Data protection and professional secrecy by profession: what Swiss law allows, what standard and EU hosting mean, and what you do yourself.
For most Swiss businesses: yes. The Data Protection Act (DSG) does not forbid AI or cloud services. It asks for a processing contract, transparency towards the people concerned, adequate security and a lawful basis when data leaves Switzerland — and Vorenq supplies its half of each.
What changes by profession is professional secrecy. Doctors, lawyers, notaries, auditors and the other professions named in the Criminal Code (StGB Art. 321) may hand their clients' secrets to a service only with the client's consent (StGB Art. 321 no. 2), and a processor may only be used where no secrecy duty forbids it (DSG Art. 9 para. 1 lit. b). The sections below say where your profession stands.
Standard uses every model, including providers in the USA. That is lawful under DSG Art. 16 where the provider is certified under the Swiss-U.S. Data Privacy Framework or bound by recognised standard contractual clauses.
EU keeps the AI processing in European data centres — the providers' EU zones, which may include Switzerland and Norway. The EU is on the Federal Council's list of countries with adequate protection (DSG Art. 16 para. 1), so this is the simpler footing, and the one we recommend to anyone holding client secrets.
Two things EU hosting does not change. Your workspace data is stored in Frankfurt either way. And most providers involved — AWS, Microsoft, OpenAI, Google and our hosting providers — are US companies, which US law (the CLOUD Act) can compel to hand over data even when it is stored in the EU. Mistral is the European-owned exception.
Answer: Yes.
The DSG applies and nothing profession-specific adds to it. Vorenq is your processor under the terms you accept at signup; name the AI service and the processing countries in your own privacy notice (DSG Art. 19). Employee data may be processed only as far as it concerns the employment relationship (OR Art. 328b) — the same rule as without Vorenq.
Answer: Yes.
Bookkeeping, payroll and tax mandates are not covered by the criminal professional-secrecy rule: StGB Art. 321 names auditors, not fiduciaries as such. You owe your clients contractual confidentiality, and business secrets are protected under StGB Art. 162 — so choose EU hosting, and mention cloud and AI services in your engagement letters. Keep the statutory books in your accounting software. For statutory audit mandates, see auditors below.
Answer: Yes — with the audit client's consent, or with audit files kept out.
Auditors bound to confidentiality by the Code of Obligations are named in StGB Art. 321, and the auditor must keep its findings secret (OR Art. 730b para. 2). A processor may only be used where no secrecy duty forbids it (DSG Art. 9 para. 1 lit. b); disclosure with the entitled person's consent is not punishable (StGB Art. 321 no. 2). So get the audit client's written consent before audit files go into Vorenq — or keep audit mandates out and use Vorenq for your firm's own administration.
Answer: Yes — with the client's consent for mandate content, or with it kept out.
Lawyers and notaries are named in StGB Art. 321, and DSG Art. 9 para. 1 lit. b applies to any service you use. Choose EU hosting, keep privileged mandate content out unless the client has consented (StGB Art. 321 no. 2), and follow your bar association's rules on cloud services. The firm's own administration without client secrets — marketing, supplier invoices, your team's scheduling — is unproblematic.
Answer: Yes for administration — keep patient data out.
These professions are named in StGB Art. 321, health data is sensitive personal data (DSG Art. 5 lit. c no. 2), processing it at scale requires an impact assessment (DSG Art. 22), and cantonal health law adds rules of its own. Keep patient data — appointment lists included — in your practice software and out of Vorenq. Use Vorenq for administration that holds no patient data: supplier invoices, purchasing, marketing, HR. Using it with patient data would first need the patients' consent, an impact assessment and a check of cantonal law.
Answer: Only after your compliance function has approved it.
For banks, bank-client secrecy is criminal law (BankG Art. 47); for every supervised institution, FINMA's outsourcing rules apply. Do not put client data into Vorenq until your compliance function has assessed it as an outsourcing. Administration without client data is unaffected.
Answer: Only after the competent data protection authority has approved it.
Cantonal and municipal bodies fall under cantonal data protection law — the federal DSG covers only private persons and federal bodies (DSG Art. 2 para. 1) — and the cantons set their own conditions for cloud services. Ask the cantonal or municipal data protection authority before using Vorenq with personal data.
Orientation based on the federal texts (DSG, StGB, OR, BankG) as read in September 2026. It is not legal advice: your professional association, your data protection officer or a lawyer decides the individual case — above all for secrecy-bound mandates, patient data and supervised institutions. Cantonal law and FINMA's rules are named here, not interpreted.