Swiss AI Resource
← Back to home

nDSG and AI: basics for Swiss companies

Last verified:

The German version is canonical; translations may differ.

This translation is an LLM draft and has not yet been human-reviewed.

What the revised Federal Act on Data Protection means for AI-supported data processing: transparency, DPIA, human review, and duties of manufacturers, providers, and users.

The revised Federal Act on Data Protection (Bundesgesetz über den Datenschutz, DSG, often called «nDSG») has been in force since 1 September 2023. The Federal Data Protection and Information Commissioner (Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter, EDÖB) makes clear: the DSG is technology-neutral and therefore directly applicable to AI-supported processing (Bearbeiten) of personal data (Personendaten). A separate Swiss AI law is not required for that.

This page summarises the key points for Swiss SMEs. It does not replace legal advice.

Who is affected?

The EDÖB addresses manufacturers, providers, and users of AI applications. Anyone who processes personal data with AI — internally or via a cloud service — remains responsible under data protection law and must meet the statutory duties.

Transparency and information

The purpose, functioning, and data sources of AI-supported processing must be disclosed transparently. For language models that communicate directly with users, those users have the right to know:

  • whether and to what extent they are corresponding with a machine;
  • whether entered data are reused to improve self-learning programmes or for other purposes.

Applications that can distort faces, images, or voice messages of identifiable persons must also be clearly recognisable.

Objection and human review

The right to transparency is closely linked to the right to object to automatic data processing or to require that automated individual decisions (automatisierte Einzelentscheidung) be reviewed by a human.

High risks and data protection impact assessment

AI-supported processing with high risks is in principle permissible, but requires appropriate protective measures. For high risks, the DSG requires a data protection impact assessment (Datenschutz-Folgenabschätzung, DSFA).

Applications aimed at undermining privacy and informational self-determination — for example blanket real-time facial recognition or «social scoring» — are prohibited under data protection law.

What SMEs can do now

  1. Inventory: Which AI tools process personal data?
  2. Adjust transparency texts and internal policies.
  3. Plan a DSFA where risk is high.
  4. Clarify with providers: processing on behalf, training use, storage location.
  5. Ensure human oversight for automated decisions with significant effect.

Disclaimer

This page is informational and not legal advice. For concrete projects, review by specialists or legal counsel is recommended.

Sources

Last verified:

This page is for information only and is not legal advice. For specific projects, consult qualified professionals.