Switzerland
Switzerland Data Privacy Laws: Federal Act on Data Protection (nFADP) Compliance Guide
Independently fact-checked against primary sources (last audited September 9, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 9, 2026. · 21 primary sources cited on this page. How we verify our legal content

Switzerland governs data privacy through the revised Federal Act on Data Protection (nFADP, SR 235.1), which took effect September 1, 2023. The law is distinct globally: criminal fines of up to CHF 250,000 fall on the responsible individual, not the company, and only willful violations are punishable.
Switzerland operates one of the most distinctive data privacy regimes in the world. The revised Federal Act on Data Protection, known in English as the nFADP (new Federal Act on Data Protection) or FADP, and in German as the revDSG (revidiertes Datenschutzgesetz), SR 235.1, replaced a 1992 law that had not kept pace with the internet era. It entered into force on September 1, 2023, with no transition grace period.
The nFADP matters for any organization that processes personal data of individuals located in Switzerland, regardless of where that organization is headquartered. Its enforcement model, which targets the individual human being responsible rather than the corporate entity, sets it apart from every major data privacy regime in Europe and North America.
This guide explains every major provision of the nFADP as it stands in September 2026, including the growing body of FDPIC enforcement decisions that have emerged since the law took effect.
Jurisdictional scope: This article addresses the federal data protection law of Switzerland (SR 235.1, nFADP/revDSG) and the role of the FDPIC. Switzerland is not a member of the European Union; the EU GDPR does not apply directly to Swiss-domiciled controllers processing data inside Switzerland. Where a Swiss organization offers goods or services to EU/EEA residents or monitors their behavior, EU GDPR compliance obligations run in parallel. For Switzerland's recording consent rules, see Switzerland recording laws.
Quick Answer: What Law Governs Data Privacy in Switzerland?
Switzerland's data privacy law is the Federal Act on Data Protection, SR 235.1, as revised in September 2023 (nFADP/revDSG). The Federal Data Protection and Information Commissioner (FDPIC), based in Bern, supervises compliance. The EU GDPR does not apply directly, but Switzerland holds an EU adequacy finding, meaning EU-Switzerland personal data flows proceed without additional safeguards. The nFADP fines individuals up to CHF 250,000 for willful violations, not companies. Processing by private entities is generally lawful unless it infringes personality rights. Breach notification must be made to the FDPIC "as soon as possible" with no fixed 72-hour deadline.
History and Legislative Background
Switzerland's first Federal Act on Data Protection was enacted on June 19, 1992 (SR 235.1). At the time, the law was considered progressive, but by the 2010s it had become outdated. It predated cloud computing, smartphone tracking, behavioral profiling, and modern data broker practices.
The Federal Council submitted a comprehensive revision bill to Parliament in 2017. Parliament adopted the revised law during the fall 2020 session after substantial debate, particularly over the penalty model. The accompanying Ordinance on Data Protection (DPO, SR 235.11) and the Ordinance on Data Protection Certification (DPCO, SR 235.13) were finalized in August 2022.
The nFADP entered into force on September 1, 2023. There was no transition period. Existing data processing activities were required to meet the new requirements from day one.
Abbreviation Guide
The law appears under multiple abbreviations in legal and business literature:
- nFADP or FADP (English): new Federal Act on Data Protection
- revDSG or DSG (German): revidiertes Datenschutzgesetz
- revLPD (French): Loi sur la protection des données, révisée
- SR 235.1: the official Swiss statute number, stable across language versions
All refer to the same law.
Scope and Applicability
Who the nFADP Covers
The nFADP applies to the processing of personal data of natural persons by:
- Private individuals and private-sector organizations (companies, associations, foundations, sole traders)
- Federal government bodies
A significant change from the 1992 law: the nFADP protects only natural persons. The old law also extended protection to legal entities (companies), which was unusual internationally. Removing corporate data subjects aligns Switzerland with the GDPR approach and with the Council of Europe's Convention 108+.
Extraterritorial Reach
Article 3 of the nFADP establishes explicit extraterritorial scope. The law applies to any processing operation that produces effects in Switzerland, regardless of where the data controller or processor is located.
In practical terms, this covers three categories of foreign organizations:
- Organizations that offer goods or services to individuals in Switzerland, whether for payment or free of charge
- Organizations that monitor the behavior of individuals in Switzerland (for example, through cookies, tracking pixels, or behavioral analytics)
- Organizations that process personal data on behalf of Swiss-based controllers
Representative Requirement for Foreign Controllers
Article 14 nFADP reaches private controllers with a registered office or domicile abroad. It does not reach processors, and it does not reach federal bodies. Such a controller must appoint a representative in Switzerland only where all four statutory conditions are met at once:
- The processing is connected with offering goods or services to, or monitoring the behavior of, persons in Switzerland
- The processing is on a large scale
- The processing is carried out regularly
- The processing poses a high risk to the personality of the data subjects
The representative serves as the contact point for data subjects and for the FDPIC, and the controller must publish the representative's name and address. Article 15 sets out the representative's duties: keeping the record of the controller's processing activities described in Article 12(2), providing that record to the FDPIC on request, and telling data subjects on request how to exercise their rights.
Core Principles
Lawfulness and Good Faith
Personal data must be processed lawfully and in good faith. There is a fundamental structural difference here from the GDPR: under Swiss law, processing by private entities is generally permitted unless it unlawfully breaches the data subject's personality rights (Article 30 nFADP). Civil actions to protect personality are governed by Articles 28, 28a and 28g to 28l of the Swiss Civil Code, which Article 32(2) nFADP applies. The nFADP does not require controllers to identify a specific legal basis (consent, legitimate interest, contract, etc.) for every processing activity, as Article 6 GDPR does.
This means consent is not the default prerequisite for ordinary personal data processing in Switzerland. A justification under Article 31 becomes necessary only where the processing unlawfully breaches personality rights. Article 30(2) sets out what counts, including processing contrary to the principles of Articles 6 and 8, processing against the express wishes of the data subject, and the disclosure of sensitive personal data to third parties.
Proportionality and Purpose Limitation
Personal data may only be collected for a specific purpose that is recognizable to the data subject, and may only be processed in a manner compatible with that purpose. The data collected must be limited to what is proportionate to the stated purpose. Article 6 nFADP.
