Are we even allowed to? AI, personal data and official secrecy
This question comes before every other one, and the answer is uncomfortable: for most of the work an administration actually does, a freely accessible AI tool is off the table. What follows from that, and why open models are a real opportunity here.
Using AI in regulated settings, 4 parts
-
Part 1 · you are here
What is actually allowed?
Factsheet, data protection, official secrecy. And what running it yourself solves.
-
Part 2
Does it have to be the strongest AI model?
Measured performance on administrative texts, licences, the limits of size.
-
Part 3
The cost driver is rarely the AI model
Cloud versus running it yourself, hardware, power, and when it tips.
-
Part 4
Swiss providers, and what they leave to you
Ten providers, three operating models, and what to watch for.
In short
- A free ChatGPT account is off limits for personal data. The federal factsheet says so in as many words. That rules out a large part of the work an administration actually does, because personal data is involved almost everywhere.
- This is exactly where open models earn their keep. Not because they are cheaper, but because they make possible work that otherwise never happens at all. A model running in your own building sends nothing outside it.
- Four questions decide the matter, and none of them is technical. Legal basis, data category, impact assessment, duty of confidentiality. Until you have answered them, there is no point discussing models.
Administrations now ask a different question from the one they asked two years ago. It is no longer 'are we allowed to use AI', but 'can we run this ourselves, so the data stays in the building'. The first half of that expectation holds. The second half is incomplete, and in practice the difference costs months.
Four terms that keep coming up in this series
- Model. A program that continues a piece of text. You give it an instruction and a text, it gives you a text back. ChatGPT is an interface to such a model, not the model itself.
- Weights. The files a model consists of. Very large files, often several dozen gigabytes. 'Open weights' means these files can be downloaded and kept. Once you have them, nobody can take them away.
- Token. The unit models are billed in. A fragment of text, sometimes a word, sometimes a syllable. As a rule of thumb, one A4 page of administrative German comes to roughly 500 tokens. That lets you convert any price list into pages.
- Graphics card. The component a model runs on. The name is misleading: this has nothing to do with what appears on a screen. Cards like these can perform very many simple calculations at once, and that is precisely what a language model needs. Whether the card sits in your building or in a provider's data centre is one of the central questions of this series.
Parameter counts, memory requirements and tokens are covered at length in our primer 4B, 70B, 397B-A17B. For this part, the four sentences above will do.
What the federal factsheet says
In 2024 the Competence Network for Artificial Intelligence of the Swiss Federal Administration published a factsheet on the use of generative AI tools. The central rule reads:
'Never enter personal data or sensitive information into these tools.'
Factsheet on the use of generative AI tools in the Federal Administration, V1.2, 18 January 2024, our translation from the German
Named explicitly: no entry of information classified as internal, confidential or secret. No entry of text covered by official secrecy under Art. 320 of the Swiss Criminal Code or by professional secrecy. And no entry of personal data of any kind, together with a warning that pseudonymisation does not reliably prevent re-identification.
That rules out a large part of the work an administration actually does. A social services department wanting to summarise case files is working with data about social assistance measures. The Federal Act on Data Protection counts these among sensitive personal data in Art. 5 lit. c no. 6, and cantonal legislation has equivalent lists. Note which law applies: a municipal social services department is subject to cantonal law, not to the federal act. The lists largely coincide, but not everywhere word for word. A residents' registration office, a debt collection office, a tax administration: the same picture throughout, plus specific duties of secrecy of their own, such as tax secrecy.
Which tools this applies to, and which it does not
The factsheet addresses publicly accessible tools. It is not a ban on contractually secured services. This distinction is regularly lost in the debate, and it produces two errors at once: some take everything to be forbidden, others take everything to be permitted. Three examples to draw the line:
| Case | Enter personal data? | Why |
|---|---|---|
| Free ChatGPT account private or set up for work |
no | Precisely the case the factsheet has in mind. No contract, no assurance about where processing happens, no rule on deletion. |
| Paid subscription without a data processing agreement |
no | Paying changes nothing on its own. What matters is whether a processing agreement exists and what it guarantees. |
| Service with a processing agreement processing in Switzerland guaranteed |
assessment needed | Here the factsheet does not apply; your data protection law does. The four questions further down lead through that assessment. |
A data processing agreement sets out what a service provider may do with your data. Your cantonal data protection authority will usually supply model templates. This table is a guide, not legal advice for your case.
