Key points
Similar principles, rights and accountability, easing programmes already built for the GDPR.
Records of processing and impact assessments for high-risk processing.
Adequacy-style approach with safeguards for exports to non-adequate countries.
Notify the FDPIC of breaches likely to result in high risk to data subjects.
The revised Federal Act on Data Protection (revFADP or nFADP) replaced Switzerland’s 1992 statute and came into force on 1 September 2023 with no transition period. It was accompanied by a new Data Protection Ordinance and an Ordinance on Data Protection Certification. The reform deliberately tracks the GDPR closely enough to preserve Switzerland’s adequacy position, while keeping several features that catch GDPR-trained teams out.
The single most important difference is the enforcement model. Swiss law punishes responsible individuals, not companies, and it does so through the criminal courts rather than through administrative fines issued by the regulator.
Who the revFADP applies to
Material and territorial scope, and the exclusions that matter in practice.
Natural persons only
Unlike the old law, the revFADP protects data relating to natural persons only. Data about legal entities fell out of scope in 2023, which narrowed the law relative to its predecessor.
Effects-based reach
The law applies to processing that has an effect in Switzerland, wherever the processing physically happens. A foreign business with Swiss-facing services can be in scope without any Swiss establishment.
Wider sensitive data
The Swiss definition of sensitive personal data is broader than the GDPR’s special categories. It expressly includes data on administrative and criminal proceedings and on social assistance measures.
Private and federal bodies
The Act governs private persons and federal bodies. Cantonal and communal public bodies remain subject to their own cantonal data protection laws, which vary.
The core duties
What a controller has to be able to show, and where the Swiss rules diverge from a GDPR baseline.
| Duty | What it requires | Swiss nuance |
|---|---|---|
| Register of processing | Maintain a record of processing activities. | Exemption for organisations with fewer than 250 employees on 1 January of any year, lost where large volumes of sensitive data or high-risk profiling are involved. |
| Privacy by design and default | Build data protection into systems from the outset and default to the least privacy-invasive setting. | Expressly codified; the FDPIC treats it as a design-stage obligation, not a retrofit. |
| Impact assessment | DPIA before processing likely to result in high risk to personality or fundamental rights. | Where high residual risk remains after mitigation, the controller must seek the FDPIC’s opinion before starting. |
| Information duty | Inform data subjects at collection, including recipients and export destinations. | Broader than the old law; the duty now attaches to all collection, not only sensitive data. |
| Data protection advisor | Optional role for the private sector. | Voluntary, unlike the GDPR’s conditional mandatory DPO. Appointing one brings a procedural benefit in the DPIA consultation route. |
| Processor engagement | Contract processors and ensure equivalent security. | Sub-processors require the controller’s prior approval. |
Rights and how they are exercised
Access
Individuals may request the data held about them and the information needed to exercise their rights. Normally free of charge, and normally answered within 30 days.
Data portability
A right to receive or transfer data in a common electronic format, where processing is automated and based on consent or contract.
Rectification and erasure
Correction of inaccurate data, and deletion or destruction where processing is unlawful or no longer justified.
Objection
Individuals may object to processing, and specifically to disclosure to third parties and to profiling in defined circumstances.
Automated decisions
Individuals must be told about decisions taken solely by automated means with legal or significant effect, and may ask for a human review.
Civil remedies
Claims run through the civil courts. The FDPIC does not award compensation, so private enforcement is a genuine channel.
Cross-border transfers
Structurally familiar to a GDPR practitioner, with a Swiss list and Swiss paperwork.
Adequate-country list
The Federal Council maintains its own list of states with adequate protection, set out in an annex to the Data Protection Ordinance. It is similar to the EU’s set of adequacy decisions but is a separate instrument and should be checked separately.
Safeguards where there is no adequacy
Transfers may rely on standard contractual clauses recognised or approved by the FDPIC, binding corporate rules, an approved code of conduct or certification, or a treaty.
EU SCCs need a Swiss overlay
The EU standard contractual clauses are accepted, but only with a Swiss addendum that names the FDPIC as a supervisory authority, substitutes Swiss law references and, where relevant, extends protection appropriately. Using the unmodified EU clauses is a common finding.
Swiss–US Data Privacy Framework
A Swiss extension of the Data Privacy Framework provides a route for transfers to participating US organisations that have self-certified under the Swiss component.
Derogations
Narrow exceptions exist for consent, contract performance, overriding public interest and legal claims. They are for occasional transfers, not for routine data flows.
Breach notification
A controller must notify the FDPIC as soon as possible where a breach of data security is likely to result in a high risk to the personality or fundamental rights of the affected individuals. There is deliberately no fixed 72-hour clock, which is one of the most frequently mis-stated points in Swiss compliance material.
That is not a relaxation. “As soon as possible” is a standard you have to be able to defend after the fact, and the absence of a stated deadline removes the comfort of a bright line. Processors must notify their controller as soon as possible; the assessment and the regulator-facing notification remain the controller’s.