Data Accuracy
Controllers must ensure personal data is accurate and up to date. Where data is inaccurate, it must be corrected or deleted. This obligation is ongoing, not a one-time collection requirement.
Privacy by Design and Privacy by Default
The nFADP formally codifies both principles in Article 7:
- Privacy by Design requires organizations to build data protection into systems and processes from the earliest design stage, selecting technical and organizational measures that minimize data processing.
- Privacy by Default requires that default settings limit data processing to the minimum necessary for the declared purpose. Users must not have to take active steps to restrict unnecessary data collection; restrictive settings must be the default.
Neither principle appeared in the 1992 law. Their formal codification introduces compliance obligations for system architects, product managers, and IT procurement teams, not just privacy lawyers.
Sensitive Personal Data
An Expanded Definition
The nFADP expanded the categories of sensitive personal data. Under Article 5(c) nFADP, sensitive personal data includes:
| Category | Notes |
|---|---|
| Religious, philosophical, political, or trade union views or activities | Same as GDPR |
| Health data | Same as GDPR |
| Intimate or private life, including sexual orientation | Same as GDPR |
| Race or ethnicity | Same as GDPR |
| Genetic data | New under the nFADP |
| Biometric data uniquely identifying a person | New under the nFADP |
| Administrative and criminal proceedings or sanctions | Broader than GDPR special categories |
| Social assistance measures | Broader than GDPR special categories |
The last two categories, administrative and criminal proceedings and social assistance measures, extend the Swiss sensitive-data definition beyond the GDPR's Article 9 list. Article 5(c)(6) covers data relating to social assistance (welfare) measures, which is narrower than social security in the everyday sense of pension and state insurance records. Organizations processing these data types in Switzerland face stricter requirements than the GDPR imposes in the EU.
Processing sensitive personal data is not unlawful in itself and does not automatically require consent. Where the processing unlawfully breaches personality rights, it needs a justification under Article 31(1): the data subject's consent, an overriding private or public interest, or the law.
Disclosing sensitive personal data to third parties is expressly listed as a breach of personality rights in Article 30(2)(c). Where consent is the justification relied on, Article 6(7)(a) requires it to be explicitly given.

Data Subject Rights
The nFADP significantly expanded individual rights compared to the 1992 law.
Right of Access (Article 25)
Any person may submit a written request to a data controller asking whether personal data concerning them is being processed. Upon receiving a valid request, the controller must provide:
- Its identity and contact details
- The personal data being processed
- The purpose of processing
- The retention period or criteria used to determine it
- The origin of data not collected directly from the subject
- Any automated individual decision-making applied, including profiling
- The recipients or categories of recipients to whom data has been or will be disclosed
The information must be provided free of charge and, as a rule, within 30 days of the request (Article 25(6) and (7) nFADP; Article 18 DPO). Swiss law does not use the GDPR's manifestly-unfounded-or-excessive fee test. Under Article 19 DPO a controller may ask the data subject to contribute to costs only where providing the information involves a disproportionate cost. The contribution may not exceed CHF 300, the controller must notify the amount before providing the information, and if the data subject does not confirm the request within ten days it is deemed withdrawn at no cost, with the 30-day clock beginning on expiry of that ten-day reflection period.
An obviously unjustified request is not a fee trigger under Swiss law at all. It is a ground to refuse, restrict or delay information outright under Article 26(1)(c) nFADP. The FDPIC's January 2025 ruling against Cembra Money Bank AG found the bank had answered 9 of 13 access requests outside the 30-day deadline, in violation of Article 25 nFADP, and had used a standardized response text that failed to provide the required individualized information.
Right to Data Portability (Article 28)
Data subjects may request their personal data in a commonly used, machine-readable electronic format, or ask the controller to transfer it directly to another controller. This right applies where the data was provided by the data subject and processed with their consent or for the performance of a contract.
Right to Rectification and Erasure
Data subjects may request correction of inaccurate personal data (Article 32(1)). Deletion is claimed through the personality action that Article 32(2) routes to Articles 28 and following of the Civil Code, under which the applicant may ask that data be deleted or destroyed. Independently, Article 6(4) obliges the controller to destroy or anonymise personal data once it is no longer needed for the purpose of the processing.
Right to Object
Data subjects may object to the processing of their personal data. An objection matters because Article 30(2)(b) makes processing contrary to the data subject's express wishes a breach of personality rights. The controller may continue only if it can show an Article 31(1) justification, in practice an overriding private or public interest.
Automated Decision-Making
Individuals have the right not to be subject to a decision based solely on automated processing, including profiling, that significantly affects them, unless they have consented, the decision is authorized by law, or it is necessary for the performance of a contract. Where an automated decision is made, the data subject may request that it be reviewed by a natural person.
Transparency: Duty to Inform
Under Articles 19 through 21 of the nFADP, controllers must proactively inform data subjects when collecting their personal data. This duty applies to all personal data, not only sensitive data, which is stricter than the 1992 law.
The required information includes:
- Identity and contact details of the controller, and of the Swiss representative if the controller is abroad
- Purpose of processing
- Recipients or categories of recipients of the data
- If data is transferred abroad: the destination country and the safeguards in place
When data is not collected directly from the individual, the controller must provide this information at the latest within one month of receiving the data, or before first disclosure to a third party if that occurs sooner.
Exceptions apply where notification would be disproportionately onerous, where the data was already known to the data subject, where recording or disclosure is explicitly required by law, or where overriding third-party interests require confidentiality.
Profiling Under Swiss Law
The nFADP draws a two-tier distinction that differs from the GDPR approach.
Standard profiling, meaning automated processing of personal data that evaluates certain personal aspects, does not require consent under Swiss law. A lawful basis is only needed if the profiling infringes personality rights.
Article 5(f) defines ordinary profiling. Article 5(g) defines high-risk profiling as profiling that poses a high risk to the data subject's personality or fundamental rights by matching data that allow an assessment to be made of essential aspects of the personality of a natural person.
Consent is not a precondition for high-risk profiling. Where it breaches personality rights it needs a justification under Article 31: the data subject's consent, an overriding private or public interest, or the law. Where consent is the justification relied on, Article 6(7)(b) requires that it be explicitly given. One route is closed off: the creditworthiness-checking interest in Article 31(2)(c) is unavailable where the matter involves high-risk profiling.
