Compliance
OVHcloud AI Endpoints in Switzerland
Structured issue-spotting for deploying OVHcloud AI Endpoints in Switzerland, read against the rules for that jurisdiction.
- Source
- Rules engine over a generic brief — no anchored quote on this page
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01What this reading assumes
- Jurisdiction
- Switzerland
- Principal framework
- The revised Federal Act on Data Protection (nFADP/revDSG), SR 235.1, in force since 1 September 2023, with the Data Protection Ordinance and the Ordinance on Data Protection Certification. The AI-relevant provisions are article 21 on automated individual decisions — a duty to inform, a right to state a point of view and a right to review by a natural person on request — article 22 on impact assessments, article 23 on prior consultation of the Commissioner where residual risk stays high, articles 16 and 17 on cross-border disclosure, article 24 on breach notification, article 9 on processors and article 7 on data protection by design. Sanctions are criminal fines of up to CHF 250,000 imposed on responsible private individuals, not administrative fines on companies, which changes who in an organisation has to have read the assessment.
- Delivery assessed
- Model API
- Data leaves the network
- unknown — the deciding question for a hosted product
- Vendor home jurisdiction
- France
- Verified vendor positions
- none — every vendor position below is a question, not an assurance
- Rules evaluated
- 36
- Rules fired
- 12
Assumptions about use
- An internal deployment used by employees, not a public-facing product.
- A person reads the output before acting on it — but that is not recorded, so the engine reports it as a gap rather than assuming it.
- No significant automated decision is taken about a person by the system alone.
02Issues to work through
Cross Cutting
Confidentiality duties bind independently of data protection law
Material can be entirely free of personal data and still be the material a contract stops you disclosing. Client retainers, non-disclosure agreements, supplier contracts and common-law duties are the usual sources, and several of them require consent before a third party processes the material at all — which a model API call is.
- Required checks
- Review the confidentiality clauses in the contracts covering the material going into the system.
- Identify any contract requiring notice or consent before a subcontractor processes the material.
- Decide whether the deployment needs a confidentiality carve-out negotiated into new contracts.
- Vendor questions
- Will the vendor accept a confidentiality undertaking beyond its standard terms?
- Which staff at the vendor can access customer content, under what controls?
- Technical controls
- Segregate the most sensitive corpora into an index that the general assistant cannot reach.
Human review required — take this to your counsel
What ends up in a prompt, and where it goes next
Every prompt is a transfer of whatever it contains. Staff paste more than they intend, retrieved context travels with the prompt, and system prompts can often be extracted from the output. Assume anything reaching the model has left your control unless the contract and the architecture say otherwise.
- Required checks
- Write down which categories of information may be entered into a prompt, and tell people.
- Establish what the system prompt contains and whether disclosing it would matter.
- Establish which shadow tools staff are already using; the policy has to name the permitted ones.
- Vendor questions
- Are prompts and completions retained, for how long, and can retention be set to zero?
- Are prompts used for abuse monitoring, and if so who can read them and for how long?
- Technical controls
- Redact or block high-risk patterns before the prompt leaves the application.
- Keep prompt and completion logs out of general-purpose observability tools.
- Set an explicit retention period on prompt logs and enforce it.
The acceptable-use policy may exclude your use case
Acceptable-use policies commonly carve out unsupervised legal, medical and financial advice, decisions about people without human review, and some surveillance and biometric uses. They are incorporated into the contract by reference and change without a signature, so the version that matters is the one live on the day you rely on it.
- Required checks
- Read the acceptable-use policy against your actual use case, not against a summary of it.
- Where a carve-out applies, decide whether human review brings the use back inside the policy.
- Set a reminder to re-read the policy — it changes without notice to you.
- Vendor questions
- Does your acceptable-use policy permit this use case, and will you confirm that in writing?
- How are we notified when the acceptable-use policy changes?
Human review required — take this to your counsel
Being able to reconstruct a decision months later
The question that arrives after a complaint is what the system was shown and what it produced on a particular day. Models change, prompts change, and indexes are rebuilt, so the answer has to be recorded at the time. Without it, the only available response is that the output cannot be reproduced.
