Companies using AI tools like ChatGPT, Copilot or similar services are almost always processing personal data, even when it does not look that way. Switzerland's revised Data Protection Act (revDSG) applies the same principles here as to any other data processing: a legal basis, transparency towards the people affected, and a contract with the provider. This article is an orientation, not legal advice for your specific situation.
The revDSG has been in force since September 2023, but the fast spread of AI tools in everyday work only now makes the question concrete for many companies: what used to be a theoretical risk now touches almost every department, from customer service to HR.
Where personal data ends up in AI tools without anyone noticing
An employee pastes a customer enquiry into ChatGPT to draft a reply. A recruiter uploads a CV to have it summarised. A consultant adds notes from a client meeting into an AI tool to produce minutes. In all three cases, personal data gets transferred to an outside provider, often without anyone realising they had just carried out data processing in the sense the revDSG means.
The key points of the revDSG for AI use
- Legal basis: processing personal data requires a legitimate reason, such as an existing contract, consent, or an overriding interest of the company.
- Transparency: the people affected generally need to know their data is being processed, even when an AI tool is involved behind the scenes.
- Data processing agreement: using an external provider such as an AI tool usually requires a contract that sets out how the provider may handle the data.
- Data transfer abroad: many AI providers process data in the US. That is not automatically forbidden under the revDSG, but it calls for additional safeguards where no adequate level of data protection exists.
US cloud tools: the blind spot for many companies
Most large AI providers are US companies, even when they run servers in Europe. That means server location alone does not create security, because US laws like the CLOUD Act can require US companies to hand over data worldwide. For companies, that means looking carefully at what contracts and safeguards a provider actually offers when choosing one, rather than relying on marketing claims alone.
Practical steps for everyday business
- Write internal guidelines: which AI tools are allowed, what data may go into them, and what may not.
- Train staff: most data protection problems come not from bad intent but from nobody realising that copying and pasting into an AI tool counts as data processing.
- Anonymise where possible: remove or replace names, addresses or customer numbers before entering data.
- Check contracts: before adopting a new AI tool, confirm whether a data processing agreement exists and what it covers.
These steps pair well with an AI strategy in 5 steps, so data protection is built in from the start rather than fixed afterwards. For an overview of where AI makes sense inside your own business, see the article on AI in SMEs.
This article is not a substitute for legal advice: whether a specific case of data processing is permitted depends on the individual situation, and that is worth a conversation with a specialised lawyer. For strategic guidance on AI in your company, see the AI consulting page.
Want to put this to work for your business? We review your website for free in classic and AI search and show the biggest levers.