Everything you need to know about FADP compliance, data security requirements, and secure data disposal.
Switzerland's revised Federal Act on Data Protection (FADP), often referred to as the nFADP ("new FADP"), came into force on September 1, 2023. As a non-EU country that still does substantial business with the European Union, Switzerland updated its data protection law specifically to keep pace with GDPR and preserve its status as a jurisdiction the EU recognizes as providing an adequate level of data protection.
Background
Switzerland's original Federal Act on Data Protection dated back to 1992. As GDPR reshaped global data protection expectations after 2018, Swiss lawmakers recognized that the older FADP risked falling out of step with EU standards — a serious concern given that an EU "adequacy" finding is what allows personal data to flow freely between the EU and Switzerland without additional safeguards. The Swiss Parliament passed the revised FADP in 2020, and after a transition period for organizations to prepare, it entered into force in September 2023.
Who Must Comply
The revised FADP applies to the processing of personal data of individuals in Switzerland by both private organizations and federal government bodies. Like GDPR, it has extraterritorial application: foreign companies that process the personal data of individuals in Switzerland in a way that produces effects there — such as offering goods or services to Swiss residents — can fall within its scope, even without a physical presence in the country.
Key Similarities to GDPR
The revised FADP was deliberately designed to align closely with GDPR, incorporating:
- Expanded transparency obligations, requiring clear information about data collection purposes
- A requirement to conduct data protection impact assessments for high-risk processing
- Mandatory data breach notification to the Federal Data Protection and Information Commissioner (FDPIC) in cases of high risk to the individual
- A "privacy by design" and "privacy by default" requirement
- Expanded individual rights, including access, correction, and data portability
Key Differences from GDPR
Despite the alignment, notable differences remain:
- The revised FADP does not include GDPR's specific fixed percentage-of-turnover fine structure; instead, penalties are levied against responsible individuals (rather than the company itself in most cases) and are capped at a fixed maximum amount
- Swiss law does not require a Data Protection Officer in all cases — appointing one is optional but can reduce certain obligations, such as the need for prior consultation with the FDPIC on high-risk processing
- Legal entities (as opposed to natural persons) are generally not protected under the revised FADP's personal data provisions, a departure from the old law which had covered them
- Genetic and biometric data that uniquely identifies a person are explicitly classified as sensitive personal data under Swiss law
Individual Rights
Individuals in Switzerland have the right to request information about what personal data is being processed about them and for what purpose, the right to have inaccurate data corrected, and rights connected to automated individual decision-making, including the right to be informed and, in certain cases, to have a human review the decision.
Enforcement and Penalties
Unlike GDPR's structure of large corporate fines, the revised FADP places criminal liability primarily on the individuals within an organization who are responsible for violations — such as failing to provide required information, disregarding due diligence duties in cross-border transfers, or violating minimum data security requirements. Penalties can reach CHF 250,000 per violation, and in certain circumstances, the company itself can be fined if identifying the responsible individual would require disproportionate investigative effort.
Cross-Border Data Transfers
The FADP restricts transferring personal data outside Switzerland unless the destination country ensures an adequate level of protection (based on a list maintained by the FDPIC), or appropriate safeguards such as standard contractual clauses or binding corporate rules are in place.
Secure Data Disposal
As with GDPR, Swiss law's storage limitation and data minimization principles require that personal data be deleted or anonymized once it is no longer necessary for the purpose it was collected for. Organizations retiring IT hardware that processed personal data under Swiss jurisdiction should apply verifiable, standards-based erasure methods and retain proof of destruction, both to satisfy the FDPIC's expectations around appropriate technical and organizational security measures and to reduce breach risk from improperly disposed devices.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
Switzerland's revised FADP brings Swiss data protection law substantially closer to GDPR while preserving some distinctly Swiss characteristics, particularly around individual criminal liability and the treatment of legal entities. Organizations processing personal data connected to Switzerland should treat FADP compliance as a close cousin of, but not identical twin to, their GDPR compliance program.
No comments yet. Be the first to comment.