Skip to content
Swiss FADP

FADP vs GDPR: What Swiss Companies Get Wrong

6 min readUpdated 15 July 2026

Switzerland's revised Federal Act on Data Protection (revFADP or nFADP) entered into force on 1 September 2023. It brought Swiss data protection law much closer to GDPR — but they are not identical. Companies operating under both regimes, and companies assuming Swiss compliance automatically satisfies GDPR obligations, make consistent and costly mistakes.

This guide covers the key differences, common misalignments, and what you need to address if you operate under both laws.


The Core Difference: Scope and Jurisdiction

GDPR applies to processing of personal data of EU/EEA residents, regardless of where the controller or processor is established.

Swiss FADP applies to processing of personal data of natural persons (natural persons only — not legal entities) where the processing has effects in Switzerland. The revised Act also introduced an extraterritorial reach similar to GDPR — it applies to foreign companies whose processing has effects in Switzerland.

Key difference: GDPR covers EU residents. FADP covers processing with effects in Switzerland. A Swiss company with EU customers needs both. A French company with Swiss customers needs both. A US company with both EU and Swiss customers needs both.


Side-by-Side Comparison

FeatureGDPRSwiss FADP
In forceMay 2018September 2023
ScopePersonal data of EU/EEA residentsPersonal data with effects in Switzerland
Legal entitiesOnly natural personsOnly natural persons (legal entities excluded)
Lawful basisRequired (6 bases in Article 6)Processing permitted unless it violates principles — less prescriptive basis system
Sensitive data categoriesSpecial categories (Article 9)Sensitive personal data — similar but not identical list
DPIA equivalentDPIA required for high-risk processingData Protection Impact Assessment required for high-risk processing
Breach notification72 hours to DPA (Article 33)"As soon as possible" to FDPIC — no strict 72-hour rule
Personal liabilityFines on organisations onlyPersonal liability for the responsible person — up to CHF 250,000
Maximum fine€20m or 4% global turnoverCHF 250,000 (individual person, not company)
DPO equivalentDPO required in some casesVoluntary appointment of an Advisor for Data Protection
Data processing registerRoPA required (Article 30)Required for companies ≥250 employees (+ similar exceptions as GDPR)
AdequacyEuropean Commission determinesSwiss Federal Council maintains own adequacy list
Supervisory authorityNational DPAs (EDPB at EU level)FDPIC (Federal Data Protection and Information Commissioner)
Right to explanationAutomated decisions — Article 22Right to explanation for automated decisions with significant effects

The Three Most Common Mistakes

Mistake 1: Assuming GDPR Compliance Covers Switzerland

GDPR compliance gets you most of the way with FADP — but not all the way. Companies that implement GDPR thoroughly but treat Switzerland as covered without checking have specific gaps:

  • Breach notification: GDPR's 72-hour rule does not apply under FADP. You must notify "as soon as possible" — but what this means in practice differs, and your procedures may be calibrated for the GDPR timeline only.
  • Lawful basis: GDPR requires explicit identification of a lawful basis for each processing activity. FADP works differently — processing is generally permitted unless it violates data protection principles (unlawfulness, bad faith, proportionality). A GDPR-style basis analysis is not strictly required, but documenting it is best practice.
  • Personal liability: This is the biggest difference. GDPR fines fall on the organisation. FADP fines fall on the responsible individual — the person who took the decision. This shifts the risk calculation significantly for executives and founders.

Mistake 2: Ignoring the Personal Liability Structure

Under FADP, fines of up to CHF 250,000 can be imposed on the natural person responsible for the violation — not on the company. This means a founder, CTO, or compliance officer can be personally fined for FADP violations.

The personal liability applies to:

  • Violations of information obligations
  • Violations of data subject rights
  • Providing false information to the FDPIC
  • Obstructing FDPIC supervision

The GDPR model — where the company pays — does not apply in Switzerland. This makes FADP compliance a personal risk for executives in a way GDPR is not.

Mistake 3: Treating Sensitive Data Categories as Identical

GDPR's special categories (Article 9) and FADP's sensitive personal data are similar but not the same.

FADP sensitive data includes:

  • Religious, ideological, political, or trade union opinions and activities
  • Health and intimate sphere (including genetic data)
  • Administrative and criminal proceedings or sanctions
  • Social assistance measures
  • Racial and ethnic origin
  • Biometric data used for unique identification

Differences from GDPR:

  • FADP includes data on social assistance measures (welfare, public benefits) — GDPR does not
  • GDPR includes sexual orientation explicitly as a special category — FADP covers this under "intimate sphere" but with different framing
  • The processing requirements differ — GDPR Article 9 requires explicit consent or a specific exception; FADP requires a justification ground but the framework is slightly less restrictive

If your product handles any sensitive data and you operate in both EU and Swiss markets, you need to verify that your data governance satisfies both sets of requirements.


The FDPIC and Swiss Enforcement

The Federal Data Protection and Information Commissioner (FDPIC) is Switzerland's independent supervisory authority. Unlike EU DPAs, the FDPIC's enforcement powers historically were limited — but the revised FADP significantly expanded them.

FDPIC powers under revised FADP:

  • Conduct investigations
  • Issue binding orders
  • Recommend that violations be addressed
  • Refer cases for criminal prosecution (fines are imposed by criminal law authorities, not the FDPIC itself)

The personal liability model means enforcement goes through the criminal courts rather than regulatory fines — which is a different mechanism from GDPR but can be equally impactful for responsible individuals.


Cross-Border Transfers Under FADP

FADP has its own adequacy framework. The Federal Council maintains a list of countries providing adequate protection. The EU/EEA countries are on this list. Transfers to countries not on the list require appropriate safeguards — the FADP equivalents of GDPR's SCCs are the Standard Data Protection Clauses approved by the FDPIC.

Transfers between Switzerland and EU: Both GDPR and FADP apply to transfers in each direction if both parties process data covered by both laws. A company transferring data from Switzerland to an EU processor must comply with FADP transfer rules. A company transferring EU data to a Swiss processor must comply with GDPR transfer rules.

The EU has granted Switzerland an adequacy decision — meaning EU-to-Switzerland transfers are lawful without SCCs.


Practical Steps If You Operate Under Both GDPR and FADP

  • Identify all processing activities with effects in Switzerland
  • Map the differences between your GDPR documentation and FADP requirements
  • Update breach notification procedures — add FDPIC notification as a parallel track to DPA notification
  • Review sensitive data categories against FADP's list (particularly social assistance data)
  • Identify the responsible person for FADP compliance — document this, given personal liability exposure
  • Check whether your Swiss customers require a privacy notice specifically addressing FADP
  • Verify cross-border transfer mechanisms for Switzerland-to-EU and Switzerland-to-third-country flows

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →