EnglishDeutsch
Switzerland flag

Switzerland

Switzerland Data Privacy Laws: Federal Act on Data Protection (nFADP) Compliance Guide

Independently fact-checked against primary sources (last audited September 9, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 9, 2026. · 21 primary sources cited on this page. How we verify our legal content

Switzerland Data Privacy Laws: Federal Act on Data Protection (nFADP) Compliance Guide

Frequently Asked Questions

Does the EU GDPR apply to Swiss companies?

The GDPR does not apply directly to Swiss-domiciled companies processing data inside Switzerland. Switzerland is not an EU or EEA member state and operates under its own nFADP (SR 235.1). However, a Swiss company that offers goods or services to EU or EEA residents, or that monitors the behavior of EU residents, must comply with the GDPR in respect of those activities under Article 3(2) GDPR, regardless of the nFADP. Many Swiss organizations therefore operate under both regimes in parallel.

How are nFADP penalties different from GDPR fines?

The nFADP imposes criminal fines of up to CHF 250,000 on the individual natural person responsible for a violation, not on the company. Only intentional violations are punishable; negligence is not covered. The GDPR, by contrast, imposes administrative fines of up to EUR 20 million or 4% of global annual turnover on the organization itself, and covers both intentional and negligent violations. If identifying the responsible individual would require disproportionate investigative effort, a Swiss company may be fined up to CHF 50,000 as a subsidiary measure.

Is a Data Protection Officer required under Swiss law?

No. The nFADP does not require private organizations to appoint a Data Protection Advisor (Datenschutzberater/-beraterin), the Swiss equivalent of a DPO. Appointment is voluntary. Appointing one can carry a practical benefit, but not automatically: under Article 23(4) nFADP a private controller may skip the FDPIC consultation on high-residual-risk processing only if it has actually consulted its data protection officer on that processing, and only if all four conditions in Article 10(3) are met, including that the officer is professionally independent and not bound by instructions and that the controller has published the officer's contact details and notified them to the FDPIC. Federal bodies are required to appoint a data protection officer under Article 25 DPO, which implements Article 10(4) nFADP.

Can personal data be transferred from Switzerland to the United States?

Yes, through several mechanisms. Since September 15, 2024, the Swiss-US Data Privacy Framework allows transfers to certified US companies listed at dataprivacyframework.gov. For non-certified US companies, organizations should use Standard Contractual Clauses with Swiss Add-ons and accompany them with a Transfer Impact Assessment. Binding Corporate Rules approved by the FDPIC are also available. Organizations are advised to maintain backup mechanisms because the parallel EU framework is under live challenge: the EU General Court dismissed Latombe v Commission (T-553/23) on September 3, 2025, and the appeal in Case C-703/25 P, lodged October 31, 2025, is still pending.

What is the deadline for reporting a data breach to the FDPIC?

The nFADP requires notification 'as soon as possible' when a breach is likely to result in a high risk to the personality or fundamental rights of the affected individuals. There is no fixed deadline comparable to the GDPR's 72-hour rule. The FDPIC has published guidelines and operates a dedicated breach notification portal at edoeb.admin.ch. Data processors must notify their controllers as soon as possible; controllers must then assess and, if required, notify the FDPIC and affected individuals.

Does Switzerland's nFADP require consent to process personal data?

Not for ordinary personal data. Unlike the GDPR, which requires a specific legal basis for every processing operation, the nFADP permits processing by private entities as a default unless it infringes the data subject's personality rights. A justification under Article 31 is required only where the processing unlawfully breaches personality rights, for example where it runs contrary to the Article 6 principles, against the data subject's express wishes, or discloses sensitive personal data to third parties (Article 30(2)). Where consent is the justification relied on, Article 6(7) requires it to be explicit for sensitive personal data and high-risk profiling. The distinction is significant for organizations moving from GDPR-compliant practices: their existing consent infrastructure may be more expansive than Swiss law strictly requires.

What is the role of the FDPIC?

The Federal Data Protection and Information Commissioner (FDPIC) is Switzerland's independent national data protection supervisory authority. The FDPIC supervises compliance with the nFADP, opens preliminary enquiries and formal investigations, issues legally binding administrative orders requiring modification or cessation of processing, provides guidance documents and recommendations, must be consulted when a DPIA reveals high residual risk unless the narrow Article 23(4) and Article 10(3) exception applies, and participates in legislative consultations. The FDPIC cannot impose fines; criminal fines are handled by cantonal prosecution authorities.

Do Swiss data protection laws apply to foreign companies?

Yes. Article 3 nFADP establishes extraterritorial scope. Any organization that processes personal data of individuals in Switzerland, offers goods or services to Swiss residents, or monitors Swiss residents' behavior must comply with the nFADP, regardless of where that organization is established. Private controllers with a registered office or domicile abroad, but not processors, must also appoint a Swiss representative under Article 14 nFADP, and only where all four conditions in Article 14(1) are met: the processing is connected with offering goods or services to, or monitoring the behavior of, persons in Switzerland; it is on a large scale; it is regular; and it poses a high risk to the personality of the data subjects.

What is the Swiss-US Data Privacy Framework?

The Swiss-US Data Privacy Framework (Swiss-US DPF) is a bilateral transfer mechanism that allows personal data to flow from Switzerland to US companies that have self-certified their compliance with the Framework's data protection principles. The Federal Council found the Framework adequate on August 14, 2024, and it took effect on September 15, 2024. Certified companies are listed at dataprivacyframework.gov. Organizations should monitor the Framework's status and maintain backup transfer mechanisms such as Swiss SCCs.

What is the SME exemption under Swiss data protection law?

Under Article 24 of the Data Protection Ordinance (DPO, SR 235.11), undertakings and other private organisations employing fewer than 250 employees on 1 January of any year, and natural persons, are exempt from the obligation to maintain a record of processing activities. Article 24 sets no general significant-risk test. The exemption is lost in only two cases, and they are exhaustive: where a large volume of sensitive personal data is processed, or where high-risk profiling is carried out. Systematic monitoring on its own does not remove it. No comparable exemption exists under the GDPR.

Updates

Swiss-US Data Privacy Framework takes effect following the Federal Council's August 14, 2024 adequacy decision. US-certified companies may receive Swiss personal data without additional transfer safeguards.

FDPIC publishes an updated version of its January 22, 2025 cookie guidelines for controllers (PDF dated October 6, 2025), clarifying when personalised advertising requires consent, explaining why location-data profiling is often high-risk profiling, and addressing cookie paywalls.

Federal Administrative Court dismisses Bürgerforum Schweiz's appeal against the FDPIC's processing ban of April 9, 2024. The association had published online the details of clergy and other church workers who had only been sent, or registered for, its Pfarrer-Check questionnaire, and the FDPIC found that publication disproportionate.

Digitec Galaxus informs the FDPIC that it has implemented a one-click opt-out from behavioral personalisation and updated its privacy policy, meeting the recommendation the FDPIC issued in April 2024 under the previous law. The FDPIC announced the closure of the case on February 12, 2026.

FDPIC issues binding order against PostFinance AG: the bank's voice recognition authentication system processes biometric data (voiceprints) without explicit customer consent, violating the proportionality principle. PostFinance ordered to obtain express consent and delete non-consented voiceprints. PostFinance has appealed the ruling to the Federal Administrative Court, so it has not yet taken full legal effect.

FDPIC publishes a consumer-facing factsheet on the use of cookies and similar technologies. Aimed at website users rather than operators, it explains how to limit tracking, and it is a follow-up to the January 22, 2025 guide for controllers rather than a revision of it.

Switzerland signs the Council of Europe Convention on AI, Human Rights, Democracy and the Rule of Law (the Vilnius Convention). Federal Council commits to preparing the domestic legislative amendments required for ratification.

FDPIC issues binding ruling against Cembra Money Bank AG: bank violated the 30-day deadline for responding to access requests under Article 25 nFADP in 9 of 13 requests reviewed, and used standardized response texts that failed to provide individualized information.

FDPIC publishes updated cookie guidelines, providing clearer expectations on consent for behavioral advertising, location-data-based profiling (classified as high-risk profiling), and cookie paywalls.

European Commission renews its adequacy finding for Switzerland under the GDPR, citing the nFADP modernization as strengthening the legal basis for free Swiss-EU personal data flows. Next scheduled Commission review: approximately 2028.

FDPIC opens a formal investigation under Article 49 ff. nFADP into BLT Baselland Transport AG over body cameras worn by train conductors, announced publicly on February 26, 2026. The investigation was still ongoing at the close of the FDPIC's reporting year on March 31, 2026.

FDPIC joins 60 other national data protection authorities in a joint statement on AI-generated images and privacy protection, confirming that generating realistic images of real individuals without consent can violate data protection law.

Federal Council submits a bill for consultation proposing an amendment to Article 57 of the Federal Constitution and a partial revision of the Federal Act on Police Information Systems, to create the legal basis for a fedpol police query platform for the cantons and the Confederation. The FDPIC published its statement on the consultation on February 20, 2026.

FDPIC issues binding order against Inkasso-Team AG: the debt collection agency's practice of publishing alleged debtors' names on a publicly accessible website violated transparency and proportionality principles under Article 6 nFADP. Company ordered to delete all published data. The Federal Administrative Court fully dismissed the company's appeal on June 22, 2026 (A-3891/2025). That judgment has entered into legal force and the website has been taken offline.

Third-round corrections: the FAQ, healthcare, checklist, erasure and objection passages now state the Swiss Article 30/31 justification model instead of GDPR-style lawful-basis rules; two duplicated clauses removed.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Federal Act on Data Protection (FADP), SR 235.1 - Official Consolidated Text(fedlex.admin.ch).gov
  2. Ordinance on Data Protection (DPO), SR 235.11(fedlex.admin.ch).gov
  3. Ordinance on Data Protection Certification, SR 235.13(fedlex.admin.ch).gov
  4. FDPIC 33rd Annual Report 2025/2026 (data protection year April 1, 2025 to March 31, 2026)(edoeb.admin.ch).gov
  5. FDPIC - Guidelines on Data Breaches(edoeb.admin.ch).gov
  6. FDPIC - The New Data Protection Act in Figures (November 2024)(edoeb.admin.ch).gov
  7. FDPIC - Adequacy Decisions for International Data Transfers(edoeb.admin.ch).gov
  8. FDPIC - Supervisory Role and Powers Under the nFADP(edoeb.admin.ch).gov
  9. EU Adequacy Decision Regarding Switzerland (January 15, 2024)(edoeb.admin.ch).gov
  10. FDPIC Ruling Against Cembra Money Bank AG (January 29, 2025)(edoeb.admin.ch).gov
  11. FDPIC Ruling Against Inkasso-Team AG (April 28, 2025)(edoeb.admin.ch).gov
  12. FDPIC Concludes Investigation into Voice Recognition at PostFinance (May 16, 2025)(edoeb.admin.ch).gov
  13. FDPIC - Digitec Galaxus: Website Personalisation Opt-Out (November 2025)(edoeb.admin.ch).gov
  14. FDPIC Cookie Guidelines: Updated Version Published (October 7, 2025; PDF dated October 6, 2025)(edoeb.admin.ch).gov
  15. FDPIC - AI and Data Protection(edoeb.admin.ch).gov
  16. Data Protection Legislation and Legal Basis - Swiss Federal Office of Justice (updated January 22, 2026)(bj.admin.ch).gov
  17. FDPIC Files Criminal Complaint Against Add Conti GmbH for Failure to Cooperate (August 21, 2025)(edoeb.admin.ch).gov
  18. Federal Administrative Court Confirms FDPIC Practice: Inkasso-Team AG Appeal Dismissed, Ruling of June 22, 2026 (A-3891/2025)(edoeb.admin.ch).gov
  19. Swiss-US Data Privacy Framework: Federal Council Media Release (August 14, 2024)(admin.ch).gov
  20. Swiss-US Data Privacy Framework - Certified Participant List(dataprivacyframework.gov).gov
  21. EU Data Protection Adequacy Decisions - European Commission(commission.europa.eu).gov
  22. Article 60 FADP - Criminal Penalties (Online Commentary)(onlinekommentar.ch)
  23. Data Protection Laws and Regulations 2025-2026: Switzerland (ICLG)(iclg.com)
  24. Chambers Data Protection and Privacy 2025 - Switzerland(practiceguides.chambers.com)
Share: