Walterdesk
← Back to blog
Compliance8 min read

LPD and Generative AI: What Obligations for Swiss Companies?

The new Federal Act on Data Protection applies fully to generative AI tools. An overview of the concrete obligations for SMBs deploying ChatGPT or similar solutions.

Since the entry into force of the new Swiss Federal Act on Data Protection (FADP/nLPD) on 1 September 2023, any Swiss company processing personal data is subject to strengthened obligations: transparency, security, minimisation, and accountability. The massive influx of generative AI tools into daily workflows puts these obligations in a new light, as every prompt sent to an AI assistant can contain personal data of clients, employees, or partners.

The first point of attention concerns the transfer of data abroad. Article 16 FADP prohibits the communication of personal data to a country that does not offer an adequate level of protection without appropriate guarantees. However, most consumer AI services process requests on servers located in the United States. A fiduciary copying an extract of client accounting into a public chatbot is therefore legally performing an international transfer of data, often without a solid contractual basis.

The second point relates to the duty to inform. The individuals concerned must know that their data is being processed by an AI system, for what purpose, and by which subcontractor. This requires updating the company’s privacy policy and, in some cases, client contracts. An SMB using AI to pre-draft responses to client files without informing them is exposing itself to well-founded complaints.

Third requirement: security of processing. Article 8 FADP imposes technical and organisational measures adapted to the risk. Concretently, this means encryption of data at rest and in transit, access control, logging, and the ability to delete data on request. With a public shared AI service, the company has no real control over these parameters; with a dedicated instance hosted in Switzerland, it can document every measure precisely.

Finally, the FADP establishes the rights of data subjects: access, correction, deletion, and objection. If your employees' conversations are stored with a foreign provider that potentially uses them to train its models, honouring a deletion request becomes practically impossible. Control over the data lifecycle is therefore a prerequisite, not an option.

In practice, three measures allow for the compliant deployment of generative AI: choosing a solution where data remains in Switzerland with an identified subcontractor, guiding usage through a clear internal policy (what data can or cannot be submitted to the AI), and keeping an up-to-date registry of processing activities that includes the new tool. A private AI instance like Walterdesk structurally addresses the first point and greatly facilitates the other two thanks to centralised administration and audit logs.

Ready to take action?

Test Walterdesk for free for 14 days, no credit card required.

LPD and Generative AI: What Obligations for Swiss Companies? | Walterdesk