By Daniel de Almeida Afonso · Last updated: September 30, 2026
Switzerland's revised Federal Act on Data Protection (FADP) came into force on 1 September 2023. It replaced a 1992 law that predated the internet as most businesses use it today, and it brings Swiss data protection much closer to the EU's GDPR.
If your business collects, stores, or processes personal data from people in Switzerland, whether or not you're based there, this guide covers what changed, who the law applies to, and what compliance actually requires.
What is the Federal Act on Data Protection (FADP)?
The FADP is Switzerland's core law governing how personal data is collected, used, stored, and shared. The revised version took effect on 1 September 2023, strengthening protections that the original 1992 law never anticipated.
The revision was passed by the Swiss Parliament on 25 September 2020. Before it could take effect, Swiss authorities needed to finalize an implementing ordinance covering practical details the statute itself left open. That ordinance is now in force alongside the act, so 1 September 2023 is the operative compliance date for every requirement below.
The update exists mainly to keep Swiss law compatible with the GDPR. That compatibility matters commercially: it underpins the European Commission's adequacy decision for Switzerland, which lets personal data move between the EU and Switzerland without extra transfer safeguards. Falling out of step with GDPR standards would put that adequacy status at risk.
Does the FADP apply to your business?
The FADP has extraterritorial reach. It applies to:
- Businesses operating in Switzerland, regardless of size or industry.
- Businesses located anywhere else in the world that process the personal data of individuals in Switzerland.
In practice, this covers a retailer with Swiss customers, a social media platform with Swiss users, a healthcare provider treating Swiss patients, or a bank serving Swiss clients, even if none of them have a physical Swiss office.
One important limit: the FADP protects only natural persons. Unlike the older Swiss law, it does not cover data belonging to companies or other legal entities. If your processing involves only corporate data (a business's own records, not information about the people behind it), the FADP doesn't apply to that data.
Foreign controllers and processors that handle Swiss personal data on a large scale, or in ways that carry higher risk, may also need to designate a representative in Switzerland. This is a practical detail many compliance checklists miss, and it's worth confirming early if your organization has no Swiss presence.
What personal data does the FADP cover?
The FADP covers any information relating to an identified or identifiable natural person. That spans:
- Basic identifiers: names, contact details, demographic information.
- Online and device data: IP addresses, device identifiers, location data, cookies, and other online identifiers.
- Sensitive personal data, which receives extra protection.
Sensitive personal data categories
The revised FADP expanded what counts as sensitive data. The full list now includes:
- Religious, philosophical, political, or trade union views and activities
- Health data
- Data relating to racial or ethnic origin
- Genetic data
- Biometric data that uniquely identifies a person
- Data on administrative or criminal proceedings and sanctions
- Data on social assistance measures
Genetic and biometric data are the two categories added in this revision; the rest carried over from the earlier law. Processing any of these categories requires stronger safeguards and a clearer legal basis than processing ordinary personal data.
Data subject rights under the FADP
Individuals whose data falls under the FADP have rights that will look familiar to anyone who has worked with the GDPR:
- Right of access: request a copy of their data and information on how it's processed.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion when data is no longer needed, consent is withdrawn, or there's no valid basis to keep it.
- Right to restriction of processing: request that processing pause while a dispute (for example, over accuracy) is resolved.
- Right to data portability: receive data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest or used for direct marketing.
Key legal requirements under the revised FADP
Scope
The FADP applies to processing that affects natural persons in Switzerland, regardless of where the processing organization is based. A company outside Switzerland that processes Swiss residents' data is in scope just as a domestic company is.
Consent
Consent under the FADP must now be specific and, in most cases, opt-in: the person takes an active step to agree before processing starts, rather than processing proceeding unless they object. This is a meaningfully higher bar than the previous law allowed, though the FADP stops short of GDPR's explicit requirement that consent be "unambiguous" in every case.
Processing sensitive personal data, or using personal data for high-risk profiling, requires explicit consent, a stricter standard than ordinary opt-in consent.
Automated individual decision-making
If an organization makes a decision about someone using only automated processing, and that decision has a legal effect or otherwise significantly affects the person, that person has the right to:
- Be informed that an automated decision was made about them
- Express their point of view
- Request that a natural person review the decision
This mirrors the logic behind GDPR Article 22, and it applies regardless of the sector, whether the automated decision concerns credit scoring, insurance, hiring, or another use case with a real-world consequence for the individual.
Privacy by design and by default
Organizations must build data protection into systems and processes from the start, not bolt it on afterward. In practice, this means minimizing the data collected, limiting who can access it, and configuring default settings to the most privacy-protective option.
Register of processing activities
Maintaining a record of processing activities is now a general obligation, not an optional best practice. The register should identify the purpose of each processing activity, the categories of data and data subjects involved, and who receives the data. Companies with fewer than 250 employees are exempt unless their processing carries a higher risk to individuals (for example, large-scale processing of sensitive data), so most small and medium-sized businesses have a narrower obligation than large enterprises.
International data transfers
Personal data can move freely to countries the Federal Data Protection and Information Commissioner (FDPIC) has recognized as providing an adequate level of protection. No additional approval or consent is required for transfers to those countries.
For transfers to countries without an adequacy finding, organizations need an additional legal safeguard, such as Standard Contractual Clauses, binding corporate rules, or the data subject's specific consent to that particular transfer. If you're setting up a cross-border transfer program more broadly, a fuller compliance guide covers the mechanisms in more depth than the Swiss-specific rules alone.
Data breach notification
The FADP requires notifying the FDPIC of a data breach that is likely to result in a high risk to the personality or fundamental rights of the affected individuals. This is a narrower trigger than the GDPR's, which requires notification unless a breach is unlikely to result in any risk at all.
There is no fixed notification deadline like the GDPR's 72 hours. The FADP requires notification "as soon as possible," which places the responsibility on the organization to act without unreasonable delay rather than against a hard clock. Affected individuals must also be informed directly when doing so is necessary to protect them, or when the FDPIC requires it.
Data Protection Impact Assessment (DPIA)
When processing is likely to pose a high risk to individuals' rights, organizations must carry out a DPIA before starting that processing. There's no prescribed template. What matters is a genuine assessment of the risks, their likely impact, and the measures in place to prevent or mitigate them. Secure Privacy's free DPIA templates are a reasonable starting point if you don't already have one.
Data Protection Officer
Unlike the GDPR, the FADP does not require organizations to appoint a Data Protection Officer. Appointing one is encouraged as good practice, and doing so can simplify some regulatory interactions, but it isn't a legal obligation under Swiss law the way it can be under the GDPR or Brazil's LGPD.
Penalties for non-compliance: the detail most guides get wrong
This is the single most misunderstood part of the FADP, so it's worth being precise.
The FADP fines responsible individuals, not the company itself. Where the GDPR imposes administrative fines directly on the organization (up to 4% of global annual turnover), the FADP takes a criminal-law approach aimed at the natural person who committed the violation.
- The maximum fine is CHF 250,000, imposed on the individual who intentionally committed a serious violation, for example, providing false information to the FDPIC, ignoring a legally binding order, or willfully violating information or disclosure duties.
- That individual remains liable even if the violation happened in the course of their employment.
- If an investigation cannot identify which individual within the organization was responsible, the company itself can be fined, but only up to CHF 50,000, a much lower ceiling than the individual penalty.
- There are no GDPR-style administrative fines against the organization as a matter of course. The FDPIC's main enforcement tool against organizations is a binding order requiring them to start, stop, or change a specific practice; if the organization complies, that alone can resolve the matter without a fine.
- In more serious cases, the FDPIC can refer a matter to prosecution authorities, which can lead to further criminal penalties.