A factsheet is neither a law nor a directive; it is a recommendation with no binding effect outside the administration. It does not apply to cantons and municipalities. The actual reason personal data does not belong in a freely accessible tool is therefore not the factsheet, but the lack of a legal basis, disclosure abroad and official secrecy. What is authoritative for your office is the material published by your cantonal data protection authority. We quote the federal factsheet because it sums up federal practice well and because the underlying rules apply everywhere. The version dates from January 2024; before relying on it, check whether a newer one exists.
Why open AI models are an opportunity here
1. You may process data that would otherwise have to stay outside
This is where open models earn their keep. They are not cheaper; they make possible work that otherwise never happens at all. What runs on a machine in your building sends no data outside it.
Two assessments fall away with it: disclosure abroad, and processing by a third party on your behalf. Everything else remains. You still need a legal basis for the processing, purpose limitation still applies, the impact assessment does not disappear, and the people concerned still have to be informed. These questions stay open even when the machine sits in your own building.
2. You choose the location, and you really do
With a hosted service you pick a region from a list. Running it yourself, you pick the room. That sounds like a difference of degree, and in law it is a difference of principle: Art. 16 of the Federal Act on Data Protection requires an adequate level of protection or suitable safeguards for disclosure abroad. If no disclosure takes place, the whole assessment falls away.
The Swiss federal government itself takes a less strict view of cloud use than many assume. A report by the Federal Chancellery from March 2025 concludes that a cloud provider is not an unauthorised third party but an auxiliary person within the meaning of Art. 320 of the Criminal Code, and that outsourcing does not constitute a breach of official secrecy, provided the requirements of the federal Digitalisation Ordinance are met. The Data Protection Commissioner of the Canton of Zurich takes a considerably more critical view of the risk posed by US providers, because the American CLOUD Act can give US authorities access to data held in European data centres.
This difference is not theory for you. Under its Art. 2 para. 1, the Federal Act on Data Protection applies only to federal bodies and private persons. Cantons and municipalities are governed in principle by cantonal law, and anyone working there cannot rely on a federal report. Art. 37 FADP provides for one exception: when implementing federal law, cantonal bodies can be bound by provisions of the federal act. For tasks such as supplementary benefits or civil status registration, that check is worth making.
3. No model gets pulled out from under you
Whoever has downloaded the model files keeps them. With a hosted model, the provider decides when a version is switched off. For a specialised application tuned and tested against particular behaviour, that means acceptance testing all over again, and you do not choose the date.
4. You can read up on what the model learned from
With most models you cannot. With Apertus, developed at ETH Zurich, at EPFL and at the Swiss National Supercomputing Centre CSCS in Lugano, you can.
That there is anything to compare at all is down to the EU AI Act. It obliges providers of general-purpose models to publish a summary of what they trained on. In Switzerland that duty does not apply. For providers doing business in the EU it does. That is why these documents exist, and you can read them.
The AI Accountability Lab at Trinity College Dublin, in Ireland, assessed 39 such summaries in a paper presented at the FAccT 2026 conference. Apertus 70B received an A for transparency and an A+ for usefulness, the best of all the summaries assessed. OpenAI, Google, Anthropic, Meta and Mistral sit in the C and D range. For a further 20 models examined, no summary existed at all; they are not among the 39.
Worth keeping straight: what was assessed is the quality of the published summary, not the quality of the model. How well Apertus actually performs is the subject of Part 2, and the answer there is less comfortable.
5. You are allowed to change the model
An open model can be adapted to your language and your cases. The technical term is fine-tuning: you show the model a few hundred to a few thousand examples from your own organisation, and it picks up tone, vocabulary and structure. This is a project for specialists, not something you do at the press of a button.
