Switzerland's revised FADP introduces two concepts that trigger heightened obligations: high-risk data processing and profiling with high risk. Understanding what triggers these designations — and what they require — is essential for any company that uses data analytics, scoring systems, or automated decision-making in the Swiss market.
Two Distinct Concepts
The revised FADP distinguishes between:
- High-risk data processing — processing likely to significantly affect the personality or fundamental rights of the data subject (triggers DPIA obligation)
- Profiling with high risk — automated processing of personal data used to evaluate personal aspects of a natural person, where it results in automated decisions producing a legal effect or similarly significant effect (triggers individual rights)
These overlap with GDPR's DPIA requirement and Article 22 (automated decision-making), but the Swiss framework has distinct terminology and scope.
High-Risk Data Processing: When a DPIA Is Required
Under FADP Article 22, a controller must conduct a data protection impact assessment (DPIA) when processing is "likely to result in a high risk to the personality or fundamental rights of the data subjects."
What triggers high risk:
| Factor | Why it indicates high risk |
|---|---|
| New technology | Novel processing methods not previously assessed |
| Large-scale processing | Processing many individuals' data or large volumes per individual |
| Sensitive personal data | Health, biometric, criminal, social welfare, racial origin, intimate sphere |
| Systematic surveillance | Monitoring behaviour of individuals in a targeted way |
| Profiling | Automated assessment of personal characteristics |
| Combination of datasets | Merging data from multiple sources to create detailed profiles |
| Data on vulnerable persons | Children, employees, patients, asylum seekers |
| Processing preventing rights exercise | Systems that restrict access to services or benefits |
The assessment is contextual. A single factor may or may not indicate high risk. The key question is: given everything about this processing activity, is there a real risk of significant impact on individuals?
What the DPIA Must Cover
A DPIA under FADP must assess and document:
- The planned processing operations and purposes — what you are doing and why
- Assessment of necessity and proportionality — is the processing justified for the stated purpose?
- Assessment of risks — risks to the personality and fundamental rights of data subjects
- Measures to address the risks — technical and organisational mitigations
This is substantially equivalent to a GDPR DPIA. Companies that have already run GDPR-format DPIAs can adapt them to satisfy FADP requirements with modest additional work.
If risks cannot be adequately mitigated: You must consult the FDPIC before proceeding. The FDPIC will assess the processing and may approve it, impose conditions, or recommend that it not proceed.
Profiling with High Risk
"Profiling" under FADP means any automated processing of personal data that evaluates personal aspects — including analysing or predicting performance at work, financial situation, health, personal preferences, interests, reliability, or behaviour.
Profiling with high risk is profiling that:
- Is carried out by private persons (not just public bodies)
- Leads to automated decision-making
- Produces a legal effect or similarly significant effect on the individual
Examples of profiling with high risk:
- Automated credit scoring determining loan eligibility
- AI-driven insurance underwriting producing individual risk scores affecting premiums or coverage
- Automated performance evaluation systems used for promotion or termination decisions
- Scoring systems determining access to services based on predicted behaviour
- AI models that assess creditworthiness for B2B contracts involving individual liability
Examples of profiling that is NOT high risk:
- Personalised content recommendations (no significant individual effect)
- Segmentation for marketing (no legal or similarly significant consequence)
- Aggregate analytics without individual-level consequential output
Rights Around Automated Decisions
FADP Article 21 gives data subjects the right to:
- Be informed that a significant decision affecting them was made based solely on automated processing
- Request a human review of the decision
- Receive an explanation of the decision logic
These rights apply when an automated processing produces a legal effect or similarly significant effect. They run parallel to GDPR Article 22 but have Swiss-specific framing.
What controllers must do:
- Inform data subjects when an automated decision is made that has a significant effect on them
- Implement a mechanism for data subjects to request review and explanation
- Have a human review process that is genuine — not just a formal step where a person rubber-stamps the automated output
Design implications for SaaS: If your product generates automated decisions that your customers use to affect their end users — job candidates, loan applicants, insurance customers — you must:
- Enable your customers to inform their users of automated decisions
- Support a human review / explanation workflow
- Document the decision logic sufficiently to explain it meaningfully
Comparison: FADP vs GDPR Automated Decisions
| Feature | FADP | GDPR |
|---|---|---|
| Scope | Private persons — broader | Both public and private |
| Trigger | Automated decision with significant effect | Solely automated decision with legal/significant effect |
| Exemptions | Limited | Contract necessity, consent, law |
| Human review | Required on request | Required (right not to be subject to solely automated decision) |
| Explanation | Required on request | Meaningful information about logic required |
| Proactive obligation | Inform when decision made | Inform in privacy notice |
Key FADP difference: Under GDPR, a decision involving some human involvement may not be "solely automated" and therefore may fall outside Article 22. The FADP's approach is less mechanical on this point — the focus is on the significant effect and the degree of automation in the decision, not the technical presence of a human reviewer.
Practical Steps for Companies Using AI or Scoring Systems
- Map every automated processing that produces individual-level outputs
- Assess which outputs have legal or significant effects on individuals
- Conduct a DPIA for any processing classified as high risk
- For profiling with high risk: build a human review pathway into the product
- For profiling with high risk: build an explanation mechanism (why was this decision made?)
- Update privacy notices to disclose automated decision-making
- Train customer-facing teams on how to handle requests for human review and explanation
- Document the decision logic sufficiently to generate meaningful explanations