The GDPR by contrast requires a lawful basis for all profiling and grants data subjects a general right to object to profiling under Article 21, with stronger protections for solely automated profiling under Article 22. The Swiss model gives organizations more latitude for standard profiling, while high-risk profiling that breaches personality rights must rest on an Article 31 justification, and that justification has to be explicit where it is consent.
Data Protection Impact Assessments
Article 22 of the nFADP requires a Data Protection Impact Assessment (DPIA) before any processing operation that is likely to result in a high risk to the personality or fundamental rights of data subjects. Article 22(2) gives two statutory examples of when such a risk arises:
- Large-scale processing of sensitive personal data
- Systematic monitoring of public areas on a large scale (for example, CCTV coverage of a city center)
High-risk profiling is not one of the two enumerated examples, but it will normally clear the general Article 22(1) test, which turns on the nature, extent, circumstances and purpose of the processing.
If the DPIA reveals that the planned processing would still present a high risk despite planned mitigation measures, the controller must seek the FDPIC's opinion before beginning the processing. A private controller may dispense with that consultation only if it has actually consulted its data protection officer on that processing (Article 23(4)), and only if all four conditions in Article 10(3) are satisfied. Having an advisor on the org chart is not enough on its own.
There is no prescribed format for DPIAs under the nFADP. Organizations may follow GDPR DPIA methodology, which the FDPIC considers adequate, or develop their own structured assessments.
Data Breach Notification
The nFADP introduced mandatory breach notification for the first time in Swiss data protection law.
Controller Obligations
Under Article 24 nFADP, a controller must notify the FDPIC as soon as possible when a data security breach is likely to result in a high risk to the personality or fundamental rights of affected individuals. There is no fixed deadline equivalent to the GDPR's 72-hour window. The FDPIC has published detailed guidelines on data breaches and operates a dedicated online notification portal.
Controllers must also notify affected data subjects if notification is necessary for their protection, or if the FDPIC requires it.
Processor Obligations
Data processors must notify the controller as soon as possible of any breach. The controller then bears responsibility for assessing whether FDPIC notification and data subject notification are required.
The "High Risk" Threshold
The nFADP's notification threshold is "high risk to personality or fundamental rights," which is a higher bar than the GDPR's standard of "risk to the rights and freedoms of natural persons." Breaches posing a moderate or low risk do not trigger notification obligations under Swiss law. Organizations operating in both Switzerland and the EU may therefore face GDPR notification duties for incidents that fall below the Swiss notification threshold.

Cross-Border Data Transfers
Adequacy Decisions
The Federal Council maintains an official list of countries whose data protection is recognized as adequate under Article 16 nFADP and Article 8 DPO. Personal data may flow freely to countries on this list without additional safeguards. The authoritative source is Annex 1 to the Data Protection Ordinance on Fedlex, which is the list itself and is amended whenever a country is added. The FDPIC's adequacy page explains how the list operates, and the Federal Office of Justice's data protection page carries the legislative background.
Switzerland's EU Adequacy Status
The European Commission's January 15, 2024 adequacy report confirmed that Switzerland continues to provide adequate data protection under the GDPR. The Commission's review specifically cited the nFADP's modernization as strengthening the adequacy basis. The next scheduled Commission review under Article 97(2) GDPR is not due until approximately 2028. Swiss-to-EU and EU-to-Swiss personal data transfers may continue without additional safeguards.
Swiss-US Data Privacy Framework
On August 14, 2024, the Federal Council decided that the Swiss-US Data Privacy Framework (Swiss-US DPF) provides adequate protection for transfers of personal data to certified US companies. The Swiss-US DPF took effect on September 15, 2024. US organizations certified under the framework and listed on the Data Privacy Framework website may receive Swiss personal data without additional transfer safeguards.
The framework remains in force. The United States is entry 44 in Annex 1 to the Data Protection Ordinance, added by the Ordinance of August 14, 2024 in force since September 15, 2024 (AS 2024 435). Annex 1 also records what the Swiss listing rests on: Executive Order 14086 of October 7, 2022, the rule establishing the US Attorney General's Data Protection Review Court, Intelligence Community Directive 126, and the designation of Switzerland on June 7, 2024 as a country covered by the two-layer redress mechanism. Withdrawal of those conditions is what would put the listing at risk.
Organizations should still keep a backup transfer mechanism such as Standard Contractual Clauses with Swiss Add-ons. The concrete reason today is not Schrems I or Schrems II but the live challenge to the parallel EU framework: the EU General Court dismissed Latombe v Commission (T-553/23) on September 3, 2025, and Mr Latombe appealed to the Court of Justice on October 31, 2025 in Case C-703/25 P, which is still pending.
Standard Contractual Clauses: The Swiss Finish
For transfers to countries without an adequacy finding, Swiss Standard Contractual Clauses are the most commonly used mechanism. The FDPIC has issued guidance indicating that organizations may adapt the EU-approved SCCs for Swiss purposes by adding "Swiss Finish" clauses. These modifications typically:
- Replace references to the GDPR with references to the nFADP
- Designate the Swiss courts or the FDPIC as the competent supervisory authority
- Incorporate Swiss-specific data subject rights
A Transfer Impact Assessment should accompany SCC-based transfers to jurisdictions that pose elevated legal risks to data subjects (for example, jurisdictions with broad government surveillance powers).
Other Transfer Mechanisms
Additional recognized transfer mechanisms under Article 16 nFADP include:
- Binding Corporate Rules approved by the FDPIC
- Standard data protection clauses approved by the FDPIC
- Codes of conduct approved by the FDPIC
- Explicit consent of the data subject after being informed of the destination and the absence of adequate protection
- Performance of a contract with the data subject or in their interest
- Overriding public interests
The FDPIC: Switzerland's Supervisory Authority
The Federal Data Protection and Information Commissioner (FDPIC) is Switzerland's independent national data protection authority. The office is based in Bern. The Commissioner is elected by the United Federal Assembly (Article 43(1) nFADP) and reports annually to the Federal Assembly, submitting the report to the Federal Council at the same time (Article 57(1) nFADP). The Judiciary Committee, not the Federal Council, may issue a reprimand (Article 44a).
