ChatGPT in Switzerland: what the law asks, and where your data goes

ChatGPT in Switzerland: what the law asks, and where your data goes

Yves Zumbühl
Yves Zumbühl

People searching for "ChatGPT Switzerland" are usually not asking about availability. The service has worked here for years, you can pay in francs or dollars, and nobody needs a VPN. The real question almost always comes from a company, and it is: are we allowed to use this, and where do our data go?

What Swiss law actually requires

Switzerland has been governed by the revised Federal Act on Data Protection (FADP) since 1 September 2023. It was deliberately aligned with the GDPR but is not identical: less formalistic, lower fines, and the sanction usually falls on the responsible natural person rather than the company. For the practical use of an AI service, three duties follow, and none of them says "Swiss servers".

You must be transparent when personal data go abroad. You must respect the processing principles, meaning good faith, proportionality, purpose limitation and data security. Unlike under the GDPR, private companies do not need a legal basis for every processing operation: processing is permitted in principle, and a justification (consent, overriding interest, or statute) becomes necessary only where it unlawfully breaches personality rights. The duty to have a statutory basis falls on federal bodies, not private firms. And for outsourcing you need a data processing agreement binding the processor to the same level of protection. The Swiss data protection commissioner publishes the authoritative guidance.

The US is not blanket-unsafe in this picture: the Federal Council recognises the Swiss-U.S. Data Privacy Framework, provided the American recipient is certified. Whether a given vendor is can be looked up in the official list.

Many Swiss companies are also subject to the GDPR on top of this, though not merely because they process some EU residents' data. Without an establishment in the EU it bites only once, under Art. 3(2) GDPR, you offer goods or services to people in the EU or monitor their behaviour. If either applies, checking only against Swiss law is checking too little.

None of this is legal advice, and your specific case belongs with your legal team. But the direction holds: a US service is not forbidden per se in Switzerland, and with a certified recipient the transfer abroad needs no additional safeguards either. What remains is accountability: transparency, respecting the processing principles, and a clean processing agreement.

Where it genuinely gets tight: professional secrecy

The point where the discussion turns is not the data protection act but Art. 321 of the Swiss Criminal Code. Doctors, lawyers, pharmacists, psychologists and their auxiliary staff are bound by professional secrecy, and breaching it is a criminal offence, not an administrative fine. For banks, banking secrecy comes on top.

Consent to data processing only goes so far here, and the question "who could theoretically access these data" suddenly carries criminal weight. It is precisely in these professions that we see the strictest hosting requirements, usually for good reason.

A "Swiss data centre" is not the same as Swiss jurisdiction

The most common error: you read "hosted in Switzerland" and consider the matter closed. Under 18 U.S.C. § 2713 the US CLOUD Act obliges providers of electronic communication and remote computing services subject to US jurisdiction to hand over data in their possession, custody or control, explicitly regardless of where it is stored. It does not reach every US-headquartered company across the board, but it does reach exactly the hyperscalers and model providers this decision is about. Whether a Swiss subsidiary changes anything is not a question of form but of actual control, and US courts have tended to read "control" broadly.

So these are three separate questions, not one: which country the servers stand in, which company operates them, and which law that company is subject to. We took this apart in detail in a post on data residency, including the trade-offs a stricter tier costs you in model choice and speed.

When Swiss hosting is worth it, and when it isn't

Honestly: not always. The most capable models today come predominantly from US providers, and Swiss hosting often means a smaller selection and sometimes slower answers. For a marketing team drafting copy, that is a bad trade.

For a medical practice, a law firm, a fiduciary or a public authority the balance shifts sharply. Professional secrecy does not, as a matter of law, mandate Swiss servers, since processing abroad can be permissible with the right contractual and technical safeguards, but it does shift the burden of justification. Here Swiss hosting is simply the option that is easiest to defend. And for everyone in between the workable rule is: choose the strictest tier the use case genuinely needs, not the strictest tier that exists.

We built botts.ai so that this tier is a setting rather than a property of the vendor: servers in Switzerland, free choice of model with the hosting country visible per model, and no training on your data. If you are evaluating what a ChatGPT alternative has to deliver for a Swiss company, that is the starting point. The model overview shows where each model runs, and the security page sets out how we handle the data along the way. If your question is less about location and more about a company-wide AI on your own knowledge, the post on the internal ChatGPT covers that case instead.

Have a specific compliance requirement, professional secrecy for instance? Get in touch and we'll help you pick the right tier.

Read next

BOTTS.AI