Skip to content
Swiss FADP

Swiss FADP vs UK GDPR: Key Differences

5 min readUpdated 29 July 2026

Swiss companies selling into the UK, and UK companies processing data of Swiss individuals, face two separate data protection regimes: the Swiss revised FADP and UK GDPR. Both are influenced by EU GDPR but are independent laws with meaningful differences. This article compares the key obligations under each and explains what you need to handle separately.


The Starting Point: Shared GDPR DNA

Both the Swiss revised FADP and UK GDPR were built on the foundation of EU GDPR:

  • Both require a lawful basis for processing personal data
  • Both give individuals data subject rights (access, erasure, portability, objection)
  • Both require data protection by design
  • Both require breach notification
  • Both regulate cross-border data transfers

For companies already compliant with EU GDPR, both Swiss FADP and UK GDPR are achievable with targeted adjustments rather than a complete rebuild.


Comparing the Frameworks

Supervisory Authority and Enforcement

Swiss FADP: The Federal Data Protection and Information Commissioner (FDPIC) is the supervisory authority. The FDPIC can open investigations, issue recommendations, and refer violations for prosecution. Criminal fines apply to individuals (up to CHF 250,000).

UK GDPR: The Information Commissioner's Office (ICO) is the supervisory authority. The ICO can issue fines of up to £17.5 million or 4% of global annual turnover. Fines apply to organisations, not typically to individuals.

Key difference: FADP personal liability (criminal, individual) vs UK GDPR institutional fines (administrative, to the organisation).

Data Breach Notification

Swiss FADP: Notify the FDPIC "as soon as possible" — no fixed timeframe. Market practice treats this as within 72 hours for high-risk breaches.

UK GDPR: Notify the ICO within 72 hours of becoming aware of the breach — a hard deadline inherited from EU GDPR.

Data Subject Rights

Both frameworks provide broadly equivalent rights. Specific differences:

RightSwiss FADPUK GDPR
AccessYes — 30 daysYes — one calendar month
CorrectionYesYes
ErasureYesYes
PortabilityYes (with conditions)Yes (for automated processing based on consent or contract)
ObjectionYesYes
Automated decisionsYes (Article 21 FADP)Yes (Article 22 UK GDPR)

Notable: UK GDPR retains EU GDPR's Article 22 automated decision-making rights. Swiss FADP has a similar provision in Article 21 nFADP but with some differences in the right to human review pathway.

Cross-Border Transfers

Swiss FADP: Uses Switzerland's own adequacy list (maintained by FDPIC). Transfer mechanisms: Swiss SCCs, Swiss DPF certification for US transfers. EU SCCs are not automatically valid for transfers from Switzerland.

UK GDPR: Uses the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs for transfers outside the UK. The EU-UK adequacy decision allows free data flow between EU and UK (current but under periodic review).

Switzerland ↔ UK: Switzerland's adequacy list includes the UK — transfers from Switzerland to the UK do not require Swiss SCCs. The UK has recognised Switzerland as adequate for UK purposes — transfers from the UK to Switzerland do not require an IDTA.

DPO Requirement

Swiss FADP: No mandatory DPO requirement. Organisations may appoint a data protection advisor voluntarily.

UK GDPR: Mandatory DPO for public authorities, organisations that carry out large-scale systematic monitoring, and organisations that process special category data at scale — same as EU GDPR.

Privacy Notice

Swiss FADP: Must cover the Article 19 requirements — controller identity, purpose, legal basis, recipients, transfers, data subject rights.

UK GDPR: Must cover the same elements as EU GDPR — generally more detailed requirements than FADP, particularly around automated decision-making disclosure.


Practical Compliance for Switzerland + UK Operations

For a company operating in both markets:

Single privacy notice with Switzerland and UK sections: Build a layered privacy notice. The core structure covers overlapping elements. Add specific sections for:

  • UK GDPR rights and ICO complaint information
  • FADP rights and FDPIC complaint information
  • UK-specific transfer mechanisms (IDTA where applicable)
  • Swiss-specific transfer mechanisms (Swiss SCCs or Swiss DPF)

Breach notification procedure: UK GDPR's 72-hour hard deadline drives the procedure. Applying the same timeline to FADP breaches ensures compliance with both.

DPA/processing agreements: Maintain a primary GDPR-aligned DPA. Add a UK addendum (addressing UK GDPR specifically) and a Swiss addendum (addressing FADP specifically) as annexes for customers in those markets.

Transfer mechanisms:

  • UK → Switzerland: UK adequacy for Switzerland applies — no IDTA needed
  • Switzerland → UK: Swiss adequacy for UK applies — no Swiss SCCs needed
  • UK or Switzerland → US: Both markets require separate DPF certifications or separate SCCs

The Stability Question

Both UK GDPR and Swiss FADP face potential evolution:

UK GDPR: The UK government has been exploring legislative reform (the Data Protection and Digital Information Act) to diverge from EU GDPR in some areas. As of 2026, significant divergence has not yet materialised, but the trajectory bears watching.

Swiss FADP: The revised FADP is new and relatively stable. The FDPIC's guidance continues to develop.

EU adequacy for UK: The EU adequacy decision for the UK is subject to review. If it lapses or is modified, UK→EU and EU→UK transfers will require SCCs. Companies with both EU and UK operations should maintain SCCs as a fallback.

ComplyOne assesses your FADP compliance alongside GDPR and identifies the gaps specific to Swiss law.

Check your Swiss FADP obligations →