The FDPIC is the independent authority responsible for supervising compliance and investigating suspected violations under the FADP.
FADP vs. GDPR: the key differences
| Area | FADP | GDPR |
|---|---|---|
| Who is fined | Responsible individual (up to CHF 250,000); company only as a fallback (up to CHF 50,000) | The organization directly (up to 4% of global turnover) |
| Data Protection Officer | Not required | Required in specified cases |
| Breach notification deadline | "As soon as possible," no fixed deadline | 72 hours |
| Breach notification threshold | High risk to the individual | Any risk, unless unlikely |
| Scope | Natural persons only | Natural persons only |
| Consent standard | Opt-in for most processing; explicit consent for sensitive data or high-risk profiling | Consent must be freely given, specific, informed, and unambiguous |
Do Swiss businesses need to comply with the GDPR too?
Having a compliant FADP program doesn't automatically satisfy the GDPR, and the reverse is also true. A Swiss company still needs to comply with the GDPR if it:
- Processes personal data of individuals located in the EU, regardless of why
- Offers goods or services to people in the EU, even without a physical EU presence
- Monitors the online behavior of people in the EU, such as through analytics or targeted advertising
If any of these apply, GDPR obligations run in parallel with FADP obligations, including, where applicable, appointing an EU representative and a Data Protection Officer, and meeting the GDPR's stricter, unambiguous consent standard.
How to comply with the Swiss FADP
A practical compliance checklist:
- Maintain a compliant privacy policy that reflects the FADP's transparency requirements
- Obtain valid opt-in consent before setting non-essential cookies, and use a compliant cookie banner
- Use explicit consent for sensitive personal data and high-risk profiling
- Maintain a register of processing activities if your business doesn't qualify for the SME exemption
- Have data breach detection and notification procedures in place, with clear internal ownership of the "as soon as possible" notification duty
- Confirm whether you need a Swiss representative if you process Swiss residents' data from outside Switzerland
- Transfer personal data internationally only to countries on the FDPIC's adequacy list, or use Standard Contractual Clauses or another valid safeguard for other transfers
- Run a Data Protection Impact Assessment before starting any high-risk processing
A cookie and consent management platform, such as Secure Privacy, handles the parts of this checklist tied to consent collection and cookie banners: recording opt-in consent, applying the stricter standard to sensitive processing, and keeping an auditable record of what each visitor agreed to. It doesn't replace the rest of your FADP program (your register of processing, breach procedures, and DPIA process still need to be built and owned internally) but it removes one of the more error-prone, manual pieces of it.
Frequently asked questions
When did the new Swiss FADP take effect?
1 September 2023. The revised act was passed by the Swiss Parliament on 25 September 2020, but didn't take effect until the implementing ordinance was finalized.
Does the FADP apply to companies outside Switzerland?
Yes. Any organization that processes the personal data of individuals in Switzerland is in scope, regardless of where the organization itself is located.
Who actually pays the fine under the FADP: the company or the individual?
Primarily the individual responsible for the violation, up to CHF 250,000. The company is fined only as a fallback, up to CHF 50,000, when the responsible individual can't be identified. This is a significant departure from the GDPR, which fines the organization directly.
Is there a 72-hour breach notification deadline like the GDPR?
No. The FADP requires notifying the FDPIC "as soon as possible" when a breach is likely to cause a high risk to affected individuals. There's no fixed number of hours, but delay beyond what's reasonable can itself become a compliance problem.
Does the FADP require a Data Protection Officer?
No. Appointing one is optional and considered good practice, but it isn't a legal requirement the way it can be under the GDPR.
Does complying with the GDPR automatically satisfy the FADP, or vice versa?
No. The two laws overlap substantially but aren't identical, particularly on penalties, breach notification timing, and the DPO requirement. A Swiss company serving EU customers, or an EU company serving Swiss customers, generally needs to satisfy both.


