Back to Blog
Swiss FADPAI GovernanceGlobal Compliance

Switzerland FADP vs EU GDPR Comparison for AI Services: Key Differences in 2026

By Robert Healey · September 29, 2026

Last reviewed: 29 September 2026. Next review: January 2027.

Venn diagram showing an AI service at the overlap of Swiss FADP and EU GDPR: transparency, DPIAs and transfers

Short answer

The Swiss FADP and EU GDPR both apply to AI services, based on where users are. The GDPR requires a lawful basis upfront and restricts solely automated decisions. The FADP allows private-sector processing unless a principle is breached. It requires information and human review for automated decisions. Fines differ: the GDPR fines organisations, while the FADP imposes criminal fines on responsible individuals.

Most AI services serve users in both Switzerland and the EU. Consequently, they fall under two privacy laws at once. The Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR) look alike. However, they differ in ways that matter for AI.

Those differences affect training data, automated decisions, vendor contracts and personal liability. Therefore, a careful Swiss FADP vs EU GDPR comparison for AI services saves time, money and regulatory stress later.

This guide explains each difference in plain language. It also shows how to run one governance programme that satisfies both laws. For a shorter overview, see Formiti's strategic comparison of the Swiss FADP and EU GDPR for AI service deployment.

Quick Answer: FADP vs GDPR Differences for AI Services

Here are the five differences that matter most:

  • Reach. Both laws apply based on where people are, not where the model runs.
  • Legal basis. The GDPR demands a lawful basis upfront. The FADP permits private-sector processing unless a principle is breached.
  • Automated decisions. The GDPR restricts them. The FADP requires information and a human review on request.
  • Penalties. The GDPR fines organisations. The FADP imposes criminal fines on responsible individuals.
  • AI-specific law. The EU has the AI Act. Switzerland has no equivalent, only sector rules and a pending treaty route.

In short, the laws overlap heavily. Nevertheless, the gaps sit exactly where AI services are most exposed.

How the Swiss FADP and EU GDPR Relate

The revised FADP entered into force on 1 September 2023. Lawmakers designed it to align with the GDPR and with Council of Europe Convention 108+. As a result, the two laws share many concepts. These include impact assessments, breach notification and privacy by design.

Moreover, the European Commission confirmed in its January 2024 review that Switzerland keeps its adequacy status. Therefore, personal data can still flow from the EU to Switzerland without extra safeguards.

However, adequacy does not mean the laws are identical. Switzerland is not part of the EU. Its law is sovereign, and the Federal Data Protection and Information Commissioner (FDPIC) enforces it.

The FDPIC has also confirmed that the FADP applies directly to AI-supported data processing. The law is technology neutral. Consequently, there is no "AI exemption" for Swiss compliance. The FDPIC has published a statement on AI and data protection.

Which Law Applies to Your AI Service?

The FADP applies when processing has an effect in Switzerland. That is true even if the processing happens abroad.

The GDPR applies in two main situations. First, when you have an establishment in the EU. Second, when you offer services to people in the EU or monitor their behaviour.

Consider a typical example. A US provider runs a chatbot from a US data centre. Users log in from Zurich and Berlin. Both laws apply.

Hosting location therefore does not remove either law. Instead, the location of your users decides which regimes you must follow. This is why one AI product often needs two separate legal analyses.

