Regulations › Rest of world

nFADP

Swiss Federal Act on Data Protection (revised)

In force privacy
WhenIn effect since 1 September 2023
Who enforces itFederal Data Protection and Information Commissioner
Who it applies toOrganizations processing personal data of people in Switzerland.

Switzerland's revised law, closely aligned with the GDPR, with fines aimed at responsible individuals.

The law in brief

Switzerland's revised Federal Act on Data Protection (nFADP) took effect on 1 September 2023. It is closely aligned with the GDPR, which helped Switzerland keep its EU adequacy status, but it differs in ways that catch organizations used to GDPR: there is no list of legal bases, penalties are criminal fines aimed at responsible individuals, and some duties are lighter for small organizations.

It protects the data of natural persons only, not legal entities.

Who it applies to

  • Private persons and federal bodies processing personal data of natural persons.
  • Processing abroad that has an effect in Switzerland. Controllers outside Switzerland that regularly process Swiss residents' data on a large scale may need a Swiss representative.
  • Small organizations (fewer than 250 employees) are exempt from keeping records of processing unless their processing is high risk.

What it requires

Inform at collection

Inform data subjects when collecting their data, including the controller's identity, purposes, recipients and any countries the data goes to.

Privacy by design and default

Design processing to comply with data protection rules, and set defaults to limit processing to the minimum necessary unless the data subject decides otherwise.

Impact assessments

Carry out a data protection impact assessment where processing may create a high risk to personality or fundamental rights.

Breach notification

Report a data security breach likely to result in a high risk to the Commissioner as soon as possible, and inform data subjects where needed for their protection or where the Commissioner requires it.

Transfers abroad

Disclose data abroad only to countries the Federal Council considers adequate, or with appropriate safeguards such as recognized standard contractual clauses.

People's rights

Individuals can obtain information about their data (generally within 30 days), receive data in a common electronic format (portability), have incorrect data corrected, object and seek restrictions, and ask for a human review of automated individual decisions.

Enforcement and penalties

Criminal fines of up to CHF 250,000 on the responsible individuals, not the company, for intentional breaches of certain duties, such as information, access and cooperation duties, unlawful disclosure abroad, and failing to meet minimum security requirements. The Federal Data Protection and Information Commissioner investigates and can order measures.

What to do first

  1. Identify who is personally exposed to criminal fines and brief them.
  2. Update privacy notices to meet the duty to inform at collection, including recipient countries.
  3. Keep records of processing unless the SME exemption applies.
  4. Run impact assessments for high-risk processing.
  5. Report high-risk breaches to the Commissioner as soon as possible.
  6. Check transfers against the Federal Council's list of adequate countries or use safeguards; the Swiss-US DPF covers certified US organizations.

Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.

Recent developments

Nothing reported yet. Regulatory Watch lists new rules, enforcement and court decisions as they arrive.

Sources