Privacy education, consultancy & implementation, in 50+ jurisdictions.contact@vedhacon.com
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Switzerland · revised FADP

Switzerland’s revised FADP, aligned yet distinct.

The revised Federal Act on Data Protection modernises Swiss privacy law and moves it closer to the GDPR, while retaining Swiss-specific features and oversight by the FDPIC.

What to note

Key points

GDPR-adjacent

Similar principles, rights and accountability, easing programmes already built for the GDPR.

Records & DPIAs

Records of processing and impact assessments for high-risk processing.

Transfers

Adequacy-style approach with safeguards for exports to non-adequate countries.

Breach reporting

Notify the FDPIC of breaches likely to result in high risk to data subjects.

The revised Federal Act on Data Protection (revFADP or nFADP) replaced Switzerland’s 1992 statute and came into force on 1 September 2023 with no transition period. It was accompanied by a new Data Protection Ordinance and an Ordinance on Data Protection Certification. The reform deliberately tracks the GDPR closely enough to preserve Switzerland’s adequacy position, while keeping several features that catch GDPR-trained teams out.

The single most important difference is the enforcement model. Swiss law punishes responsible individuals, not companies, and it does so through the criminal courts rather than through administrative fines issued by the regulator.

Article 2 and 3

Who the revFADP applies to

Material and territorial scope, and the exclusions that matter in practice.

Natural persons only

Unlike the old law, the revFADP protects data relating to natural persons only. Data about legal entities fell out of scope in 2023, which narrowed the law relative to its predecessor.

Effects-based reach

The law applies to processing that has an effect in Switzerland, wherever the processing physically happens. A foreign business with Swiss-facing services can be in scope without any Swiss establishment.

Wider sensitive data

The Swiss definition of sensitive personal data is broader than the GDPR’s special categories. It expressly includes data on administrative and criminal proceedings and on social assistance measures.

Private and federal bodies

The Act governs private persons and federal bodies. Cantonal and communal public bodies remain subject to their own cantonal data protection laws, which vary.

Accountability

The core duties

What a controller has to be able to show, and where the Swiss rules diverge from a GDPR baseline.

Principal obligations under the revised FADP
DutyWhat it requiresSwiss nuance
Register of processingMaintain a record of processing activities.Exemption for organisations with fewer than 250 employees on 1 January of any year, lost where large volumes of sensitive data or high-risk profiling are involved.
Privacy by design and defaultBuild data protection into systems from the outset and default to the least privacy-invasive setting.Expressly codified; the FDPIC treats it as a design-stage obligation, not a retrofit.
Impact assessmentDPIA before processing likely to result in high risk to personality or fundamental rights.Where high residual risk remains after mitigation, the controller must seek the FDPIC’s opinion before starting.
Information dutyInform data subjects at collection, including recipients and export destinations.Broader than the old law; the duty now attaches to all collection, not only sensitive data.
Data protection advisorOptional role for the private sector.Voluntary, unlike the GDPR’s conditional mandatory DPO. Appointing one brings a procedural benefit in the DPIA consultation route.
Processor engagementContract processors and ensure equivalent security.Sub-processors require the controller’s prior approval.
Profiling is a two-tier concept. The revFADP separates ordinary profiling from “high-risk profiling”, which matches data to assess essential aspects of someone’s personality. The high-risk tier carries stricter consent and assessment expectations, and has no exact GDPR twin.
Data subject rights

Rights and how they are exercised

Access

Individuals may request the data held about them and the information needed to exercise their rights. Normally free of charge, and normally answered within 30 days.

Data portability

A right to receive or transfer data in a common electronic format, where processing is automated and based on consent or contract.

Rectification and erasure

Correction of inaccurate data, and deletion or destruction where processing is unlawful or no longer justified.

Objection

Individuals may object to processing, and specifically to disclosure to third parties and to profiling in defined circumstances.

Automated decisions

Individuals must be told about decisions taken solely by automated means with legal or significant effect, and may ask for a human review.

Civil remedies

Claims run through the civil courts. The FDPIC does not award compensation, so private enforcement is a genuine channel.

Article 16 and 17

Cross-border transfers

Structurally familiar to a GDPR practitioner, with a Swiss list and Swiss paperwork.

1

Adequate-country list

The Federal Council maintains its own list of states with adequate protection, set out in an annex to the Data Protection Ordinance. It is similar to the EU’s set of adequacy decisions but is a separate instrument and should be checked separately.

2

Safeguards where there is no adequacy

Transfers may rely on standard contractual clauses recognised or approved by the FDPIC, binding corporate rules, an approved code of conduct or certification, or a treaty.

3

EU SCCs need a Swiss overlay

The EU standard contractual clauses are accepted, but only with a Swiss addendum that names the FDPIC as a supervisory authority, substitutes Swiss law references and, where relevant, extends protection appropriately. Using the unmodified EU clauses is a common finding.

4

Swiss–US Data Privacy Framework

A Swiss extension of the Data Privacy Framework provides a route for transfers to participating US organisations that have self-certified under the Swiss component.

5

Derogations

Narrow exceptions exist for consent, contract performance, overriding public interest and legal claims. They are for occasional transfers, not for routine data flows.

Article 24

Breach notification

A controller must notify the FDPIC as soon as possible where a breach of data security is likely to result in a high risk to the personality or fundamental rights of the affected individuals. There is deliberately no fixed 72-hour clock, which is one of the most frequently mis-stated points in Swiss compliance material.

That is not a relaxation. “As soon as possible” is a standard you have to be able to defend after the fact, and the absence of a stated deadline removes the comfort of a bright line. Processors must notify their controller as soon as possible; the assessment and the regulator-facing notification remain the controller’s.

