Start with the proposed processing, not the badge

A security badge does not answer whether a particular Swiss legal workflow is appropriate for a cloud AI service. Map the documents and personal data involved, the purpose of the task, the people using it, and the outputs the team expects to retain.

The FDPIC explains that the Swiss Federal Data Protection Act applies to AI-supported processing. This guide proposes procurement questions to help a legal team investigate its workflow. It does not determine the lawful arrangement for a particular matter or replace the professional-secrecy and contractual analysis that may also be required.

Map the whole data lifecycle

Data stageQuestion for the vendor
InputWhich documents, prompts, and metadata are transmitted?
ProcessingWhich entities and services process each category?
AccessWho can access data for support or operations?
RetentionWhat remains in logs, outputs, and backups?
ExitWhat can be exported, deleted, and evidenced?

Ask the vendor to distinguish standard settings from optional arrangements. A feature available under a negotiated enterprise agreement may not apply to a trial account.

Separate hosting location from transfer analysis

A statement that files are stored in a chosen region does not explain remote support, model providers, logs, or onward processing. Ask for a data-flow description that covers those paths. Have the privacy reviewer assess the applicable transfer conditions using the current law and actual arrangement.

For example, the main document store may have one location while a support function has access from another. That is a question to investigate and document, not a fact to infer from the hosting label. Record unresolved points as procurement conditions rather than assuming that a general privacy statement answers them.

Check training use and retention as different promises

A no-training commitment addresses one use of data. It does not necessarily specify how long operational logs are kept, whether support personnel can access content, or how a deleted document is handled in backups. Request the relevant contractual wording and operational explanation for each question.

Inspect exceptions, incorporated policies, change-notice provisions, and the mechanism for adding subprocessors. If a vendor answer conflicts with a contract term, resolve the discrepancy before approval. Keep the evidence version and date so a later reviewer can understand which commitments supported the decision.

Approve a defined use with follow-up ownership

Write a decision identifying the approved task, permitted data, access restrictions, contractual conditions, and review date. Specify who owns unresolved actions and which changes trigger reassessment. Avoid a permanent organisation-wide approved label based on one limited pilot.

For Judicio procurement, use the Security page and Trust Centre as starting points, then confirm the arrangements available for the relevant plan with the team. A regional article does not promise Swiss data residency or establish that a particular deployment meets a customer's obligations. Keep the approval tied to the evidence actually obtained.

Sources and next steps

This is an editorial workflow guide for legal professionals. The suggested checks are our practical recommendations, not a statement that a regulator requires a particular software workflow.

Explore Document Review and Review Matrix, or review Judicio's regional coverage and limitations. Check the underlying source and your organisation's approved process before relying on an output.