> Quelle: https://souverana.ch/en/insights/revdsg-ki/
> Sprache: en

# revFADP and AI: what the law actually requires

The fine falls not on the company but on the person who approved the tool, up to CHF 250’000. That makes the approval a matter for management.

Guide · Published 4 Aug 2026 · Updated 24 Aug 2026 · Joel Barmettler

## What does the revFADP require for AI use?

**Whoever approves an AI tool within a company is personally liable, with fines of up to CHF 250’000. The revFADP places the same requirements on AI as on any other data processing: a purpose, a contract with every service provider, adequate security, transparency towards the people affected and, where the risk is high, an impact assessment carried out in advance. The law does not mention artificial intelligence anywhere; it still applies, because it is written to be technology-neutral.**

**In brief**

-   You have probably already met four of the five requirements without calling it AI. The check is still worthwhile, because the fine falls on you personally, not on the company.
-   Whoever holds oversight is also liable for what they negligently let happen. It is not enough to have issued no instructions.
-   Check the subscription tier before you approve a tool. The confidentiality and training assurances are missing from consumer subscriptions, even at the same providers.
-   A chat tool for drafting text does not need an impact assessment. That only becomes necessary with high-risk profiling or the large-scale processing of especially sensitive data.
-   Record who approved which tool. Without a name, responsibility falls by default on whoever introduced it.

Few people who decide on AI tools know this quirk of Swiss data protection law: the fines under Articles 60 to 63 are directed at the person who acted within the company, not at the business itself. That makes the question of who approves a tool, and on what contractual basis, a matter for management.

Most offences are prosecuted only on complaint, the cantonal prosecution authorities have jurisdiction, and the FDPIC? can file a criminal complaint. Prosecution becomes time-barred after five years.

This article deepens a section of the [regulatory map](/insights/ki-regulierung-schweiz/). Souverana is not a law firm; a sensitive case still calls for legal advice alongside it.

This is the second part of our series on law and regulation; it examines the law that almost every Swiss AI initiative is actually measured against.

Series · Law & Regulation

1.  1[AI regulation in Switzerland: what already applies](/en/insights/ki-regulierung-schweiz/)
2.  2revFADP and AI: what the law actually requiresYou are reading this part
3.  3[Professional secrecy and AI: what may go to the cloud](/en/insights/berufsgeheimnis-cloud/)
4.  4[AI governance: one page is enough to start](/en/insights/ki-governance/)
5.  5[EU AI Act Switzerland: role first, then duties](/en/insights/eu-ai-act-schweiz/)

## Five requirements, and none of them is new

You have probably already handled four of the five. If you revised your privacy policy in 2023, set up a register of processing activities and signed a data processing agreement with your cloud provider, adding AI simply means entering one more tool. What is new is only the pace at which these tools enter the company, often bypassing procurement altogether.

**A purpose, and proportionality.** Under Art. 6, you process personal data? lawfully, in good faith and proportionately. In practice, this means you can state what the AI needs the data for, and you give it no more than that. Whoever uses a language model to summarise text has already met this point without thinking about it.

**A contract with every service provider.** Art. 9 ties the handover to a processor? to two conditions and makes disregarding them a criminal offence. That is why this point gets its own section further down.

**Adequate security.** Art. 8 obliges controllers and processors jointly to take suitable technical and organisational measures. For AI tools, this means above all: [controlled access↗](/en/insights/souveraene-ki-plattform/) and a provider that can evidence its security.

**Transparency.** Under Art. 19, you inform the people affected adequately as soon as you collect their data. What this means for your privacy policy follows further down.

**An impact assessment where the risk is high.** Art. 22 requires a data protection impact assessment? in advance wherever a processing may carry a high risk to personality or fundamental rights.

## The real work sits in the contract

Art. 9 ties the handover to two conditions. First, the provider may only process the data in ways you yourself would be permitted to. Second, no statutory or contractual duty of confidentiality may stand in the way. On top of that comes your duty to satisfy yourself of the provider’s data security.

