The revised Federal Act on Data Protection (Bundesgesetz über den Datenschutz, DSG, often called «nDSG») has been in force since 1 September 2023. The Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) makes clear: the DSG is technology-neutral and therefore directly applicable to AI-supported processing (Bearbeiten) of personal data (Personendaten). A separate Swiss AI law is not required for that.
This page summarises the key points for Swiss SMEs. It does not replace legal advice.
Who is affected?
The EDÖB addresses manufacturers, providers, and users of AI applications. Anyone who processes personal data with AI — internally or via a cloud service — remains responsible under data protection law and must meet the statutory duties.
Transparency and information
The purpose, functioning, and data sources of AI-supported processing must be disclosed transparently. For language models that communicate directly with users, those users have the right to know:
- whether and to what extent they are corresponding with a machine;
- whether entered data are reused to improve self-learning programmes or for other purposes.
Applications that can distort faces, images, or voice messages of identifiable persons must also be clearly recognisable.
Objection and human review
The right to transparency is closely linked to the right to object to automatic data processing or to require that automated individual decisions (automatisierte Einzelentscheidung) be reviewed by a human.
High risks and data protection impact assessment
AI-supported processing with high risks is in principle permissible, but requires appropriate protective measures. For high risks, the DSG requires a data protection impact assessment (Datenschutz-Folgenabschätzung, DSFA).
Applications aimed at undermining privacy and informational self-determination — for example blanket real-time facial recognition or «social scoring» — are prohibited under data protection law.
What SMEs can do now
- Inventory: Which AI tools process personal data?
- Adjust transparency texts and internal policies.
- Plan a DSFA where risk is high.
- Clarify with providers: processing on behalf, training use, storage location.
- Ensure human oversight for automated decisions with significant effect.
Disclaimer
This page is informational and not legal advice. For concrete projects, review by specialists or legal counsel is recommended.