Introduction: A New Era of Data Protection Arrives in Switzerland
Switzerland has ushered in a new era of data protection with the introduction of the new Federal Act on Data Protection (nFADP). The new legislation replaces the previous law from 1992, reflects the ongoing digital age, and brings Swiss regulations closer to the European Union's General Data Protection Regulation (GDPR). The new law introduces several new requirements that companies must meet to remain compliant.
This article aims to guide companies — especially those encountering the intricacies of data protection for the first time — through the new landscape shaped by the nFADP. It outlines the key changes, critical provisions, compatibility with the EU GDPR, and the steps needed to achieve compliance.
Key Changes Under the nFADP
The nFADP builds on the existing data protection framework and introduces several new elements. These include:
- Stronger transparency requirements: The nFADP places great emphasis on transparency, requiring companies to justify their reasons for collecting customer data and disclose who will have access to it. This information must be explicit, clear, and easily accessible (nFADP Article 15). Data subjects now have the right to understand the duration and use of data storage and to have inaccurate data corrected without justification.
- Right to information: The law states that any individual can request information from the data controller about whether their personal data is being processed (Art. 25 nFADP).
- Expanded compliance obligations for companies: The nFADP has extended its reach beyond Swiss borders, similar to GDPR (Article 3). All Swiss and international companies that offer goods or services to Swiss residents or monitor their behavior must comply with the nFADP. Companies without a physical presence in Switzerland must appoint a Swiss representative responsible for all data processing matters (nFADP Article 3).
- Strengthened regulatory powers and sanctions: The Federal Data Protection and Information Commissioner (FDPIC) has had its powers strengthened under the nFADP. It can impose strict sanctions on individuals who fail to comply with the regulations, with fines of up to CHF 250,000 for individuals, and in some cases, a company may face a fine of up to CHF 50,000 if a violation occurs in the course of business, particularly when identifying the individual at fault within the organization would require disproportionate effort (Article 60 nFADP).
- Reporting data security breaches: Companies must promptly report data security breaches to the FDPIC and affected parties (nFADP Article 24) to limit damage, maintain trust, and avoid further legal complications.
- Privacy by design and privacy by default: Following GDPR's example (Article 25), Article 7 of the nFADP requires companies to incorporate data protection principles from the design phase of products or services onward and to apply the strictest privacy settings by default. This forward-looking approach helps ensure data protection is considered at every operational level.
- Data protection impact assessment: Private and public bodies that process data must conduct a data protection impact assessment (DPIA) when data processing is likely to pose a high risk to the personality or fundamental rights of data subjects (Art. 22 nFADP).
- The role of the FDPIC: The nFADP grants the FDPIC additional tasks and powers, bringing changes for data processors and data subjects alike. Going forward, the FDPIC will charge private data processors for a number of its services (Art. 59 nFADP).
- Data protection advisor: The appointment of a data protection advisor to the FDPIC is provided for under Article 10(3) nFADP for private individuals and Article 10(4) nFADP for federal bodies. Private companies can appoint a data protection advisor who doesn't necessarily need to be an employee and whose main task is to provide independent data protection advice, establish rules and regulations, and conduct training. After a data protection impact assessment, companies can rely solely on the advisor's guidance without needing to further consult the FDPIC.
Understanding the Differences Between the nFADP and GDPR
Despite shared goals, the nFADP and GDPR have differences that companies operating in both jurisdictions need to understand. Here's a comparative analysis:
nFADPGDPRAppointing a Data Protection AdvisorRecommended but not mandatory (nFADP Articles 10 and 12)Mandatory for certain companies (GDPR Article 37)Data Security Breaches (Data Breach)Immediate reporting required (nFADP Article 24)Reporting required within 72 hours (GDPR Article 33)SanctionsUp to CHF 250,000 for individuals (nFADP Articles 60-64)Up to €20 million or 4% of global annual revenue for companies (GDPR Article 83)Disclosure of InformationLess strict requirements for privacy notices (nFADP Article 19)Detailed requirements for privacy notices (GDPR Articles 13 and 14)Data TransfersDecision rests with the Federal Council (nFADP Article 16)Decision rests with the European Commission (GDPR Chapter V)TransparencyStronger transparency requirements (nFADP Article 19)Comprehensive transparency obligations (Art. 13 GDPR)
Preparing for nFADP Compliance: A Practical Guide
Transitioning from the DSG to the nFADP
For companies that were previously compliant with the old DSG, transitioning to the nFADP may seem daunting, but it's essential. A gap analysis to identify data protection shortcomings and risks, along with developing a strategic plan to address these gaps, is critical. Implementing robust data processing procedures, strict security measures, and effective training programs ensures a smooth transition.
The Continued Relevance of GDPR
Despite the introduction of the nFADP, Swiss companies must not overlook GDPR, especially if they process data from EU citizens. GDPR compliance not only ensures smooth data exchange with EU partners but also supports the company's global competitiveness.
Conclusion
The nFADP represents a significant milestone in Switzerland's data protection landscape. Understanding the implications of this new law is crucial for Swiss companies and those operating in Switzerland to ensure compliance, avoid substantial penalties, and maintain customer trust.
By understanding the key provisions of the nFADP, appreciating the differences from GDPR, and planning a smooth transition, companies can ensure secure and responsible handling of personal data. While the task may seem daunting, the benefits of a robust data protection practice are substantial.
Here are some key takeaways from this article:
- The nFADP is a major overhaul of Swiss data protection law, bringing it more closely in line with GDPR.
- The nFADP introduces a range of new requirements for companies, including stricter transparency requirements, expanded reporting obligations for data security breaches, and increased sanctions for individuals and, in some cases, companies.
- Companies operating in Switzerland or processing personal data of Swiss residents must take steps to ensure nFADP compliance.
- A number of resources are available to help companies understand and comply with the nFADP, including the FDPIC's website and guidance documents.
We hope this article has helped provide an overview of the nFADP. If you have further questions, we're happy to help.
Webinar Recap: Switzerland's New Data Protection Act (nFADP) — Now Available!
If you missed our webinar on Switzerland's new data protection law, we've got you covered here. If you have any questions, don't hesitate to contact us.
Your browser does not support HTML video.