Swiss FADP vs EU GDPR for AI Services: Side-by-Side Comparison

TopicSwiss FADPEU GDPRWhy it matters for AI
Territorial scope (FADP Art. 3; GDPR Art. 3)Effects in SwitzerlandEstablishment, or offering services to or monitoring people in the EUOne AI service often triggers both
Legal basis (FADP Arts. 6, 30–31; GDPR Arts. 5–6)No general requirement in the private sector. Principles apply, and justification is needed if they are breachedOne of six lawful bases is required upfrontTraining-data analysis can differ
Consent (FADP Art. 6(6)–(7); GDPR Arts. 4(11), 7, 9(2)(a))Needed only in certain cases. Must be explicit for sensitive data and high-risk profilingOne lawful basis among six. Explicit for special categoriesConsent design must meet the stricter case
Sensitive data (FADP Art. 5(c); GDPR Arts. 9–10)Includes biometric and genetic data, criminal and administrative proceedings, and social assistance dataSpecial categories include sex life, sexual orientation and trade union membershipEdge cases differ for biometrics and inference models
Profiling (FADP Art. 5(f)–(g); GDPR Art. 4(4))Profiling and a separate "high-risk profiling" categoryProfiling, plus automated decision rulesHigh-risk profiling raises consent and DPIA questions
Automated decisions (FADP Art. 21; GDPR Art. 22)Inform, allow a statement, and give human review on requestRight not to be subject to solely automated decisions, with exceptions and safeguardsInterface and workflow design differ
DPIA (FADP Art. 22; GDPR Art. 35)Required for high risk to personality or fundamental rightsRequired for high risk to rights and freedomsOne joint assessment can serve both
Prior consultation (FADP Art. 23; GDPR Art. 36)FDPIC, unless a registered advisor was consultedSupervisory authorityAdvisor route can reduce friction in Switzerland
Records of processing (FADP Art. 12 and ordinance; GDPR Art. 30)Required, with an exemption below 250 employeesRequired, with a similar exemptionAI processing often removes the exemption
DPO (FADP Art. 10; GDPR Arts. 37–39)Optional data protection advisor for private bodiesMandatory in defined casesGovernance model differs
Representative (FADP Art. 14; GDPR Art. 27)Swiss representative if strict cumulative conditions are metEU representative for non-EU controllers, with limited exceptionsTwo separate appointments
Breach notification (FADP Art. 24; GDPR Arts. 33–34)To the FDPIC as soon as possible if high riskTo the authority within 72 hours unless risk is unlikelyTiming playbooks must reflect both
Transfers (FADP Arts. 16–17; GDPR Arts. 44–49)Federal Council adequacy list, recognised clauses, Swiss-US frameworkCommission adequacy, SCCs, EU-US frameworkModel hosting and sub-processors need mapping
Enforcement (FADP Arts. 49–51, 60–66; GDPR Arts. 58, 83)FDPIC orders, plus criminal fines up to CHF 250,000 on individualsAdministrative fines up to EUR 20 million or 4% of turnoverLiability lands on different parties
AI-specific law (Regulation (EU) 2024/1689)None yet. Council of Europe route in progressEU AI Act in force, phasedEU AI Act may reach Swiss providers

Legal Basis for AI Training and Operation

The GDPR approach

The GDPR starts from a prohibition. You may not process personal data unless a listed lawful basis applies. For AI services, that means naming a basis before training begins. The GDPR text sets out the six lawful bases.

In December 2024, the European Data Protection Board (EDPB) issued an opinion on AI models. It confirmed that legitimate interest can support model development. However, it requires a careful three-step test. Read the EDPB Opinion 28/2024 on AI models.

The EDPB also warned that model anonymity is not automatic. Moreover, unlawful development can affect later deployment. Therefore, training data provenance deserves real documentation.

The FADP approach

The FADP starts from personality protection. Private-sector processing is broadly allowed if it respects the core principles. These include lawfulness, good faith, proportionality, purpose limitation and accuracy. The full text is the Federal Act on Data Protection (SR 235.1).

A justification becomes necessary when processing breaches someone's personality. For example, this happens when processing goes against a person's express objection. It also happens when sensitive data is disclosed to third parties. Justification can rest on consent, law, or an overriding private or public interest.

Where consent is required, it must be explicit for sensitive data and high-risk profiling.

What this means in practice

A Swiss analysis may pass where an EU analysis fails. Nevertheless, the FADP is not a free pass. Proportionality and purpose limitation still constrain scraped or repurposed datasets.

The FDPIC also expects transparency about the purpose, functionality and data sources of AI-based processing. Consequently, the safest approach is to build to the stricter standard.

The EU has also proposed GDPR changes to ease AI training, including a clearer legitimate interest route. However, those proposals remain under negotiation and may change. Do not treat them as law.

Sensitive Data, Profiling and Biometrics

Both laws protect sensitive data more strictly. However, the lists differ.

