Swiss nFADP

The Swiss nFADP,
explained plainly

The nFADP is the revised Swiss Federal Act on Data Protection, in force since September 2023. Here is what it actually requires: the data-protection principles, the record of processing, DPIAs, breach notification to the FDPIC and how it lines up with the GDPR — and how a Swiss team runs the whole programme in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The law

What the Swiss nFADP actually requires.

The nFADP modernized Swiss data-protection law and pulled it closer to the EU GDPR, partly to preserve Switzerland’s adequacy with the EU. It is a law you comply with continuously, not a certificate you earn once, built on a small set of principles and a handful of concrete duties.

The data-protection principles

Lawfulness, good faith, proportionality, purpose limitation, accuracy and data security — the baseline every processing activity has to respect.

Privacy by design and default

Build data protection into systems from the start, and set the most protective options as the default rather than something a user has to find.

Records, DPIAs and breaches

A record of processing (with an SME exemption), a DPIA for high-risk processing, and breach notification to the FDPIC as soon as possible.

A programme, not a certificate

There is no nFADP certificate. Compliance is a system you run: documented processing, current safeguards and evidence you can show on request.

The full picture

Swiss nFADP, explained in full.

A plain-language walkthrough — what it is, what it asks for, and what it takes to keep it current.

01

What is the Swiss nFADP?

The nFADP is the revised Swiss Federal Act on Data Protection — often written as the revFADP, and in German the revised DSG (nDSG). It came into force on 1 September 2023, replacing a law that dated back to the early 1990s and bringing Swiss data protection up to date with how organizations actually handle personal data today.

It is a federal law, not a standard you certify against. There is no "nFADP certificate" to hang on the wall and no accredited body that audits you against it. You comply with it the way you comply with any law: by meeting its duties in how you actually process personal data, and by being able to show that you do if the regulator or an affected person asks.

A large part of the revision was deliberately aimed at staying close to the EU GDPR. Switzerland is not an EU member, but keeping Swiss law broadly equivalent helps preserve the EU’s recognition that Switzerland offers an adequate level of protection — which is what lets personal data flow freely between the EU and Switzerland without extra safeguards.

02

What changed from the old law

The most consequential change is also the easiest to miss: the nFADP protects only the personal data of natural persons. The previous law also covered the data of legal entities, companies and other organizations, and that protection is gone. If your old documentation treated supplier or corporate records as in scope on that basis, the picture has narrowed.

The revision also sharpened the duties around transparency and information. Information obligations toward the people whose data you process are broader than before, so individuals know what is collected, why, and where it may go. Two new categories, genetic data and biometric data that uniquely identifies a person, were added to the list of "sensitive" personal data, which carries stricter handling requirements.

Finally, the revision introduced privacy by design and privacy by default as explicit obligations, rather than good practice you might adopt voluntarily. Together these changes move Swiss law from a lighter, principles-only regime toward something a GDPR-trained team will recognize.

03

Who the nFADP applies to

The nFADP applies to private persons and federal bodies that process the personal data of natural persons. For most companies that means almost any handling of customer, employee, prospect or user data falls within scope — collecting it, storing it, using it, sharing it or deleting it.

Crucially, it can reach beyond Switzerland’s borders. The law applies to processing that has an effect in Switzerland, even when the organization doing it sits abroad. So a non-Swiss company serving Swiss residents can find itself subject to the nFADP much the way a non-EU company can find itself subject to the GDPR.

The practical consequence for Swiss-based teams is that the nFADP is rarely the only law in play. Many Swiss companies also serve customers in the EU, which brings the GDPR alongside it. That overlap, two closely related but distinct regimes, is the single biggest reason Swiss teams want to map their obligations once and reuse the work, rather than run two separate programmes.

04

The data-protection principles and privacy by design

At the centre of the nFADP is a small set of principles that every processing activity has to respect. Personal data must be processed lawfully and in good faith; collection and use must be proportionate and tied to a specified, recognizable purpose; data must be accurate and kept current; and it must be protected by appropriate security measures against loss and unauthorized access.

