1. The DPA also applies to processing using AI
The Federal Commissioner for Data Protection and Transparency indicates that the Federal Data Protection Act directly applies to AI-based treatments. It particularly highlights the requirements for transparency on the purpose, operation and sources of data.
This page provides an operational method and does not replace legal advice adapted to the activity, data and persons concerned.
2. Inventory before connecting
For each process, note the categories of data consulted, their origin, the purpose, the recipients, the useful life and the systems concerned. Separate necessary data from simply available data. An entire box, shared drive or entire CRM should not be exposed if a few folders or fields are enough.
Could we simply explain to the person concerned why this data is used and what the agent prepares or decides?
3. Limit permissions and actions
Distinguish between reading, creating drafts, modifying and sending. The principle of least privilege consists of authorizing only what is necessary for the use case. Involving, sensitive or unusual actions may remain subject to an authorized person.
Also provide for revocation, rotation of identifiers, history of actions and a procedure when the result is incorrect. Security is about more than server location.
4. Document suppliers and responsibilities
Identify the data controller, subcontractors, applicable processing locations, possible transfers and contractual commitments. Check if the data is used to train models and under what conditions. The answer must be able to be supported by a current contract or documentation, not just a sales phrase.
When individuals are directly affected by the processing, determine how they are informed and how they can exercise their rights. Decisions with a significant effect deserve specific analysis.
5. Checklist before a pilot
- Purpose and expected result written.
- Data categories and sources inventoried.
- Technical access limited as needed.
- Actions prohibited or subject to validation defined.
- Documented subcontractors and processing locations.
- Use or non-use for confirmed training.
- Expected retention and deletion periods.
- Logging, revocation and incident management tested.
- Information of people and rights analyzed.
- Internal manager of the named driver.
Official source
PFPDT — AI and data protection, accessed July 21, 2026.
The exact obligations depend on the context. For sensitive data or high-risk processing, have the device validated by the competent data protection person or legal advice.