Under the FADP, sensitive data includes health data and genetic data. It also covers biometric data that uniquely identifies a person. In addition, it includes data on criminal and administrative proceedings and social assistance measures.

The GDPR lists special categories separately. These include data on sex life, sexual orientation and trade union membership. Criminal data receives its own treatment.

For AI, these differences matter most in three areas:

  • Face and voice recognition
  • Health-related inference models
  • Systems that score people using behavioural data

The FADP also defines high-risk profiling. This means profiling that combines data to assess essential aspects of a person's personality, with high risk. The GDPR has no separate category. Instead, it triggers a DPIA for systematic and extensive evaluation of individuals.

Automated Decision-Making: Article 21 FADP vs Article 22 GDPR

This is the most important difference for AI services. Article 22 of the GDPR gives individuals a right not to be subject to solely automated decisions. The decision must have legal or similarly significant effects. Exceptions exist for contract necessity, law and explicit consent, with safeguards.

Article 21 of the FADP works differently. It focuses on transparency and review. The controller must inform the person about the automated decision. Upon request, the person can state their view and ask for review by a human.

In addition, the FADP access right covers the existence of an automated decision and its underlying logic. The GDPR offers a similar right to meaningful information about the logic involved.

Therefore, the practical difference is one of emphasis. Switzerland expects you to inform and allow review. The EU often expects you to justify the automation itself.

A workable design pattern covers both:

  1. Disclose that the decision is automated.
  2. Explain the consequence in plain words.
  3. Offer human review by default.
  4. Log the reasoning so you can explain it later.

Transparency Duties for AI Services

Both laws require clear information at the point of collection. The FADP requires you to disclose the countries where data is sent. The GDPR requires details on recipients and transfers.

Moreover, the FDPIC expects users to know when they interact with a machine. It also expects clarity on whether inputs may be reused, for example for training.

Many providers copy EU privacy notices into Swiss markets. As a result, Swiss references are often missing. This is a visible documentation gap on inspection.

DPIAs and Prior Consultation

Both laws require a data protection impact assessment for high-risk processing. AI often qualifies because it uses new technology, large datasets or profiling.

The structure is similar. You describe the processing, assess the risks and set out measures. Consequently, one well-built assessment can serve both laws.

The consultation step differs slightly. Under the FADP, you consult the FDPIC if high risk remains after mitigation. However, a private controller can skip this step if it consulted its registered data protection advisor. The GDPR requires prior consultation with the supervisory authority in similar cases.

For a practical starting point, use Formiti's data protection impact assessment template. Life sciences teams with high assessment volumes can also use the DPIA factory and AI governance service. It turns repeated assessments into reusable blueprints.

Records, DPO and Governance Roles

Both laws require records of processing. Both also offer an exemption for organisations with fewer than 250 employees. However, the exemption disappears for risky processing.

AI services often lose the exemption. Large-scale sensitive data or high-risk profiling is enough. Therefore, assume you need a full record.

Governance roles diverge more. The GDPR requires a Data Protection Officer in defined cases. The FADP offers an optional data protection advisor for private bodies. Nevertheless, appointing one brings real procedural benefits in Switzerland.

For many AI providers, an outsourced DPO service provides independence without a full-time hire.

Swiss Representative vs EU Representative

Foreign organisations may need a local representative in each jurisdiction. The rules differ.

Article 14 of the FADP sets strict conditions. A foreign private controller needs a Swiss representative only if all are met. It must offer services to or monitor people in Switzerland. The processing must also be extensive, regular and high risk.

Article 27 of the GDPR applies to non-EU controllers offering services to or monitoring people in the EU. It contains limited exceptions.

Importantly, an EU representative does not cover Switzerland. The two appointments are separate. Formiti provides both a Swiss FADP representative service and an EU GDPR representative service.

Breach Notification

AI services face unusual incident types. Examples include prompt injection, training data leakage and exposed model logs.

Under the GDPR, you notify the authority within 72 hours unless a risk is unlikely. Under the FADP, you notify the FDPIC promptly if the breach is likely to cause high risk.

