AuditXYZ

Compliance Framework

Federal Act on Data Protection (Bundesgesetz über den Datenschutz) (FADP (nDSG))

Switzerland's revised FADP modernizes the country's data protection framework to align closely with the GDPR, introducing enhanced transparency obligations, breach notification requirements, and significant personal liability for violations.

$8,000–$100,0002–8 months2020 (revised FADP enforced September 1, 2023)
Issuing BodySwiss Federal Assembly / Federal Data Protection and Information Commissioner (FDPIC)
First Published1992-06-19
Latest Version2020 (revised FADP enforced September 1, 2023)
Typical Cost$8,000–$100,000
Typical Timeline2–8 months
Audit RequiredNo
Audit FrequencyNo mandatory external audit. The FDPIC may open investigations. Data Protection Impact Assessments required for high-risk processing.
Geographyswitzerland

FADP: The Complete Guide

Switzerland's revised Federal Act on Data Protection (Bundesgesetz über den Datenschutz, or nDSG), effective September 1, 2023, represents a major overhaul of the country's data protection framework. Originally enacted in 1992, the revised FADP aligns Swiss law closely with the GDPR to maintain the EU's adequacy finding and ensure seamless cross-border data flows with Europe. For international organizations, Switzerland's FADP is the GDPR's closest near-twin — but with important Swiss-specific features, most notably a criminal liability regime that targets responsible individuals rather than organizations.

What the FADP Is and Who Enforces It

The revised FADP was adopted by the Swiss Federal Assembly and replaces the 1992 Act with a substantially modernized framework. The Federal Data Protection and Information Commissioner (FDPIC) is the independent oversight authority responsible for supervising compliance, investigating complaints, and issuing recommendations. Unlike the GDPR's supervisory authorities, which can impose binding fines directly, the FDPIC's primary enforcement tool is investigative recommendations. Criminal sanctions are imposed by cantonal courts at the request of the FDPIC or through public prosecution.

The FDPIC has been active in investigating complaints since the revised FADP entered force. In 2024-2025, the FDPIC issued investigative findings on cookie consent practices, addressed complaints regarding social media platform data sharing, and published opinions on AI-generated data and automated decision-making. Switzerland's position as a global financial and pharmaceutical hub means FDPIC decisions carry significant practical weight for many international organizations.

Territorial and Material Scope

The revised FADP applies to:

  • Processing of personal data of natural persons (unlike the old FADP, which also covered legal entities' data) by private individuals or federal bodies.
  • Processing that has effects in Switzerland, regardless of where the processing occurs.

This means foreign organizations whose data processing activities affect Swiss residents — for example, through digital services targeted at Switzerland or through processing of Swiss employee data — must comply with the FADP. Foreign controllers must designate a representative in Switzerland where they meet specified volume thresholds.

The revised FADP does not apply to personal data processed by individuals for exclusively personal purposes, to data processed by the judicial authorities, or to data processed at the international level by federal bodies governed by specific treaties.

Core Obligations Under the Revised FADP

Privacy by design and by default (Art. 7) — Technical and organizational measures must be implemented from the design stage to ensure data protection is built into processing systems. Default settings must restrict processing to the minimum necessary for the stated purpose. This obligation is more explicitly codified than in the 1992 Act and parallels GDPR Article 25.

Broad duty to inform (Art. 19) — Controllers must proactively inform data subjects when collecting any personal data — not just sensitive data as under the old law. Information must include: the identity and contact details of the controller, the processing purpose, recipients, countries to which data is transferred (if applicable), and the right to request information about the data held. The expanded duty to inform represents one of the most significant operational changes from the 1992 Act.

Record of processing activities (Art. 12) — Controllers and processors must maintain records of processing activities documenting purposes, data categories, recipients, retention periods, and security measures. Small and medium enterprises with limited processing risk may be exempt from this requirement under the implementing ordinance.

Data Protection Impact Assessment (Art. 22) — Where processing is likely to result in high risk to data subjects' personalities or fundamental rights, a DPIA must be conducted before commencing processing. The FDPIC may consult on the DPIA for unresolvable risks. The FADP does not require consultation with the FDPIC as a default (unlike GDPR's mandatory prior consultation for residual high-risk processing), but the FDPIC may initiate contact upon reviewing an assessment.

