Published on September 17, 2026
INTERNAL, CONFIDENTIAL, SECRET: the Confederation classifies its documents. And your SME?
Before deciding what its AI assistant was allowed to read, the Swiss Parliament needed something few companies possess: a classification system for its own documents. Without it, the question of "where to draw the line" is unanswerable—because you don't know what you're talking about. Here's how to do the same exercise at home, without a legal department and without a six-month project.
The three levels of the Confederation
The Ordinance on the Protection of Information of the Confederation (OPrI, RS 510.411) defines three levels. INTERNAL (art. 7): information which, if disclosed by unauthorized persons, may harm the interests of the country. CONFIDENTIAL (art. 6): those whose disclosure may be detrimental to these interests. SECRET (Art. 5): those whose disclosure could cause serious harm. The Parliament's AI assistant stops at the first level.
Why does this concern you, even without being a state secret?
The scale cannot be transposed as is—you don't have documents whose leak would endanger the country. But the mechanism itself is entirely transferable: We cannot decide where a document has the right to go until we have determined its value.
And the hierarchy already exists within your organization, without ever having been written down. No one hesitates to send the sales brochure by email; everyone would hesitate to do the same with the salary scale. Between the two, there is an implicit scale that everyone applies in their own way—that is to say, inconsistently.
The four levels of an SME
Four are enough. More than that, and nobody uses them.
- Audience — what is already online or intended to be online: brochures, job offers, articles, published rates. No restrictions.
- Internal — information that circulates within the company without being secret: procedures, meeting minutes, schedules, product documentation. A leak is embarrassing, but it doesn't cost anything.
- Confidential — information whose disclosure has a direct cost: contracts under negotiation, salary scales, margins, client lists, HR files, correspondence with a lawyer. This is the most populated level, and the most poorly managed.
- Sensitive data — the legal category of art. 5 let. c of the nLPD: health, private life, religious, philosophical, political or trade union opinions, social welfare measures, criminal and administrative proceedings or sanctions, genetic and biometric data. Here, it is no longer a question of caution, it is a question of law.
A medical certificate in an employee's file falls under the fourth level, not the third. Many companies find out about this at the worst possible time.
How to sort things out without spending six months on it
Don't start with your files, start with your workflows. List the ten types of documents your teams handle each week—supplier invoices, contracts, applications, meeting minutes, statements of account, customer correspondence—and assign a level to each. kind, not for every file.
Ten lines in a table, an afternoon's work, and you have what Parliament took months to formalize. The exercise has a secondary benefit: it generally reveals two or three data streams that no one knew contained sensitive information.
Each level has its own accommodation
Classification is useless if it doesn't lead to a technical rule. Here's the one we apply with our clients.
Public and internal Any compliant tool will do, including a shared Swiss cloud. The risk is low and convenience is paramount.
Confidential Dedicated Swiss cloud, no subcontractors subject to the CLOUD Act, logging of every process. This is the level at which nLPD compliance for the majority of SMEs is determined.
Sensitive data : local execution. Not because the Swiss cloud is legally inadequate, but because at this level the only guarantee that doesn't depend on any contract is physical — the document does not leave your machines.
What this changes in a supplier negotiation
Once you have this framework in hand, the conversation with an AI provider changes in nature. You no longer ask "Are you sovereign?", a question to which everyone answers yes. You ask: up to what level of my framework is your solution usable, and what do you propose above that?
That's precisely the question Parliament asked itself. Its answer was: up to the INTERNE level with Swisscom, nothing above that for the time being. At least it's clear.
Start with the table, not the tool
Most enterprise AI projects begin with choosing a tool and end with a discussion about compliance. Reversing this order takes an afternoon and avoids the discussion altogether.
Ten types of documents, four levels, a column "where it has the right to go". The rest follows from that.
Frequently asked questions
What are the classification levels of the Swiss Confederation?
The OPrI (RS 510.411) defines three: INTERNAL (art. 7), CONFIDENTIAL (art. 6) and SECRET (art. 5), from least serious to most serious according to the harm that would be caused by disclosure to unauthorized persons.
Does a small or medium-sized enterprise (SME) need to classify its documents?
While not legally required, without classification, it cannot rationally decide where its AI is allowed to go. Four levels—public, internal, confidential, and sensitive data—are sufficient for the vast majority of Swiss companies.
What constitutes sensitive data under the nLPD?
Article 5 letter c refers to data on religious, philosophical, political or trade union opinions or activities, on health, private life or racial affiliation, social assistance measures, criminal and administrative proceedings or sanctions, as well as genetic and biometric data.
Should all data be processed locally?
No, and it would be unnecessarily expensive. Public and internal levels are handled perfectly well in a compliant Swiss cloud. Local execution is justified for the most sensitive confidential documents and for sensitive data as defined by the nLPD (Swiss Federal Act on Data Protection).
To learn more: Why the Swiss Parliament has capped its AI at "INTERNAL"«, And what your colleagues are already doing with your documents.
Ten types of documents, four levels. We'll do the exercise with you in twenty minutes.
