PHTM·

AI and the FDPA: what your SME must check

5 min readPHTM Consulting

Artificial intelligence adoption in Swiss SMEs is accelerating rapidly: 34% use it consciously in 2025 compared to 22% in 2024 according to the AXA/Sotomo study. But this adoption comes with a critical blind spot. Only 34% of SMEs have established clear rules about what data their employees can input into AI tools, according to 2025 sector data.

This gap exposes business leaders to concrete legal risks. The FDPA (Federal Data Protection Act) applies directly to AI-based processing according to the Federal Data Protection and Information Commissioner (FDPIC). Fines reach a maximum of CHF 250,000 for executives in cases of intentional violation, unlike the European GDPR which targets companies. If identifying the perpetrator represents disproportionate effort, the fine can be transferred to the company up to CHF 50,000.

The FDPA imposes several requirements on SMEs using AI. Manufacturers and operators of artificial intelligence systems must make transparent the purpose, functioning and source of processed data. This obligation affects even SMEs that integrate external AI tools.

Companies must maintain a register of processing activities, except exemption for those with fewer than 250 employees if processing presents limited risk. This exemption does not automatically apply to AI systems that handle sensitive data.

Rapid notification to the FDPIC becomes mandatory in case of data security breaches involving AI. Companies must also guarantee data protection by default and delete or anonymize personal data that is no longer necessary in their artificial intelligence systems.

The real daily risk

The main risk is not a sophisticated cyberattack but an employee entering sensitive information into a public tool without malicious intent, according to sector analyses. An employee who pastes a customer list into ChatGPT to "clean the data" or asks Claude to analyze a report containing personal data creates an immediate violation.

This scenario becomes more likely when only 23% of companies with fewer than 10 people have defined AI usage rules. Most executives underestimate this daily exposure.

Practical usage charter

An effective AI usage charter must specify four elements: which tools are authorized, what data can be entered, who verifies generated content and how to report an incident. This documentation can fit on half a page but covers essential legal obligations.

Public tools (ChatGPT, Claude, Gemini) require particular precautions. Their terms of use often allow analysis of entered data to improve their models. Paid "enterprise" versions of these tools generally offer more confidentiality guarantees.

Team training remains critical. Concretely explaining that you never enter names, email addresses, invoice amounts or medical data into a public tool is often sufficient. The concrete examples approach works better than abstract principles.

Simple internal audit

Your SME can verify its compliance with a quick audit. First question: is there a written policy on AI usage, even basic? Second check: do employees know what data they can or cannot enter into artificial intelligence tools?

Third control: is there an inventory of AI tools used in the company, including browser extensions and mobile applications? Fourth point: is there a procedure for reporting a data incident in an AI system?

If three out of four answers are negative, your legal exposure justifies rapid action. If only one answer is positive, the urgency becomes obvious.

Costs and alternatives

AI-FDPA compliance generally costs less than comprehensive AI support for an SME. A usage charter and team training represent a few thousand francs, versus tens of thousands for a fine.

Some SMEs can postpone these investments. If you use no AI tools and formally prohibit their professional use, specific FDPA obligations for artificial intelligence do not apply. This position becomes difficult to maintain when employees use browser extensions or applications integrating AI.

For very small structures (fewer than 5 people) without sensitive data, a clear and documented oral policy may suffice temporarily. But the rapid evolution of tools makes this approach fragile.

Frequently asked questions

Do free AI tools expose my SME more?

Yes, significantly. Free versions of ChatGPT, Claude or Gemini often use conversations to improve their models. Their terms of use are less protective than paid "enterprise" versions that offer confidentiality guarantees.

Must my 15-person SME maintain a register of AI processing?

Not automatically. The exemption applies to companies with fewer than 250 employees if processing presents limited risk. But if your AI systems process sensitive data (health, biometric data, information on prosecutions), the register becomes mandatory.

How to quickly train my teams on AI compliance?

Start with concrete examples: "Never enter customer names, email addresses or amounts into ChatGPT". This practical approach works better than theoretical training on data protection. A one-hour session with real use cases is often sufficient.

What are the first signs of a data breach with AI?

An employee who realizes they entered sensitive data into a public tool, a customer information leak traced to AI usage, or discovering that confidential data is circulating in conversations with intelligent assistants. Rapid declaration to the FDPIC limits sanctions.

Can I use AI to process data from my Swiss clients?

Yes, but with precautions. Choose tools with confidentiality guarantees, inform your clients about automated processing, and ensure you can delete their data from the AI system. "Enterprise" versions of large models generally offer these features.

AI-FDPA compliance does not require a complete overhaul of your processes, but demands systematic attention to data flows. A pragmatic approach, focused on your SME's real use cases, often suffices to cover legal obligations while preserving the benefits of artificial intelligence.

Our automation services include FDPA compliance audits for intelligent systems we implement. Want to assess your SME's exposure? Request a free diagnostic to identify your compliance priorities.