One point of standing first. The German, French and Italian texts of the Act are the binding ones. Fedlex publishes an English translation, but English is not an official language of the Confederation and that translation has no legal force. This page is a working guide for a reader who works in neither German nor French; where it matters, check the binding text, and where it diverges from anything here, it governs.
Does the GDPR apply to a Swiss entity?
Not as Swiss law. Switzerland is neither an EU nor an EEA member state, so the GDPR is not part of the domestic legal order and no Swiss authority enforces it. The instrument a Swiss entity answers to is the revFADP, supervised by the Federal Data Protection and Information Commissioner (FDPIC; EDÖB / PFPDT). Three consequences worth holding separately rather than blending:
- The Swiss regime is not the GDPR with different numbers. No prohibition on automated decisions, no fixed breach clock, criminal rather than administrative sanctions — each changes a control design, and each is set out below.
- A Swiss entity can still be caught by the GDPR on the Regulation's own extraterritorial terms where it offers goods or services to, or monitors the behaviour of, people in the EU. A second regime alongside the FADP, not a replacement.
- A Swiss entity selling into the EU is also within the EU AI Act. Article 2 of Regulation (EU) 2024/1689 applies to providers placing AI systems on the Union market irrespective of establishment, and reaches third-country providers whose system output is intended to be used in the Union. A purely domestic Swiss deployment is outside it — the distinction decides whether an AI programme needs one framework or two.
What does Art. 21 revFADP actually require?
The provision defines an automated individual decision through two cumulative elements: the decision rests exclusively on automated processing, and it has legal consequences for the data subject or significantly affects them. Three duties follow — inform, unprompted rather than on enquiry; hear, giving the data subject the opportunity on request to state their position; and review, where the data subject requires the decision to be reviewed by a natural person.
The contract exception turns on the outcome, not the contract
Art. 21 para. 3 lit. a lifts the duty where the decision is directly connected with the conclusion or performance of a contract and the data subject's request is granted. The operative word is granted. An approved quotation falls within the exception; a refused credit or insurance application does not. The cases where automation says no — declined application, withheld activation, negative assessment — remain fully within the duty, and those are precisely the cases a GDPR-derived template treats as covered by contractual necessity. The second exception is express consent; federal bodies must additionally label the decision as automated under para. 4.
Which entity in a group structure is actually caught?
The Swiss-language commentary rarely has to answer this: its readers are already the Swiss entity. For a group it is the first question. The Art. 21 duties attach to the controller — the entity deciding the purpose and means of the processing. Where a shared platform run from London or Frankfurt decides about people in Switzerland on behalf of a Swiss subsidiary, the subsidiary is normally the controller and owes those duties, though it operates none of the infrastructure. A group that treats Switzerland as one integration produces evidence it cannot attribute to the entity that owes the duty.
For a controller with no Swiss establishment at all, Art. 14 requires a private controller domiciled or established abroad to designate a representative in Switzerland. The FDPIC states four cumulative conditions: the processing is connected with the offer of goods or services, or the monitoring of behaviour, in Switzerland; it is on a large scale, not merely isolated instances; it is on a regular basis, not occasional or time-limited; and it poses a high risk to the personality rights of the data subjects.
Two readings follow. The duty is narrower than the GDPR's Article 27 analogue, because it also requires large scale, regularity and high risk together. And Art. 14 exists only because the Act reaches controllers with no Swiss establishment: a foreign vendor running a scoring model for Swiss customers cannot infer from the absence of a Swiss entity that the Act does not concern it, only that the representative duty may not bite.
Where do AI agents cross the threshold?
The definition is technology-neutral, so it catches systems nobody internally calls an AI decision. The FDPIC confirmed in its update of 8 May 2025 that the FADP applies to all types of technology and is therefore directly applicable to AI-supported processing, naming transparency about purpose, functioning and data sources; human review of automated decisions; the right to know whether one is speaking to a machine; an impact assessment for high-risk applications; and recognisability of deepfakes. Three constructions from practice fail on that wording.
The agent decides and nobody called it a decision
A workflow screens applications against rules and model outputs and passes only borderline cases to a person. For the rejected cases nobody decided anything — the system did. That is an automated individual decision, however firmly the process documentation calls it pre-selection.
The nominal human who approves lists
The commonest design error is a person placed in the process for form's sake, confirming whole batches without assessing the individual case. Two questions decide it: did the examination happen on the substance, and can that be established afterwards? A click that does not record what was examined proves nothing. See what counts as human involvement.