The Canton of Ticino has done exactly that. The Centro sistemi informativi in the Department of Finance and Economy runs a translation tool on a fine-tuned Apertus 8B, in its own data centre, for Italian, German, French, Spanish, Romanian and Ukrainian. The figures from Artificialy, the Ticino company involved: the unmodified Apertus 8B reached 90 per cent, the larger Apertus 70B 92 per cent, the fine-tuned small model 94 per cent.
What those percentages measure exactly has not been disclosed. They are vendor figures from an in-house translation comparison, as at March 2026 with roughly 100 test participants. Whether this became a production system we could not verify. The case shows that the approach works. As proof of performance it only goes so far.
What else applies in regulated sectors
Hospitals, medical practices, law firms, banks and insurers face the same question under different rules. Three differences matter.
Data protection law applies to them in full. Under Art. 2 para. 1 it covers private persons and federal bodies. A privately run hospital therefore falls under federal law, a cantonal hospital under cantonal law. Two institutions doing the same job, two legal regimes.
Alongside official secrecy come specific duties of confidentiality, and they differ from sector to sector. For health and legal professions, Art. 321 of the Criminal Code applies. It names a closed list: clergy, lawyers, notaries, auditors, doctors, dentists, pharmacists, midwives, psychologists, nursing professionals and others, expressly including their auxiliary staff. The penalty is the same as for official secrecy, namely a custodial sentence of up to three years or a monetary penalty; prosecution follows only on complaint by the injured party, whereas official secrecy is prosecuted ex officio.
Banks and insurers are not on that list. For them, bank client confidentiality under Art. 47 of the Banking Act applies, with a logic of its own, alongside the supervisory rules of the Swiss Financial Market Supervisory Authority on outsourcing functions. We have not examined that part; it has to be settled before any decision in this field.
What you take on by running it yourself
The drawbacks are less visible than the benefits, because they only appear in operation. 'Running it' does not mean setting it up once and letting it go. It means:
What operating it actually involves
- Setting up. Somebody installs the serving software, downloads the model files and configures access for your staff. One-off, a few days.
- Keeping current. New model versions appear every few months. Each one means testing against your own cases again before it goes live. Switching is never just an installation.
- Keeping it available. If the service is down on a Monday morning, somebody has to be reachable who can bring it back. That is an on-call duty, not something done on the side.
- Planning capacity. One card handles a limited number of simultaneous requests. As use grows, a second one is needed. If nobody keeps an eye on this, you notice it when the answers get slow.
- Logging and deleting. A self-hosted model records every request. That is a new collection of personal data with a deletion policy of its own.
With a hosted service
The provider handles those five points. When everybody logs on at once on Monday morning, it adds capacity automatically. You pay for what you use and you can walk away.
the work sits outsideRunning it yourself
You handle those five points. When everybody logs on at once, it simply gets slow until somebody buys a second card. You pay a fixed sum, at night and over the holidays too.
the work sits with youThere is no support. When the model in your building answers wrongly, there is no hotline. There is you.
And the licence is not automatically free. 'Open weights' means the model files can be downloaded. It does not mean you may do anything you like with them.
Why open weights are not free use The Chinese group Tencent excludes the EU, the United Kingdom and South Korea from the licensed territory of its video model. Switzerland is not on that list, so the model may be used here. That is precisely the lesson: the territorial scope sits in the licence and follows no logic you could guess. With the next model the list may read differently. Read the article →
The four questions before any procurement
The debate inside administrations usually turns on the wrong axis. It runs between 'cloud' and 'run it ourselves', as though that were a matter of principle. A more useful way to sort it is by data: what arises, and what follows from that.
What we recommend
Sort by data first. For anything that contains no personal data, such as factsheets, directives, templates and official reports, the route is short. For personal data, settle the legal basis first, and do it before you talk to any provider.
