Home › Law library › Swiss nFADP (revDSG)
CH
Swiss nFADP (revDSG)
Federal Act on Data Protection of 25 September 2020 (revised FADP / nFADP)
Sourced. Last verified 9 October 2026
Switzerland Privacy
- Status
- In force since 1 September 2023 (no transition period).
- Who it applies to
- Processing of personal data of natural persons (not companies) by private persons and federal bodies, including processing abroad that has an effect in Switzerland.
- Size thresholds
- None — applies regardless of size. Firms under 250 employees are exempt from records of processing unless they process sensitive data at large scale or do high-risk profiling.
- Regulator
- Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
- Breach or incident reporting
- Notify the FDPIC as soon as possible if a breach is likely to cause a high risk; inform individuals where needed for their protection or if the FDPIC requires it. Processors must tell controllers as soon as possible.
- Deadline to answer personal data requests
- Generally within 30 days (Art 25(7) FADP); normally free of charge.
- Data protection officer
- Optional. A 'data protection advisor' may be appointed voluntarily (brings some DPIA relief).
- Local representative
- Foreign private controllers must appoint a Swiss representative if they target/monitor people in Switzerland AND the processing is large-scale, regular and high-risk (all conditions).
- Sending data abroad
- Allowed to countries on the Federal Council's adequacy list (incl. EEA, UK) and to Swiss-US DPF certified US firms; otherwise use standard data protection clauses (e.g. adapted EU SCCs), BCRs or a legal exception.
- Cookies and consent
- Telecommunications Act requires informing users about cookies and how to refuse them (opt-out model); consent may be needed for some uses depending on circumstances.
- Maximum penalty
- Criminal fines up to CHF 250,000, imposed mainly on the responsible individual (e.g. manager), for intentional breaches of key duties.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Publish a privacy notice incl. identity, purposes, recipients and destination countries.
- Keep a record of processing (unless the under-250-staff exemption applies).
- Run a DPIA for processing likely to pose a high risk.
- Report high-risk breaches to the FDPIC as soon as possible.
- Answer access requests within 30 days, free of charge.
- Apply privacy by design and by default; sign processor agreements.
Sources
- Primary source: https://edoeb.admin.ch/en/representatives-in-accordance-with-article-14-fadp
- Second source: https://dlapiperdataprotection.com/?c=CH&t=law
- Regulator: Federal Data Protection and Information Commissioner (FDPIC / EDÖB)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].