Compliance
Data protection and AI voice: what Swiss law actually requires
Do you need the caller's consent? May you record? What the FADP requires, and five false claims in circulation.
A phone assistant that answers on your behalf processes personal data: a number, a name, often a reason for the call, sometimes a medical appointment. The question comes up in almost every conversation, and the answers you find online are rarely good ones. Many are copied from the European GDPR, which does not work the same way. Others amount to one line on a vendor's page.
This article gathers what Swiss law actually requires, with a link to the text every time. It is not legal advice: for a specific situation, and above all in healthcare, talk to a lawyer. But you should be able to ask your provider the right questions once you have read it.
What the FADP requires, and what it does not
The Federal Act on Data Protection (FADP, SR 235.1) has been in force in its revised version since 1 September 2023. It says nothing about artificial intelligence, and that is on purpose. The Federal Data Protection and Information Commissioner confirmed as much in a statement in November 2023.
« La loi fédérale sur la protection des données (LPD), formulée de manière neutre du point de vue technologique, est donc directement applicable à l'utilisation de traitements de données basés sur l'IA. » (Translated from the French: “The Federal Act on Data Protection (FADP), which is drafted in technology-neutral terms, therefore applies directly to the use of AI-based data processing.”)
In other words: there is no special regime to wait for, and nothing justifies putting the subject off. The rules that apply to your customer file already apply to your voice assistant.
The principles are short (art. 6 FADP): lawfulness, good faith, proportionality, and purposes that are specified and recognisable to the data subject. Security comes on top of that (art. 8), meaning technical and organisational measures proportionate to the risk. Booking an appointment at a garage and booking an appointment with a psychiatrist do not call for the same level of care.
Do you need the caller's consent?
No, in the vast majority of cases.
This is the point the market gets wrong most often. The GDPR requires a legal basis for every processing operation, consent being one of them. The FADP does not work that way. A private company may process personal data with no legal basis and no consent. A justification within the meaning of art. 31 FADP only becomes necessary if one of three things happens (art. 30 FADP): you breach the principles of art. 6 and 8, the person has expressly objected to the processing, or you disclose sensitive data to a third party.
What you have to say, and when
The obligation that really concerns you is the duty to inform (art. 19 FADP). When you collect the data you must communicate, adequately and as a minimum: your identity and contact details, the purpose of the processing, and where applicable the recipients or categories of recipients. If the data goes abroad, you also have to state the country and the safeguard you are relying on (art. 19 para. 4).
Art. 20 releases you from this in particular where the person already has that information. In practice, for an inbound call, it is settled by two sentences the assistant says at the start of the call, plus an up to date privacy page.
Do you have to say that it is an AI?
The FDPIC is clear about it on its page on artificial intelligence: transparency covers the purpose, the way the system works and the sources of the data, and people must be able to know whether they are interacting with a machine, and whether what they say is used to improve the model. For an automated individual decision, add the right to have a natural person review it (art. 21 para. 2 FADP). And it always remains possible to object expressly to the processing (art. 30 para. 2 let. b).
Our reading, beyond the text: announcing the AI is also the right commercial decision. Someone who works out after three sentences that they were left believing they were talking to a person will remember nothing else about the call.
Are you allowed to record a call?
Here we leave the FADP for the Criminal Code, and it is stricter than many people assume. Art. 179ter of the Swiss Criminal Code punishes a party to a non-public conversation who records it without the consent of the other participants. The penalty goes up to one year of custody or a monetary penalty, and the offence is prosecuted on complaint.
There is an exception, art. 179quinquies, in the wording in force since 1 July 2023. It makes the recording non-punishable, and without prior warning, for conversations about orders, instructions, reservations or other business transactions of the same kind within a business relationship. This is the exception you see quoted everywhere. It is far narrower than it looks, and the FDPIC sets out the three restrictions itself.
The consequence for a voice assistant is direct, and rarely written down: an assistant taking reservations may fall within the exception, but the same assistant handling a complaint no longer does, and a recording reused to improve a model or for quality control falls out of it as well. The simple, solid answer is therefore to announce the recording, or not to keep the audio.
Can the data leave Switzerland?
Yes, and this is the second most widespread misconception. The FADP does not require hosting in Switzerland. It requires you to know where the data goes and on what basis (art. 16 and 17), and to say so.
- The transfer is lawful to a state that offers adequate protection. The list is annex 1 to the ordinance (DPO), and it is binding. Every EU and EEA state is on it.
- Failing that, you need approved standard contractual clauses, binding corporate rules, or one of the exceptions in art. 17.
- The United States was added with effect from 15 September 2024, but only for companies certified under the Swiss-U.S. Data Privacy Framework. If your provider is not certified, or stops being certified, adequacy no longer applies.
This is the most useful question to put to a provider, and it is not a trick one: where the database is, where the voice engine runs, which telephony operator carries the call, and under what regime each of them works. A provider that answers “hosted in Switzerland” without separating the three has not answered you. Ours are on our privacy page.
Do you need a record of processing activities?
Art. 12 FADP requires a record of processing activities and leaves the exception to the Federal Council. That exception is art. 24 DPO, and it is worth reading in full rather than summarised as “fewer than 250 employees, no record”.
The exemption is therefore conditional. A four-person practice whose assistant handles reasons for consultation all day long may well be processing sensitive data on a large scale, and fall back under the obligation. A garage of the same size, far less likely. Headcount alone does not settle it.
What is the real exposure?
The figures travel badly, so let us take them one at a time.
- The FDPIC does not impose fines. It opens investigations and takes administrative measures: adapt, suspend or stop a processing operation, delete data (art. 49 to 51 FADP). Fines are handed down by the cantonal criminal authorities.
- The maximum is CHF 250,000, and it hits the natural person, not the company. The company can be convicted, and only by way of exception, where the fine does not exceed CHF 50,000 and prosecuting an individual would be disproportionate (art. 64 para. 2 FADP).
- Only intentional conduct is punishable. Negligence is not. See the criminal provisions as the FDPIC presents them.
None of which makes the subject harmless. The real risk for an SMB is not the fine: it is a decision of the FDPIC forcing you to stop a processing operation your phone answering depends on, and the time an investigation costs.
Five false claims in circulation
Every one of these can be read today on the sites of providers selling in Switzerland.
| What you read | What the text says | |
|---|---|---|
| Consent | You need the caller’s consent | As a rule, neither legal basis nor consent (art. 30 and 31) |
| Hosting | You have to host in Switzerland | Transfer is lawful under conditions (art. 16 and 17) |
| Fines | The FDPIC can fine you CHF 250,000 | It orders measures. The cantons fine, and they fine a person |
| Record | Every SMB has to keep a record | Exempt under 250 employees, unless sensitive data on a large scale |
| Recording | You can record for quality purposes | Mass transactions, and as evidence only |
What this looks like in practice
Reduced to what to do before you put an assistant on your line:
- Say who you are, and why
Two sentences at the start of the call cover art. 19: the name of the business, and what the assistant does with what it is told.
- Announce that it is an AI
The FDPIC files this under transparency. It is also what avoids the one bad surprise the caller will remember.
- Do not record the audio, or announce it
A transcript and a summary are enough to run a phone answering service. If you keep the audio, art. 179ter applies and the exception is narrow.
- Write down where the data goes
Database, voice engine, telephony operator. Three lines on your privacy page, with the country and the safeguard.
- Sign a processing agreement
Art. 9 FADP governs the use of a processor, and your provider should be able to hand you one without you having to ask twice.
- Set a retention period
The proportionality of art. 6 translates into a number of days. Keeping a call history indefinitely is never the correct default.
None of this is specific to artificial intelligence. These are the obligations an outsourced phone answering service already carries. If you are not yet clear on what a voice assistant actually does with a call, start there. After that come our comparison of the two models and, if you are looking for the figures first, our article on pricing.
One last remark, which is not a legal one. In an interview for the Confederation's SME portal, Manuel Kugler, of the Swiss Academy of Engineering Sciences, puts his finger on what actually holds companies back:
« L'un des grands défis est la rapidité avec laquelle l'IA évolue. Les PME manquent généralement de temps pour se tenir au courant et évaluer correctement le potentiel de l'IA pour leur entreprise. » (Translated from the French: “One of the big challenges is the speed at which AI is moving. SMBs generally lack the time to keep up and to assess properly what AI can do for their business.”)
That holds for compliance too. The list above fits on one page, and a serious provider has already dealt with most of it for you.
Sources
- FADP (SR 235.1), official text on Fedlex, French version
- DPO (SR 235.11), official text on Fedlex, French version
- FDPIC, recording of conversations
- FDPIC, artificial intelligence and data protection
- FDPIC, statement of 9 November 2023 on AI
- FDPIC, disclosure of data abroad
- FDPIC, criminal provisions
- FDPIC, Swiss-U.S. Data Privacy Framework (15 September 2024)
- The Confederation's SME portal, interview with Manuel Kugler (SATW)
Hear Voko answer a call
Fifteen minutes, your own questions, and a clear quote at the end.