AI LAW RADAR · Daily Last verified 19 Aug 2026

Jurisdiction dossier

Switzerland: AI regulation & deadlines

No AI-specific statute is in force, and Switzerland is not in the EU or the EEA, so the GDPR does not supply an automated-decision rule here — art. 21 of the Federal Act on Data Protection of 25 September 2020 (SR 235.1) does, and it never prohibits anything. Its official rubric is «Duty to provide information in the case of an automated individual decision». Art. 21(1) requires the controller to inform the data subject about any decision based exclusively on automated processing that has a legal consequence for, or a considerable adverse effect on, the data subject — a disjunctive trigger whose second limb reaches further down than the GDPR's «similarly significantly affects». Art. 21(2) adds two reactive safeguards that arm only on request: the controller shall allow the data subject to express their point of view, and the data subject may request review by a natural person. Art. 21(3) disapplies both paragraphs where the decision is directly connected with the conclusion or processing of a contract between controller and data subject and the data subject's request is granted, or where the data subject has explicitly consented to the decision being automated — so the contract exception does not cover the declined loan or the rejected application, which is exactly where the duty bites. Art. 21(4) makes a federal body designate an automated decision as such, without any request. There is no right to an explanation of the logic. In force since 1 September 2023, fixed by Federal Council decision of 31 August 2022 with no transition period; the 1992 Act it replaced had no automated-decision provision at all. Scope is broad: art. 3(1) applies the Act to circumstances having an effect in Switzerland even if initiated abroad, and the art. 12(5) small-business exemption is from the record-keeping duty alone, not from art. 21. Enforcement is criminal and cantonal, not administrative — the FDPIC cannot impose a fine. Art. 60(1) sets a fine not exceeding CHF 250,000, on complaint, on private persons who wilfully provide false or incomplete information under arts. 19, 21 and 25–27 or wilfully fail to inform under arts. 19(1) and 21(1); refusing the art. 21(2) human review is not an offence, because para. 2 is not in the list. Art. 64(2) caps the alternative of fining the business itself at CHF 50,000, so the headline figure is aimed at the responsible individual. Five-year limitation under art. 66. 1 obligation tracked — 1 in force.

Binding — Binding sectoral Flagship law: revFADP art. 21

No AI-specific statute is in force, and Switzerland is not in the EU or the EEA, so the GDPR does not supply an automated-decision rule here — art. 21 of the Federal Act on Data Protection of 25 September 2020 (SR 235.1) does, and it never prohibits anything. Its official rubric is «Duty to provide information in the case of an automated individual decision». Art. 21(1) requires the controller to inform the data subject about any decision based exclusively on automated processing that has a legal consequence for, or a considerable adverse effect on, the data subject — a disjunctive trigger whose second limb reaches further down than the GDPR's «similarly significantly affects». Art. 21(2) adds two reactive safeguards that arm only on request: the controller shall allow the data subject to express their point of view, and the data subject may request review by a natural person. Art. 21(3) disapplies both paragraphs where the decision is directly connected with the conclusion or processing of a contract between controller and data subject and the data subject's request is granted, or where the data subject has explicitly consented to the decision being automated — so the contract exception does not cover the declined loan or the rejected application, which is exactly where the duty bites. Art. 21(4) makes a federal body designate an automated decision as such, without any request. There is no right to an explanation of the logic. In force since 1 September 2023, fixed by Federal Council decision of 31 August 2022 with no transition period; the 1992 Act it replaced had no automated-decision provision at all. Scope is broad: art. 3(1) applies the Act to circumstances having an effect in Switzerland even if initiated abroad, and the art. 12(5) small-business exemption is from the record-keeping duty alone, not from art. 21. Enforcement is criminal and cantonal, not administrative — the FDPIC cannot impose a fine. Art. 60(1) sets a fine not exceeding CHF 250,000, on complaint, on private persons who wilfully provide false or incomplete information under arts. 19, 21 and 25–27 or wilfully fail to inform under arts. 19(1) and 21(1); refusing the art. 21(2) human review is not an offence, because para. 2 is not in the list. Art. 64(2) caps the alternative of fining the business itself at CHF 50,000, so the headline figure is aimed at the responsible individual. Five-year limitation under art. 66.