These principles are not a checklist you complete once. They are conditions that have to hold continuously across everything you do with personal data, which is why "are we still proportionate, still on-purpose, still secure?" is a question a programme keeps asking rather than answers and files away.

Privacy by design and by default

The revision turned two practices into explicit duties. Privacy by design means data-protection considerations are built into systems and processes from the start, not retrofitted after launch. Privacy by default means the most data-protective settings apply automatically — the protective option is the one a user gets without having to seek it out. Both shift the work upstream, into how products and processes are designed, rather than leaving it as a compliance clean-up later.

05

The record of processing and the SME exemption

The nFADP expects controllers and processors to keep a record of their processing activities — an inventory of what personal data they handle, for what purposes, who it is shared with, and how long it is retained. It is the document that lets you, and the regulator, see the shape of your data processing at a glance, and it is usually the first thing you reach for when any other obligation comes up.

There is a meaningful carve-out for smaller organizations. Companies with fewer than 250 employees are exempt from the record-keeping duty, provided their processing is low-risk — in practice, where it does not involve large-scale processing of sensitive data or high-risk profiling. The exemption is real, but it is conditional: a small company doing genuinely sensitive or high-risk processing does not get to skip the record.

In practice many SMEs keep a record anyway, because the conditions that lift the exemption are exactly the cases where you most want one, and because the record is the backbone the rest of the programme hangs off. Letting it drift out of date is how a small team ends up reconstructing its data flows from memory the moment a question arrives.

06

Data protection impact assessments (DPIAs)

Where a planned processing activity is likely to result in a high risk to the personality or fundamental rights of the people affected, the nFADP requires a data protection impact assessment (DPIA) before you start. Large-scale processing of sensitive data, or systematic large-scale monitoring, are the kinds of activity that typically trigger one.

A DPIA is a structured look-before-you-leap: you describe the planned processing, assess the risks it poses to the individuals involved, and set out the measures that bring those risks down to an acceptable level. If a high risk remains even after your measures, the law expects you to consult the Federal Data Protection and Information Commissioner before going ahead.

Because the trigger is the riskiness of a specific activity, DPIAs are not a one-off. New products, new data sources and new uses of existing data each raise the question again, which is why teams that treat the DPIA as a living, reusable assessment fare better than those that write one and forget it.

07

Breach notification to the FDPIC

When a data security breach is likely to lead to a high risk to the personality or fundamental rights of the people affected, the nFADP requires you to notify the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible. Where it is necessary for their protection, or where the FDPIC requires it, you must also inform the affected individuals.

The phrase that matters is "as soon as possible". Unlike the GDPR’s fixed 72-hour clock, the nFADP sets a less rigid timeline — but the practical demand is the same: when a breach happens, you need to assess it and report it quickly, which is only realistic if you already know what data you hold and where it lives. A breach is the worst moment to discover your record of processing is out of date.

08

The nFADP vs the GDPR (and why Swiss firms often need both)

The nFADP and the GDPR are close relatives, by design, and a team that understands one will recognize most of the other: the same principles, the same emphasis on transparency, similar records, DPIAs and breach duties. But they are not identical, and the differences are exactly where a careless "we already do GDPR" assumption goes wrong.

The notable divergences: the nFADP’s record-keeping exemption for companies under 250 employees has no clean GDPR equivalent; breach notification is "as soon as possible" rather than a fixed 72-hour deadline; the nFADP has no general mandate to appoint a data protection officer the way the GDPR does in defined cases; and, most strikingly, the enforcement model is different — the nFADP’s fines fall on responsible individuals, not primarily on the company. Scope differs too: the nFADP no longer covers the data of legal entities, where the GDPR never did.

For a Swiss company that also serves EU customers, both laws apply at once — and that is the common case, not the edge case. The efficient way to handle it is to treat the overlapping obligations as one body of work: map a control or a record once, then satisfy whichever law it answers to, instead of maintaining two parallel binders that drift apart.

