> Quelle: https://souverana.ch/en/insights/berufsgeheimnis-cloud/
> Sprache: en

# Professional secrecy and AI: what may go to the cloud

'That does not work for us' is the standard answer to AI in law firms and medical practices. Art. 321 of the Swiss Criminal Code says something narrower, and most of daily work falls outside it entirely.

Guide · Published 4 Aug 2026 · Updated 24 Aug 2026 · Joel Barmettler

## May holders of professional secrecy use AI?

**Yes, and for most of daily work, without extra effort. Art. 321 of the Swiss Criminal Code makes disclosing an entrusted secret an offence and says nothing about tools. Only for data that actually contains a secret do two further steps apply: an assessment of foreign-authority access and contract clauses that go beyond an ordinary Data Processing Agreement. The law also recognises the consent of the person entitled to the secret.**

**In brief**

-   Sort your data before you talk about tools. The larger part of daily work contains no entrusted secrets, and a blanket ban locks it down too.
-   [A data centre in Frankfurt↗](/en/insights/souveraene-ki-infrastruktur/) does not exempt you. The duty to assess applies to every foreign country; only the result differs by jurisdiction.
-   Pass the duty of confidentiality on to every service provider by contract. Whether the term auxiliary person covers them is not settled.
-   If you work with official data, the public prosecutor investigates ex officio, meaning even without a report from the affected person.
-   The duty does not end with the mandate or the office. It continues to apply, even years after leaving the role.

Anyone managing client, patient or official data hears the same sentence whenever AI comes up: that does not work here. Art. 321 of the Swiss Criminal Code says something narrower. Whoever discloses an entrusted secret commits an offence. Whether a language model was involved is not something the law addresses.

Art. 9 revFADP permits handing data to a service provider only as long as no duty of secrecy stands in the way. That is exactly where the [revFADP guide](/insights/revdsg-ki/) (in German) ends, and this is where we continue. Every statutory reference has been checked against the original text. Souverana is not a law firm; where secret data is involved, legal advice is part of the process.

This is the third part of our Law & Regulation series; it covers the sharpest boundary Swiss law draws around AI use.

Series · Law & Regulation

1.  1[AI regulation in Switzerland: what already applies](/en/insights/ki-regulierung-schweiz/)
2.  2[revFADP and AI: what the law actually requires](/en/insights/revdsg-ki/)
3.  3Professional secrecy and AI: what may go to the cloudYou are reading this part
4.  4[AI governance: one page is enough to start](/en/insights/ki-governance/)
5.  5[EU AI Act Switzerland: role first, then duties](/en/insights/eu-ai-act-schweiz/)

## Who is on the list

Art. 321 of the Swiss Criminal Code names the professions individually: clergy, lawyers, defence counsel, notaries, patent attorneys, auditors bound to confidentiality, doctors, dentists, chiropractors, pharmacists, midwives, psychologists, nurses, physiotherapists, occupational therapists, dieticians, optometrists and osteopaths. The law also expressly names their auxiliary persons and students, and Art. 321bis covers research on human beings. Whoever falls under none of these does not come under Art. 321. That does not mean no criminally backed duty of confidentiality exists: fiduciary mandates, for instance, are protected through contract and trade secrecy, and Art. 62 revFADP puts the intentional disclosure of secret personal data from someone’s professional activity under a fine of up to CHF 250,000.

The law covers the auxiliary person? the same way it covers the doctor herself. Practice staff count as such, and with a cloud service, so do the provider’s employees, as long as they can see the data in plaintext. Official secrecy under Art. 320 applies to authorities, and banking secrecy under the Banking Act applies to banks.

Key figure

up to 3 years

Custodial sentence for violating professional or official secrecy, or alternatively a monetary penalty. For comparison: the revFADP only threatens fines.

