Regulation Finder/Switzerland

Switzerland

Comprehensive

Federal Act on Data Protection (nFADP / revDSG) 2020

Authority: Federal Data Protection and Information Commissioner (FDPIC) | Enforcement: Active | Enacted: September 2023

Overview

Switzerland's revised Federal Act on Data Protection (nFADP) came into force in September 2023, replacing the 1992 law. It aligns closely with GDPR while maintaining Swiss specifics such as criminal penalties against individuals rather than administrative fines against organisations. Switzerland has EU adequacy status, facilitating seamless data flows with the EEA. The FDPIC is an active enforcer with expanded investigative powers under the new law.

14-Topic Coverage

Data Protection Authority

Fully Addressed

FDPIC is an independent federal authority overseeing compliance, investigations, and recommendations. Expanded powers under the nFADP include authority to issue orders and open investigations ex officio.

The FDPIC can open investigations ex officio or upon complaint. Under the nFADP, the Commissioner gained power to issue binding orders (previously limited to recommendations). The FDPIC cooperates with EDPB and participates in international enforcement networks.

nFADP Articles 43-59

Data Subject Rights

Fully Addressed

Rights to access, rectification, erasure, data portability, and objection to automated individual decisions. Right of access is a cornerstone of Swiss data protection.

The right of access (Article 25) allows individuals to obtain all data held about them, free of charge. Data portability (Article 28) enables requesting data in commonly used electronic format. The right to erasure and objection complement the framework, aligning with GDPR standards.

nFADP Articles 25-29, 32

Cross-Border Transfer

Fully Addressed

Transfers to countries with adequate protection per Federal Council list, or with safeguards such as SCCs, BCRs, or specific contractual clauses. EU/EEA countries are deemed adequate.

The Federal Council maintains an adequacy list. EU/EEA countries are recognised. For non-adequate countries, standard contractual clauses, BCRs, or specific safeguards are required. Transfer impact assessments may be needed. FDPIC must be notified of certain BCR arrangements.

nFADP Articles 16-18

Breach Notification

Fully Addressed

Must notify FDPIC as soon as possible of breaches likely to result in high risk to data subjects. Notification to affected individuals required when necessary for their protection.

Unlike the GDPR's 72-hour rule, Switzerland requires notification "as soon as possible" without a fixed deadline. The notification must describe the nature of the breach, consequences, and measures taken. Processors must notify controllers without delay.

nFADP Article 24

DPO Requirements

Partially Addressed

Not mandatory but voluntary appointment of a Data Protection Advisor (DPA) provides regulatory advantages. Federal bodies must appoint a DPA.

Private organisations that appoint a DPA can be exempted from the requirement to consult the FDPIC before high-risk processing (Article 23 consultation). Federal bodies must designate a DPA. The DPA must have adequate expertise and independence.

nFADP Articles 10, 23

Children's Data

Partially Addressed

General provisions apply. No specific age threshold defined in the nFADP. Processing of children's data must respect personality rights and proportionality.

Switzerland has not set a specific age for digital consent (unlike GDPR Article 8). General principles of data minimisation and proportionality apply with heightened protection for minors. The Civil Code provisions on capacity and parental authority supplement the nFADP.

nFADP general provisions, Swiss Civil Code Articles 12-19

Penalties & Enforcement

Fully Addressed

Criminal fines up to CHF 250,000 against responsible individuals (not organisations). FDPIC can issue administrative orders. Unique personal liability model in global data protection.

Switzerland uniquely targets individuals rather than organisations for criminal penalties. Violations include breach of information/access duties, duty of care for cross-border transfers, breach of professional secrecy, and failure to comply with FDPIC orders. The personal liability model is a strong deterrent for senior management.

nFADP Articles 60-66

Sector-Specific Rules

Fully Addressed

FINMA financial data rules, health data regulations under cantonal laws, telecom provisions under the Federal Data Communications Act. Banking secrecy remains a distinct feature.

FINMA oversees data processing in financial services. Swiss banking secrecy (Article 47 Banking Act) provides additional protections. Health data is also governed by cantonal health laws. The Federal Telecommunications Act addresses data in electronic communications.

Banking Act Article 47, FINMA Circulars, Federal Telecommunications Act

AI & Automated Decisions

Partially Addressed

Right to be informed about automated individual decisions under Article 21. No dedicated AI legislation yet, but FDPIC guidance on AI and data protection published.

Article 21 requires controllers to inform data subjects of fully automated decisions that significantly affect them. Data subjects may request human review. Switzerland has published national AI strategy but no specific AI regulation beyond the nFADP provisions.

nFADP Article 21

Data Localisation

Not Addressed

No general data localisation requirement. Switzerland actively promotes free data flows with adequate safeguards for international transfers.

nFADP Articles 16-18

Significant Data Fiduciary

Not Addressed

No equivalent concept. The nFADP applies uniformly to all controllers regardless of size, though the DPA voluntary appointment mechanism creates a de facto distinction.

nFADP general application

Government Data

Fully Addressed

nFADP applies to federal government bodies with specific provisions. Cantonal data protection laws govern cantonal and municipal authorities. Federal bodies must appoint a Data Protection Advisor.

Part 3 of the nFADP contains specific rules for federal bodies including legal basis requirements, disclosure between federal bodies, and outsourcing provisions. Each canton has its own data protection law for cantonal government processing.

nFADP Part 3 (Articles 33-42)

Key Statistics

Maximum Penalty
CHF 250,000 (criminal, against individuals)
Sections in Law
74
Authority
FDPIC

Coverage Summary

Fully Addressed9/14
Partially Addressed3/14
Not Addressed2/14
Pending0/14

Need Compliance Help?

Our data privacy team can help you navigate Switzerland's regulations.

Book a Consultation