checked 19 Aug 2026 primary source ↗

The Register

1 obligation
Switzerland Binding

revFADP art. 21 — the automated-decision article that never prohibits anything

Binds Every controller within the Act's scope, private or federal, with no size, sector or turnover threshold — enterprise, SME and federal body alike. The obligation is drafted onto «the controller» without qualification, and the small-and-medium carve-outs that exist elsewhere in the revFADP do not reach it: the exemption in art. 12(5) from keeping a record of processing activities, granted to businesses with fewer than 250 employees whose processing poses a low risk of a violation of personality, is an exemption from the record duty alone and has no counterpart for art. 21. Switzerland is not an EU or EEA member and the GDPR does not supply this rule domestically, so art. 21 is the operative automated-decision provision for anyone processing in or into Switzerland. Extraterritorial reach follows art. 3(1), under which the Act «applies to circumstances that have an effect in Switzerland, even if they are initiated abroad» — a marketplace test written more broadly than GDPR art. 3(2), with no establishment or targeting requirement on its face, so an offshore scoring engine producing a considerable adverse effect on a person in Switzerland is inside the scope. Art. 14 requires a controller with no domicile or registered office in Switzerland to designate a representative in Switzerland in the cases it lists. Hiring, credit scoring, insurance underwriting and tenant screening all sit squarely in the wording: each turns on a decision exclusively automated and each produces either a legal consequence or a considerable adverse effect. Two boundaries are worth stating because they are where the article stops. First, «based exclusively on automated processing» — a decision with a human materially in the loop is outside art. 21 altogether, and the Act supplies no gloss on how much review defeats exclusivity. Second, profiling as such is not caught: the revFADP defines profiling in art. 5(f) and high-risk profiling in art. 5(g), and attaches consequences to them elsewhere, but art. 21 is triggered by the decision and its effect, not by the profiling that fed it.. Article 21 of the Federal Act on Data Protection of 25 September 2020 (SR 235.1) is the closest thing Switzerland has to GDPR art. 22, and the difference starts with the heading, which is worth quoting because almost every secondary account renames it. The official English rubric is «Duty to provide information in the case of an automated individual decision» — not «automated individual decision-making», and not a prohibition. Nothing in the article forbids a solely automated decision. Art. 21(1) provides that «the controller shall inform the data subject about any decision that is based exclusively on automated processing and that has a legal consequence for or a considerable adverse effect on the data subject (automated individual decision)». The trigger is therefore disjunctive and the second limb is softer than the GDPR's: a «considerable adverse effect» reaches further down than «similarly significantly affects», and the Swiss text needs no legal consequence at all if the adverse effect is considerable. Art. 21(2) supplies the safeguard pair: «It shall on request allow the data subject to express their point of view. The data subject may request that the automated individual decision be reviewed by a natural person.» Both limbs are reactive — they arm only on request, and the controller owes nothing until asked. Art. 21(3) then disapplies paras 1 and 2 entirely where (a) «the automated individual decision is directly connected with the conclusion or the processing of a contract between the controller and the data subject and the data subject's request is granted», or (b) «the data subject has explicitly consented to the decision being automated». Limb (a) is narrower than it looks and is the one most often mis-summarised: the contract connection alone does not suffice, because the exception also requires that the data subject's request be granted. A solely automated contractual refusal — the declined loan, the rejected policy, the failed tenancy screen — is precisely the case the exception does not cover, so the duty bites hardest exactly where the outcome is adverse. Art. 21(4) is the public-sector rule: a federal body issuing an automated individual decision «must designate the decision accordingly», a labelling duty owed without any request, and para. 2 falls away where art. 30(2) of the Administrative Procedure Act of 20 December 1968 or another federal act denies the data subject a hearing before the decision is taken. There is no right to an explanation of the logic anywhere in art. 21. The nearest thing sits in the art. 25 right of access, which is a general access right and not an automated-decision one.

