The revised Swiss FADP applies to any processing of personal data that has effects in Switzerland — regardless of where the company doing the processing is based. If you run a SaaS company in Germany, the Netherlands, or the UK and you have Swiss customers, Swiss employees, or your processing otherwise touches Switzerland, FADP obligations apply to you.
This is frequently overlooked. Most EU SaaS companies assume GDPR compliance is sufficient. It is not — Switzerland is not an EU member state, FADP is a separate law, and there are meaningful differences between the two.
Does FADP Apply to Your Company?
The extraterritorial reach of FADP follows the same logic as GDPR: it is triggered by effects in Switzerland, not the location of the company.
FADP applies to you if you:
- Have Swiss users or customers whose personal data you process
- Have employees based in Switzerland
- Process data on behalf of Swiss organisations (as a processor/service provider)
- Your product or service is targeted at the Swiss market
Practical examples:
- A Berlin-based HR SaaS with Swiss company customers processing employee data → FADP applies
- A UK marketing platform used by Swiss businesses to process customer emails → FADP applies
- A US analytics company with Swiss enterprise customers → FADP applies to Swiss customer data
Key Differences Between FADP and GDPR
If you are already GDPR-compliant, FADP compliance is achievable with targeted effort — but it is not automatic. The key differences:
1. Swiss Adequacy Status
Switzerland has had EU adequacy status for GDPR purposes since 2000, allowing free data flow from the EU to Switzerland. But the Swiss FDPIC (the supervisory authority) maintains its own list of countries with "adequate" data protection for FADP purposes. This list is separate from the EU's adequacy list.
Implications:
- Data flowing from the EU to Switzerland: covered by EU adequacy
- Data flowing from Switzerland to the US: requires Swiss-specific transfer mechanisms, not just EU mechanisms
- If you process data in Switzerland (e.g., using Swiss-based servers) and transfer it, Swiss transfer rules apply
2. Transfer Mechanisms: Swiss SCCs and DPF
Switzerland has its own Standard Contractual Clauses for data transfers. EU SCCs are not automatically valid for transfers from Switzerland — you may need to use Swiss SCCs or ensure the EU SCCs cover the Swiss aspect of your processing.
The Swiss-US Data Privacy Framework (DPF): Switzerland has its own bilateral arrangement with the US. US companies can certify under the Swiss-US DPF separately from the EU-US DPF. Check your US vendors' Swiss DPF certification, not just their EU certification.
3. Breach Notification: No Hard 72-Hour Deadline
GDPR requires notification to the supervisory authority within 72 hours. FADP requires notification "as soon as possible" — there is no fixed timeframe. In practice, this is typically interpreted as within 72 hours for serious breaches, but the regulation itself does not specify.
4. Personal Liability
FADP's most distinctive feature: violations can trigger personal criminal liability against the responsible individual, not just company fines. Maximum CHF 250,000. This applies to the individual who made the relevant decision — the founder, CTO, or compliance lead.
This liability structure is absent from GDPR. For EU SaaS companies operating in Switzerland, this means the person responsible for data protection decisions has personal exposure, not just the company.
5. DPA Requirement
FADP requires a declaration of data processing in service agreements. This is broadly equivalent to GDPR Article 28 DPA requirements, but Swiss customers may request Swiss-specific DPA terms that reference FADP obligations explicitly.
What EU SaaS Companies Need to Add for FADP Compliance
If you are GDPR-compliant and want to extend to Swiss compliance:
1. Swiss-specific privacy notice sections Add a section to your privacy notice addressing FADP specifically:
- The Swiss supervisory authority (FDPIC) as the relevant authority for Swiss data subjects
- Swiss data subject rights (broadly equivalent to GDPR but should be stated explicitly)
- Cross-border transfer mechanisms used for Swiss data
2. Review transfer mechanisms for Swiss data Audit which US and third-country vendors process Swiss customer data. Confirm they have Swiss DPF certification or that Swiss SCCs are in place.
3. Appoint a Swiss representative (if required) Non-Swiss organisations regularly processing data of a large number of Swiss residents, or processing that poses high risks, must appoint a representative in Switzerland. This is analogous to the GDPR representative requirement.
The FDPIC has published guidance on the threshold — it is not precisely defined. For significant Swiss market operations, appoint a representative as a precaution.
4. Update DPA terms If enterprise customers ask for Swiss-specific DPA terms, be ready to accommodate them. A Swiss DPA addendum can be a short document that supplements your existing GDPR-compliant DPA.
5. Breach notification procedure Your existing 72-hour breach notification process should apply to Swiss data breaches. The FADP "as soon as possible" standard is met by the same process.
The Practical Compliance Assessment
For most EU SaaS companies with Swiss customers:
- 70–80% of GDPR compliance applies directly
- The gaps are: Swiss transfer mechanisms, Swiss-specific privacy notice updates, possible representative appointment, and awareness of personal liability
A half-day compliance gap assessment against FADP, starting from an existing GDPR compliance programme, is usually sufficient to identify and address the specific Swiss requirements.