Switzerland's revised FADP creates something most founders don't expect: personal criminal liability for data protection violations. The maximum fine is CHF 250,000 — and it falls on the individual responsible, not the company. For a startup founder or CTO, this is not abstract legal theory. It is a direct personal financial and reputational risk.
This article explains the risk, who is most exposed, and the specific steps that reduce your exposure to the minimum.
The Risk Is Real — But Manageable
The CHF 250,000 maximum is a ceiling. Most enforcement actions against individuals will result in lower fines, calibrated to severity, intent, and mitigating factors. The Swiss criminal law system applies proportionality.
But the risk is not zero. Several factors increase exposure for startup founders and executives:
- You are the person making the compliance decisions — "the responsible person" under FADP
- Startups often lack formal compliance processes, making gaps easier to identify in an investigation
- The FDPIC's expanded powers under the revised Act enable more active investigation
- The personal liability model means your company's insurance does not automatically protect you
The good news: the same factors that increase exposure are also the ones you can directly address. Building a documented compliance programme is the single most effective thing you can do.
Which Violations Carry Personal Liability
Under FADP Articles 60–66, personal liability applies to:
Information violations:
- Not providing required privacy information to data subjects
- Providing false information to data subjects about processing
- Failing to disclose cross-border transfers appropriately
Data subject rights violations:
- Refusing or obstructing access requests
- Providing incomplete or false data in response to access requests
- Obstructing erasure, rectification, or restriction without legal justification
FDPIC violations:
- Providing false information to the FDPIC
- Obstructing an FDPIC investigation
- Failing to comply with an FDPIC order
Professional confidentiality violations:
- Unlawfully disclosing data subject to professional secrecy
The violations most likely to affect startup founders are the first two categories — privacy information failures and mishandled data subject requests.
The Six Highest-Risk Situations for Swiss Startups
1. No Swiss-Compliant Privacy Notice
Your website and product do not have a privacy notice, or the notice does not cover FADP requirements — particularly cross-border transfers to the US (AWS, Google, Meta, etc.).
Fix: Publish a FADP-compliant privacy notice that explicitly covers: purposes, recipients, countries of transfer, and data subject rights. Update it when processing changes.
2. US Vendor Transfers Without Documentation
You use US-based tools (Shopify, HubSpot, Slack, AWS us-east) without documented transfer mechanisms. Even if GDPR SCCs are in place, Swiss FADP requires Swiss-specific instruments unless the vendor is Swiss-US DPF certified.
Fix: Check each US vendor's DPF certification status. Where not certified, execute Swiss SCCs. Document all mechanisms in your transfer record. Disclose in privacy notice.
3. Ignored Data Subject Access Requests
A customer, prospect, or former employee submits a data access request — and it is not responded to within 30 days, or is ignored entirely. This is one of the highest-frequency enforcement triggers.
Fix: Create a designated email address or webform for data requests. Designate who handles them. Set up a tracking system with the 30-day deadline. Build the ability to export user data before you need it.
4. No Process for Breach Detection and FDPIC Notification
A security incident occurs — a database misconfiguration exposes customer data, credentials are compromised, a file is sent to the wrong person. Without a breach procedure, the response is slow and poorly documented.
Under FADP, high-risk breaches must be reported to the FDPIC "as soon as possible." A company with no process will miss this.
Fix: Implement a breach response procedure. Name who is responsible. Define the risk assessment that determines whether FDPIC notification is required. Document all incidents — notified or not.
5. Health, Biometric, or Other Sensitive Data Without Justification
You process health data (a wellness feature), biometric data (face ID for login), or other FADP sensitive categories without a clear justification ground documented.
Fix: Audit all features that could touch sensitive categories. Document the justification (explicit consent, legal obligation, etc.). Conduct a DPIA if the processing is large-scale or high-risk.
6. No Designated Responsible Person
No one in the company has clear responsibility for FADP compliance. When the FDPIC investigates, they will determine responsibility from evidence — email chains, meeting records, decision logs. Whoever made the relevant decision is the responsible person.
Fix: Designate the responsible person for FADP compliance in writing. Ensure they have authority, resources, and awareness of their obligations. Document compliance decisions with the decision-maker named.
The Compliance Programme That Protects You
You do not need a sophisticated compliance infrastructure to demonstrate good faith. What you need is documentation that shows:
- You knew what you were processing — a maintained processing register
- You told people about it — a compliant, current privacy notice
- You secured it appropriately — documented security measures
- You handled requests properly — a logged DSAR process
- You knew about breaches — a breach detection and response procedure
- Someone was responsible — a named responsible person
This is a few documents and a few processes. For a 20-person startup, it is a day's work to implement if you start from scratch.
Timeline: When to Act
The revised FADP came into force on 1 September 2023. There is no transition period — the obligations are in force now. If you have Swiss customers, Swiss employees, or your processing otherwise has effects in Switzerland, you are already in scope.
The FDPIC is building its investigation capacity under the new Act. Early enforcement tends to target the most visible failures — missing privacy notices, unresponsive access requests, notable breaches. Getting the basics in place now removes your exposure from these first-wave enforcement scenarios.
Cost vs Risk
A basic FADP compliance programme for a startup costs:
- External DPO / legal review: CHF 3,000–8,000 for initial setup
- Privacy notice and documentation: 1–2 days of internal time
- Ongoing maintenance: A few hours per quarter
Against a maximum personal liability of CHF 250,000 — plus the reputational damage of a criminal proceeding — the cost of compliance is trivially small.
The question is not "can we afford to comply?" It is: "can we afford not to?"