Whoever intentionally hands over the processing without meeting these conditions is liable to prosecution under Art. 61. Prosecution requires a complaint. No contract with specific content is prescribed: the law demands the conditions, not a template. The contract is the means of meeting and evidencing them. Without one, you have no proof from the very first prompt.

The second condition is the point at which law firms, medical practices and hospitals must clarify professional secrecy? before signing the contract, and banks must clarify banking client confidentiality under the Banking Act. For everyone else, we check four points for every AI tool:

-   **A data processing agreement that covers every function in use.** Products keep growing: what applies to the chat does not automatically apply to [web search↗](/en/insights/google-gemini-datenschutz/) or the coding agent sitting alongside it.
-   **A duty of confidentiality that binds the provider itself.** It must include sub-processors and continue to apply after the contract ends. Technical measures do not cover this.
-   **The assurance that your content is not used for the provider’s own purposes**, in particular not for its training.
-   **Free use of the results**, without an additional licence and without a restriction that does not fit your business.

Under Art. 9(3), a sub-processing arrangement also needs the prior authorisation of the controller?. In practice, this almost always becomes a general authorisation with a duty to notify, and providers design it very differently. Just how differently is shown by the comparison of [OpenAI’s contracts](/en/insights/chatgpt-dsgvo-konform/).

## Why the fine falls on you personally

Key figure

CHF 250’000

The maximum fine under the revFADP, imposed on the responsible natural person, not on the company.

Source: Art. 60 to 63 revFADP, in force since 1 September 2023

There is only an exception downward. Where the fine would not exceed CHF 50’000 and identifying who acted within the company would be disproportionate for that amount, the authority can convict the business itself instead (Art. 64). Above that threshold, it stays with the person. This is the exception, and it does not extend upward.

In practice, this rule works through ownership. Because the penalty falls on a person, every AI tool is worth assigning a named person responsible, who knows the contract and decides the approved data classes. Without that role, the risk falls in practice on whoever introduced the tool: often a team lead who never saw the contract.

## Transparency: three additions to your privacy policy

Everyday AI tool use rarely needs its own disclosure. Art. 19 targets the collection of the data, not every tool along the processing chain. What matters is whether the purpose changes. An assistant that shortens an existing text does not change it. A system that turns a job application into an assessment does.

Three additions are still worthwhile in almost every privacy policy:

-   Mandatory: where personal data goes abroad, Art. 19(4) requires you to name the country and the safeguard you rely on. This also includes the categories of recipients (Art. 19(2)(c)).
-   Name the purposes for which AI works with personal data, as soon as something new happens with it.
-   Record that personal data can also be generated using AI, for instance when a system turns a job application into an assessment.

It gets stricter as soon as a machine alone makes a decision that has a legal effect or materially affects the person concerned. Art. 21 then applies: you must inform the person affected, and they can demand that a natural person review the decision. The law itself names two exceptions: where the decision grants a contractual request, and where the person has expressly consented. Today, only decisions made exclusively by automated means are covered. It is exactly this threshold that upcoming Swiss regulation is likely to lower.

## How to get started

1.  01
    
    Define data classes
    
    Which data may go into which tool? Three levels are enough: public, internal, especially sensitive.
    
2.  02
    
    Review contracts
    
    The four points above, per tool, and for every function your people actually use.
    
3.  03
    
    Name a person responsible
    
    One responsible person per tool, who knows the contract and sets the approved data classes.
    
4.  04
    
    Update the register
    
    Wherever AI works with personal data, it belongs in the register of processing activities. This is only mandatory from 250 employees, or where especially sensitive data is processed on a large scale, or with high-risk profiling (Art. 12(5) revFADP, Art. 24 of the Data Protection Ordinance (DSV)). It is still worthwhile voluntarily: it takes care of part of the future requirements at the same time.
    

The revFADP does not prohibit AI use anywhere, and the list above contains no ban either. It wants someone to make the decisions and be able to evidence them. A blanket ban within the company achieves the opposite: the work migrates to private accounts, and those you no longer see.

Want to know whether your contracts and data classes hold up for AI use?

