Using ChatGPT and comparable tools with company data is legal in Switzerland, provided you meet the requirements of the revised Federal Act on Data Protection (FADP, widely called the nLPD in French) and, where you serve users in the European Union, the EU AI Act. The tools are not the problem; ungoverned use is. This article is general information, not legal advice. Obtain your own counsel before relying on any of it.
What the revised Swiss FADP requires
The revised FADP has applied since 1 September 2023 and governs any processing of personal data by private and federal bodies (Swiss Confederation, 2020). When you enter personal data into an AI tool, the core obligations continue to apply.
A lawful basis and transparency. You must have a proper basis for the processing and inform data subjects about it, including, in substance, that AI tooling is involved.
Data minimisation and purpose limitation. Feed the tool only the personal data a task genuinely requires, and use it only for the purpose collected.
A processing agreement with providers. Where a provider processes personal data on your behalf, the FADP requires the same guarantees you are bound by, in practice a data processing agreement before processing begins.
A lawful basis for cross-border transfer. Sending data to a model hosted outside Switzerland is a cross-border transfer and needs an adequate legal basis, such as an adequacy decision or appropriate contractual safeguards. The Federal Data Protection and Information Commissioner (FDPIC) supervises compliance and publishes guidance for organisations.
What the EU AI Act adds
If you operate in or serve the EU, Regulation (EU) 2024/1689, the Artificial Intelligence Act, layers a risk-based regime on top of data-protection law (European Parliament & Council of the European Union, 2024). Obligations scale with how an AI system is used: a small set of practices is prohibited outright, high-risk uses carry substantial requirements, and most general productivity uses fall into lower-risk categories that still attract transparency duties. The Act entered into force in 2024 and its obligations phase in over a staged timeline, so the relevant date depends on the use case. Even for low-risk uses, expectations around transparency and human oversight apply.
What compliant use actually looks like
In practice, safe AI use rests on a handful of controls that translate the law into engineering and policy.
- Least-privilege access. The AI reaches only the data a given task requires, nothing more, enforced technically, not by trust.
- A processing agreement and known data residency. You know where data goes, who touches it, and under what terms.
- Guardrails and logging. Explicit rules for what the tool may and may not do, with an audit trail that lets you reconstruct decisions.
- No unreviewed personal or confidential data in prompts to consumer-grade tools that lack an enterprise agreement and appropriate data terms.
- A record of the use case and its risk classification, so that an AI Act assessment, if it applies, is straightforward rather than retrofitted.
Governance here is not a bolt-on. It is what makes these tools usable in a regulated business at all: without it, the same capability that saves hours also creates disproportionate legal and reputational exposure.
Getting AI into your workflow safely and legally, with the access controls, processing terms, and guardrails that satisfy the FADP and the EU AI Act, is part of our Knowledge Systems service.
References
European Parliament & Council of the European Union. (2024). Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Swiss Confederation. (2020). Federal Act on Data Protection (FADP) of 25 September 2020 (SR 235.1). Fedlex. https://www.fedlex.admin.ch/eli/cc/2022/491/en
