Lukas Huber
KI-Berater für Schweizer KMU
Since 1.9.2023, the revised Swiss FADP applies to all SMEs. Learn why Swiss hosting is essential and how to use ChatGPT in a DSG-compliant way.
Key Takeaways
- ▸Seit 1. September 2023 gilt das revidierte DSG auch für KMU; eine Kleinunternehmen-Ausnahme existiert nicht, daher müssen alle Personendaten DSG-konform gehostet werden.
- ▸Für Schweizer KMU mit EU-Kunden greift die DSGVO: Bereits eine deutschsprachige Website reicht, bei Verstössen drohen Bussen bis 4 Prozent des Jahresumsatzes.
- ▸Schweizer Server sind nicht automatisch EU-konform, aber mit DSGVO kompatibel; Anbieter unterliegen dem strengen Fernmeldegeheimnis, was Datenschutz erhöht.
- ▸Beim Einsatz von Cloud-Diensten und KI-Tools wie ChatGPT müssen KMU sicherstellen, dass keine Personendaten auf ausländische Server gelangen, besonders bei amerikanischen Anbietern.
Frequently Asked Questions
Is my Swiss SME affected by the revised DSG?+
Yes, the revised Swiss Data Protection Act (DSG) has been in force since 1 September 2023. Importantly, there is no small business exemption. The law applies to practically every company that processes personal data – and almost all businesses do. Even maintaining a customer database in Excel, sending newsletters, managing employee data, or running a contact form on your website is subject to the DSG. The requirements include increased transparency obligations towards affected individuals and technical security measures. DSG-compliant Swiss hosting is therefore no longer a nice-to-have in 2025 but a fundamental duty for every SME.
Does the GDPR also apply to Swiss companies?+
Yes, the EU GDPR can become relevant for Swiss SMEs as soon as they have customers in the EU. Operating a German-language website or an online shop can already be sufficient to fall within the scope of the GDPR. What matters is not the size of the company, but whether you offer goods or services to EU citizens or monitor their behaviour. Violations can lead to fines of up to 4 percent of annual turnover. Even though Switzerland is not part of the EU, Swiss companies with EU contacts must therefore comply with both the DSG and the GDPR, which makes compliance more complex.
Why are Swiss servers important for DSG compliance?+
Swiss servers are the foundation of DSG compliance because hosting providers in Switzerland are subject to strict telecommunications secrecy. This protects data better than some foreign providers. Swiss servers are not automatically subject to EU directives, but they are compatible with the GDPR. For Swiss SMEs, this is the easiest way to meet the requirements of both the DSG and the GDPR. Storing personal data on servers in countries with inadequate data protection standards risks violations. Choosing a Swiss hosting provider minimises this risk and ensures that data processing remains traceable and legally secure.
What is the difference between the DSG and the GDPR?+
The DSG is the Swiss data protection act and applies to companies in Switzerland that process personal data – regardless of size. The GDPR is the EU General Data Protection Regulation and only applies to Swiss companies additionally if they offer goods or services in the EU or monitor the behaviour of EU persons. Both laws require similar principles, such as data minimisation, transparency, and security measures. However, there are differences in fines: the GDPR threatens up to 4 percent of annual turnover, while the DSG has its own sanctions. Swiss SMEs should keep both regulations in mind if they have EU customers.
May I use AI tools like ChatGPT with personal data?+
AI tools like ChatGPT can be useful, but they must not cause personal data to end up unprotected with third parties. The revised DSG and the GDPR require you to process personal data securely. When you type text into public AI tools, this may mean transferring data to servers abroad. Using such tools is generally permitted if you anonymise the data or ensure that processing is DSG-compliant. The guide emphasises that Swiss servers and clear internal rules help you use AI tools without endangering data. So carefully check which data you enter into AI tools before doing so.
What consequences can result from violations of the DSG and GDPR?+
Violations of the GDPR can result in fines of up to 4 percent of annual turnover – this also applies to Swiss companies with EU customers. The revised DSG also provides for sanctions, including fines for those responsible and for data protection violations. In addition, supervisory authorities may order measures such as information or deletion obligations. For SMEs, reputational damage is also significant alongside the financial consequences. Using DSG-compliant Swiss hosting and implementing legal obligations significantly reduces these risks. The principles are: document, inform, and ensure secure data processing.
Related Articles
Grab the AI-Readiness Check.
10 questions, 5 minutes, you'll see exactly where your SME stands with AI today. Plus field-tested articles straight to your inbox.
100% free · No spam · Unsubscribe anytime