09

Enforcement and the CHF 250,000 fines

The FDPIC supervises compliance with the nFADP. It can investigate, issue rulings and order processing to be changed, suspended or stopped — the supervisory backbone of the law. But the part that surprises people is how the financial penalties work.

For certain breaches, the nFADP allows criminal fines of up to CHF 250,000. The striking detail is who pays: the fine is imposed on the responsible private individual (the person who breached a specific duty), not, as a first resort, on the company. That is a deliberate departure from the GDPR’s corporate-percentage fines, and it changes the internal conversation: data-protection duties are something specific people can be held personally accountable for, which raises the stakes for getting roles, decisions and records clear.

For a compliance programme, the implication is practical. The defence against a penalty is the same as the work of running the programme well: knowing what you process, why it is lawful and proportionate, that it is documented and secured, and that you can show all of it. A programme kept current is the evidence that the duties were met — and the thing you least want to be assembling from memory after the fact.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your nFADP programme, in one Swiss-hosted workspace.

Everything the law asks you to maintain — records, safeguards, assessments, reviews, connected and ready to show, on infrastructure that stays in Switzerland. Pick one to see it.

Every nFADP duty, in one view

See the nFADP’s obligations — principles, records, DPIAs, breach duties, and where you stand on each, mapped to the policies, processing activities and safeguards that satisfy them, so your programme stays live instead of being reconstructed when a question lands.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Document once. Reuse across the laws and standards you add.

The nFADP overlaps heavily with the GDPR, and its security duties touch ISO 27001. Map a record or a safeguard once in devguard and the same work satisfies it wherever it appears — so the second regime is a fraction of the effort of the first, with one source kept current instead of several.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already running nFADP compliance? Move it across.

If you already maintain an nFADP programme, you do not want to rebuild it from a blank page. In a scoped conversation we agree exactly what moves — your record of processing, policies, DPIAs and breach history, and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
Swiss nFADP FAQ

Swiss nFADP, answered plainly.

When did the Swiss nFADP come into force?

The revised Federal Act on Data Protection (the nFADP, also called the revFADP or revised DSG) came into force on 1 September 2023, replacing the previous law from the early 1990s and modernizing Swiss data protection to line up more closely with the EU GDPR.

Is the nFADP the same as the GDPR?

No, but they are deliberately close. The nFADP shares the GDPR’s principles, records, DPIAs and breach duties, yet differs in important ways: it no longer covers the data of legal entities, gives an SME record-keeping exemption, sets breach notification as "as soon as possible" rather than 72 hours, and imposes fines on responsible individuals rather than on the company.

Do small companies need a record of processing?

Companies with fewer than 250 employees are exempt from the record-of-processing duty — but only if their processing is low-risk. If you process sensitive data at scale or carry out high-risk profiling, the exemption does not apply and the record is required. Many SMEs keep one regardless, because it is the backbone the rest of the programme depends on.

Who do you notify about a data breach under the nFADP?

You notify the Federal Data Protection and Information Commissioner (FDPIC) as soon as possible when a breach is likely to lead to a high risk to the affected people’s personality or fundamental rights. Where necessary for their protection, or where the FDPIC requires it, you must also inform the individuals concerned.

How large are the fines under the nFADP?

For certain breaches the nFADP allows criminal fines of up to CHF 250,000. The unusual part is who pays: the fine falls on the responsible private individual, not primarily on the company — a deliberate contrast with the GDPR’s corporate-percentage penalties.

Can I reuse my nFADP work for the GDPR?

Largely, yes. The two laws overlap so heavily that most records and safeguards you maintain for one carry over to the other. The efficient approach is to map the overlapping obligations once and keep a single source current, rather than running two parallel programmes that drift apart.

See how your nFADP program would look in devguard.

The fastest way to know if this fits is a short conversation about how you handle the nFADP today — what you maintain, where the effort goes, and what moving it would involve. Swiss-hosted throughout. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free