GDPR-Compliant AI Tools: What Swiss Companies Need to Check
Switzerland's revised Data Protection Act (DSG) has been in effect since September 2023. If you use AI tools that process personal data - such as applicant or customer data - you remain responsible under data protection law, even when an external provider handles the processing.
What to check when choosing a provider
1. Where is the data stored?
A provider that clearly communicates which country the data is stored in builds trust. If a provider doesn't state this, it's worth asking directly.
2. Is data used to train the AI?
Reputable providers explicitly rule out using submitted customer or applicant data to train the underlying AI models.
3. Are there clear deletion policies?
Personal data can't be kept indefinitely. A tool should offer defined, adjustable retention periods - and allow deletion on request.
4. Is there a data processing agreement?
If an external provider processes personal data on your behalf, a proper data processing agreement is required - a serious provider should offer one without you having to ask.
5. Who are the sub-processors?
Many AI tools rely on other external services themselves (hosting, AI model providers). Transparency about who's involved behind the scenes belongs in a serious privacy policy.
The human decision still matters
Especially for automated evaluations (e.g. in recruiting), a human should always make the final call - a fully automated decision without human review is legally risky under data protection law.
All 147codez tools are built GDPR- and DSG-compliant, with clear retention periods and data processing agreements with every service provider.
Learn more about our tools