- Required checks
- Decide what is recorded per interaction: model and version, prompt template version, retrieved document ids, output, reviewer and outcome.
- Set how long those records are kept, balanced against the retention duties that also apply to them.
- Vendor questions
- Does the vendor pin model versions, and how much notice is given before a model is retired or changed?
- Technical controls
- Version prompt templates in source control and log the version used.
- Log the model identifier and version returned by the provider, not the one you requested.
Vendor documentation has not been verified
We could not verify a data processing agreement, a subprocessor list, a position on training on customer data and a stated processing region for this vendor from a retrieved document. That is a gap in our evidence, not a finding against the vendor: until a document has been fetched and read, nothing here should be treated as settled either way.
- Required checks
- Obtain the current versions of the processing agreement, subprocessor list, security page and any regional-processing commitment.
- Check that what the sales conversation promised also appears in the contract.
- Vendor questions
- Where is your data processing agreement published, and which version applies to us?
- Where is your subprocessor list, and how much notice do we get before it changes?
- Do you train on customer content by default, and where is that stated contractually?
- In which country or region is inference performed, and where are logs retained?
We were not told whether a person reviews the output
Where output influences a decision about a person, the reviewer has to be able to disagree with it. That needs three things a rubber-stamp review lacks: enough information to judge, enough time to judge, and an override that is used often enough to be real. Design it before the volume makes it impossible.
- Required checks
- Name the role that reviews the output and what they see when they do.
- Decide what evidence is retained about each review, so the practice can be shown to exist.
- Set a threshold below which the system must not act without review.
- Vendor questions
- Does the product expose the retrieved context and the confidence behind a suggestion, or only the answer?
- Technical controls
- Show the reviewer the retrieved sources next to the suggestion, not the suggestion alone.
- Record the reviewer’s decision, including overrides, as part of the audit trail.
Human review required — take this to your counsel
An AI deployment creates new copies of the data
Vector indexes, prompt logs, completion caches, evaluation datasets, fine-tuning checkpoints and backups are all copies of the source material in places the existing retention schedule does not mention. Deletion requests are the moment this is discovered, because deleting the source document does not delete its embedding.
- Required checks
- List every store the deployment creates and add each to the retention schedule.
- Establish how a deletion request propagates to the index, the caches and the logs.
- Establish how long backups keep material that has been deleted from the live system.
- Vendor questions
- What does the vendor retain, where, and for how long after we delete our copy?
- Technical controls
- Store the source document id with every embedding so deletion can cascade.
- Set time-to-live on prompt and completion logs rather than relying on manual cleanup.
The vendor’s terms may not permit the deployment you are planning
Provider terms routinely restrict things architectures assume: sharing seats, building a competing service, benchmarking and publishing results, reselling capacity, and processing certain data categories. A consumer or self-serve plan often carries different terms from the enterprise agreement, and the enterprise agreement is the one worth reading.
- Required checks
- Identify which contract actually governs — self-serve terms, an order form, or a negotiated agreement.
- Check restrictions on seat sharing and on service accounts, which a shared internal assistant can breach without anyone noticing.
- Check whether the terms allow the categories of data you intend to send.
- Vendor questions
- Which agreement governs our use, and can we have the current version in writing?
- Are there restrictions on the data categories or the industries we may use the service for?
Switzerland
A European Data Privacy Framework certification does not cover a Swiss transfer
The Swiss adequacy list treats the United States as adequate only for organisations certified under the Principles of the Swiss-US Privacy Framework, resting on Executive Order 14086, the Data Protection Review Court rule and Intelligence Community Directive 126. A vendor certified under the EU-US framework alone is not covered, and unlawful disclosure abroad is a criminal offence with personal liability.
- Required checks
- Check the vendor’s certification record for the Swiss programme by name, not for a framework certification generally.
- If it is not certified for Switzerland, use clauses notified to or approved by the Commissioner, or binding corporate rules — and record which.
