Financial services companies in Switzerland operate at the intersection of FADP, FINMA regulatory requirements, banking secrecy law, and anti-money laundering obligations. Data protection in Swiss finance is not simply a matter of implementing GDPR-equivalent controls — it involves navigating a layered regulatory environment where data obligations are more demanding, and where the personal liability framework under FADP adds individual exposure that does not exist in EU financial regulation.
The Regulatory Stack for Swiss Financial Services
FADP (nFADP / revDSG): The revised Federal Act on Data Protection, in force September 2023. Sets the baseline data protection obligations.
FINMA Circular 2023/1: FINMA's operational risk circular, which includes data security requirements for supervised financial institutions.
Banking Act (BankG) and Banking Secrecy: Article 47 of the Banking Act imposes criminal penalties for disclosure of confidential client information. This is distinct from FADP but interacts with it — both require protecting client information, but the banking secrecy obligation is more specific and has criminal enforcement.
AMLA / KYC requirements: Anti-money laundering law requires retention of KYC documentation for 10 years after the business relationship ends — creating a long-tail data retention obligation that must be reconciled with FADP data minimisation principles.
DORA (EU): For Swiss fintech and financial institutions with EU operations or EU-regulated activities, DORA's ICT risk management requirements also apply.
Personal Liability Under FADP for Financial Services
FADP's personal criminal liability provision (up to CHF 250,000) is particularly significant in financial services:
- Compliance decisions are often made by named individuals (CCO, CIO, Head of Compliance)
- Financial institutions are subject to regular regulatory examination
- FINMA examinations may reveal FADP violations
- The FDPIC has expanded investigation powers under the revised Act
Financial services executives should be aware that compliance failures related to customer data — missed access requests, undisclosed processing, inadequate security leading to a breach — can result in personal liability, not just institutional fines.
Customer Data Processing in Swiss Financial Services
Lawful Bases
Most financial services data processing has a clear legal basis:
| Processing activity | Lawful basis |
|---|---|
| Account opening and KYC | Contract performance + legal obligation (AMLA) |
| Transaction processing | Contract performance |
| Credit assessment | Contract performance, legitimate interest |
| Marketing to existing customers | Legitimate interest (with opt-out) |
| Regulatory reporting | Legal obligation |
| Fraud detection | Legitimate interest |
| Investment suitability assessment | Contract performance + legal obligation (FinSA) |
Consent is rarely the primary basis in financial services — the service relationship is the primary basis. Consent is appropriate for optional communications and marketing to prospects.
Privacy Notice Requirements
Swiss financial services privacy notices must cover:
- All standard FADP Article 19 requirements (identity, purposes, recipients, transfers, rights)
- Disclosure of cross-border transfers with specific transfer mechanisms — particularly important for financial institutions using US cloud providers for core banking infrastructure
- Clear statement on banking secrecy and how it interacts with data protection rights
- Retention periods aligned with AMLA requirements
Cross-Border Transfers in Financial Services
Swiss banks and financial institutions routinely transfer data internationally:
- To correspondent banks and financial counterparties
- To group entities in non-adequate countries
- To US cloud service providers
- To SWIFT (the global financial messaging network)
Each transfer requires a valid FADP transfer mechanism. Swiss SCCs or Swiss DPF certification are the typical instruments. FINMA expects financial institutions to document these transfers in their operational risk inventory.
Data Retention in Swiss Finance
AML/KYC data retention requirements under AMLA create specific challenges:
KYC documentation: Must be retained for 10 years after the end of the business relationship. This is a legal obligation under AMLA — it overrides FADP data minimisation for the specific documents required.
Transaction records: Similar 10-year requirement for transactions subject to AML monitoring.
Customer communication records: FINMA-supervised entities have requirements to retain relevant communications.
Marketing and ancillary data: Not subject to AMLA retention. FADP minimisation applies — retain only as long as necessary for the specific purpose.
The practical requirement: maintain a data lifecycle policy that distinguishes AMLA-required retention from data that can and should be deleted when no longer needed.
Breach Response in Swiss Financial Services
A data breach in a Swiss financial institution triggers multiple notification obligations:
FADP: Notify FDPIC as soon as possible for high-risk breaches (essentially all customer financial data breaches).
FINMA: FINMA expects to be notified of significant cybersecurity incidents and data breaches. This is separate from the FADP obligation. FINMA Circular 2023/1 sets operational risk incident reporting expectations.
Banking secrecy: Depending on the nature of the breach, there may be obligations to notify affected customers under banking secrecy and financial consumer protection frameworks.
DORA (if applicable): EU-regulated operations face DORA's ICT incident reporting requirements, which include strict timelines.
FINMA Examination Focus Areas
FINMA examinations increasingly include data protection as a component of operational risk assessment. Examination focus areas:
- ICT and cyber risk management (FINMA Circular 2023/1)
- Cloud computing adoption — data residency, access controls, contract governance
- Third-party ICT provider risk management (DORA-aligned requirements)
- Customer data protection practices in digital banking
Swiss financial institutions should treat FADP compliance as inseparable from their broader operational risk framework.