An AI tool belongs in your data-protection records when its use processes personal data. Start with the actual data flow, not the supplier’s description of the product. Assess Swiss FADP and GDPR applicability separately; professional secrecy may add further requirements.
Removing names is not the same as demonstrating anonymity. Staab and colleagues' study of attribute inference from Reddit profiles, revised in 2024, found that the tested language models could infer personal attributes from text and that the evaluated anonymisation measures did not reliably prevent this. That setting does not establish the risk of every legal document, but it gives a concrete reason to test residual inference rather than assume redaction is sufficient.
Define roles and keep a processing record
Identify the controller, processors, purposes, affected people, data categories, recipients, retention and security measures. Record which information enters prompts, attachments, logs, embeddings and outputs. Include subprocessors and international transfers. A contractual “no training” setting addresses one reuse pathway; lawfulness and confidentiality need the rest of this record.
Check the small-organisation exceptions
GDPR Article 30(5) is not a blanket exemption for organisations with fewer than 250 employees. Its exceptions do not apply to processing that is not occasional, is likely to result in a risk, or includes Article 9 or Article 10 data. A provisional agreement of 26 June 2026 in procedure 2025/0130/COD on the Commission proposal COM(2025) 501 would extend the exemption to organisations with fewer than 1,000 employees unless, and to the extent that, a specific processing activity is likely to result in a high risk. It is pending, not law (checked 26 September 2026). FADP Article 12(5) directs the Federal Council to provide exceptions for companies with fewer than 250 employees whose processing poses a low risk of harm to the personality of the people concerned. It did so in Article 24 of the Data Protection Ordinance (DPO): undertakings and other private organisations with fewer than 250 employees on 1 January of a year are exempt from keeping a record unless they process sensitive personal data on a large scale or carry out high-risk profiling. Legal files often contain sensitive personal data, such as data on administrative and criminal proceedings, so check both exclusions, not headcount alone.
Decide whether a DPIA is required
Under GDPR Article 35, a DPIA is required where processing is likely to result in a high risk to people’s rights and freedoms. Consider its examples, applicable supervisory-authority lists and the use as a whole. Large-scale processing of special-category or criminal-offence data and specified automated evaluations are relevant examples. Financial data is not automatically an Article 9 category; criminal data falls under Article 10.
FADP Article 22 uses its own high-risk test for personality or fundamental rights; a high risk arises in particular from large-scale processing of sensitive personal data. Article 5(c) lists those categories, including health data and data on administrative and criminal proceedings or sanctions, which legal files often contain. Describe the processing, assess risks and define measures. Revisit the assessment when the use, model, data or safeguards change.
Check automated decisions and scores
Where an AI tool scores or evaluates a person, check GDPR Article 22 as well. In SCHUFA (C-634/21), on 7 December 2023, the Court of Justice held that a credit information agency’s automated establishment of a probability value about a person’s ability to meet future payment commitments is itself automated individual decision-making where a third party to which the value is transmitted draws strongly on it to establish, implement or terminate a contractual relationship with that person. In Dun & Bradstreet Austria (C-203/22), on 27 February 2025, it held that, for automated decision-making within Article 22(1), the right of access under Article 15(1)(h) lets the person require the controller to explain the procedure and principles actually applied; where the controller considers that this information contains protected third-party data or trade secrets, it must provide it to the competent supervisory authority or court, which balances the rights and interests at issue.
FADP Article 21 requires the controller to inform people of decisions based exclusively on automated processing that have a legal consequence or considerable adverse effect for them. On request, it must let them state their view, and they may ask for review by a natural person. These duties are subject to the exceptions in Article 21(3): the decision is directly connected with concluding or performing a contract with the person and their request is granted, or the person has explicitly consented to the decision being automated.
Review vendor contracts and access
Check instructions, confidentiality, subprocessors, support access, security, deletion, audit evidence and relevant transfer safeguards. Under FADP Article 9, processing may be assigned to a processor only if the processor handles the data as the controller itself may and no statutory or contractual duty of confidentiality prohibits the assignment; the controller must satisfy itself that the processor can guarantee data security, and further subcontracting needs its prior approval. For lawyers, that confidentiality test includes Article 13 of the Lawyers Act (BGFA). Disclosure abroad follows FADP Article 16. Restrict access by matter and role, including retrieval results, and verify that approved settings are actually enabled. Contractual incident targets can support escalation; the statutory notification duties run on their own clocks.
Use privacy-enhancing measures proportionately
Minimise inputs and test whether removing identifiers genuinely prevents identification. Pseudonymised records remain personal data when re-identification is possible. Redaction, local processing, access controls, encryption and isolated testing can reduce particular risks, but each has limits. Test leakage through logs, retrieved passages and embeddings, not only the visible prompt.
Incident response: thresholds, clocks and roles
Under GDPR Article 33(1), the controller notifies the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach, unless it is unlikely to result in a risk to people’s rights and freedoms. Explain a delay beyond that period. Article 33(2) requires a processor to notify its controller without undue delay after awareness. Article 33(5) requires documentation of breaches, including those not notified.
Article 34 has a different test for communication to affected people: likely high risk, subject to its exceptions. Treat authority notification and communication to individuals as separate decisions.
Pending, not law (checked 26 September 2026)
The Commission’s Digital Omnibus proposal COM(2025) 837 of 19 November 2025 would require notification to the supervisory authority only for breaches likely to result in a high risk, where feasible within 96 hours, through a single entry point. It would also introduce EU-level lists of processing that does and does not require a DPIA. The legislative procedure 2025/0360/COD is ongoing. Until an amending act is adopted and applies, Article 33 and its 72-hour rule remain the law.
Under Swiss FADP Article 24, the controller informs the FDPIC as soon as possible if a breach is likely to result in a high risk to personality or fundamental rights. A processor informs the controller as soon as possible. Communication to affected people follows the separate statutory conditions. Record the evidence, risk assessment, decision and responsible person.
A proposed contractual target of 24 to 48 hours is only an illustrative service-level target. It is not a statutory grace period, does not replace “without undue delay”, and may be too slow for the incident. Agree prompt escalation and staged updates. Assess professional secrecy separately; a confidentiality incident and a statutory notification threshold are different tests.
An operating record for a small team
Prepare and test the response
0/7Key Takeaway
Primary sources
- GDPR: Articles 9, 10, 15, 22, 28, 30, 33, 34, 35
- Court of Justice, SCHUFA Holding (C-634/21), 7 December 2023; Dun & Bradstreet Austria (C-203/22), 27 February 2025
- Swiss FADP: Articles 5, 9, 12, 16, 21, 22, 24
- Swiss Data Protection Ordinance (DPO): Article 24
- FDPIC: Article 24, data security breaches
- Lawyers Act (BGFA): Article 13
- Proposal COM(2025) 837 (Digital Omnibus), pending
- Proposal COM(2025) 501, procedure 2025/0130/COD, pending