Data breach notification (Art. 24) — Controllers must notify the FDPIC of security breaches that pose a high risk to the personality or fundamental rights of affected data subjects as quickly as possible (interpreted as promptly and in any case within 72 hours by the FDPIC's guidance). Notification of affected data subjects is required where necessary to protect them.

Criminal Liability — A Key Swiss Distinction

The FADP's most distinctive and consequential feature compared to the GDPR is its criminal liability regime. While the GDPR imposes administrative fines on organizations, the revised FADP imposes criminal sanctions on responsible natural persons. Intentional violations of the duty to inform, breach notification obligations, due diligence obligations for cross-border transfers, and minimum security requirements can result in fines of up to CHF 250,000 against the responsible individual.

This personal liability framework makes Switzerland's FADP a uniquely powerful deterrent at the individual executive and DPO level. Directors, senior managers, privacy officers, and other individuals with personal data protection responsibilities should receive targeted training on the specific FADP obligations that carry criminal consequences.

Sensitive Personal Data Under the Revised FADP

The revised FADP's definition of sensitive personal data now includes genetic data and biometric data that uniquely identifies a natural person — updates not in the 1992 Act. The full list covers:

  • Health data.
  • Data concerning intimate or sexual conduct.
  • Social welfare data (receipt of benefits).
  • Racial or ethnic origin.
  • Political opinions, social activities, or other beliefs.
  • Administrative and criminal proceedings and sanctions.
  • Genetic data.
  • Biometric data that uniquely identifies a person.

Processing sensitive personal data requires explicit consent unless a specific statutory exception applies. Higher security standards and access controls are expected for sensitive data processing.

Cross-Border Transfers

Cross-border data transfers are restricted to countries that offer adequate data protection under the Federal Council's list. Key mechanisms:

  • Federal Council adequacy list — Countries recognized as providing equivalent protection. The EU/EEA is listed as adequate. The UK has time-limited recognition. Transfers to listed countries proceed without additional safeguards.
  • Standard contractual clauses — The FDPIC has approved specific FADP SCCs for use in non-adequate country transfers. GDPR SCCs are generally also recognized but organizations should verify current FDPIC guidance.
  • Binding corporate rules — Subject to FDPIC approval.
  • Consent — Individual consent for specific transfers, though reliance on consent alone is discouraged for systematic processing.
  • Exceptions — For transfers necessary for contract performance, legal claims, vital interests, or where the transfer is from a public register.

For organizations already using GDPR SCCs for EU data transfers, Swiss FADP compliance typically requires supplementary FADP-compliant SCC addenda or separate FADP SCCs for Swiss data flows.

Who Needs to Comply

Any organization processing personal data of Swiss residents with effects in Switzerland must comply. For foreign organizations, designation of a Swiss representative is required if: the processing concerns a large number of Swiss data subjects, the processing is regular or likely to carry high risk to Swiss residents' personalities, and the processing is not incidental. The representative must be based in Switzerland and is the contact point for the FDPIC and for data subjects.

The FADP achieves approximately 85% structural overlap with the GDPR — the highest of any non-EU law. The EU adequacy finding confirms this equivalence. Key differences:

  • Criminal vs. administrative liability — FADP targets responsible individuals; GDPR targets organizations.
  • No private right of action — The FADP channels enforcement through the FDPIC and criminal prosecution; GDPR allows DPAs to impose direct administrative fines and individuals to claim compensation in court.
  • Natural persons only — Revised FADP covers only natural persons' data; the 1992 Act also covered legal entities.
  • FDPIC enforcement model — Investigative recommendations without direct fine authority, supplemented by criminal sanction referral.

Compared to Canada's PIPEDA (60% GDPR overlap), the FADP is significantly stricter in its transparency requirements, breach notification scope, and criminal liability. Compared to CCPA (55% GDPR overlap), the FADP is far more rights-protective and imposes obligations regardless of business revenue or volume.

