Introduction
Many German managing directors have a false sense of security: the GDPR is implemented, a data protection officer is appointed, and processes are documented. But those serving Swiss customers often overlook a massive, existence-threatening risk.
The Swiss Data Protection Act (nFADP) has now been in force for more than two years. The initial grace periods and ambiguities are finally over in 2026. Swiss authorities are actively enforcing the law. And it carries an entirely new dimension of liability: while the GDPR primarily fines the company as a legal entity, the nFADP relies on the personal, criminal responsibility of decision-makers.
Navigating the New Swiss Federal Act on Data Protection (nFADP): A Detailed Guide
In plain terms: as a managing director, you're personally liable with your private assets in a worst-case scenario — up to CHF 250,000. And yes, that applies even if your company is based exclusively in Germany.
When Does Swiss Data Protection Law Apply to Your Company?
Just like the GDPR, the nFADP applies the so-called market location principle. What matters isn't where your company is based, but where the data subjects reside. As soon as you process data belonging to people located in Switzerland, you're subject to the law.
Typical scenarios in the German SME and SaaS sector include:
- E-commerce: You run an online shop and ship goods to customers in Switzerland (often recognizable by prices listed in CHF or a .ch domain).
- B2B SaaS and cloud services: Your software solution is used by Swiss companies or their end users.
- Digital marketing: You track the behavior of website visitors from Switzerland for analytics or advertising purposes.
- HR and recruiting: You employ cross-border commuters or process applications from people residing in Switzerland.
Important: nFADP protection applies to all individuals residing in Switzerland — regardless of their nationality.
Personal Liability: The Fundamental Difference From the GDPR
In Germany and the EU, we're used to data protection violations hitting the company. Multi-million euro fines are painful for the balance sheet, but they rarely threaten the managing director's personal bank account directly.
In Switzerland, it's different. The nFADP is deliberately designed to hold decision-makers accountable.
- The fine of up to CHF 250,000 hits you personally, as a natural person.
- As a rule, the company isn't allowed to cover this fine on your behalf (recourse and indemnification bans).
- Since this is a criminal sanction, a worst-case scenario could result in an entry in the Swiss criminal record.
Just as in German criminal law, no "corporate shield" protects you here either. Whoever makes the decisions is the focus of Swiss investigators.
The "Intent Trap": Why Inaction Counts as Intent
A common misunderstanding stems from the wording of the law: under Art. 61 nFADP, only those who act intentionally can be held criminally liable. Many managing directors therefore feel safe and think: "I don't intend to harm anyone, so I'm not acting intentionally."
That's a dangerous misconception. Criminal law recognizes the concept of conditional intent (dolus eventualis). This applies when you consider a breach of duty possible and knowingly accept it anyway.
If, in 2026, you know full well that your company serves Swiss customers or processes data from Switzerland, but fail to implement compliance measures out of convenience or cost concerns, you're knowingly accepting the legal violation. Swiss authorities treat this systematic disregard for the law as conditional intent. After more than two years of nFADP enforcement, the argument "we didn't know" no longer holds up.
GDPR vs. nFADP: The 3 Critical Differences and Your To-Dos
| Topic | nFADP | GDPR |
|---|---|---|
| Scope | Switzerland, partly with cross-border relevance | EU/EEA, partly with cross-border relevance |
| Terminology | Personal data, processing, data processor | personal data, processing, data processor |
| Sanctions | Up to CHF 250,000, partly against natural persons | Up to €20 million or 4% of annual turnover |
| Data protection advisor | mostly voluntary | mandatory in certain cases |
| Data Protection Impact Assessment | for anticipated high risk | for high risk |
| Notification obligation | to the FDPIC for high risk | to the supervisory authority for risk |
If you're already GDPR-compliant, you've covered about 80% of the way. But the remaining 20% determines your personal liability. You urgently need to review and implement the following three differences:
1. Update Your Information Obligations (Privacy Policy)
The nFADP mandatorily requires disclosure of every country data is transferred to (third-country transfers). While the GDPR often allows for generic wording here, Switzerland demands transparency.
Your task: Add a specific section for Swiss users to your privacy policy and list all recipient countries in full.
Tip: With heyData, you can create and maintain your privacy policy — including country-specific adaptations for Switzerland. Check now whether your policy is nFADP-compliant.
2. Update Your Contracts (DPA)
A standard GDPR Data Processing Agreement (DPA) is often not sufficient for Swiss customers or service providers. The nFADP not only uses its own terminology ("data processor" instead of the GDPR's equivalent term), but Switzerland also maintains its own list of safe third countries, independent of the EU.
Your task: Add a "Switzerland clause" to your DPAs for Swiss business relationships that explicitly accounts for the nFADP and Swiss data export rules.
3. Tighten Processes for Data Subject Rights and Data Breaches
If a Swiss customer requests access to their data (Art. 25 nFADP) and you refuse or provide an incomplete response, you face direct personal criminal liability. The same applies if you fail to meet the obligation to report data breaches to the Federal Data Protection and Information Commissioner (FDPIC).
Your task: Make sure your support and data protection teams immediately recognize and prioritize requests from Switzerland. Missing deadlines is not a minor offense.
Appointing a Representative in Switzerland: When Is It Required?
An often overlooked requirement is the obligation to appoint a representative in Switzerland (Art. 14 nFADP). This applies to you if your company has no registered office in Switzerland, but:
- Extensively processes data belonging to people in Switzerland,
- the processing poses a high risk to the personal rights of data subjects (e.g., through profiling or processing sensitive health and financial data), and
- the processing takes place regularly.
As a rule of thumb: Pure online shops in standard B2C business rarely need a representative. But as soon as you host sensitive company and user data from Switzerland as a SaaS provider, or conduct intensive tracking, appointing a Swiss representative becomes mandatory. Specialized providers now offer this function cost-effectively as an interface with the FDPIC.
Want to know where your company currently stands on nFADP compliance? heyData's digital audit helps you find out quickly and easily. Book your free initial consultation.
Conclusion
The revised Swiss Data Protection Act is no longer a toothless tiger. By 2026, the nFADP has become a real, personal liability risk for German managing directors. Anyone serving the Swiss market can no longer afford to put this off.
The good news: the risk can be minimized with manageable effort. Since most German companies already have a GDPR foundation in place, targeted updates to your privacy policy, DPAs, and internal processes for access requests are enough to get out of the danger zone. Acting now protects not just the company from reputational damage, but above all, protects you personally from steep private fines.
FAQ
Does the nFADP only apply to Swiss companies?
Does the nFADP only apply to Swiss companies?
No. Companies outside Switzerland can also be affected if they process personal data relating to Switzerland or specifically offer services to people in Switzerland.
Is GDPR compliance enough for the nFADP?
Is GDPR compliance enough for the nFADP?
Not automatically. GDPR compliance is a good foundation, but Swiss specifics should be reviewed and documented separately.
When is a Data Protection Impact Assessment necessary?
When is a Data Protection Impact Assessment necessary?
When data processing is likely to pose a high risk to the individuals affected, for example with sensitive data, extensive profiling, or new technologies.
What needs to happen in the event of a data security breach?
What needs to happen in the event of a data security breach?
The incident should be assessed internally right away. If a high risk to affected individuals is likely, the FDPIC must be informed as quickly as possible.







