Skip to content
Swiss FADP

High-Risk Data Processing and Profiling Under Swiss FADP

7 min readUpdated 15 July 2026

Switzerland's revised FADP introduces two concepts that trigger heightened obligations: high-risk data processing and profiling with high risk. Understanding what triggers these designations — and what they require — is essential for any company that uses data analytics, scoring systems, or automated decision-making in the Swiss market.


Two Distinct Concepts

The revised FADP distinguishes between:

  1. High-risk data processing — processing likely to significantly affect the personality or fundamental rights of the data subject (triggers DPIA obligation)
  2. Profiling with high risk — automated processing of personal data used to evaluate personal aspects of a natural person, where it results in automated decisions producing a legal effect or similarly significant effect (triggers individual rights)

These overlap with GDPR's DPIA requirement and Article 22 (automated decision-making), but the Swiss framework has distinct terminology and scope.


High-Risk Data Processing: When a DPIA Is Required

Under FADP Article 22, a controller must conduct a data protection impact assessment (DPIA) when processing is "likely to result in a high risk to the personality or fundamental rights of the data subjects."

What triggers high risk:

FactorWhy it indicates high risk
New technologyNovel processing methods not previously assessed
Large-scale processingProcessing many individuals' data or large volumes per individual
Sensitive personal dataHealth, biometric, criminal, social welfare, racial origin, intimate sphere
Systematic surveillanceMonitoring behaviour of individuals in a targeted way
ProfilingAutomated assessment of personal characteristics
Combination of datasetsMerging data from multiple sources to create detailed profiles
Data on vulnerable personsChildren, employees, patients, asylum seekers
Processing preventing rights exerciseSystems that restrict access to services or benefits

The assessment is contextual. A single factor may or may not indicate high risk. The key question is: given everything about this processing activity, is there a real risk of significant impact on individuals?


What the DPIA Must Cover

A DPIA under FADP must assess and document:

  1. The planned processing operations and purposes — what you are doing and why
  2. Assessment of necessity and proportionality — is the processing justified for the stated purpose?
  3. Assessment of risks — risks to the personality and fundamental rights of data subjects
  4. Measures to address the risks — technical and organisational mitigations

This is substantially equivalent to a GDPR DPIA. Companies that have already run GDPR-format DPIAs can adapt them to satisfy FADP requirements with modest additional work.

If risks cannot be adequately mitigated: You must consult the FDPIC before proceeding. The FDPIC will assess the processing and may approve it, impose conditions, or recommend that it not proceed.


Profiling with High Risk

"Profiling" under FADP means any automated processing of personal data that evaluates personal aspects — including analysing or predicting performance at work, financial situation, health, personal preferences, interests, reliability, or behaviour.

Profiling with high risk is profiling that:

  • Is carried out by private persons (not just public bodies)
  • Leads to automated decision-making
  • Produces a legal effect or similarly significant effect on the individual

Examples of profiling with high risk:

  • Automated credit scoring determining loan eligibility
  • AI-driven insurance underwriting producing individual risk scores affecting premiums or coverage
  • Automated performance evaluation systems used for promotion or termination decisions
  • Scoring systems determining access to services based on predicted behaviour
  • AI models that assess creditworthiness for B2B contracts involving individual liability

Examples of profiling that is NOT high risk:

  • Personalised content recommendations (no significant individual effect)
  • Segmentation for marketing (no legal or similarly significant consequence)
  • Aggregate analytics without individual-level consequential output

Rights Around Automated Decisions

FADP Article 21 gives data subjects the right to:

  1. Be informed that a significant decision affecting them was made based solely on automated processing
  2. Request a human review of the decision
  3. Receive an explanation of the decision logic

These rights apply when an automated processing produces a legal effect or similarly significant effect. They run parallel to GDPR Article 22 but have Swiss-specific framing.

What controllers must do:

  • Inform data subjects when an automated decision is made that has a significant effect on them
  • Implement a mechanism for data subjects to request review and explanation
  • Have a human review process that is genuine — not just a formal step where a person rubber-stamps the automated output

Design implications for SaaS: If your product generates automated decisions that your customers use to affect their end users — job candidates, loan applicants, insurance customers — you must:

  1. Enable your customers to inform their users of automated decisions
  2. Support a human review / explanation workflow
  3. Document the decision logic sufficiently to explain it meaningfully

Comparison: FADP vs GDPR Automated Decisions

FeatureFADPGDPR
ScopePrivate persons — broaderBoth public and private
TriggerAutomated decision with significant effectSolely automated decision with legal/significant effect
ExemptionsLimitedContract necessity, consent, law
Human reviewRequired on requestRequired (right not to be subject to solely automated decision)
ExplanationRequired on requestMeaningful information about logic required
Proactive obligationInform when decision madeInform in privacy notice

Key FADP difference: Under GDPR, a decision involving some human involvement may not be "solely automated" and therefore may fall outside Article 22. The FADP's approach is less mechanical on this point — the focus is on the significant effect and the degree of automation in the decision, not the technical presence of a human reviewer.


Practical Steps for Companies Using AI or Scoring Systems

  • Map every automated processing that produces individual-level outputs
  • Assess which outputs have legal or significant effects on individuals
  • Conduct a DPIA for any processing classified as high risk
  • For profiling with high risk: build a human review pathway into the product
  • For profiling with high risk: build an explanation mechanism (why was this decision made?)
  • Update privacy notices to disclose automated decision-making
  • Train customer-facing teams on how to handle requests for human review and explanation
  • Document the decision logic sufficiently to generate meaningful explanations

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →