← Blog

Using ChatGPT for your session notes? What Swiss law says — and what you risk

By Anne T. T. · Published August 3, 2026 · 8 min read

Many therapists quietly use ChatGPT to reformulate a session note, draft a report or summarise an anamnesis. It is fast and impressive — and it sends what you type to servers operated by a third party, generally outside Switzerland. For a profession bound by professional secrecy (art. 321 Swiss Criminal Code) and the nFADP, that habit deserves a serious look.

The legal frame: two layers of protection

1. Professional secrecy — art. 321 Criminal Code

Psychologists (like physicians) may not disclose a secret entrusted to them in the course of their profession. Disclosure to ANY third party — including a software vendor whose service is not bound into your practice by proper safeguards — can fall under this provision. It is a criminal offence, prosecuted on complaint.

2. Data protection — nFADP

Health data is sensitive data. Processing it through a provider requires a legal basis, proportionality, adequate safeguards for any transfer abroad, and a processing agreement. Our nFADP guide for therapists covers the fundamentals.

The three traps of “I anonymise before pasting”

  • Re-identification: in a caseload of 40 patients, “woman, 34, teacher, twins, grief” is not anonymous. Anonymisation fails as soon as the person remains recognisable.
  • Accumulation: each prompt seems harmless; the session history reconstructs the file.
  • Consumer settings: free/consumer versions may use content to improve services depending on settings, and retention/processing happen outside your control — without a DPA meant for health data.

The 10-question checklist before any AI tool

  1. Where is the data hosted (Switzerland, EU, USA)?
  2. Does the provider sign a data processing agreement (DPA) compliant with the nFADP?
  3. Are your inputs used to train models? Can this be disabled AND is it contractual?
  4. How long does the provider retain the data?
  5. Is the tool designed for health data (encryption, per-practitioner isolation)?
  6. Can you work without ever entering identifying data?
  7. Are your patients informed (and consent documented) if an AI processes their data?
  8. What happens in a data breach — who notifies the FDPIC?
  9. Can you export and delete the data at any time?
  10. Can the provider document all of this in writing?

If a provider cannot answer these questions in writing, the tool is not made for your practice. For the specifics of AI-assisted notes, see our dedicated guide: AI and session notes: confidentiality under the nFADP.

Using AI without betraying secrecy: what a compliant setup looks like

  • Processing under contract (DPA), with providers hosted in Switzerland or the EU
  • No training on your content, contractually
  • Per-practitioner encryption, so even the vendor cannot read your notes
  • Patient information and documented consent — our consent forms guide shows how

This is the setup Therago runs: self-hosted voice recognition and sovereign AI processing in Switzerland, AES-256 per-therapist encryption — designed so dictating your notes never means handing them to a consumer chatbot.

This article is general information, not legal advice. In doubt about a specific situation, consult a lawyer or your professional association (FSP, ASP, SBAP).

AI that respects professional secrecy

Dictation, structured notes and billing — processed in Switzerland, encrypted per therapist, never used for training.

Try Therago free
ChatGPT & Professional Secrecy: Swiss Therapist Risks | Therago