Expanded Powers Under the nFADP
The nFADP substantially strengthened the FDPIC's supervisory toolkit compared to the 1992 law, under which the Commissioner could only issue recommendations that parties were free to ignore:
- Preliminary enquiries: Low-threshold preliminary examinations where there is a suspicion of a data protection issue. These can be concluded without opening a formal investigation.
- Formal investigations: Opened under Article 49 ff nFADP where there are clear indications of a violation. The FDPIC may gather evidence and compel production of documents.
- Binding administrative orders: Following an investigation, the FDPIC may issue legally binding orders requiring a controller or processor to modify or cease specific processing activities. These orders are enforceable and may be appealed to the Federal Administrative Court.
- Mandatory DPIA consultation: Controllers must seek the FDPIC's opinion before proceeding where a DPIA reveals high residual risk, unless the narrow Article 23(4) and Article 10(3) exception applies.
- Amicus participation: The FDPIC may participate in court proceedings involving data protection matters.
What the FDPIC Cannot Do
The FDPIC cannot impose fines. This is a fundamental structural difference from EU Data Protection Authorities, which under the GDPR may levy administrative fines of up to EUR 20 million or 4% of global annual turnover. In Switzerland, monetary penalties rest exclusively with cantonal criminal prosecution authorities, and only for intentional violations.
Enforcement Track Record (2023-2026)
The FDPIC's most recent reporting year gives the clearest picture of enforcement activity to date:
- In its 33rd Annual Report, covering April 1, 2025 to March 31, 2026, the FDPIC records 2,447 reports received, 2,347 of them against private entities, plus 156 low-threshold interventions, 22 preliminary investigations and 9 formal investigations, 6 of which were opened during that reporting year. Two cases were pending before the Federal Administrative Court at the close of the year.
- Mediation requests are not a data protection enforcement measure. They belong to the Freedom of Information Act: an applicant or affected third party who disagrees with a federal authority's decision on access to official documents submits a mediation request to the FDPIC. The FDPIC received 203 of them in 2025, one more than the year before, and reached an amicable solution in 73 percent of the sessions held. These figures say nothing about nFADP enforcement.
Key enforcement actions since the nFADP took effect include the following. One entry, the Digitec Galaxus investigation, was decided under the previous law and is labeled as such.
| Date | Case | Outcome |
|---|---|---|
| April 2024 | Digitec Galaxus (online retailer) | Investigation concluded under the pre-2023 DSG, not the nFADP. FDPIC found linking the ordering process to account creation violated proportionality, and issued formal recommendations including an option to object to marketing use of personal data |
| January 29, 2025 | Cembra Money Bank AG | Binding order: bank violated 30-day deadline for access requests and used inadequate standardized response texts |
| April 28, 2025 | Inkasso-Team AG | Binding order: debt collector's publication of alleged debtors' names on public website violated proportionality and transparency; ordered to delete published data. The company appealed, and on June 22, 2026 the Federal Administrative Court fully dismissed the appeal (A-3891/2025). That judgment has entered into legal force and the website has been taken offline |
| May 16, 2025 | PostFinance AG | Binding order: bank's use of voice recognition for authentication constituted biometric data processing without explicit consent; ordered to obtain express consent and delete voiceprints lacking consent. PostFinance has appealed to the Federal Administrative Court, so the ruling has not yet taken full legal effect |
| August 14, 2025 | Add Conti GmbH | FDPIC ordered the data-brokering company to cooperate and filed a criminal complaint with the St. Gallen public prosecutor for breach of the duty to cooperate in an Article 49 investigation. Both the data protection investigation and the criminal proceedings were still pending when the 33rd Annual Report went to press |
| October 2, 2025 | Coop | Preliminary investigation into AI video surveillance at automatic checkouts closed without a formal investigation; the processing was found to comply with the nFADP |
| October 6, 2025 | Bürgerforum Schweiz | Federal Administrative Court dismissed the association's appeal, upholding the FDPIC's processing ban of April 9, 2024. The association had published online the details of clergy and other church workers who had merely been sent, or registered for, its Pfarrer-Check questionnaire, which the FDPIC found disproportionate |
| February 12, 2026 | Digitec Galaxus (closure) | Galaxus told the FDPIC on November 27, 2025 that it had implemented a one-click personalisation opt-out. The FDPIC announced the closure of the case on February 12, 2026 |
| February 24, 2026 (ongoing) | BLT Baselland Transport AG | Formal investigation opened under Article 49 ff. nFADP into body cameras worn by train conductors; announced February 26, 2026 and still ongoing at March 31, 2026 |
| March 3, 2026 (ongoing) | Swiss digital identity and age-verification provider | Formal investigation under Article 49 nFADP into the use of biometric data collected during identity verification to train the company's AI systems |
| April 17, 2026 | Cream della Cream Switzerland GmbH and Philipp Plein International AG | Binding order after the companies kept using customer email addresses and phone numbers for advertising despite objections and confirmed deletions, in breach of good faith. Ordered to stop on objection and delete on request; the ruling entered into legal force when the 30-day appeal period expired |
Criminal Penalties: Switzerland's Unique Individual-Liability Model
Structure of the Penalty Regime
Articles 60 through 66 of the nFADP establish the criminal penalty framework. The maximum fine is CHF 250,000. This fine is imposed on the natural person who committed the violation, not on the organization as an entity. The legislative history of the nFADP makes clear that Parliament intended these penalties to target management personnel and decision-makers, not front-line employees carrying out instructions.
This model is effectively unique globally. The GDPR imposes administrative fines on the organization itself. Canada's PIPEDA imposes fines on organizations. Australia's Privacy Act imposes penalties on entities. Switzerland's choice to target the individual is a deliberate legislative policy choice rooted in Swiss criminal law tradition, which generally requires a responsible natural person for criminal sanctions.
Intent Requirement: Only Willful Violations Are Punishable
Only intentional (willful) violations trigger criminal penalties under the nFADP. Negligent violations, including failures arising from poor data governance, inadequate systems, or organizational oversights, are not punishable. Prosecutors must establish that the accused acted with intent to violate the law.
This intent requirement substantially narrows the scope of criminal exposure compared to the GDPR, where administrative fines may be imposed for negligent violations. However, it creates particular risk for individuals who knowingly disregard clear compliance obligations.
Specific Criminal Offenses
| Article | Offense |
|---|---|
| Art. 60 | Violating the duty to provide information, the access right, or the duty to cooperate with the FDPIC; providing false information to the FDPIC |
| Art. 61 | Cross-border transfer without adequate safeguards; failing to engage processors meeting security requirements; failing to meet minimum data security standards |
| Art. 62 | Breach of professional confidentiality: intentionally disclosing confidential personal data obtained through professional activities |
| Art. 63 | Disregard of decisions: wilfully failing to comply with a ruling issued by the FDPIC, or with an appeal court decision that refers to the penalty under Article 63 |
Failing to appoint a Swiss representative is not a criminal offense anywhere in Articles 60 to 63. The FDPIC's remedy is administrative: under Article 51(4) nFADP it may order a private controller with a registered office or domicile abroad to appoint a representative under Article 14. Criminal liability arises only if the organization then wilfully defies that order, which brings it within Article 63.
Company Liability as Exception
Where identifying the specific responsible individual within a company would require disproportionate investigative effort, the company itself may be fined up to CHF 50,000. This subsidiary entity liability is the exception rather than the rule and applies only when the per-individual attribution is genuinely impracticable.
Prosecution by Cantonal Authorities
Prosecution and adjudication of criminal acts is a matter for the cantons under Article 65(1) nFADP. The FDPIC does not prosecute. But it is not shut out of the criminal track: Article 65(2) provides that the FDPIC may file a complaint with the competent prosecution authority and exercise the rights of a private claimant in the proceedings.
The FDPIC has used that power. On August 14, 2025 it filed a criminal complaint against the data broker Add Conti GmbH with the St. Gallen public prosecutor for refusing to cooperate in an Article 49 investigation, and announced the step on August 21, 2025.
Which offenses reach a prosecutor at all depends on who may complain. The offenses in Articles 60(1), 61 and 62 are prosecuted only on complaint. Providing the FDPIC with false information or refusing to cooperate in an investigation (Article 60(2)) and disregarding an FDPIC ruling (Article 63) are prosecuted ex officio.
This decentralized model means enforcement may vary across cantons. As of September 2026 there are no publicly reported criminal convictions under the new law, and the Add Conti criminal proceedings were still pending when the FDPIC's 33rd Annual Report went to press.

Record of Processing Activities
Controllers and processors must maintain a written record of their processing activities under Article 12 nFADP. The record must include:
- Identity of the controller or processor
- Purpose of each processing activity
- Categories of data subjects and personal data processed
- Categories of recipients, including cross-border recipients
- Destination countries and safeguards for cross-border transfers
- Retention periods or determination criteria
- General description of technical and organizational security measures
SME Exemption
Article 24 DPO exempts undertakings and other private organisations employing fewer than 250 employees on 1 January of any year, and natural persons, from the obligation to keep a record of processing activities. This exemption has no equivalent in the GDPR, which applies to all organizations regardless of size except for a narrow exception for occasional processing by SMEs.
The exemption falls away in exactly two situations, and those two are exhaustive: where a large volume of sensitive personal data is being processed, or where high-risk profiling is being carried out. There is no general significant-risk test. Systematic monitoring of individuals is not a disqualifier, so an SME that systematically monitors individuals, but neither processes a large volume of sensitive data nor carries out high-risk profiling, keeps the exemption.
Data Protection Advisor
Voluntary for Private Organizations
Unlike the GDPR, which mandates a Data Protection Officer (DPO) for certain categories of controller (public bodies, organizations conducting large-scale systematic monitoring, or large-scale sensitive data processors), the nFADP does not require private organizations to appoint a Data Protection Advisor (Datenschutzberater/-beraterin).
The Compliance Incentive
Appointing a Data Protection Advisor can carry a concrete compliance benefit, but the benefit is neither automatic on appointment nor unconditional. Under Article 23(4) nFADP a private controller may dispense with consulting the FDPIC only if it has actually consulted its data protection officer on that specific processing. Under Article 10(3) it may invoke that exception only if all four of the following hold:
- The officer exercises the function towards the controller in a professionally independent manner and is not bound by instructions
- The officer carries out no activities incompatible with the role
- The officer has the required expertise
- The controller publishes the officer's contact details and notifies them to the FDPIC
An organization that appoints a non-independent internal advisor, or never notifies the FDPIC, keeps the prior-consultation duty in full. Skipping the consultation on the mistaken belief that the exemption applies is the kind of failure the FDPIC can address by ruling, with Article 63 exposure if that ruling is then defied.
Federal bodies are required to appoint a data protection officer under Article 25 DPO, which implements the delegation in Article 10(4) nFADP. Article 10 itself governs officers appointed by private controllers.
Comparing the nFADP and the GDPR
While the nFADP was designed to remain compatible with the GDPR and preserve the EU adequacy finding, meaningful differences remain that organizations must track when operating across both jurisdictions.
| Feature | nFADP (Switzerland) | GDPR (EU/EEA) |
|---|---|---|
| Legal basis requirement | Not required for all processing; required only when personality rights are infringed | Required for every processing operation (Art. 6) |
| Who is penalized | The individual natural person responsible | The organization (controller or processor) |
| Maximum penalty | CHF 250,000 on individual | EUR 20M or 4% global turnover on organization |
| Intent requirement | Only willful violations punishable | Both intentional and negligent violations covered |
| Supervisory authority fines | FDPIC cannot fine | DPAs can fine directly |
| Breach notification deadline | "As soon as possible" (no fixed period) | 72 hours |
| DPO / Data Protection Advisor | Voluntary for private sector | Mandatory in specified circumstances |
| SME record-keeping exemption | Yes (fewer than 250 employees on 1 January of any year); lost only where a large volume of sensitive personal data is processed or high-risk profiling is carried out | No general SME exemption |
| Sensitive data scope | Broader: includes admin/criminal proceedings, social assistance measures | Narrower enumerated list (Art. 9) |
| Profiling | No standalone consent requirement; high-risk profiling that breaches personality rights needs an Article 31 justification, and consent, where relied on, must be explicit (Art. 6(7)(b)) | Lawful basis required; right to object to all profiling |
| Data subjects covered | Natural persons only | Natural persons only |
| Extraterritorial scope | Yes, effects in Switzerland | Yes, targeting EU residents |
AI and Data Protection
The FDPIC has confirmed that the nFADP applies directly to AI-powered data processing. The law is drafted in a technology-neutral manner: AI systems that process personal data of individuals in Switzerland must comply with the nFADP's principles of lawfulness, purpose limitation, proportionality, and data minimization.
