Switzerland
ComprehensiveFederal Act on Data Protection (nFADP / revDSG) 2020
Authority: Federal Data Protection and Information Commissioner (FDPIC) | Enforcement: Active | Enacted: September 2023
Overview
Switzerland's revised Federal Act on Data Protection (nFADP) came into force in September 2023, replacing the 1992 law. It aligns closely with GDPR while maintaining Swiss specifics such as criminal penalties against individuals rather than administrative fines against organisations. Switzerland has EU adequacy status, facilitating seamless data flows with the EEA. The FDPIC is an active enforcer with expanded investigative powers under the new law.
14-Topic Coverage
Data Protection Authority
Fully AddressedFDPIC is an independent federal authority overseeing compliance, investigations, and recommendations. Expanded powers under the nFADP include authority to issue orders and open investigations ex officio.
The FDPIC can open investigations ex officio or upon complaint. Under the nFADP, the Commissioner gained power to issue binding orders (previously limited to recommendations). The FDPIC cooperates with EDPB and participates in international enforcement networks.
Consent Requirements
Fully AddressedConsent or other legitimate basis required. Explicit consent required for processing sensitive personal data and high-risk profiling. Consent must be informed and given voluntarily.
Unlike the GDPR, the nFADP does not require a specific legal basis for processing non-sensitive data — the general principle of good faith and proportionality applies. However, explicit consent is required for sensitive data and high-risk profiling. Consent must be specific to each processing purpose.
Data Subject Rights
Fully AddressedRights to access, rectification, erasure, data portability, and objection to automated individual decisions. Right of access is a cornerstone of Swiss data protection.
The right of access (Article 25) allows individuals to obtain all data held about them, free of charge. Data portability (Article 28) enables requesting data in commonly used electronic format. The right to erasure and objection complement the framework, aligning with GDPR standards.
Cross-Border Transfer
Fully AddressedTransfers to countries with adequate protection per Federal Council list, or with safeguards such as SCCs, BCRs, or specific contractual clauses. EU/EEA countries are deemed adequate.
The Federal Council maintains an adequacy list. EU/EEA countries are recognised. For non-adequate countries, standard contractual clauses, BCRs, or specific safeguards are required. Transfer impact assessments may be needed. FDPIC must be notified of certain BCR arrangements.
Breach Notification
Fully AddressedMust notify FDPIC as soon as possible of breaches likely to result in high risk to data subjects. Notification to affected individuals required when necessary for their protection.
Unlike the GDPR's 72-hour rule, Switzerland requires notification "as soon as possible" without a fixed deadline. The notification must describe the nature of the breach, consequences, and measures taken. Processors must notify controllers without delay.
DPO Requirements
Partially AddressedNot mandatory but voluntary appointment of a Data Protection Advisor (DPA) provides regulatory advantages. Federal bodies must appoint a DPA.
Private organisations that appoint a DPA can be exempted from the requirement to consult the FDPIC before high-risk processing (Article 23 consultation). Federal bodies must designate a DPA. The DPA must have adequate expertise and independence.
Children's Data
Partially AddressedGeneral provisions apply. No specific age threshold defined in the nFADP. Processing of children's data must respect personality rights and proportionality.
Switzerland has not set a specific age for digital consent (unlike GDPR Article 8). General principles of data minimisation and proportionality apply with heightened protection for minors. The Civil Code provisions on capacity and parental authority supplement the nFADP.
Penalties & Enforcement
Fully AddressedCriminal fines up to CHF 250,000 against responsible individuals (not organisations). FDPIC can issue administrative orders. Unique personal liability model in global data protection.
Switzerland uniquely targets individuals rather than organisations for criminal penalties. Violations include breach of information/access duties, duty of care for cross-border transfers, breach of professional secrecy, and failure to comply with FDPIC orders. The personal liability model is a strong deterrent for senior management.
Sector-Specific Rules
Fully AddressedFINMA financial data rules, health data regulations under cantonal laws, telecom provisions under the Federal Data Communications Act. Banking secrecy remains a distinct feature.
FINMA oversees data processing in financial services. Swiss banking secrecy (Article 47 Banking Act) provides additional protections. Health data is also governed by cantonal health laws. The Federal Telecommunications Act addresses data in electronic communications.
Cookie/Tracking
Fully AddressedFederal Telecommunications Act (FTC) requires consent for cookies and tracking technologies. Aligns with EU ePrivacy framework in practice.
Article 45c of the Telecommunications Act requires informed consent for storing or accessing data on user devices. This mirrors the EU ePrivacy Directive approach. Industry practice follows EU cookie consent standards given the close alignment.
AI & Automated Decisions
Partially AddressedRight to be informed about automated individual decisions under Article 21. No dedicated AI legislation yet, but FDPIC guidance on AI and data protection published.
Article 21 requires controllers to inform data subjects of fully automated decisions that significantly affect them. Data subjects may request human review. Switzerland has published national AI strategy but no specific AI regulation beyond the nFADP provisions.
Data Localisation
Not AddressedNo general data localisation requirement. Switzerland actively promotes free data flows with adequate safeguards for international transfers.
Significant Data Fiduciary
Not AddressedNo equivalent concept. The nFADP applies uniformly to all controllers regardless of size, though the DPA voluntary appointment mechanism creates a de facto distinction.
Government Data
Fully AddressednFADP applies to federal government bodies with specific provisions. Cantonal data protection laws govern cantonal and municipal authorities. Federal bodies must appoint a Data Protection Advisor.
Part 3 of the nFADP contains specific rules for federal bodies including legal basis requirements, disclosure between federal bodies, and outsourcing provisions. Each canton has its own data protection law for cantonal government processing.
Key Statistics
- Maximum Penalty
- CHF 250,000 (criminal, against individuals)
- Sections in Law
- 74
- Authority
- FDPIC
Coverage Summary
Quick Navigation
Need Compliance Help?
Our data privacy team can help you navigate Switzerland's regulations.
Book a Consultation