Most Swiss AI governance documents open by invoking GDPR. That single framing choice misstates which statute has jurisdiction, and everything built on top of it inherits the error.
Key points
- A Swiss organisation deploying AI is governed primarily by the FADP, not the GDPR, but most Swiss compliance writing defaults to GDPR language anyway.
- The GDPR still applies, through a genuine EU nexus rather than by default or by convention.
- Getting the order backwards changes which regulator has jurisdiction, which breach clock starts, and which legal basis needs justifying.
- The fix is a two-line jurisdictional statement at the front of the document, not a rewrite of the compliance programme.
The pattern
Search for an AI governance checklist for Switzerland and most of what comes back is a GDPR checklist with a Swiss company’s name at the top. Impact assessments modelled on GDPR Article 35. Legal-basis language lifted from Article 6. Breach timelines quoting the 72-hour standard. All applied by default to organisations whose primary statute is the Federal Act on Data Protection.
This is not a pedantic distinction. The FADP and the GDPR are separate instruments, from separate legislatures, with different mechanics in several places that matter operationally.
Where they actually differ
Breach notification. The GDPR requires notification to the supervisory authority within 72 hours in most cases. The FADP sets no fixed hour-based deadline; it requires notification as soon as possible. That is materially different, and arguably more demanding, because there is no clean deadline to plan against.
Legal basis. The GDPR’s six lawful bases are a specific statutory list. The FADP is structured differently, and legitimate-interest reasoning under the FADP does not automatically inherit GDPR case law or guidance on the concept.
Regulator. GDPR violations concern an EU member state’s supervisory authority. FADP compliance sits with the Swiss Federal Data Protection and Information Commissioner: a different regulator, a different enforcement posture, different guidance.
Impact assessments. Both frameworks have them, but they are not drop-in equivalents. A DPIA built to satisfy GDPR Article 35 criteria does not automatically satisfy what an FADP-primary assessment should evaluate, even though the two documents look superficially similar.
None of this makes the two frameworks opposed. In most practical respects they are aligned in spirit, both built on data minimisation, purpose limitation and accountability. But “similar in spirit” and “the same statute” are different claims, and only one of them is true.
When the GDPR actually applies to a Swiss organisation
Through nexus, not through geography or convention. Three questions settle it:
- Do we process the data of EU-resident customers?
- Do we have EU-based staff, or an EU subsidiary or parent company?
- Does our AI system process EU residents’ data as a matter of course, even if the organisation is entirely Swiss?
If the answer to any of these is yes, the GDPR applies alongside the FADP. Not instead of it, and not as the senior partner. The FADP remains the organisation’s own primary statute; the GDPR is a parallel obligation triggered by the nexus, running concurrently rather than superseding.
Why the ordering matters in practice
Get the hierarchy backwards in an internal governance document and three things go quietly wrong.
The wrong regulator gets named as the one to notify in a breach scenario, which costs time exactly when time is short.
Legal-basis language gets borrowed from case law that does not govern the FADP-primary parts of the processing, producing a document that looks rigorous but rests on the wrong authority.
Internal literacy training, itself an obligation under Article 4 of the AI Act where that applies through nexus, teaches staff the wrong starting framework, which then propagates into every decision they make about the system afterwards.
The fix is short
One clear paragraph at the top of any AI governance or data protection document: this organisation is governed primarily by the Swiss FADP; the GDPR applies in parallel where a specific nexus exists. Name the nexus.
That single framing decision, stated explicitly rather than assumed, keeps everything built on top of it anchored to the statute that actually has jurisdiction.
This describes the general FADP and GDPR relationship for a Swiss organisation with EU touchpoints and is not legal advice. The specific nexus analysis for any given organisation should be confirmed with counsel.