Specific guidance published by the FDPIC establishes that:
- Manufacturers, providers, and users of AI applications must ensure that individuals affected retain the greatest possible degree of control over their personal data
- AI systems must make their purpose, functionality, and data sources transparent
- AI-supported processing that poses high risks requires a DPIA
- Prohibited AI applications include real-time mass facial recognition in public spaces and social scoring systems
In March 2025, Switzerland signed the Council of Europe Convention on Artificial Intelligence, Human Rights, Democracy and the Rule of Law (the "Vilnius Convention"). The Federal Council announced that the necessary amendments to Swiss law to ratify the Convention would be prepared. This signals that Switzerland's AI governance framework will continue to develop and that data protection and AI regulation will be treated as closely interrelated.
On February 23, 2026, the FDPIC joined 60 other national data protection authorities in a joint statement on AI-generated images and privacy protection, confirming that generating realistic images of real individuals without consent can constitute a violation of data protection law. Separately, the FDPIC marked Data Protection Day on January 28, 2026 with a conference contribution on generative AI and data protection.
Cookie Guidance and Tracking Technologies
The FDPIC published cookie guidelines for website and app operators on January 22, 2025, and issued an updated version of those guidelines on October 7, 2025 (the PDF itself is dated October 6, 2025). That updated guide is the document a business reader needs. On March 31, 2026 the FDPIC published a separate factsheet aimed at website users, explaining how they can limit tracking; it is an awareness piece and does not change the controller guidance. Key conclusions from the guidance for controllers include:
- Behavioral advertising: Integrating third-party cookies or similar technologies that share visitor data with advertisers in exchange for payment requires the data subject's consent, because this constitutes a disclosure of personal data to third parties for purposes not apparent from the initial collection.
- Location data: Profiling based on location data often constitutes high-risk profiling because location data enables identification of the individual and can reveal essential aspects of personality. Such profiling therefore needs an Article 31 justification, and any consent relied on must be explicit.
- Cookie paywalls: Whether a choice between consent or a paid subscription constitutes valid consent requires assessment on the specific facts. The FDPIC's guidance sets out conditions under which such consent can be lawfully obtained.
Sector-Specific Considerations
Financial Services
Switzerland's banking secrecy tradition, embedded in the Banking Act (SR 952.0) and Article 47 of the Banking Act, intersects with the nFADP in complex ways. Financial institutions must balance data protection requirements against anti-money laundering reporting obligations, tax information exchange agreements, and financial market supervision requirements under FINMA supervision. The FDPIC's 2025 ruling against Cembra Money Bank is the clearest signal yet that financial sector data practices will receive scrutiny under the new law.
Healthcare
Health data is classified as sensitive under Article 5(c) nFADP. Healthcare providers, insurers, pharmaceutical companies, and research institutions processing health data must apply heightened safeguards, conduct DPIAs for large-scale health data processing, and be ready to identify an Article 31 justification wherever the processing unlawfully breaches personality rights, in particular where health data is disclosed to third parties (Article 30(2)(c)). Cross-border clinical trials involving Switzerland must address transfer mechanism requirements for health data flows.
Technology, Cloud Services, and SaaS
Cloud providers, SaaS platforms, and IT service companies serving Swiss clients operate as data processors under the nFADP and must satisfy Article 9 requirements: processing only on documented controller instructions, implementing adequate technical and organizational security measures, notifying controllers of breaches as soon as possible, and supporting controller compliance with data subject rights requests. Article 14 nFADP does not apply to processors, so a foreign SaaS provider acting purely as a processor carries no representative duty of its own. A foreign provider that acts as a controller for its own purposes may need a Swiss representative, but only where all four conditions of Article 14(1) are met.
Practical Compliance Checklist
Organizations subject to the nFADP should complete these steps:
- Map processing activities. Document all personal data processing involving individuals in Switzerland. Confirm whether the SME exemption from record-keeping applies.
- Update privacy notices. Ensure notices disclose the controller's identity and Swiss representative (if applicable), processing purposes, recipients, cross-border transfer destinations and safeguards, and data subject rights.
- Review Article 31 justifications. Identify the processing that unlawfully breaches personality rights, in particular disclosure of sensitive data to third parties, and record the Article 31 justification relied on; where that justification is consent, make it explicit.
- Audit cross-border transfers. Verify that all international flows to non-adequate countries use SCCs with Swiss Finish, Binding Corporate Rules, or another recognized mechanism. Conduct Transfer Impact Assessments where required.
- Establish breach response procedures. Set up internal processes to detect, triage, and report breaches to the FDPIC's online portal. Assign responsibility chains clearly to specific individuals, given personal criminal exposure.
- Conduct DPIAs for high-risk processing. Identify all high-risk processing operations and complete DPIAs before launch. If you appoint a Data Protection Advisor to gain the FDPIC prior-consultation exemption, satisfy every Article 10(3) condition and consult the advisor on each high-risk operation, or the exemption does not apply.
- Review processor contracts. Ensure all data processing agreements satisfy nFADP requirements for security, breach notification, sub-processor restrictions, and access right support.
- Train staff on individual liability. Because the nFADP imposes criminal sanctions on individuals, training must reach decision-makers. Staff who authorize data processing must understand they, personally, bear criminal exposure for willful violations.
- Monitor FDPIC enforcement guidance. The FDPIC regularly publishes new guidance, investigation outcomes, and binding orders. Subscribe to FDPIC news releases at edoeb.admin.ch.
Recent Developments
This article presents general legal information about Switzerland's Federal Act on Data Protection (nFADP/revDSG, SR 235.1) as verified in September 2026. It does not constitute legal advice and does not address any individual's or organization's specific circumstances. Data protection law and its enforcement practice continue to evolve. Organizations subject to the nFADP should consult a lawyer licensed in Switzerland for advice on their specific compliance obligations.
More on Switzerland law
This page covers one area of law in Switzerland. For a complete guide to Switzerland's legal system, including employment, family, driving, tenancy, inheritance, criminal law and consumer rights, see our full Switzerland law hub.
Frequently Asked Questions
Does the EU GDPR apply to Swiss companies?
The GDPR does not apply directly to Swiss-domiciled companies processing data inside Switzerland. Switzerland is not an EU or EEA member state and operates under its own nFADP (SR 235.1). However, a Swiss company that offers goods or services to EU or EEA residents, or that monitors the behavior of EU residents, must comply with the GDPR in respect of those activities under Article 3(2) GDPR, regardless of the nFADP. Many Swiss organizations therefore operate under both regimes in parallel.
How are nFADP penalties different from GDPR fines?
The nFADP imposes criminal fines of up to CHF 250,000 on the individual natural person responsible for a violation, not on the company. Only intentional violations are punishable; negligence is not covered. The GDPR, by contrast, imposes administrative fines of up to EUR 20 million or 4% of global annual turnover on the organization itself, and covers both intentional and negligent violations. If identifying the responsible individual would require disproportionate investigative effort, a Swiss company may be fined up to CHF 50,000 as a subsidiary measure.
Is a Data Protection Officer required under Swiss law?
No. The nFADP does not require private organizations to appoint a Data Protection Advisor (Datenschutzberater/-beraterin), the Swiss equivalent of a DPO. Appointment is voluntary. Appointing one can carry a practical benefit, but not automatically: under Article 23(4) nFADP a private controller may skip the FDPIC consultation on high-residual-risk processing only if it has actually consulted its data protection officer on that processing, and only if all four conditions in Article 10(3) are met, including that the officer is professionally independent and not bound by instructions and that the controller has published the officer's contact details and notified them to the FDPIC. Federal bodies are required to appoint a data protection officer under Article 25 DPO, which implements Article 10(4) nFADP.
Can personal data be transferred from Switzerland to the United States?
Yes, through several mechanisms. Since September 15, 2024, the Swiss-US Data Privacy Framework allows transfers to certified US companies listed at dataprivacyframework.gov. For non-certified US companies, organizations should use Standard Contractual Clauses with Swiss Add-ons and accompany them with a Transfer Impact Assessment. Binding Corporate Rules approved by the FDPIC are also available. Organizations are advised to maintain backup mechanisms because the parallel EU framework is under live challenge: the EU General Court dismissed Latombe v Commission (T-553/23) on September 3, 2025, and the appeal in Case C-703/25 P, lodged October 31, 2025, is still pending.
What is the deadline for reporting a data breach to the FDPIC?
The nFADP requires notification 'as soon as possible' when a breach is likely to result in a high risk to the personality or fundamental rights of the affected individuals. There is no fixed deadline comparable to the GDPR's 72-hour rule. The FDPIC has published guidelines and operates a dedicated breach notification portal at edoeb.admin.ch. Data processors must notify their controllers as soon as possible; controllers must then assess and, if required, notify the FDPIC and affected individuals.
Does Switzerland's nFADP require consent to process personal data?
Not for ordinary personal data. Unlike the GDPR, which requires a specific legal basis for every processing operation, the nFADP permits processing by private entities as a default unless it infringes the data subject's personality rights. A justification under Article 31 is required only where the processing unlawfully breaches personality rights, for example where it runs contrary to the Article 6 principles, against the data subject's express wishes, or discloses sensitive personal data to third parties (Article 30(2)). Where consent is the justification relied on, Article 6(7) requires it to be explicit for sensitive personal data and high-risk profiling. The distinction is significant for organizations moving from GDPR-compliant practices: their existing consent infrastructure may be more expansive than Swiss law strictly requires.
What is the role of the FDPIC?
The Federal Data Protection and Information Commissioner (FDPIC) is Switzerland's independent national data protection supervisory authority. The FDPIC supervises compliance with the nFADP, opens preliminary enquiries and formal investigations, issues legally binding administrative orders requiring modification or cessation of processing, provides guidance documents and recommendations, must be consulted when a DPIA reveals high residual risk unless the narrow Article 23(4) and Article 10(3) exception applies, and participates in legislative consultations. The FDPIC cannot impose fines; criminal fines are handled by cantonal prosecution authorities.
Do Swiss data protection laws apply to foreign companies?
Yes. Article 3 nFADP establishes extraterritorial scope. Any organization that processes personal data of individuals in Switzerland, offers goods or services to Swiss residents, or monitors Swiss residents' behavior must comply with the nFADP, regardless of where that organization is established. Private controllers with a registered office or domicile abroad, but not processors, must also appoint a Swiss representative under Article 14 nFADP, and only where all four conditions in Article 14(1) are met: the processing is connected with offering goods or services to, or monitoring the behavior of, persons in Switzerland; it is on a large scale; it is regular; and it poses a high risk to the personality of the data subjects.
What is the Swiss-US Data Privacy Framework?
The Swiss-US Data Privacy Framework (Swiss-US DPF) is a bilateral transfer mechanism that allows personal data to flow from Switzerland to US companies that have self-certified their compliance with the Framework's data protection principles. The Federal Council found the Framework adequate on August 14, 2024, and it took effect on September 15, 2024. Certified companies are listed at dataprivacyframework.gov. Organizations should monitor the Framework's status and maintain backup transfer mechanisms such as Swiss SCCs.
What is the SME exemption under Swiss data protection law?
Under Article 24 of the Data Protection Ordinance (DPO, SR 235.11), undertakings and other private organisations employing fewer than 250 employees on 1 January of any year, and natural persons, are exempt from the obligation to maintain a record of processing activities. Article 24 sets no general significant-risk test. The exemption is lost in only two cases, and they are exhaustive: where a large volume of sensitive personal data is processed, or where high-risk profiling is carried out. Systematic monitoring on its own does not remove it. No comparable exemption exists under the GDPR.
Updates
Swiss-US Data Privacy Framework takes effect following the Federal Council's August 14, 2024 adequacy decision. US-certified companies may receive Swiss personal data without additional transfer safeguards.