Compliance Steps and Timeline

PhaseActivitiesTypical Duration
AssessmentGap analysis vs. GDPR, criminal liability risk assessment, duty-to-inform audit2-4 weeks
DesignUpdated privacy notices, DPIA process, breach notification plan, Swiss SCCs3-6 weeks
ImplementationRecords of processing, representative designation, privacy by design review4-8 weeks
OngoingFDPIC guidance monitoring, annual DPIA review, training on criminal liabilityContinuous

Key compliance steps:

  1. Gap analysis against GDPR — Identify Swiss-specific requirements beyond existing GDPR compliance, focusing on criminal liability, expanded duty to inform, and Swiss transfer mechanisms.
  2. Information notices — Update all privacy notices to cover the expanded duty-to-inform obligations under Article 19, including for data collected offline.
  3. Records of processing — Maintain processing activity records meeting FADP requirements, including retention period documentation.
  4. DPIA process — Establish DPIA procedures for high-risk processing and document assessment outcomes.
  5. Breach notification — Implement processes to notify the FDPIC as quickly as possible following a high-risk breach, with documentation of the assessment.
  6. Cross-border transfers — Verify adequacy of destination countries per the Swiss Federal Council's current list and implement FADP-approved SCCs where needed.
  7. Representative appointment — Designate a Swiss representative if required as a foreign controller.
  8. Individual liability training — Train executives and privacy function personnel on the specific FADP obligations carrying criminal penalties.

How Privacy Automation Helps

The FADP's overlap with the GDPR means organizations with GDPR compliance programs can leverage the same operational infrastructure — data mapping, consent management, DSR workflows, breach notification — for Swiss compliance with targeted gaps filled. TruePrivacy supports the data discovery and DSR automation layer that underpins both GDPR and FADP compliance, covering both frameworks among its 12-plus supported programs. AI data discovery across 128-plus sources supports the broad duty-to-inform by maintaining an accurate and current data inventory.

At $5,000 per year with 24-hour onboarding and an AuditXYZ score of 88/100, TruePrivacy is well-suited for organizations extending European privacy programs to Switzerland. The criminal liability regime and FDPIC-specific engagement require qualified Swiss legal counsel. See best privacy management tools for broader comparisons.

Frequently Asked Questions

If we are GDPR-compliant, what additional steps do we need for the FADP? The main incremental steps are: expanding duty-to-inform notifications to cover all personal data (not just GDPR-specific triggers), ensuring breach notification procedures cover the FDPIC in addition to EU supervisory authorities, implementing FADP-specific SCCs or addenda for non-EU-adequate country transfers that involve Swiss data, designating a Swiss representative if required, and briefing responsible individuals on the personal criminal liability provisions.

Does the criminal liability under the FADP apply to company officers or only to individual employees? The revised FADP's criminal sanctions apply to the natural person responsible for the violation — this may be a company director, a chief privacy officer, a DPO, or any other individual who made the decision or bore responsibility for the non-compliant practice. Companies as legal entities face fines of up to CHF 50,000 in specific circumstances where identifying the responsible individual is impractical. The primary deterrent is individual liability.

Are there any FADP-specific DPO requirements? The revised FADP does not mandate appointment of a Data Protection Advisor (the Swiss equivalent of a DPO) but permits controllers to voluntarily appoint one. Voluntarily appointing a Data Protection Advisor may relieve the controller of some DPIA consultation obligations. Unlike the GDPR's mandatory DPO in certain circumstances, the FADP leaves this as a voluntary governance choice.

What is the difference between the FDPIC's adequacy list and the EU's adequacy list? Switzerland maintains its own list of countries with adequate data protection, determined by the Federal Council. While there is broad alignment with the EU list, Swiss adequacy determinations are independent and may differ on timing or scope. For example, the UK's adequacy status under Switzerland is assessed separately from its EU adequacy arrangement. Organizations should verify the current Swiss Federal Council list before assuming EU adequacy transfers cover Swiss data.

Does the FADP apply to the processing of employee personal data by Swiss-based companies? Yes. Swiss employers processing their employees' personal data fall within FADP scope. The duty to inform, security obligations, and breach notification apply to HR data processing. The revised FADP did not introduce a separate employment data regime, but the Federal Council's implementing ordinance and FDPIC guidance address proportionality principles for HR processing. Employee monitoring, health data processing, and cross-border HR transfers all require FADP-compliant treatment.

Request a FADP (nDSG) consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

GDPRHigh85%

Related frameworks

Get matched with a FADP (nDSG) auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.