Affected individuals must be informed where necessary for their protection or where the FDPIC requires it. Notably, information reported to the FDPIC under this duty may not be used in criminal proceedings against the notifying person without their consent, which softens the self-incrimination problem created by the individual-liability model.
Enforcement: the Swiss exception
This is where Switzerland departs most sharply from the rest of the world. The FDPIC can investigate, issue binding orders and ban processing, but the FDPIC cannot levy fines. Sanctions are criminal, are imposed by cantonal prosecutors and courts, and land on the responsible natural person with fines of up to CHF 250,000.
Only wilful breaches are punishable; negligence is not criminalised. Where identifying the responsible individual would require disproportionate investigative effort, the company itself may be fined, but only up to CHF 50,000.
| Conduct | Examples |
|---|---|
| Breach of information, access and cooperation duties | Wilfully failing to inform data subjects, or giving false or incomplete information in response to an access request. |
| Breach of duties of care | Wilfully exporting data without an adequate basis, or handing processing to a processor without the required assurances. |
| Breach of professional confidentiality | Disclosing confidential personal data learned in the course of a profession. |
| Disregard of FDPIC decisions | Wilfully ignoring a binding ruling of the FDPIC or a decision of an appeal court. |
revFADP compared with the GDPR
If you have a working GDPR programme, these are the deltas to close.
| Topic | Revised FADP | GDPR |
|---|---|---|
| Who is penalised | The responsible natural person | The organisation |
| Maximum penalty | CHF 250,000 on an individual | EUR 20m or 4% of global turnover |
| Fault required | Wilful breaches only | Intentional and negligent |
| Who imposes it | Criminal courts, via cantonal prosecutors | The supervisory authority directly |
| Breach deadline | As soon as possible, no fixed period | 72 hours |
| DPO | Voluntary for the private sector | Mandatory in defined cases |
| Records exemption | Under 250 employees, with conditions | No general SME exemption |
| Legal basis | No general list; private processing is lawful unless it unlawfully breaches personality rights | Requires an Article 6 basis |
| Scope of data subjects | Natural persons only | Natural persons only |
| Sensitive data | Broader, includes administrative and criminal proceedings and social assistance | Narrower enumerated list |
A delta-closing roadmap
For an organisation with an existing GDPR programme, this is usually weeks of targeted work rather than a rebuild.
Confirm applicability
Test for effects in Switzerland, and check whether the four conditions requiring a Swiss representative are all met for your processing.
Re-scope sensitive data
Re-run your classification against the broader Swiss definition. Administrative and criminal proceedings data and social assistance data are the usual additions.
Name responsible individuals
Given personal criminal exposure, map each obligation to a named role with real authority, and make sure those people are trained and resourced.
Fix the transfer paperwork
Add the Swiss addendum to EU standard contractual clauses, check the Federal Council’s own adequacy annex, and confirm Swiss DPF certification where you rely on it.
Rewrite notices
Ensure notices cover recipients, export destinations and safeguards, the Swiss representative where applicable, and automated decision-making.
Adapt the incident runbook
Replace the 72-hour trigger with an evidenced “as soon as possible” process, and record the reasoning behind timing decisions.
Set the DPIA consultation path
Define when high residual risk triggers a referral to the FDPIC, and who signs it off.
Frequently asked
Does GDPR compliance mean we are compliant in Switzerland?
It gets you most of the way, and the two regimes share principles, rights and accountability. It does not finish the job. The transfer paperwork needs a Swiss overlay, the sensitive-data definition is broader, the breach timing rule is different, and accountability must be assigned to named individuals because liability is personal.
Can the FDPIC fine our company?
No. The FDPIC investigates and issues binding orders but has no power to impose fines. Financial sanctions are criminal and are imposed by cantonal prosecution authorities and courts, normally on the responsible individual rather than the company.
Do we need a Swiss representative?
Only where all the statutory conditions are met together, broadly that you are a foreign controller processing Swiss data on a large scale and regularly, in connection with offering goods or services or monitoring behaviour, and the processing carries a high risk. Failing to appoint one is not itself a criminal offence, but it is a supervisory issue.
Is there a 72-hour breach deadline?
No. Swiss law requires notification “as soon as possible” where the breach is likely to result in a high risk. The absence of a fixed deadline makes the timing a judgement you must be able to justify, so document when you learned what and why you acted when you did.
Do we need a data protection officer?
Not in the private sector, where the data protection advisor role is voluntary. Appointing one is still worth considering, because it supports the DPIA consultation route and gives you a defensible accountability structure.
Does the law still cover data about companies?
No. That was a feature of the old 1992 Act. Since September 2023 the revFADP protects data relating to natural persons only.
From applicability to evidence
We map your processing to this regime, build the controls behind the obligations, and prepare the evidence that proves compliance.
Start a conversation