Data Protection Atlas

revFADP (Switzerland)

Tier 2 In force

Switzerland’s complete rewrite of its 1992 law — aligned with the GDPR and Convention 108+ while staying distinctly Swiss: duties are enforced through criminal fines on responsible individuals rather than administrative fines on companies.

Identity

Citation
Revised Federal Act on Data Protection (revFADP / nFADG), Switzerland
Jurisdiction
Switzerland
Type
comprehensive

Adopted 2020; in force 1 Sep 2023 with no transition period

Amended by: Data Protection Ordinance (DPO) 2023; Federal Council adequacy list

← Switzerland overview

Structure

What each Part or Chapter does, and the provisions worth knowing inside it. An orientation to the shape of the instrument — not a substitute for reading the official text.

Chapters 1–2 — Scope, definitions, principles

Natural persons only (legal-person data dropped in the revision); an effects-based territorial reach.

  • Art 5 Definitions — including ‘high-risk profiling’, a Swiss addition with stricter consent consequences.
  • Art 6 Principles: lawfulness, good faith, proportionality, purpose limitation.
Chapter 3 — Duties of controllers and processors

The GDPR-familiar toolkit, Swiss-flavoured.

  • Art 19 A duty to inform on every collection of personal data — broader than many firms expected.
  • Art 22 Impact assessments for high-risk processing.
  • Art 24 Breach notification to the FDPIC ‘as soon as possible’ where high risk to the data subject.
Chapter 4 — Rights of data subjects

Access is the workhorse of Swiss privacy practice and litigation.

  • Art 25 The access right — abuse of it can be refused, but the bar is high.
  • Art 28 Data portability, new in the revision.
Chapter 5 — Cross-border disclosure (Arts 16–18)

Adequacy is decided by the Federal Council, not the regulator.

  • Art 16 Transfers to countries on the Federal Council’s adequacy list (Annex 1 of the Ordinance) — the EU / EEA included.
  • Art 17 Otherwise: safeguards such as the EU SCCs with Swiss amendments, or BCRs.
Chapter 8 — Criminal provisions (Arts 60–63)

The distinctive Swiss enforcement model.

  • Arts 60–61 Fines to CHF 250,000 — imposed on the responsible private individuals for wilful breaches of information, disclosure, care and security duties.

Regulatory enforcement

Interactions and conflicts

Runs in parallel with the GDPR for any Swiss organisation serving the EU market — dual compliance is the norm, and the EU reaffirmed Switzerland’s adequacy in its 2024 review. The individual criminal-liability model conflicts with GDPR-style corporate-risk programmes: Swiss counsel plan around named officers, not turnover percentages.

Sources

Never independently verified — seeded from the prototype.