Skip to content
Swiss FADP

Who Is Personally Liable Under Swiss FADP?

6 min readUpdated 15 July 2026

The personal liability structure under Switzerland's revised FADP is the most significant difference from GDPR — and the one most often overlooked by companies that assume Swiss compliance mirrors EU compliance. Under GDPR, the organisation pays the fine. Under FADP, the responsible individual can be held personally liable for up to CHF 250,000.


The Core Difference from GDPR

Under GDPR, sanctions are imposed on the organisation (the controller or processor). The maximum fines — €20 million or 4% of global turnover — fall on the company. Individuals can face employment consequences, but the regulatory fine is a corporate liability.

Under Swiss FADP, the mechanism is different. The FADP creates criminal sanctions, not administrative fines. The fine — up to CHF 250,000 — is imposed on the natural person responsible for the violation. The company is not directly fined under the FADP criminal enforcement model (though civil claims and reputational damage remain a company-level concern).

This shift from corporate to personal liability is deliberate. The Swiss legislator's intention was to ensure individuals within organisations take accountability — not just delegate compliance to a legal team and assume the corporate shield protects them.


Which Violations Trigger Personal Liability

FADP Articles 60–66 define the criminal offences. Personal liability applies to:

Information Obligations

Failing to provide the required information to data subjects when collecting their data — or providing false or misleading information. This includes:

  • Missing or inadequate privacy notices
  • Failing to inform data subjects about cross-border transfers
  • Not disclosing automated decision-making when required

Data Subject Rights

Deliberately obstructing data subjects from exercising their rights:

  • Refusing to respond to access requests
  • Providing incorrect or incomplete data in response to an access request
  • Obstructing erasure, rectification, or restriction requests without legal justification

FDPIC Obligations

  • Providing false information to the FDPIC during an investigation
  • Obstructing the FDPIC's supervisory activities
  • Failing to comply with an FDPIC order

Professional Confidentiality

Disclosing personal data in breach of professional confidentiality obligations without justification.


Who Is the "Responsible Person"?

The law applies to the person who took the decision or who was responsible for the act or omission in question. In practice, this is typically:

  • Founders and CEOs — where compliance decisions are made at the top
  • CTOs — where technical implementation of data protection is their responsibility
  • Operations leads or compliance officers — where a specific person was designated to handle a specific obligation
  • HR managers — for employee data violations
  • Marketing managers — for consent violations in marketing activities

"The company didn't have a process" does not transfer liability to the company. If a person had responsibility for implementing a process and did not, that person may bear liability.

Employee liability: Employees can also be personally liable if they themselves take the relevant decision or action — the liability is not limited to executives.


The CHF 250,000 Maximum: What It Means in Practice

CHF 250,000 per violation, per person. This is not a per-incident cap for the whole organisation — it is the maximum per individual violation.

Put in context:

  • CHF 250,000 is approximately €260,000 / £220,000
  • For a founder or senior executive at a startup, this is a significant personal financial exposure
  • The fine is personal — it cannot be indemnified by the company under Swiss law in most circumstances

Most violations will result in lower fines, calibrated to severity and culpability. But the ceiling is high enough to constitute a material personal risk.


The Enforcement Path

Unlike GDPR, where DPAs impose fines directly, FADP enforcement involves criminal proceedings:

  1. The FDPIC investigates and establishes facts
  2. The FDPIC may recommend that criminal proceedings be initiated
  3. Criminal prosecution is handled by cantonal authorities (Swiss criminal courts)
  4. The court (not the FDPIC) imposes the fine

This mechanism is slower than GDPR enforcement — criminal proceedings take longer than administrative sanctions. But the consequence — a criminal conviction, not just a regulatory fine — is more severe. A FADP conviction is a criminal record, not a corporate entry on a regulatory register.


Good Faith and Mitigation

Swiss criminal law principles apply. Mitigating factors include:

  • Genuine belief that processing was lawful (honest mistake, not negligence)
  • Immediate corrective action when a violation was identified
  • Cooperation with the FDPIC investigation
  • No prior violations
  • Complexity of the legal question involved

Aggravating factors include:

  • Deliberate, knowing violation
  • Repeated violations
  • Obstruction of the FDPIC
  • Large number of people affected
  • Sensitive data involved

Building a documented compliance programme — even an imperfect one — demonstrates good faith. A company where no one has looked at FADP compliance is in a very different position from one that has a process, designated a responsible person, and made efforts to comply.


What This Means for Founders and Executives

Designate a responsible person clearly. Ambiguity about who is responsible for FADP compliance does not protect anyone — it means enforcement authorities will determine who was responsible after the fact, based on evidence.

Document decisions. When you make a compliance decision — "we assessed this processing as low risk," "we decided not to notify the FDPIC" — document it, including the reasoning. This shows good faith if the decision is later questioned.

Don't treat Swiss compliance as "same as GDPR." The mechanisms differ enough that GDPR compliance alone leaves gaps — particularly around the personal liability model, breach notification timing, and sensitive data categories.

Know that indemnification has limits. D&O (Directors and Officers) insurance typically covers certain regulatory actions but may not cover criminal fines. Check your policy.


Recommended Steps

  • Designate a named person responsible for FADP compliance and document this
  • Ensure that person has the authority and resources to fulfil the obligations
  • Document compliance decisions — not just what you decided, but why
  • Implement a breach response procedure with clear escalation and documented notification decisions
  • Train executives and senior managers on personal liability under FADP
  • Review D&O insurance coverage for FADP criminal exposure
  • Conduct a FADP gap assessment and address any critical gaps proactively

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →