Data Protection Matters
← All privacy laws

Switzerland

nFADP

Federal Act on Data Protection (FADP) of 25 September 2020, the revised Swiss data protection act (SR 235.1)

Keywords

nFADPrevFADPFADPnLPDSwitzerlandSwiss data protectionFDPICpersonal dataprivacy by designDPIAdata breachcross-border transfersSCCcriminal finesSR 235.1
Plain-English overview, not the law. This is a general summary we wrote to help you get oriented. It is not legal advice, it is not binding, and it may simplify, omit, or get things wrong. We also cannot guarantee that the source we link to is the correct, current, or official text; we may have linked or labelled it wrong. For anything that matters, find and read the law itself and seek advice for your situation.

What it is

The revised Federal Act on Data Protection (FADP, also called the nFADP or nLPD), dated 25 September 2020, is Switzerland's main data protection statute. It entered into force on 1 September 2023 and replaced the 1992 act, bringing Swiss law closer to the GDPR and to the modernized Council of Europe Convention 108+. It protects the personal data of natural persons only, and no longer covers data about legal entities.

Who it applies to

The Act applies to private persons and to federal bodies that process personal data. It reaches processing abroad that has an effect in Switzerland, so non-Swiss organizations can be caught. Foreign private controllers that process data of people in Switzerland on a regular, large-scale basis with a high risk must designate a representative in Switzerland. The Act speaks of "controllers" and "processors" in the same sense as the GDPR.

Core principles

Personal data must be processed lawfully, in good faith and proportionately, and obtained for a specific purpose that is recognizable to the person concerned. Data must be accurate, kept no longer than needed, and protected by appropriate security measures. Unlike the GDPR, the Act does not require a legal basis for every processing activity by a private person. Processing is generally allowed unless it unlawfully harms personality rights. Consent is needed only in specific cases, such as sensitive data or high-risk profiling, and where consent is relied on it must be informed and voluntary.

Individual rights

People have the right to be informed when their data is collected, and the right of access, which should generally be answered within 30 days. They also have the right to data portability and to be informed of and challenge certain automated individual decisions. A person can ask a court to stop unlawful processing, to correct or delete data, or to block disclosure to third parties.

Key obligations

Controllers must apply privacy by design and by default, ensure data security, and keep a record of processing activities (with exemptions for small businesses whose processing carries low risk). They must carry out a data protection impact assessment before processing that is likely to carry a high risk. Appointing a data protection officer is optional for private controllers, though it can ease some duties, such as consulting the FDPIC after an impact assessment. Processors may only act under a contract or by law, and sub-processing needs the controller's approval.

Breach notification

A breach of data security that is likely to lead to a high risk to the person concerned must be reported to the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible. Affected individuals must be informed where this is needed for their protection or where the FDPIC requests it. Processors must notify the controller of any breach as quickly as possible.

International transfers

Personal data may be disclosed abroad if the Federal Council has determined that the destination provides an adequate level of protection. Otherwise a safeguard is needed, such as a treaty, data protection clauses in a contract, standard contractual clauses recognized by the FDPIC, or binding corporate rules, and some narrow exceptions are listed. The Federal Council publishes the list of countries with adequate protection.

Enforcement and penalties

The FDPIC supervises the Act, can open investigations and can issue binding orders, but cannot itself impose fines. Instead the Act creates criminal offences, with fines of up to CHF 250,000 on the responsible private individuals (not the company) for wilful breaches, such as failing to inform people, unlawful foreign disclosure, or ignoring an FDPIC decision. Prosecution is carried out by the cantonal authorities, generally on complaint. For minor fines the business itself can be ordered to pay instead of identifying the individual.

The official text

The authoritative versions of the Act are the German, French and Italian texts published on Fedlex, the Swiss federal publication platform. The English version linked here is a translation provided for information only and has no legal force. Use the authoritative text, not this summary, for anything that matters.

Below is the source we understand to be the official text (English, non-binding translation). We cannot guarantee it is correct, current, complete, or the authoritative version, and we may have linked or labelled it wrong, so please check it yourself and do not rely on it or on our summary:

Go to the source →