Swiss FADP compliance, automated

heyData helps you meet the requirements of Switzerland's revised Federal Act on Data Protection (nFADP) on an ongoing basis – with guided software, certified privacy experts, and documentation that's ready when you need it.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
SCHEDULE A DEMO
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
WHAT'S INCLUDED?
revDSG-Arbeitsbereich mit 82% Fertigstellung der TOM-Dokumentation und Übersicht zu Schulungen und AVV-Status.
Awarded for excellent customer reviews.
Capterra Logo mit 4,9 von 5 Sternen Bewertung.
DATA PROTECTION THAT SCALES

Compliance runs on trust.

2,500+
Companies Trust heyData Across DACH and the EU
DACH focus
For Data Protection, Information Security, and Compliance
Avg. 24h
Expert Response Time
Ongoing updates
Instead of One-off Document Storage
SOUND FAMILIAR?

The Swiss FADP has been in force for years. Is your setup still holding up?

Most companies got the basics in place when the law took effect. The harder question now is: what's drifted out of date, who still owns it, and how do you keep it current as your business changes?

Personal fines are possible

The Swiss FADP allows fines of up to CHF 250,000 against individuals. Without clean documentation, it's hard to prove that decisions were made carefully and in good faith.

The record of processing activities is often outdated

Art. 12 of the Swiss FADP requires a record of processing activities. An old spreadsheet rarely holds up when your processes, tools, and data flows keep changing.

Data breaches require clear procedures

When a data security breach happens, you need to assess it quickly, document it, and – where required – notify the FDPIC. Without a process in place, an incident turns into a scramble fast.

What heyData covers for your revDSG compliance

From initial documentation to ongoing operations: all key data protection obligations are bundled into one system.
Already in use at
RECORDING

Record of processing activities

Guided workflows help you record processing activities in a structured way and keep them up to date.

Art. 12 revFADP
Mandatory documentation
TOMS

TOM Documentation

Technical and organizational measures are recorded, evaluated, and documented in a transparent manner.

Art. 8 FADP
TOMs
Risk analysis

DPIA assessment

The platform helps you identify when a data protection impact assessment becomes relevant and how to document it.

Art. 22 revFADP
DPIA
Information Request

Privacy Policy & Data Subject Rights

Create appropriate privacy notices and process requests for information, deletion, or correction in a structured manner.

Art. 25-27 revFADP
Deletion
Incident Management

Incident Response

Clear procedures help you assess and document data protection incidents internally and respond in a timely manner.

Data breach
FDPIC
Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

From unclear to Swiss FADP-ready in four steps

No months-long legal projects. No manual document chaos. A guided process that evolves with your company.
01

Inventory

You answer guided questions about your data, tools, processes, and responsibilities. This reveals what is already in place and where there are gaps.
02

Setup

Records of processing activities, TOMs, privacy notices, DPIA assessments, and core processes are established step by step.
03

Launch

Your setup goes live: with clean documentation, clear responsibilities, and support from data protection experts.
04

Ongoing operations

New tools, processes, or regulatory changes are continuously integrated. This ensures compliance remains a core part of your infrastructure.
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Get started
No commitment.
OUR EXPERTS

Your Certified DPO with Industry Expertise.

Foteini Baladima

Team Lead Domain Experts Privacy
  • TÜV-certified DPO
  • Legal Expert
  • GDPR
  • nFADP

Regina Frey

Head of Domain Experts
  • ISO 27001
  • Legal Expert
  • NIS2
  • GDPR
  • nFADP
  • UK GDPR

Sofie Hof

Senior Domain Expert Privacy
  • DPO
  • Legal Expert
  • GDPR
  • UK GDPR
  • nFADP

Dominik Appelt

Domain Expert Privacy and Security
  • DPO
  • Legal Expert
  • GDPR
  • AI Act

Nelly Kameni

Domain Expert Privacy
  • DPO
  • Legal Expert
  • GDPR
  • nFADP

Umut Karatas

Junior Domain Expert Privacy
  • DPO
  • Lawyer
  • GDPR
  • UK GDPR

Roy-Darius Kouevi

Junior Domain Expert Privacy
  • DPO
  • Legal Expert
  • GDPR
  • UK GDPR
WHY HEYDATA

What our customers say

2,500+ customers trust heyData with their information security.

SAAS
23.09.2025

Customer Story: How Ostrom Scales Data Protection Professionally with heyData

How Ostrom scales data protection with heyData from its first hundred to 100,000 customers — without a dedicated full-time role.

Learn more

With heyData, we save time, reduce risks, and actively strengthen our customers' trust.

Lara Schimweg
Founder & CEO, Xeno GmbH

Thanks to the platform, we can handle onboarding centrally and efficiently.

Julia Streichan
Co-Founder, Sprintwerk GmbH

What sets heyData apart is its responsiveness and fast execution.

Sandra Scherzer
Legal Team, Bioland

The software helps us document all IT security measures relevant to data protection and review them regularly.

Dennis Kuhlmann
CEO, KUMA IT-Solutions GmbH
DISCOVER THE BENEFITS

Why choose heyData over Excel, a law firm, or a standalone solution?

Most companies have tried every option. Here is what they report.

Do-it-yourself
Law firm
Generic platform
Record of processing activities
Guided, up-to-date, and centrally managed
Often Excel-based and quickly outdated
Usually created once
Not always focused on Switzerland
DPIA assessment
Integrated workflow
Manual or unclear
Additional effort
Often GDPR-heavy
Incident management
Structured processes and documentation
Stress in an emergency
Not always available on an ongoing basis
Often without a clear process
Updates
Ongoing within the platform
Must be tracked internally
Usually fee-based
Varying speeds
Expert
Combines software and consulting
No support
Expensive and case-based
Often just help center or chat
Scaling
Expandable for GDPR, ISO 27001, AI Act
Duplicated work
Separate mandates
Limited integration options
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Contact us
Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

How far along is your Swiss FADP compliance, really?

Find out quickly where your data protection setup stands, which gaps are critical, and what the next logical steps are.
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Ask an expert
No commitment. Just clarity.
FAQ

FAQs

Can't find what you're looking for? Our team will get back to you within one business day.

Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Ask our team

Does the nFADP only apply to Swiss companies?

No. The nFADP can also affect companies outside Switzerland if they process personal data of individuals in Switzerland. This is particularly relevant for SaaS providers with Swiss customers.

Is GDPR compliance enough for the nFADP?

Not automatically. The nFADP is similar to the GDPR but has its own requirements and differences, for example regarding the record of processing activities, notification obligations, and possible personal fines.

What happens in the event of a data security breach?

You must assess and document the incident and inform the FDPIC if there's a high risk for the individuals affected. A clear incident response process helps you react quickly and cleanly.

Can CEOs be personally affected?

Yes. An important difference from the GDPR is that the nFADP can impose fines on natural persons. That's why responsibilities, processes, and evidence should be clearly documented.

How long does implementation take?

That depends on your processes, tools, and company size. An initial structure can often be set up quickly; full operation, including DPIA reviews, consent, and ongoing maintenance, takes more time depending on complexity.

What's the difference between revDSG and nFADP?

Both terms refer to the same law. revDSG stands for the revised Swiss Data Protection Act (revidiertes Datenschutzgesetz), while nFADP stands for new Federal Act on Data Protection. The law has been in force since September 1, 2023.

Verlaufshintergrund mit Blau- und Grüntönen, der von oben links nach unten rechts verläuft.

Ready to make revDSG compliance easier?

No Excel graveyards. No legal chaos. Just a data protection setup that you can understand, maintain, and verify.
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Book a demo now
Porträt eines lächelnden Mannes mit kurzem dunklem Haar und Bart vor grauem Hintergrund.
Speak with an expert
 

revDSG is just the beginning. Your compliance will continue to grow.

If you set up your data protection properly, you can reuse many of the foundations for other frameworks.
DATA PRIVACY
Verlauf von blau zu grün mit weichem, gebogenen Design.
Kreisdiagramm mit grünem Fortschrittsbalken, der 78 Prozent anzeigt.

GDPR

For companies with EU customers or users, GDPR compliance is often the next logical step. Many data protection processes can be maintained on a common foundation.

Learn more
INFOSEC
Blauer und grüner Farbverlauf mit unregelmäßiger Wellenlinie in der Mitte.
Kreisdiagramm zeigt 38% in grün und 62% in grau.

ISO 27001

Information security is built on clear processes, responsibilities, and evidence. Your TOM documentation is a valuable starting point for this.

Learn more
AI & GOVERNANCE
Kreisdiagramm mit grünem Abschnitt, der 22 Prozent anzeigt.

EU AI Act

If you are using or developing AI, governance, risk management, and documentation become increasingly important. A solid data protection setup helps you get started.

Learn more