FDPIC publishes an updated version of its January 22, 2025 cookie guidelines for controllers (PDF dated October 6, 2025), clarifying when personalised advertising requires consent, explaining why location-data profiling is often high-risk profiling, and addressing cookie paywalls.
Federal Administrative Court dismisses Bürgerforum Schweiz's appeal against the FDPIC's processing ban of April 9, 2024. The association had published online the details of clergy and other church workers who had only been sent, or registered for, its Pfarrer-Check questionnaire, and the FDPIC found that publication disproportionate.
Digitec Galaxus informs the FDPIC that it has implemented a one-click opt-out from behavioral personalisation and updated its privacy policy, meeting the recommendation the FDPIC issued in April 2024 under the previous law. The FDPIC announced the closure of the case on February 12, 2026.
FDPIC issues binding order against PostFinance AG: the bank's voice recognition authentication system processes biometric data (voiceprints) without explicit customer consent, violating the proportionality principle. PostFinance ordered to obtain express consent and delete non-consented voiceprints. PostFinance has appealed the ruling to the Federal Administrative Court, so it has not yet taken full legal effect.
FDPIC publishes a consumer-facing factsheet on the use of cookies and similar technologies. Aimed at website users rather than operators, it explains how to limit tracking, and it is a follow-up to the January 22, 2025 guide for controllers rather than a revision of it.
Switzerland signs the Council of Europe Convention on AI, Human Rights, Democracy and the Rule of Law (the Vilnius Convention). Federal Council commits to preparing the domestic legislative amendments required for ratification.
FDPIC issues binding ruling against Cembra Money Bank AG: bank violated the 30-day deadline for responding to access requests under Article 25 nFADP in 9 of 13 requests reviewed, and used standardized response texts that failed to provide individualized information.
FDPIC publishes updated cookie guidelines, providing clearer expectations on consent for behavioral advertising, location-data-based profiling (classified as high-risk profiling), and cookie paywalls.
European Commission renews its adequacy finding for Switzerland under the GDPR, citing the nFADP modernization as strengthening the legal basis for free Swiss-EU personal data flows. Next scheduled Commission review: approximately 2028.
FDPIC opens a formal investigation under Article 49 ff. nFADP into BLT Baselland Transport AG over body cameras worn by train conductors, announced publicly on February 26, 2026. The investigation was still ongoing at the close of the FDPIC's reporting year on March 31, 2026.
FDPIC joins 60 other national data protection authorities in a joint statement on AI-generated images and privacy protection, confirming that generating realistic images of real individuals without consent can violate data protection law.
Federal Council submits a bill for consultation proposing an amendment to Article 57 of the Federal Constitution and a partial revision of the Federal Act on Police Information Systems, to create the legal basis for a fedpol police query platform for the cantons and the Confederation. The FDPIC published its statement on the consultation on February 20, 2026.
FDPIC issues binding order against Inkasso-Team AG: the debt collection agency's practice of publishing alleged debtors' names on a publicly accessible website violated transparency and proportionality principles under Article 6 nFADP. Company ordered to delete all published data. The Federal Administrative Court fully dismissed the company's appeal on June 22, 2026 (A-3891/2025). That judgment has entered into legal force and the website has been taken offline.
Third-round corrections: the FAQ, healthcare, checklist, erasure and objection passages now state the Swiss Article 30/31 justification model instead of GDPR-style lawful-basis rules; two duplicated clauses removed.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Reviewed and approved by an editor
Sources and References
- Federal Act on Data Protection (FADP), SR 235.1 - Official Consolidated Text(fedlex.admin.ch).gov
- Ordinance on Data Protection (DPO), SR 235.11(fedlex.admin.ch).gov
- Ordinance on Data Protection Certification, SR 235.13(fedlex.admin.ch).gov
- FDPIC 33rd Annual Report 2025/2026 (data protection year April 1, 2025 to March 31, 2026)(edoeb.admin.ch).gov
- FDPIC - Guidelines on Data Breaches(edoeb.admin.ch).gov
- FDPIC - The New Data Protection Act in Figures (November 2024)(edoeb.admin.ch).gov
- FDPIC - Adequacy Decisions for International Data Transfers(edoeb.admin.ch).gov
- FDPIC - Supervisory Role and Powers Under the nFADP(edoeb.admin.ch).gov
- EU Adequacy Decision Regarding Switzerland (January 15, 2024)(edoeb.admin.ch).gov
- FDPIC Ruling Against Cembra Money Bank AG (January 29, 2025)(edoeb.admin.ch).gov
- FDPIC Ruling Against Inkasso-Team AG (April 28, 2025)(edoeb.admin.ch).gov
- FDPIC Concludes Investigation into Voice Recognition at PostFinance (May 16, 2025)(edoeb.admin.ch).gov
- FDPIC - Digitec Galaxus: Website Personalisation Opt-Out (November 2025)(edoeb.admin.ch).gov
- FDPIC Cookie Guidelines: Updated Version Published (October 7, 2025; PDF dated October 6, 2025)(edoeb.admin.ch).gov
- FDPIC - AI and Data Protection(edoeb.admin.ch).gov
- Data Protection Legislation and Legal Basis - Swiss Federal Office of Justice (updated January 22, 2026)(bj.admin.ch).gov
- FDPIC Files Criminal Complaint Against Add Conti GmbH for Failure to Cooperate (August 21, 2025)(edoeb.admin.ch).gov
- Federal Administrative Court Confirms FDPIC Practice: Inkasso-Team AG Appeal Dismissed, Ruling of June 22, 2026 (A-3891/2025)(edoeb.admin.ch).gov
- Swiss-US Data Privacy Framework: Federal Council Media Release (August 14, 2024)(admin.ch).gov
- Swiss-US Data Privacy Framework - Certified Participant List(dataprivacyframework.gov).gov
- EU Data Protection Adequacy Decisions - European Commission(commission.europa.eu).gov
- Article 60 FADP - Criminal Penalties (Online Commentary)(onlinekommentar.ch)
- Data Protection Laws and Regulations 2025-2026: Switzerland (ICLG)(iclg.com)
- Chambers Data Protection and Privacy 2025 - Switzerland(practiceguides.chambers.com)