[AI Governance](/en/leistungen/ki-governance/)

Where the revFADP leaves off, the other parts of the series begin: professional secrecy for especially protected data, AI governance for the organisation, and the EU AI Act for the view towards Europe.

The author

![Portrait of Joel Barmettler](/_astro/joel-barmettler.CGKHGWrV_sJ0IG.webp)

Joel Barmettler

AI Architect · Souverana, Zurich

Joel Barmettler guides Swiss companies from AI strategy to integration: sovereign, confidential and production-ready. He built the Swiss AI Hub as its architect and today co-owns its architecture; he personally leads every Souverana mandate. Mandates from one-person firms to Fortune 500 corporations.

[Book an intro call](https://meet.brevo.com/joel-barmettler/30-minute-meeting) [More about Souverana](/en/) [LinkedIn](https://www.linkedin.com/in/joel-barmettler-b9ab361b7)

## Frequently asked questions

Does the revFADP apply to the use of AI?

Yes, without limitation. The law is written to be technology-neutral and does not mention artificial intelligence anywhere. As soon as an AI application processes personal data, the same requirements apply as for any other processing: a defined purpose, a contract with the service provider, data security, transparency, and, where the risk is high, an impact assessment.

How high are the fines under the revFADP?

Up to CHF 250’000. They are directed at the person who acted within the company. Where the fine would not exceed CHF 50’000 and identifying that person would be disproportionate, the company can be convicted in their place. Only intentional conduct is punishable, and most offences are prosecuted only on complaint.

Do I need a data processing agreement for an AI tool?

In practice, yes, even though the law does not prescribe a contract with specific content. Art. 9 of the revFADP ties the handover to conditions: the provider may only process the data in ways you yourself would be permitted to, no duty of confidentiality may stand in the way, and you must satisfy yourself of the provider's data security. Whoever intentionally disregards these conditions is liable to prosecution under Art. 61. The contract is the means of meeting and evidencing them, and it must cover every function actually in use.

When does an AI project need a data protection impact assessment?

When the processing carries a high risk to the personality or fundamental rights of the people affected, for instance with extensive profiling or especially sensitive data. Art. 22 of the revFADP requires one in advance. In practice, this is a structured conversation, not a project.

May holders of professional secrecy engage AI providers?

Only with additional review. Art. 9 of the revFADP expressly permits a handover to a processor only where no statutory or contractual duty of confidentiality stands in the way. Law firms, medical practices and hospitals must therefore clarify professional secrecy before signing the contract; banks must clarify banking client confidentiality.

LinkedIn

## Share this article

Ready-formatted graphics and a suggested post for your LinkedIn feed: download, copy, post.

![Scale of revFADP fines from CHF 0 to 250’000: only up to CHF 50’000 can the company be convicted instead, above that the fine always falls on the person who acted. Below it, the five requirements: purpose, contract, security, transparency, impact assessment.](/media/revdsg-ki-en/infografik.png)

[Download infographic (PNG)](/media/revdsg-ki-en/infografik.png)

Suggested post

Who in your company actually approved the team's use of AI tools? At many SMEs, the honest answer is nobody, not formally.

Under the revFADP, this carries a consequence few people know: the penalty provisions (Art. 60 to 63) are directed at the person who acted within the company, not at the company itself. Up to CHF 250’000, only intentional conduct is punishable, and prosecution mostly requires a complaint. Only up to CHF 50’000 can the company be convicted instead, and only where identifying the person would be disproportionate.

What the law actually requires for AI use is nothing new: a purpose, a contract with every service provider, adequate security, transparency, and, where the risk is high, an impact assessment. A company that tidied up properly in 2023 has long since met four of the five.

Our conclusion from consulting practice: the hurdle is rarely the law. It is the missing ownership. Every tool needs a named person who knows the contract and sets the approved data classes. Without one, the risk falls in practice on whoever introduced the tool, often a team lead who never saw the contract.

The article covers the five requirements in detail, the four points that belong in every provider contract, and the three additions your privacy policy needs. Link in the comments.

#revFADP #DataProtection #AI #Switzerland