In force since 1 September 2023, and the date belongs to the totally revised Act rather than to any amendment of it. The Federal Act on Data Protection was adopted by the Federal Assembly on 25 September 2020; art. 74(2) left commencement to the Federal Council, which fixed it by decision (BRB) of 31 August 2022, and the consolidated Fedlex text carries the running head «of 25 September 2020 (Status as of 1 September 2023)» with the closing line «Commencement date: 1 September 2023». There was no transition period and no staged entry into force for art. 21: unlike the 2018 EU changeover there was no two-year runway, and unlike the Mauritian scheme there is no power to appoint different dates for different sections. The Act replaced the Federal Act on Data Protection of 19 June 1992 outright, and the 1992 Act contained no automated-decision provision at all, so 1 September 2023 is the first date on which any Swiss automated-decision rule bound a private controller. Two adjacent dates should not be carried into this row. The Data Protection Ordinance (DPO, SR 235.11) of 31 August 2022 commenced the same day but adds nothing on automated decisions. And the Council of Europe's modernised Convention 108+, which Switzerland signed on 10 October 2018 and whose art. 9(1)(a) carries a right not to be subject to a solely automated decision, is not yet in force — it needs 38 ratifications under its own amending-protocol terms and Switzerland's ratification followed the revFADP rather than preceding it, so the treaty is not an independent operative source here in the way the Malabo Convention is for Namibia. Convention 108 in its original 1981 form, which Switzerland ratified on 2 October 1997, has no automated-decision article. One live supersession watch: Switzerland and the EU concluded a package of bilateral agreements in 2025 whose institutional provisions could bear on the adequacy footing this Act was drafted to protect, and the European Commission's adequacy decision for Switzerland, adopted 15 January 2024 under GDPR art. 45, is subject to periodic review. Neither touches the text of art. 21, and neither is treated as changing it here.

Stated maximum penalty — CHF 250,000 — but on a natural person, on complaint only, and not for every breach of art. 21, and each of those three qualifications is load-bearing. The revFADP gives the Federal Data Protection and Information Commissioner no power to impose an administrative fine at all; this is the structural difference from the GDPR and the reason the headline figure is so often misread as a corporate exposure. Art. 60(1) provides that «on complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who: a. violate their duties under Articles 19, 21 and 25–27, in that they wilfully provide false or incomplete information; b. fail wilfully: 1. to provide information to the data subject in accordance with Articles 19 paragraph 1 and 21 paragraph 1». Three limits follow from that text. It reaches art. 21(1), the duty to inform, and it does not reach art. 21(2): a controller who receives a request for human review and simply refuses it commits no offence under art. 60, because para. 2 appears nowhere in the list. It requires wilfulness — negligence is not enough. And it is an offence prosecuted «on complaint» (Antragsdelikt), not ex officio. Art. 64 then decides who pays. Art. 64(1) routes corporate criminal liability to arts. 6 and 7 of the Federal Act of 22 March 1974 on Administrative Criminal Law, and art. 64(2) provides that «if a fine not exceeding 50,000 francs is under consideration and if the identification of the perpetrators in accordance with Article 6 ACLA requires measures that would be disproportionate in view of the potential penalty, the authority may decide not to pursue these persons but instead to order the business to pay the fine». So the CHF 250,000 maximum is aimed at the responsible individual, and the route to fining the undertaking instead is capped at CHF 50,000 and is available only as a proportionality shortcut. Art. 65(1) makes prosecution and adjudication a matter for the cantons, with the FDPIC able under art. 65(2) to file a complaint and exercise the rights of a private claimant; art. 66 sets a five-year statute of limitations. The FDPIC's own powers under art. 51 are corrective rather than pecuniary — it may order processing to be adjusted, suspended or terminated and data to be deleted. Impact tier: all entities.

In force · 1 Sep 2023 checked 19 Aug 2026 revFADP art. 21 ↗ high confidence

Questions & answers

From the data

When does revFADP art. 21 take effect in Switzerland?

revFADP art. 21 is already in force, with obligations live since September 1, 2023. No AI-specific statute is in force, and Switzerland is not in the EU or the EEA, so the GDPR does not supply an automated-decision rule here — art. 21 of the Federal Act on Data Protection of 25 September 2020 (SR 235.1) does, and it never prohibits anything. Its official rubric is «Duty to provide information in the case of an automated individual decision». Art. 21(1) requires the controller to inform the data subject about any decision based exclusively on automated processing that has a legal consequence for, or a considerable adverse effect on, the data subject — a disjunctive trigger whose second limb reaches further down than the GDPR's «similarly significantly affects». Art. 21(2) adds two reactive safeguards that arm only on request: the controller shall allow the data subject to express their point of view, and the data subject may request review by a natural person. Art. 21(3) disapplies both paragraphs where the decision is directly connected with the conclusion or processing of a contract between controller and data subject and the data subject's request is granted, or where the data subject has explicitly consented to the decision being automated — so the contract exception does not cover the declined loan or the rejected application, which is exactly where the duty bites. Art. 21(4) makes a federal body designate an automated decision as such, without any request. There is no right to an explanation of the logic. In force since 1 September 2023, fixed by Federal Council decision of 31 August 2022 with no transition period; the 1992 Act it replaced had no automated-decision provision at all. Scope is broad: art. 3(1) applies the Act to circumstances having an effect in Switzerland even if initiated abroad, and the art. 12(5) small-business exemption is from the record-keeping duty alone, not from art. 21. Enforcement is criminal and cantonal, not administrative — the FDPIC cannot impose a fine. Art. 60(1) sets a fine not exceeding CHF 250,000, on complaint, on private persons who wilfully provide false or incomplete information under arts. 19, 21 and 25–27 or wilfully fail to inform under arts. 19(1) and 21(1); refusing the art. 21(2) human review is not an offence, because para. 2 is not in the list. Art. 64(2) caps the alternative of fining the business itself at CHF 50,000, so the headline figure is aimed at the responsible individual. Five-year limitation under art. 66.