- Repeat the check for subprocessors, because the transfer chain does not stop at the contracting entity.
- Vendor questions
- Are you certified under the Swiss-US Privacy Framework specifically, and can you show the current listing?
- If not, which transfer mechanism do you offer for Switzerland, and has it been notified to the Commissioner?
Human review required — take this to your counsel
We have no evidence of this vendor’s certification position for Switzerland
We could not verify which certifications this vendor holds. In Switzerland that matters twice over: the certification ordinance provides a recognised route to demonstrating a data protection posture, and the adequacy list turns on certification under the Swiss programme specifically rather than a European one. This is a gap in our evidence rather than a finding against the vendor.
- Required checks
- Ask for the certification position in writing, naming Switzerland rather than Europe.
- Vendor questions
- Which data protection or security certifications do you hold, and what is in scope of each?
- Are any of them recognised under the Swiss certification ordinance?
No AI statute is not the same as no duties
The Commissioner’s position is that the FADP is drafted in a technology-neutral manner and therefore applies to AI-supported data processing, and that the people affected should be granted the greatest possible protection. It expects transparency about the purpose, the functionality and the data sources of an AI system, and that a person knows whether they are dealing with a machine.
- Required checks
- Do not tell a stakeholder that Switzerland has no rules on AI — say it has no AI statute and describe what does apply.
- Write down the purpose, the functionality and the data sources in terms a person outside the project could follow.
- Make it evident to a user when they are interacting with a machine rather than a person.
- Vendor questions
- What can you tell us about the data your model was trained on, in enough detail for us to describe it?
The Swiss AI bill is still in preparation, and its shape is not knowable yet
The federal communications office states that in Switzerland there is currently no specific legislation on AI. The Federal Council has decided to ratify the Council of Europe AI Convention and to legislate sector-specifically as far as possible, with a consultation draft due by the end of 2026, and no draft had been opened at the review date. Planning against a specific Swiss AI obligation is planning against nothing.
- Required checks
- Do not build to a hypothetical Swiss AI regime; build to the FADP and the sectoral rules that exist.
- Watch for the consultation opening, because sector-specific legislation means the relevant rule may arrive in your own sector’s statute rather than in an AI act.
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
03What this reading does not know
- Whether any of the data falls into a special or sensitive category.
- Whether any material is covered by legal professional privilege.
- Whether prompts or documents leave the company network.
- Whether a person reviews the output before it is acted on.
04Instruments these issues point at
- proposalSwiss AI billThe Federal Council decided to ratify the Council of Europe AI Convention and to legislate sector-specifically as far as possible, with cross-sector rules limited to fundamental-rights areas such as data protection. As at the review date no consultation draft has been opened.
- regulationDPO / VDSGImplements the FADP: minimum data security requirements, processor obligations, and the criteria for assessing adequacy. Its Annex 1 is the operative Swiss adequacy list, and its United States entry is limited to organisations certified under the Principles of the Swiss-US Privacy Framework.
- guidanceFDPIC AI statementThe Commissioner’s position that the FADP, being technology-neutral, applies directly to AI-supported data processing — so the absence of an AI statute is not an absence of duties. It also expects transparency about purpose, functionality and data sources, and that people know when they are dealing with a machine.
- statutenFADP / revDSGSwitzerland’s general data protection statute. It governs automated individual decisions, impact assessments, prior consultation of the Commissioner, cross-border disclosure and processors — and, unusually, breaches attract criminal fines imposed on the responsible individual rather than administrative fines on the company.
05Vendor documents being watched
- Model documentationhttps://www.ovhcloud.com/en/public-cloud/ai-endpoints/catalog/not yet fetched
- Pricinghttps://docs.ovhcloud.com/en/guides/public-cloud/ai-machine-learning/ai-endpoints-billingnot yet fetched
- Security pagehttps://www.ovhcloud.com/en/enterprise/certification-conformity/not yet fetched
06Ask about your own deployment
This page reads the rules against a generic organisation. Your size, industry, data and existing contracts change which of these issues matter and which fall away.