Review is promised and architecturally impossible
Review presupposes the reviewer can reconstruct what the original decision rested on: which inputs, which model version, which rules, at what moment. The mechanism is counter-intuitive and worth stating plainly — re-running the agent produces a new decision, not an explanation of the old one. Reviewing and repeating are different operations; only the first satisfies Art. 21 para. 2. See traceability for AI agents and audit trail requirements for AI agents.
What are the sanctions, and who actually pays them?
Here the Swiss system differs from the GDPR at the root, and English-language market commentary reproduces the difference wrongly more often than not.
Art. 60 to 63 FADP are criminal provisions imposing fines on natural persons, up to CHF 250,000. They are not administrative fines on undertakings and there is no turnover-based ceiling. Under Art. 64 para. 2 the authority may order the undertaking to pay instead, but only where a fine of no more than CHF 50,000 is in issue and identifying the individuals responsible would require disproportionate investigative measures. The company is the fallback with the lower ceiling, not the primary addressee.
Second: the FDPIC does not levy fines. It issues rulings (Verfügungen / décisions). Non-compliance with a ruling is itself punishable under Art. 63, and fines are pronounced by the cantonal criminal prosecution authorities.
Third, and this reorders the work: the catalogue is exhaustive. A missing record of processing activities (Art. 12), an omitted impact assessment (Art. 22) and an unreported breach (Art. 24) are not punishable in themselves; they acquire sanction relevance only indirectly, through an FDPIC ruling and Art. 63. The claim that a missing impact assessment costs CHF 250,000 is, in that form, wrong — see the register of corrections. Art. 61 does capture three breaches of due diligence, and only when intentional: unlawful disclosure abroad (Art. 16 and 17); engaging a processor without meeting Art. 9 para. 1 and 2; and failure to observe the minimum data security requirements of Art. 8 para. 3. That last route, not a missing register, is how logging gaps become criminally relevant.
Is there a 72-hour breach deadline in Switzerland?
No. Art. 24 FADP requires notification to the FDPIC as soon as possible, and only where the breach is likely to result in a high risk to the personality or fundamental rights of the data subject. The FDPIC's own guidance on Art. 24 sets no fixed number of hours; it says the controller cannot wait for the results of lengthier investigations. Two divergences from the GDPR follow: there is no hour-count, and the trigger threshold is higher, because the GDPR notifies as soon as a risk is not unlikely. Art. 24 para. 6 adds a limited use restriction — a notification may be used in criminal proceedings against the notifying person only with that person's consent.
The 24-hour figure English coverage attaches to Swiss breaches belongs to a different statute and a different addressee. Under Art. 74a et seq. of the Information Security Act (ISA; ISG / LSI), SR 128, in force since 1 April 2025, operators of critical infrastructure must report a cyberattack to the NCSC — the National Cyber Security Centre, a federal office since 1 January 2024, styled BACS in German and OFCS in French — within 24 hours of discovery, completing an incomplete initial report within 14 days. Sanctions have applied since 1 October 2025, with fines up to CHF 100,000. That duty binds a far narrower set of operators than the FADP, which binds every controller; one incident can trigger both. NIS2 is an EU directive and does not apply in Switzerland at all, though it reaches Swiss suppliers contractually through their EU customers. See cyber incident reporting in Switzerland.
What else does a Swiss deployment have to carry?
Two adjacent duties, each with a trap for a reader arriving from the GDPR. Art. 12 FADP requires a record of processing activities; Art. 24 of the Data Protection Ordinance (DSV / OPDo), SR 235.11, exempts private-law bodies with fewer than 250 employees on 1 January of a given year — unless sensitive personal data are processed on a large scale or high-risk profiling is carried out, which a scoring model applied to people readily is. Art. 22 FADP requires an impact assessment where processing may entail a high risk, naming the use of new technologies expressly, and has no size threshold at all: the 250 figure belongs to the record, not the assessment. See the AI impact assessment under Art. 22.
For FINMA-supervised institutions, FINMA Guidance 08/2024 of 18 December 2024 sets expectations for governance and risk management when using AI. One correction matters more than the content: it is a supervisory communication — Aufsichtsmitteilung, communication sur la surveillance, FINMA Guidance in FINMA's own English — expressly not a circular and not binding regulation, though English coverage routinely calls it one. The binding instruments are FINMA Circulars 2023/1 and 2018/3. See FINMA Guidance 08/2024 in full.
Is there a Swiss AI Act?
No. On 12 February 2025 the Federal Council settled the approach: ratify the Council of Europe Framework Convention on Artificial Intelligence, make the amendments ratification requires, and otherwise regulate sector by sector — expressly not a horizontal statute on the EU model, with binding measures confined to data protection, transparency, non-discrimination and supervision. Switzerland signed the Convention in Strasbourg on 27 March 2025. The Federal Office of Justice leads the legislative work and a consultation draft was announced for the end of 2026; no consultation procedure had been opened as at 2 September 2026. This is the item most likely to change, so re-check it before each milestone rather than inheriting this paragraph.