Consequently, your incident playbook needs a single triage step with two notification tracks. Assess the risk once. Then apply each law's threshold and timing.

Cross-Border Transfers and AI Supply Chains

AI services rarely keep data in one place. Model providers, cloud hosts and logging tools often sit abroad.

Under the FADP, transfers can rely on the Federal Council's list of adequate countries. Otherwise, you need safeguards such as standard contractual clauses recognised by the FDPIC. Since 15 September 2024, transfers to certified US companies can also use the Swiss-US Data Privacy Framework.

The GDPR follows a parallel structure. It uses Commission adequacy decisions, standard contractual clauses and the EU-US Data Privacy Framework.

However, adequacy is not a shortcut. You still need to know where data rests, where inference runs and who can access logs. Therefore, map every flow before you rely on any transfer mechanism.

Enforcement and Penalties

This is where the comparison stops being academic.

The GDPR targets organisations. Supervisory authorities can impose administrative fines up to EUR 20 million or 4% of worldwide turnover. Individuals can also claim compensation.

The FADP works differently. The FDPIC can investigate and order measures. However, it cannot issue administrative fines. Instead, cantonal prosecutors can impose criminal fines of up to CHF 250,000. These fines target the responsible individuals for intentional violations of specified duties. In limited cases, a company can be fined up to CHF 50,000 instead.

Consequently, personal accountability becomes a board topic. Managers who approve AI tools carry direct exposure. Document who approves each system, and why.

AI-Specific Rules: EU AI Act vs Switzerland

Neither the GDPR nor the FADP is an AI law. The EU has added one on top. Switzerland has chosen a different path.

The EU AI Act

The EU AI Act takes a risk-based approach. Prohibited practices have applied since February 2025. Obligations for general-purpose AI models have applied since August 2025. The text is Regulation (EU) 2024/1689.

The Digital Omnibus on AI entered into force on 27 July 2026. It moved the deadline for stand-alone high-risk systems to 2 December 2027. It also moved the deadline for AI embedded in regulated products to 2 August 2028.

Nevertheless, transparency duties under Article 50 have applied since 2 August 2026. A grace period for machine-readable content marking runs to 2 December 2026.

The AI Act also has extraterritorial reach. Swiss providers selling into the EU inherit these duties regardless of where they sit.

Switzerland

Switzerland has no Swiss AI Act. In February 2025, the Federal Council chose a sector-specific approach. It signed the Council of Europe AI Convention on 27 March 2025. The Federal Council set out its approach to AI regulation in February 2025.

The government plans to publish a consultation draft by the end of 2026. Ratification still needs parliamentary approval and may face a referendum. The Convention applies primarily to state actors.

Consequently, existing law does the work today. That includes the FADP and sector rules such as FINMA Guidance 08/2024 for financial institutions. Track the consultation closely, because it may shape private-sector duties.

AI Vendor Risk: Where Both Laws Converge

Most organisations buy AI rather than build it. However, both laws keep the deployer accountable.

The GDPR requires a compliant processor contract. The FADP requires the same in substance. It also demands that processors guarantee data security and use sub-processors only with authorisation.

Ask every AI supplier these questions:

  • Where is data stored and processed?
  • Does the vendor train on your data?
  • Which sub-processors are involved?
  • What audit rights do you have?
  • How quickly will they report an incident?

Record the answers in an AI register so ownership stays clear.

Formiti's AI vendor risk management service assesses AI tools and suppliers. It also builds your AI register and maps EU AI Act duties. Meanwhile, the Privacy360 platform keeps the resulting evidence audit-ready.

Sector Notes: Financial Services, Life Sciences and Legal Tech

Financial services

Regulated firms face extra layers. Swiss institutions must consider FINMA expectations. UK-regulated firms serving Swiss or EU clients face FCA and accountability duties too. Formiti's AI governance policy and compliance framework for UK financial services maps model decisions to named accountable individuals.

Life sciences

Health and genetic data are sensitive under both laws. Trials, labs and diagnostics platforms therefore face the strictest analysis. In addition, sponsors often run multi-country studies. The life sciences DPO, DPIA factory and AI governance service offers one operating model for data and AI compliance.

