |
|---|---|---|
Fines | up to CHF 250,000, against the responsible natural person | up to EUR 20 million or 4 % of worldwide annual turnover, against the undertaking |
Notification deadline | "as soon as possible", no fixed period (Art. 24 revDSG) | 72 hours from awareness (Art. 33 GDPR) |
Notification threshold | only where risk is high | already at ordinary risk |
Governing principle | permitted unless prohibited | prohibited unless permitted |
Data protection adviser | optional (Art. 10 revDSG) | mandatory in many cases (Art. 37 GDPR) |
Right of access | Art. 25 revDSG | Art. 15 GDPR |
The first row carries the greatest practical weight. Whoever decides on an AI tool inside a Swiss organisation is personally liable under the DSG, whereas the GDPR addresses the undertaking. The fine requires intent and is prosecuted only on complaint; under Art. 64 para. 2 revDSG the business may be sentenced instead, but only up to CHF 50,000 and only where identifying the responsible individual would be disproportionate.
One change from the previous regime is easily missed: the old Swiss act also protected data relating to legal entities. Since the revision, protection extends only to natural persons, as under the GDPR.
Where practice falls short today
The gap rarely lies in understanding the law, but in the missing internal rule. The AXA SME labour market study 2025 found that 34 per cent of Swiss SMEs deliberately deploy AI while 29 per cent have never used it. Of those actually deploying it, only about a third have defined clear internal rules for handling it in a data protection compliant way.
The consequence is that staff decide for themselves which tool to open and which documents to paste into it. For a legal team working with client files, due diligence material and HR data, that is the actual source of risk, not the question of whether the DSG applies.
Regulatory framework: the DSG rather than an AI act
Switzerland has no dedicated AI statute so far. The Federal Council signed the Council of Europe convention on AI and human rights on 27 March 2025, and the consultation draft is expected by the end of 2026. Until then the DSG remains the governing instrument. Prohibited are applications designed to undermine informational self-determination; the FDPIC cites mass real-time facial recognition in public spaces and social scoring as examples.
Organisations with an EU nexus also face the EU AI Act, which can apply independently of the DSG. What it means for Swiss law firms is covered in the article on the EU AI Act.
How CASUS meets the requirements
CASUS is a Swiss legal AI platform for law firms and in-house teams, usable in the browser and in the Word add-in. Its answers to the four procurement questions are as follows.
Hosting is in Zurich, with inference running on Google Vertex AI in Belgium and Microsoft Azure OpenAI in Switzerland North and Sweden Central. There is no inference in the United States; third-country transfers run on EU standard contractual clauses with the Swiss addendum. Customer data is not used for training or fine-tuning, by CASUS or by the model providers, and an opt-out from abuse monitoring is in place for Azure, so no human review takes place. CASUS staff are auxiliary persons of the lawyer under Art. 321 of the Criminal Code, with the duty of confidentiality anchored in their employment contracts and applying without time limit. Sub-processors are listed in the trust centre, and the details are set out under security and data residency.
For work across large document sets, the AI Data Room detects personal data such as names, addresses or bank details and prioritises sensitive categories, which prepares anonymisation ahead of disclosure. For data protection questions, Legal Research returns source-based, traceable results from statutes and case law rather than general web answers. Teams that want to test this can try the platform free for fourteen days.
FAQ
Does the Swiss DSG apply to AI applications?
Yes. The act is technology-neutral and applies directly to any AI-assisted processing of personal data. The FDPIC confirmed this in updated guidance dated 8 May 2025. No separate AI legislation is required for it.
When does an AI project require a DPIA?
Under Art. 22 revDSG where processing may entail a high risk to personality or fundamental rights, and para. 2 states that high risk arises "in particular where new technologies are used". The provision names large-scale processing of sensitive data and systematic surveillance of public areas.
Must an AI tool be able to explain how it reached a result?
Under Art. 25 para. 2 lit. f revDSG the data subject may request information about the existence of an automated individual decision and the logic behind it. Where the decision stays with a lawyer and the tool only proposes, there is no automated individual decision; that division of labour should be documented.
Is the provider of an AI tool a processor?
As a rule yes, which brings Art. 9 revDSG into play. The controller must satisfy itself that the provider ensures data security, and sub-processors require prior authorisation under Art. 9 para. 3 revDSG.
May law firms put client data into an AI tool?
Only where no duty of confidentiality stands in the way, per Art. 9 para. 1 lit. b revDSG. Privilege under Art. 13 BGFA and Art. 321 of the Criminal Code is such a duty, and Art. 321 no. 1 extends it to auxiliary persons, so it must be contractually secured that the provider's staff fall within it.
How do fines differ between the DSG and the GDPR?
The DSG sanctions the responsible natural person with a fine of up to CHF 250,000, on intent and only on complaint. The GDPR directs fines of up to EUR 20 million or 4 per cent of worldwide annual turnover at the undertaking. Under Art. 64 para. 2 revDSG the business may be sentenced instead, but only up to CHF 50,000.
Must a data breach be reported within 72 hours?
Not under Swiss law. Art. 24 revDSG requires notification to the FDPIC "as soon as possible" and only where a high risk is likely. The 72-hour deadline comes from Art. 33 GDPR and applies there already at ordinary risk.







