Compliance

The Swiss Data Protection Act (nLPD) and artificial intelligence: what Swiss businesses need to know in 2026

The Swiss Data Protection Act (nLPD) and artificial intelligence: what Swiss businesses need to know in 2026

The new Swiss Federal Act on Data Protection (nLPD) has been in force since 1 September 2023. Nearly three years on, many Swiss businesses have still not clarified how it applies to the artificial intelligence solutions they use or are considering adopting.

The most common question we receive is this: “Is our clients’ data safe if we use an AI agent or a document pipeline?”

The answer depends on how the system is built. Not all AI systems are equal from the standpoint of nLPD compliance — and the difference between a compliant system and a non-compliant one is not always visible from the outside.

1. The nLPD in brief — what changes compared to the old LPD

The nLPD has modernised the Swiss data protection framework, bringing it closer to the European GDPR while retaining features specific to the Swiss legal system.

The most relevant changes for businesses using AI:

Broader definition of personal data. The nLPD explicitly includes genetic and biometric data among the categories requiring special protection.

Privacy by design obligation. Systems that process personal data must be designed with data protection as a foundational element, not as a later add-on.

Greater transparency. Data subjects have the right to know when their decisions are influenced by automated systems, and to request a human review.

Breach notification obligation. Data breaches must be reported to the Federal Data Protection and Information Commissioner (FDPIC) within defined timeframes.

Stricter penalties. Violations can result in fines of up to CHF 250,000 for the responsible natural persons.

2. Why AI poses specific challenges to the nLPD

AI systems process data differently from traditional software, and this creates specific challenges for nLPD compliance.

AI models learn from data. An AI system that is trained on client data incorporates that information into the model.

Automated decisions require transparency. If an AI agent makes or influences decisions concerning people — approving a loan, responding to an insurance request, classifying a client — the nLPD requires that the data subjects be able to request an explanation and a human review.

Data crosses borders. Many commercial AI systems process data on foreign servers — typically in the United States.

Logs and conversations are personal data. Conversations with an AI agent contain personal data. They must be managed, stored and deleted in accordance with nLPD principles.

3. The four key requirements for nLPD-compliant AI systems

An nLPD-compliant AI system must meet these four fundamental requirements.

1. Swiss or equivalent data residency. The personal data of Swiss clients must be processed on infrastructure with servers in Switzerland or in countries with a level of protection recognised as equivalent.

2. No use of data for training. Client data must not be used to train third-party AI models. This is a critical point: many commercial AI providers use user conversations and data to improve their own models.

3. Traceability and audit trail. Every operation of the AI system must be traced: which data it accessed, which actions it performed, and when.

4. Right to human review. When the AI system influences decisions concerning people, those people must have the right to request that the decision be reviewed by a human operator.

4. Swiss data residency: what it means in practice

“Swiss data residency” does not simply mean that the provider company is headquartered in Switzerland. It means that the physical servers on which the data is processed and stored are physically located in Switzerland.

This distinction matters because many IT providers are legally based in Switzerland but use foreign cloud infrastructure — typically AWS, Google Cloud or Azure with regions in Germany, Ireland or the United States.

To verify the real data residency of an AI system, ask the provider:

  • In which cloud region is the data processed? (e.g. Switzerland North on Azure, eu-central-1 on AWS)
  • Is the data ever replicated or transferred to foreign regions for backup or disaster recovery?
  • Where are the system’s conversations and logs stored?
  • Where are the AI models that process the data run?

Atenek uses infrastructure with data residency in Switzerland for all Swiss clients as standard — not as an optional add-on.

5. What to ask your AI provider

Before adopting any AI system that processes your clients’ personal data, ask the provider for a written answer to these questions:

  1. Where is our clients’ data physically processed and stored?
  2. Is our clients’ data used to train AI models? In what form?
  3. Is there a complete audit trail of all system operations?
  4. How is data deletion handled upon request?
  5. How are data breaches handled and within what timeframes are they notified?
  6. Has the system been assessed by a legal professional for nLPD compliance?

If the provider cannot answer these questions precisely, or gives vague answers, that is a warning sign.

nLPD compliance is not an optional feature of an AI system — it is a legal requirement.

FAQ

Does the nLPD also apply to small Swiss businesses? Yes. The nLPD applies to any private entity that processes personal data in Switzerland, regardless of size.

What does a company that is not nLPD-compliant risk? Fines go up to CHF 250,000 for the responsible natural persons.

Is an AI system based on ChatGPT nLPD-compliant? It depends on how it is configured and which infrastructure it uses. The commercial models from OpenAI, Google and others process data on servers mainly in the United States.

How do I know whether my AI provider is truly nLPD-compliant? Ask for a written statement specifying where the data is processed, whether it is used for training, and how the right to human review is guaranteed.

Is Atenek nLPD-compliant? Yes. For all Swiss clients we use infrastructure with data residency in Switzerland, the data is never used to train third-party models, every operation is traced with a complete audit trail, and every system includes human review mechanisms.

Want to explore a similar use case?

Contact us for an analysis of your processes.

Richiedi l'analisi →

Risposta entro 24 ore lavorative

Scrivici su WhatsApp