Who must comply with AI rules in Switzerland?

Current obligations bind, among others, Every controller within the Act's scope, private or federal, with no size, sector or turnover threshold — enterprise, SME and federal body alike. The obligation is drafted onto «the controller» without qualification, and the small-and-medium carve-outs that exist elsewhere in the revFADP do not reach it: the exemption in art. 12(5) from keeping a record of processing activities, granted to businesses with fewer than 250 employees whose processing poses a low risk of a violation of personality, is an exemption from the record duty alone and has no counterpart for art. 21. Switzerland is not an EU or EEA member and the GDPR does not supply this rule domestically, so art. 21 is the operative automated-decision provision for anyone processing in or into Switzerland. Extraterritorial reach follows art. 3(1), under which the Act «applies to circumstances that have an effect in Switzerland, even if they are initiated abroad» — a marketplace test written more broadly than GDPR art. 3(2), with no establishment or targeting requirement on its face, so an offshore scoring engine producing a considerable adverse effect on a person in Switzerland is inside the scope. Art. 14 requires a controller with no domicile or registered office in Switzerland to designate a representative in Switzerland in the cases it lists. Hiring, credit scoring, insurance underwriting and tenant screening all sit squarely in the wording: each turns on a decision exclusively automated and each produces either a legal consequence or a considerable adverse effect. Two boundaries are worth stating because they are where the article stops. First, «based exclusively on automated processing» — a decision with a human materially in the loop is outside art. 21 altogether, and the Act supplies no gloss on how much review defeats exclusivity. Second, profiling as such is not caught: the revFADP defines profiling in art. 5(f) and high-risk profiling in art. 5(g), and attaches consequences to them elsewhere, but art. 21 is triggered by the decision and its effect, not by the profiling that fed it.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Switzerland?

Stated statutory maxima include: revFADP art. 21 — CHF 250,000 — but on a natural person, on complaint only, and not for every breach of art. 21, and each of those three qualifications is load-bearing. The revFADP gives the Federal Data Protection and Information Commissioner no power to impose an administrative fine at all; this is the structural difference from the GDPR and the reason the headline figure is so often misread as a corporate exposure. Art. 60(1) provides that «on complaint, a fine not exceeding 250,000 francs shall be imposed on private persons who: a. violate their duties under Articles 19, 21 and 25–27, in that they wilfully provide false or incomplete information; b. fail wilfully: 1. to provide information to the data subject in accordance with Articles 19 paragraph 1 and 21 paragraph 1». Three limits follow from that text. It reaches art. 21(1), the duty to inform, and it does not reach art. 21(2): a controller who receives a request for human review and simply refuses it commits no offence under art. 60, because para. 2 appears nowhere in the list. It requires wilfulness — negligence is not enough. And it is an offence prosecuted «on complaint» (Antragsdelikt), not ex officio. Art. 64 then decides who pays. Art. 64(1) routes corporate criminal liability to arts. 6 and 7 of the Federal Act of 22 March 1974 on Administrative Criminal Law, and art. 64(2) provides that «if a fine not exceeding 50,000 francs is under consideration and if the identification of the perpetrators in accordance with Article 6 ACLA requires measures that would be disproportionate in view of the potential penalty, the authority may decide not to pursue these persons but instead to order the business to pay the fine». So the CHF 250,000 maximum is aimed at the responsible individual, and the route to fining the undertaking instead is capped at CHF 50,000 and is available only as a proportionality shortcut. Art. 65(1) makes prosecution and adjudication a matter for the cantons, with the FDPIC able under art. 65(2) to file a complaint and exercise the rights of a private claimant; art. 66 sets a five-year statute of limitations. The FDPIC's own powers under art. 51 are corrective rather than pecuniary — it may order processing to be adjusted, suspended or terminated and data to be deleted. Impact tier: all entities.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.