Source: Art. 320 and 321 of the Swiss Criminal Code

## What counts as a secret at all

This question decides which data needs special treatment at all. It is rarely asked. The law protects what was entrusted to the professional because of their profession, or what they perceived in the course of practising it. The statute itself does not define the term secret. Legal doctrine tests two things: whether the information is generally known, and whether the person entitled to it wants it kept secret.

That produces a sorting that every law firm and every practice can carry out itself:

| Protected | Not protected |
| --- | --- |
| The client’s identity, and already the fact that a mandate exists | The abstract legal question with no connection to a case |
| The facts of the matter, the diagnosis, the file note, the findings | Specialist knowledge, statutory texts, published case law |
| Correspondence bearing names, file references or recognisable details | Templates and boilerplate text with no case connection, website copy |
| Appointments and invoices, to the extent they identify a person | Internal processes with no personal connection |

In most organisations, the right-hand column is the larger part of daily work. The ordinary rules apply to it: the revFADP and the contract with the provider. Only the left-hand column needs the additional steps.

This sorting is also why a blanket ban is expensive. It locks down the right-hand column too, even though no entrusted secrets sit there.

## The path the law itself names

Under Art. 321(2), disclosing the secret with the consent of the person entitled to it is not an offence. It also stays unpunished for someone who, on their own request, has received written authorisation from the superior authority or the supervisory authority. For official secrecy, the superior authority’s written consent is enough. Consent removes only the liability to punishment under Art. 321, and only that. The obligations under the revFADP and the assessment of foreign-authority access remain in place.

Risk

The law prescribes no particular form for the consent of the person entitled to it. Legal doctrine nonetheless requires informed consent tied to the specific processing, and does not regard a blanket clause in the general terms and conditions as sufficient. Have the wording reviewed before it goes into the engagement letter or the patient information.

## What the contract additionally needs

For the left-hand column, the two steps outlined in our pillar article on [AI regulation in Switzerland](/insights/ki-regulierung-schweiz/) (in German) still apply. Two points are worth going into in more depth.

First, the assessment of foreign-authority access, FLARA? for short. The methodology commonly used in Switzerland comes from David Rosenthal and is published free of charge as an open spreadsheet by the Zurich law firm VISCHER. It asks how likely access actually is, and leaves the merely theoretically conceivable aside. The result is a dated assessment you can present to a supervisory authority or in the event of a liability claim. The best known example is the US CLOUD Act?. But disclosure obligations exist in every jurisdiction where a provider or its parent company is based.

Second, plaintext access. An ordinary Data Processing Agreement? covers personal data; secrets do not appear in it. [The most important addendum↗](/en/insights/google-gemini-datenschutz/) governs who at the provider may see plaintext at all: only on a need-to-know basis and only with your prior approval. Without that approval, two exceptions remain: documented emergency operation and a valid order from an authority. The same obligations must apply to sub-processors.

Evidence

That the effort can be managed is shown by an organisation that itself falls under Art. 321: the law firm VISCHER states that it has met the additional requirements for itself and can use AI in daily work with all its data. Published in its AI series, Part 27, April 2025.

## How to get started

1.  01
    
    Clarify whether you are covered
    
    Do you fall under Art. 320, under Art. 321, or under neither? The eighteen professions are named individually; their auxiliary persons and students are covered by force of law as well, and Art. 321bis covers research on human beings.
    
2.  02
    
    Make two piles
    
    Sort your types of data using the table above. The larger pile needs no special treatment.
    
3.  03
    
    Check for consent
    
    For the left-hand column: does your engagement letter or patient information already contain consent that is informed and tied to the specific processing?
    
4.  04
    
    Check the provider
    
    One FLARA per provider with a foreign connection, plus the plaintext-access clause. Anyone who will not sign it is out of the running for the left-hand pile.
    

You carry a professional or official secrecy duty and want to know which architecture holds up to it?

[AI architecture & solution selection](/en/leistungen/ki-architektur/)

The remaining parts of the series map out the surrounding terrain: the map of the rules, the revFADP, AI governance and the EU AI Act.

The author

![Portrait of Joel Barmettler](/_astro/joel-barmettler.CGKHGWrV_sJ0IG.webp)

Joel Barmettler

AI Architect · Souverana, Zurich

Joel Barmettler guides Swiss companies from AI strategy to integration: sovereign, confidential and production-ready. He built the Swiss AI Hub as its architect and today co-owns its architecture; he personally leads every Souverana mandate. Mandates from one-person firms to Fortune 500 corporations.

[Book an intro call](https://meet.brevo.com/joel-barmettler/30-minute-meeting) [More about Souverana](/en/) [LinkedIn](https://www.linkedin.com/in/joel-barmettler-b9ab361b7)

## Frequently asked questions

May lawyers and doctors use AI tools?

Yes. Art. 321 of the Swiss Criminal Code prohibits disclosing an entrusted secret and says nothing about tools. For data that actually is a secret, an assessment of foreign-authority access and additional contract clauses are needed. For everything else in day-to-day law firm or practice work, the ordinary rules apply.

Who falls under professional secrecy under Art. 321?

The law lists eighteen professions by name, among them clergy, lawyers, defence counsel, notaries, patent attorneys, auditors, doctors, dentists, pharmacists, midwives, psychologists, nurses and physiotherapists. Their auxiliary persons are expressly covered as well. Authorities and officials fall under official secrecy under Art. 320 of the Swiss Criminal Code.

Does professional secrecy also apply to fiduciaries?

Not under Art. 321. The list names only auditors bound to confidentiality under the Code of Obligations. That does not mean no criminally backed duty of confidentiality exists: Art. 62 revFADP puts the intentional disclosure of secret personal data from someone's professional activity under a fine of up to CHF 250,000, on complaint, and even after that activity has ended. Contract and trade secrecy add further protection.

What counts as a secret within the meaning of Art. 321?

Covered is whatever was entrusted to the professional because of their profession, or whatever they perceived in the course of practising it. This already includes the mere fact that someone is a client or a patient at all. Generally accessible knowledge and questions unconnected to a case are not covered.

Has the US adequacy decision softened professional secrecy?

No. The Federal Council's decision of 14 August 2024, in force since 15 September 2024, concerns data protection law. Professional and official secrecy sit in the Swiss Criminal Code and remain untouched. The assessment of foreign-authority access is still needed, for every country where a provider or its parent company is based.

LinkedIn

## Share this article

Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.

![Two columns sort law-firm and practice data: on the left, entrusted secrets such as identity, diagnosis and case-linked correspondence (vetted provider only); on the right, legal questions, specialist knowledge and templates with no case connection (standard rules under the revFADP and contract).](/media/berufsgeheimnis-cloud-en/infografik.png)

[Download infographic (PNG)](/media/berufsgeheimnis-cloud-en/infografik.png)

Suggested post

Do you run a law firm, a medical practice or a fiduciary office, and is the standard answer to AI there "that does not work for us"?

Art. 321 of the Swiss Criminal Code says something narrower. It names eighteen professions and makes disclosing an entrusted secret an offence, with up to three years. It says nothing about tools.

What matters, therefore, is sorting the data. Protected is the case itself: the client's identity, the diagnosis, correspondence with a file reference. Not a secret are the abstract legal question, specialist knowledge, published case law and templates with no case connection. In most organisations, that is the larger part of daily work. For the protected half, the law itself names a path, the consent of the person entitled to it, plus an assessment of foreign-authority access and clauses on plaintext access.

Our conclusion: a blanket ban locks down both columns and pushes the work onto private accounts. Whoever sorts can clear the larger part for use right away.

Assessment, not legal advice. The article carries the sorting table, two organisations worked through in full and four questions a provider must answer. Link in the comments.

#ProfessionalSecrecy #AI #Switzerland #DataProtection