Affected individuals must be informed where necessary for their protection or where the FDPIC requires it. Notably, information reported to the FDPIC under this duty may not be used in criminal proceedings against the notifying person without their consent, which softens the self-incrimination problem created by the individual-liability model.

Articles 60 to 65

Enforcement: the Swiss exception

This is where Switzerland departs most sharply from the rest of the world. The FDPIC can investigate, issue binding orders and ban processing, but the FDPIC cannot levy fines. Sanctions are criminal, are imposed by cantonal prosecutors and courts, and land on the responsible natural person with fines of up to CHF 250,000.

Only wilful breaches are punishable; negligence is not criminalised. Where identifying the responsible individual would require disproportionate investigative effort, the company itself may be fined, but only up to CHF 50,000.

What attracts criminal liability
ConductExamples
Breach of information, access and cooperation dutiesWilfully failing to inform data subjects, or giving false or incomplete information in response to an access request.
Breach of duties of careWilfully exporting data without an adequate basis, or handing processing to a processor without the required assurances.
Breach of professional confidentialityDisclosing confidential personal data learned in the course of a profession.
Disregard of FDPIC decisionsWilfully ignoring a binding ruling of the FDPIC or a decision of an appeal court.
Governance consequence. Because exposure is personal, accountability has to be assigned to named individuals who actually have the authority and budget to discharge it. Diffuse ownership is not just a control weakness in Switzerland; it is a way of exposing whoever happens to be nearest the decision.
Delta analysis

revFADP compared with the GDPR

If you have a working GDPR programme, these are the deltas to close.

Key differences between the revised FADP and the GDPR
TopicRevised FADPGDPR
Who is penalisedThe responsible natural personThe organisation
Maximum penaltyCHF 250,000 on an individualEUR 20m or 4% of global turnover
Fault requiredWilful breaches onlyIntentional and negligent
Who imposes itCriminal courts, via cantonal prosecutorsThe supervisory authority directly
Breach deadlineAs soon as possible, no fixed period72 hours
DPOVoluntary for the private sectorMandatory in defined cases
Records exemptionUnder 250 employees, with conditionsNo general SME exemption
Legal basisNo general list; private processing is lawful unless it unlawfully breaches personality rightsRequires an Article 6 basis
Scope of data subjectsNatural persons onlyNatural persons only
Sensitive dataBroader, includes administrative and criminal proceedings and social assistanceNarrower enumerated list
The legal-basis difference is conceptual, not cosmetic. Swiss law does not require you to select a lawful basis before processing. Instead, processing by private persons is permissible unless it unlawfully infringes personality rights, at which point a justification — consent, overriding private or public interest, or law — is needed. Teams that mechanically port a GDPR Article 6 register into Switzerland often document the wrong thing.
Practical steps

A delta-closing roadmap

For an organisation with an existing GDPR programme, this is usually weeks of targeted work rather than a rebuild.

1

Confirm applicability

Test for effects in Switzerland, and check whether the four conditions requiring a Swiss representative are all met for your processing.

2

Re-scope sensitive data

Re-run your classification against the broader Swiss definition. Administrative and criminal proceedings data and social assistance data are the usual additions.

3

Name responsible individuals

Given personal criminal exposure, map each obligation to a named role with real authority, and make sure those people are trained and resourced.

4

Fix the transfer paperwork

Add the Swiss addendum to EU standard contractual clauses, check the Federal Council’s own adequacy annex, and confirm Swiss DPF certification where you rely on it.

5

Rewrite notices

Ensure notices cover recipients, export destinations and safeguards, the Swiss representative where applicable, and automated decision-making.

6

Adapt the incident runbook

Replace the 72-hour trigger with an evidenced “as soon as possible” process, and record the reasoning behind timing decisions.

7

Set the DPIA consultation path

Define when high residual risk triggers a referral to the FDPIC, and who signs it off.

Questions

Frequently asked

Does GDPR compliance mean we are compliant in Switzerland?

It gets you most of the way, and the two regimes share principles, rights and accountability. It does not finish the job. The transfer paperwork needs a Swiss overlay, the sensitive-data definition is broader, the breach timing rule is different, and accountability must be assigned to named individuals because liability is personal.

Can the FDPIC fine our company?

No. The FDPIC investigates and issues binding orders but has no power to impose fines. Financial sanctions are criminal and are imposed by cantonal prosecution authorities and courts, normally on the responsible individual rather than the company.

Do we need a Swiss representative?

Only where all the statutory conditions are met together, broadly that you are a foreign controller processing Swiss data on a large scale and regularly, in connection with offering goods or services or monitoring behaviour, and the processing carries a high risk. Failing to appoint one is not itself a criminal offence, but it is a supervisory issue.

Is there a 72-hour breach deadline?

No. Swiss law requires notification “as soon as possible” where the breach is likely to result in a high risk. The absence of a fixed deadline makes the timing a judgement you must be able to justify, so document when you learned what and why you acted when you did.

Do we need a data protection officer?

Not in the private sector, where the data protection advisor role is voluntary. Appointing one is still worth considering, because it supports the DPIA consultation route and gives you a defensible accountability structure.

Does the law still cover data about companies?

No. That was a feature of the old 1992 Act. Since September 2023 the revFADP protects data relating to natural persons only.

Sources and scope. This guide summarises the revised Federal Act on Data Protection and its ordinances in original wording, and refers to article numbers as factual references only. It is general information, not legal advice, and it does not reproduce statutory text. Confirm the current position with the FDPIC or Swiss counsel before relying on it.
How we help

From applicability to evidence

We map your processing to this regime, build the controls behind the obligations, and prepare the evidence that proves compliance.

Start a conversation