That takes four answers. The questions are the same everywhere, the answers are not. First: is the processing covered by a legal basis, and does an ordinance suffice, or does it take an act of the competent legislative body, which depending on the municipality means the municipal assembly, the municipal parliament or the cantonal legislature? Second: is this sensitive personal data within the meaning of the law that applies to you? Third: is a data protection impact assessment or a prior check required, and does the data protection authority have to be involved? Fourth: does a duty of confidentiality stand in the way of passing the data to a service provider?
Who to take this to. For federal bodies, Art. 34 of the Federal Act on Data Protection is the bottleneck. In cantons and municipalities the same four questions sit in cantonal law, only under different article numbers. The fastest route runs through your cantonal data protection authority, whose advice is free. The conference of Swiss data protection commissioners publishes material on this that you can cite to your own committee.
Before you buy
- Put in writing which categories of data actually reach the application, and how they get there: copied by hand, pulled from a specialist system, or processed in bulk. For the data protection assessment that makes a difference.
- Establish early whether an impact assessment is required. Where sensitive data is processed on a large scale using a new technology, it is mandatory under Art. 22 of the Federal Act on Data Protection and the cantonal equivalents, not optional. It comes before procurement.
- Remember the personal dimension of official secrecy. Art. 320 of the Criminal Code is federal law and applies to the individual member of staff, whatever data protection act governs your office. Settle first whether disclosure occurs at all: on the federal view, a contractually bound service provider is an auxiliary person and not a third party, in which case the question is closed. If that construction does not hold in your case, a blanket release under no. 2 helps little, because it does not legitimise systematic disclosure. You then need a legal basis for bringing the provider in. This fork belongs at the start of the assessment, not at the end.
- Have the provider show you how it handles sub-processors. Art. 9 para. 3 of the Federal Act on Data Protection requires your prior approval. A workable arrangement lists every sub-processor by name and location and informs you of changes in advance, with a right to object.
- Only start testing once the legal basis is settled. Until it is, test with material that contains no personal data. That already answers most of the quality question.
Once the legal question is settled, the second one follows: which model can actually do your job? The answer has been measured, though it comes from Germany, and one Swiss model performs worse than many expect.
Disclosure
- digitario advises administrations and companies on selecting, procuring and introducing AI systems. This article ends with an offer to talk.
- It was written without a commission, without payment and without prior sight by any of the providers named. None of them supplied material that is not publicly available.
- The four legal questions above will also be answered by your cantonal data protection authority, free of charge. We recommend starting there.
Open questions
The legal question is settled. What now?
Once the four questions are answered, the second half begins: which model suits your cases, which operating model suits your organisation, and what it costs over the years. In an initial conversation we work through your expected volumes and lay out the options. The legal questions themselves are answered free of charge by your cantonal data protection authority, and that is where we will point you first.
Sources
- Switzerland. Factsheet on the use of generative AI tools in the Federal Administration, Competence Network for AI, V1.2 of 18 January 2024 · cnai.swiss
- Switzerland. Federal Chancellery, legal framework for the use of public cloud services in the Federal Administration, report implementing milestone 5 of the cloud strategy, March 2025
- Switzerland. Data Protection Commissioner of the Canton of Zurich, factsheet on using cloud products from US companies and factsheet on the use of AI by public bodies · datenschutz.ch
- Switzerland. Federal Act on Data Protection (FADP, SR 235.1), in particular Art. 2, 5, 9, 16, 22 and 34 · fedlex.admin.ch
- Switzerland. Swiss Criminal Code, Art. 320 official secrecy and Art. 321 professional secrecy · fedlex.admin.ch
- Switzerland. Canton of Ticino, translation tool on a fine-tuned Apertus 8B, 17 March 2026 · apertus-ai.org
- Ireland. Blankvoort, Pandit and Gahntz, assessing the training data transparency of GPAI models, FAccT 2026, AI Accountability Lab at Trinity College Dublin · doi.org/10.1145/3805689.3806755
- European Union. Regulation on artificial intelligence (AI Act), obligations for providers of general-purpose models
- Our own work. digitario, primer on model sizes and tokens · digitario.ch/artikel/modellgroessen-und-tokens-verstehen