Legal tech and professional services

Law firms and legal tech vendors carry confidentiality duties on top of privacy law. In Switzerland, lawyers also face professional secrecy rules. Uploading privileged material to a public AI tool creates real risk. Formiti's legal tech privacy frameworks cover AI tooling reviews, DPIAs and regulatory accountability.

A Practical Playbook: One Programme, Two Annexes

You do not need two compliance programmes. Instead, build one core programme and add jurisdiction annexes.

  1. Map your AI systems. List every model, tool and vendor. Record purpose, data types and locations.
  2. Confirm which laws apply. Test each system against FADP and GDPR scope rules.
  3. Run one joint DPIA. Add a Swiss annex and an EU annex for differences.
  4. Redesign automated decision flows. Disclose, explain and offer human review.
  5. Appoint representatives. Check Swiss Article 14 and EU Article 27 separately.
  6. Update notices and records. Add Swiss references, transfer countries and a Swiss processing record.
  7. Harden vendor contracts. Cover sub-processors, audits, incidents and training use.
  8. Set review dates. Models drift, laws change and vendors update terms.

For a board-level view, read Formiti's plan for AI governance across GDPR, FADP, PDPA and the EU AI Act.

Finally, keep the evidence. Regulators care about proof that controls operated, not just that they existed. The Swiss nFADP compliance checklist offers a useful companion for the Swiss items.

Common Mistakes to Avoid

  • Assuming GDPR compliance is enough. It is a strong base, but Swiss add-ons remain.
  • Copying EU privacy notices. Swiss references and transfer countries are often missing.
  • Relying on one representative. An EU representative does not cover Switzerland.
  • Treating the FADP as an admin issue. Criminal liability attaches to individuals.
  • Trusting adequacy blindly. You must still verify where data actually rests.
  • Ignoring shadow AI. Staff adopt tools faster than policies can keep up.
  • Waiting for a Swiss AI Act. The FADP already applies to AI today.

How Formiti Helps

Formiti is a global privacy and AI governance consultancy with offices in Zug, Dublin and Birmingham. Its team supports organisations that must satisfy several regimes at once.

Relevant services include:

Ready to close the gaps? Book a consultation with Formiti for a jurisdictional gap assessment before your next Swiss or EU launch.

Frequently Asked Questions

Does the Swiss FADP apply to AI services hosted outside Switzerland?

Yes, if the processing has effects in Switzerland. Hosting location does not remove the FADP.

Is GDPR compliance enough for Switzerland?

It covers most of the ground. However, Swiss-specific items remain. Examples include a Swiss representative where required, Swiss notice references and Swiss breach timing.

What is the biggest difference between the FADP and GDPR for AI?

Automated decisions and enforcement stand out. The FADP requires information and human review on request. It also imposes criminal fines on individuals.

Do I need both a Swiss and an EU representative?

Possibly. The appointments are separate. Each depends on its own scope conditions.

Is there a Swiss AI Act?

No. Switzerland chose a sector-specific approach. A consultation draft to implement the Council of Europe AI Convention is due by the end of 2026.

Does the EU AI Act apply to Swiss companies?

It can. The Act may apply if you place AI systems on the EU market. It may also apply if your output is used in the EU.

Which law has higher fines?

The GDPR has higher headline fines, up to EUR 20 million or 4% of turnover. However, FADP fines fall on individuals, which changes behaviour inside organisations.

Conclusion

AI services rarely sit under one privacy law. Instead, they cross borders by design. The Swiss FADP and the EU GDPR overlap heavily. Even so, their differences on legal basis, automated decisions, representatives and enforcement are real.

Therefore, the smartest approach is one programme with two annexes. Map your systems. Run one joint DPIA. Redesign automated decisions. Then keep evidence of every control.

Start with the gaps that carry personal liability. Then work outward. With Formiti's AI vendor risk management service, you can turn a complex dual-law challenge into a manageable routine.

This article is general information, not legal advice. Laws and deadlines change, so confirm current requirements with a qualified adviser before acting.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.