The revised Swiss Federal Act on Data Protection (FADP) has been in force since 1 September 2023. If you operate in Switzerland, have Swiss customers, or your data processing has effects in Switzerland, you must comply. This checklist covers every obligation an SME needs to address.
Who This Applies To
The FADP applies to private persons (individuals and legal entities) who process personal data of natural persons where the processing has effects in Switzerland. This includes:
- Swiss-based companies processing data of Swiss residents
- Foreign companies whose processing has effects in Switzerland (extraterritorial reach)
- Companies outside Switzerland selling products or services to Swiss customers
Core Compliance Checklist
Principles of Data Processing
The FADP requires that personal data be processed in accordance with five key principles. Document compliance with each:
- Lawfulness — processing has a legal justification (justified purpose, consent, or legal obligation)
- Good faith — processing does not deceive data subjects about how their data is used
- Proportionality — only process data that is necessary for the stated purpose
- Purpose limitation — data collected for one purpose is not repurposed without justification
- Data accuracy — data is accurate and, where necessary, kept up to date
Unlike GDPR, FADP does not require you to select from a fixed list of lawful bases — but you must be able to justify each processing activity.
Privacy Notice (Data Protection Declaration)
- Publish a privacy notice (data protection declaration) on your website and in your product
- The notice must cover:
- Identity and contact details of the controller
- Purpose of processing
- Recipients or categories of recipients
- Whether data is transferred abroad and which safeguards apply
- How data subjects can exercise their rights
- Ensure the notice is in plain language
- Update the notice when processing activities change
Key FADP requirement: The privacy notice must specifically address cross-border transfers — more prominently than many GDPR notices do.
Data Processing Register
- Maintain a register of processing activities if you have 250+ employees
- Exception: Also required regardless of headcount if processing sensitive personal data, or if the processing poses high risks to data subjects
- The register must include: purpose, recipients, transfer countries, security measures, and retention periods
- Designate a responsible person for maintaining and updating the register
Data Subject Rights
Under FADP, data subjects have the right to:
- Information (access) — know whether their data is being processed and obtain a copy
- Implement a procedure for responding to access requests — respond within 30 days
- Rectification — correct inaccurate data
- Erasure — delete data in specific circumstances
- Objection to automated decisions — data subjects have the right to an explanation and to request human review of automated decisions with significant effects
FADP-specific right: The right to explanation for automated decisions that produce a legal or similarly significant effect is explicitly provided.
Sensitive Personal Data
- Identify all processing of sensitive personal data:
- Religious, ideological, political, or trade union opinions
- Health data, genetic data, biometric data (for identification)
- Administrative and criminal proceedings or sanctions
- Social welfare measures
- Racial and ethnic origin
- Intimate sphere data
- Ensure processing of sensitive data has a justification (explicit consent, legal obligation, vital interests, or other recognised ground)
- Apply heightened security measures to sensitive data processing
Data Protection Impact Assessment
- Identify processing activities likely to pose a high risk to data subjects
- Conduct a Data Protection Impact Assessment (DPIA) before beginning high-risk processing
- High-risk indicators include: new technologies, large-scale processing, profiling, sensitive data, systematic monitoring
- Document the DPIA and retain it
- Where risks cannot be adequately mitigated, consult the FDPIC before proceeding
Data Security
- Implement technical and organisational measures appropriate to the risk of the processing
- Consider: encryption, access controls, pseudonymisation, audit logging, backup procedures, physical security
- Document the security measures implemented
- Review security measures when processing activities or risks change
Data Breach Notification
- Implement a breach detection and response procedure
- Notify the FDPIC "as soon as possible" when a breach is likely to lead to a high risk to the persons concerned
- The FADP does not specify a 72-hour deadline (unlike GDPR) — but "as soon as possible" means prompt action
- Notify affected data subjects where the breach requires it to protect them
- Log all breaches, including assessment of whether notification was required
- Maintain breach records for at least 2 years
Cross-Border Data Transfers
- Identify all transfers of personal data to countries outside Switzerland
- Check whether the destination country is on the Federal Council's adequacy list
- For transfers to non-adequate countries, implement appropriate safeguards:
- Standard Data Protection Clauses (Swiss SCCs approved by FDPIC)
- Binding Corporate Rules
- Other FDPIC-approved safeguards
- Disclose cross-border transfers and safeguards in your privacy notice
- Note on EU transfers: The EU has granted Switzerland adequacy — EU-to-Switzerland transfers are lawful under GDPR without SCCs. Switzerland-to-EU transfers are also generally unproblematic given EU adequacy status.
Personal Liability: Identify the Responsible Person
- Designate the person responsible for FADP compliance in your organisation
- Document this designation — given personal liability under FADP (up to CHF 250,000 for the responsible person), clarity on who is responsible for each obligation matters
- Ensure the responsible person has adequate authority, resources, and awareness of their obligations
Data Processing Agreements (Processor Relationships)
- Identify all third parties who process personal data on your behalf
- Execute data processing agreements with each processor
- Ensure processors are bound by security and confidentiality obligations
- Maintain records of processor agreements
FADP uses the concept of "disclosure" to third parties rather than GDPR's controller/processor distinction — but the practical requirement to regulate third-party processing contractually is equivalent.
Voluntary: Advisor for Data Protection
The FADP allows (but does not require for most organisations) the voluntary appointment of an Advisor for Data Protection (the equivalent of a DPO). Appointing one and registering with the FDPIC provides procedural benefits — including that the FDPIC must notify the advisor before taking certain investigative steps.
SME-Specific Priorities
If you are an SME with limited resources, focus in this order:
- Privacy notice — visible, accurate, covers cross-border transfers
- Designated responsible person — given personal liability, this is non-negotiable
- Breach procedure — know who to call, what to document, and that FDPIC must be notified when high risk
- Processor contracts — sign agreements with vendors processing your customers' data
- Processing register — document what you process, why, and where it goes
- Sensitive data governance — if you process any FADP sensitive categories, treat this as urgent