Compliance9 min readPublished on 2026-06-24

Claude AI in Switzerland: revFADP/nFADP Compliance and Data Sovereignty

How Swiss companies use Claude AI in line with the revFADP/nFADP: data sovereignty, no-training, data residency and the sticking points for banks, pharma and law firms.

In a nutshell

Switzerland has its own data protection law (revFADP/nFADP, in force since September 2023), not the GDPR. Claude can be used compliantly: Anthropic does not train on company data, offers a DPA, configurable retention and processing in controlled regions. The real sticking point for Swiss banks, pharma and law firms is data residency and professional secrecy, solvable with a privacy-by-design architecture.

Data protection in Switzerland is not the GDPR (but it looks like it)

Switzerland has its own law: the revised Federal Act on Data Protection — revFADP in English, also known as revDSG in German and nLPD in French — has been in force since 1 September 2023. It is not the European GDPR, but it closely resembles it.

The principles are familiar: lawfulness and transparency of processing, data minimisation, security, and strong accountability for whoever processes the data. Companies must keep a record of processing activities, notify breaches to the Federal Data Protection and Information Commissioner (FDPIC) and, in several cases, carry out an impact assessment.

The practical difference for those adopting AI does not lie in the principles but in a cultural sensitivity: in Switzerland, data residency and confidentiality carry more weight than elsewhere. Before sending a single document to an AI model, a Swiss bank or pharmaceutical company wants to know exactly where that data ends up and who can see it.

The real sticking point with AI: where the data ends up

When you use a language model, the question that matters is one: is my data used to train the model, and where is it processed?

This is where many Swiss companies get stuck. The fear — often legitimate for free consumer tools — is that confidential data ends up in the model's training or on servers whose jurisdiction is unknown. For a company bound by banking or professional secrecy, that is a risk you cannot take.

The good news is that this concern, with the right enterprise tools, is solvable at the contractual and architectural level. It is not a matter of blind trust: it is a matter of written guarantees and deployment choices.

Claude and compliance: what Anthropic actually offers

With Claude, the levers for compliance are there, and they are concrete.

No training on company data: on the Claude for Work plans (Team and Enterprise) and via the API, Anthropic does not use the contents of conversations or API calls to train its models. It is a contractual guarantee, not a checkbox setting.

Data Processing Agreement and configurable retention: Anthropic provides a DPA and, on the enterprise and API plans, reduced or zero retention options for those who need them.

Choice of processing region: by using Claude through Amazon Bedrock or Google Vertex AI you can pin inference to specific European regions, keeping processing within the EU/EEA — recognised as adequate by Switzerland.

Enterprise controls: SSO, audit logs, role management and usage policies, which map directly onto the accountability requirements of the revFADP. For the broader European picture see our guide on data sovereignty and AI in Europe and the one on Claude and the GDPR.

Want to use Claude in Switzerland, compliant with the revFADP?

30 minutes to discuss your specific case.

Book a call

Banking secrecy, professional secrecy and health data

The three most sensitive Swiss sectors deserve specific attention.

Banks and wealth management: banking secrecy (Art. 47 of the Banking Act) and FINMA supervision impose strong caution. Sending identifiable client data to an external service requires minimisation (pseudonymisation or removal of identifiers), no-training guarantees and, ideally, processing in a controlled region. With these measures, document analysis, research synthesis and report preparation become viable.

Pharma and life sciences: pharmacovigilance data, clinical trials and health data are sensitive personal data. The same principles apply: minimisation, DPA, controlled deployment. We explore the topic in Claude for pharmacovigilance.

Law firms: attorney professional secrecy is almost absolute. The path is the same as for law firms: no identifiable data in prompts without the right guarantees, and an architecture that keeps control of the data.

A privacy-by-design architecture for Switzerland

Compliance is not bought: it is designed. A Claude deployment built for the Swiss context starts from four choices.

Data residency: choosing the access channel (direct API, Bedrock, Vertex) and the region according to where the data is allowed to sit.

Upstream minimisation: filtering and pseudonymising data before it reaches the model, so that sensitive data never leaves the perimeter.

Contracts and documentation: a signed DPA, an up-to-date record of processing activities and, where needed, a data protection impact assessment.

Control and traceability: audit logs, access management and internal usage policies. On these pillars you build a system that an auditor — or FINMA — can verify. It is the same approach we take with the GDPR for companies: privacy-by-design, not a rubber stamp after the fact.

How to get started, without risk

The practical path is simple and prudent.

You start with an assessment: which processes carry the most value, which data they touch, what level of sensitivity. Then a pilot on a low-risk use case — internal documentation, research, synthesis — with the right data and the right guarantees. You measure, you validate compliance, and only then do you scale.

Maverick AI supports Swiss companies — in Ticino, in the French-speaking region and in German-speaking Switzerland — along this path: from choosing a revFADP-compliant architecture through to implementation and team training. If you are evaluating Claude for your organisation, let's talk.

FT
Federico Thiella·Founder, Maverick AI

Works with European companies on Claude and Anthropic ecosystem adoption. Has led AI implementations in private equity, consulting, manufacturing and professional services.

LinkedIn

Want to use Claude in Switzerland, compliant with the revFADP?

Maverick AI designs Claude implementations compliant with Swiss data protection, for banks, pharma, law firms and companies in Ticino and the French-speaking region. Let's discuss your case.

Write to us

Frequently asked questions: Claude AI and data protection in Switzerland

Claude can be used in compliance with the revFADP/nFADP, but compliance depends on how you implement it, not on the model itself. The levers are there: Anthropic does not train on company data (Work/Enterprise plans and API), provides a Data Processing Agreement, configurable retention and enterprise controls (SSO, audit logs). You then need the right architectural choices — data residency, minimisation, documentation — to meet the accountability the law requires.
No, not on the business plans. On Claude for Work (Team and Enterprise) and via the API, Anthropic does not use the contents of conversations or API calls to train its models: it is a contractual guarantee. Be careful, however, with free consumer tools, where the terms are different.
Yes. By using Claude through Amazon Bedrock or Google Vertex AI you can pin inference to specific European regions, keeping processing within the EU/EEA, recognised as adequate by Switzerland. It is the standard way to meet the data residency requirements of Swiss banks and healthcare companies.
Yes, with the appropriate safeguards. Banking secrecy (Art. 47 of the Banking Act) and FINMA supervision require data minimisation (pseudonymisation or removal of client identifiers), no-training guarantees and processing in a controlled region. With this architecture, use cases such as document analysis, research and reporting are fully viable.
Yes. Pharma (pharmacovigilance and clinical data) and law firms (professional secrecy) follow the same principles: upstream minimisation, DPA, controlled deployment and traceability. They are among the sectors where a compliant implementation makes the biggest difference, because the value of the use cases is high and the confidentiality constraint is at its maximum.

Stay informed on AI for business

Get updates on Claude AI, business use cases and implementation strategies. No spam, just useful content.

Want to learn more?

Contact us to find out how we can help your company with tailored AI solutions.

Anthropic implementation partner in Italy. We work with companies in PE, pharma, fashion, manufacturing and consulting.

Book an introductory call
Claude AI in Switzerland: nFADP Data Protection 2026 | Maverick AI