What does a group compliance function do differently?
- Name the Swiss controller for each system, and test Art. 14 only where that controller has no Swiss establishment — all four conditions together, not the GDPR representative analysis carried over.
- Inventory decisions, not models. Legal consequence or significant effect is the test; the internal label is irrelevant.
- Separate substantive human decisions from confirmations, record which one happened, and stand up the Art. 21 para. 2 review process before the first request arrives, with a named owner and an internal deadline.
- Make a single decision reconstructable — inputs, model or rule version, timestamp, authorisation, result — captured with the operation rather than rebuilt from a deployment log.
- Set thresholds above which an automated action needs human release before it executes, enforced outside the agent. See approving AI actions before execution and governed workflow automation.
- Run the two notification duties separately — FDPIC under the FADP, NCSC under the ISA.
In practice
BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, which is the record an Art. 21 para. 2 review has to read months later. BarzelOps runs the cross-system workflow with durable state, approval checkpoints and tenant isolation, so a shared platform's operations remain attributable to the individual Swiss controller.
Frequently asked questions
Does the GDPR apply to a Swiss company?
Not as Swiss law. Switzerland is outside the EU and EEA; the operative instrument is the revised FADP, SR 235.1. A Swiss entity may separately fall within the GDPR where it targets or monitors people in the EU.
Does Swiss law prohibit automated decisions?
No. Art. 21 revFADP is a duty to inform, with a right to state a position and a right to review by a natural person. Article 22 GDPR, by contrast, is a prohibition with exceptions. The duty falls away only where the decision is connected with a contract and the request is granted, or on express consent.
Is there a 72-hour breach deadline?
No. Art. 24 FADP requires notification to the FDPIC as soon as possible, and only above a high-risk threshold. The 24-hour clock is the separate ISA duty owed to the NCSC by critical infrastructure operators.
How large are the fines?
Up to CHF 250,000, criminal, against natural persons. The undertaking can be ordered to pay only in the alternative and only up to CHF 50,000 under Art. 64 para. 2. The FDPIC issues rulings; it does not levy fines.
Does the EU AI Act reach a Swiss company?
Yes, where it places an AI system on the Union market or its output is intended to be used in the Union — Article 2 of Regulation (EU) 2024/1689 applies irrespective of establishment. A purely domestic deployment is outside it.
Where this leads
Art. 21 revFADP, the FINMA expectations and the ISA reporting duty state one requirement in three vocabularies: it is not enough that a system worked. Someone has to establish, months later, what it did, on which data and model version, and on whose authority. Until that is true, the human review Art. 21 promises is an intention the architecture cannot honour.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
In forceRevised FADP in force since 1 September 2023
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
BarzelOps
Governed workflow automation across the systems that run the business.
- Durable, idempotent execution: a timeout is retried once, never filed twice.
- Human approval checkpoints that pause the workflow and resume it.
- Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.
Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Related
- The AI impact assessment under Art. 22 revFADP
- FINMA Guidance 08/2024: what supervised institutions implement
- Cyber incident reporting: 24 hours to the NCSC
- Traceability for AI agents in a Swiss deployment
- AI governance — the complete guide
- Glossary of regulatory and technical terms
Sources
- Federal Act on Data Protection (FADP; DSG / LPD), SR 235.1 — binding texts: German, French; English translation, fedlex.admin.ch.
- Ordinance on Data Protection (DSV / OPDo), SR 235.11, Art. 24 — German, French, fedlex.admin.ch.
- FDPIC, Update: current data protection legislation is directly applicable to AI, 8 May 2025.
- FDPIC, Obligation to appoint a representative under Article 14 FADP.
- FDPIC, Guidelines on reporting data security breaches and informing data subjects in accordance with Article 24 FADP.
- Swiss Federal Council, media release of 12 February 2025 on the regulatory approach to artificial intelligence.
- Swiss Federal Council, media release of 26 March 2025: Switzerland signs the Council of Europe Convention on Artificial Intelligence, signature 27 March 2025.
- FINMA, FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence, 18 December 2024. FINMA Circular 2018/3 on outsourcing is cited without a link: only volatile archive URLs are available for it.
- Information Security Act (ISA; ISG / LSI), SR 128, Art. 74a et seq. — German, French, fedlex.admin.ch.
- NCSC, Reporting obligation for cyberattacks on critical infrastructures.
- Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence, Article 2.
This article is a working guide for English-speaking readers and does not constitute legal advice. The binding texts are the German, French and Italian ones.