Swiss FADP compliance, automated
heyData helps you meet the requirements of Switzerland's revised Federal Act on Data Protection (nFADP) on an ongoing basis – with guided software, certified privacy experts, and documentation that's ready when you need it.

.avif)
Compliance runs on trust.
The Swiss FADP has been in force for years. Is your setup still holding up?
Most companies got the basics in place when the law took effect. The harder question now is: what's drifted out of date, who still owns it, and how do you keep it current as your business changes?
Personal fines are possible
The Swiss FADP allows fines of up to CHF 250,000 against individuals. Without clean documentation, it's hard to prove that decisions were made carefully and in good faith.
The record of processing activities is often outdated
Art. 12 of the Swiss FADP requires a record of processing activities. An old spreadsheet rarely holds up when your processes, tools, and data flows keep changing.
Data breaches require clear procedures
When a data security breach happens, you need to assess it quickly, document it, and – where required – notify the FDPIC. Without a process in place, an incident turns into a scramble fast.
heyData combines software, experts, and continuous updates
One platform
Build your record of processing activities, TOM documentation, DPIA review, and data subject rights workflows in a structured way.
- Guided record of processing activities
- Clean TOM documentation
- A DPIA workflow for high-risk processing
- A privacy notice, ready to use right away
Expert support
Get support from privacy experts who specialize in Swiss law – for day-to-day questions, edge cases, and practical implementation.
- A dedicated expert assigned to your account
- Support on complex cases and escalations
- Help with incident response and regulator communication
- Real answers, not just tool documentation
Your setup stays up to date
New requirements, new tools, or additional frameworks slot into your existing processes — without rebuilding from scratch.
- Continuous updates built into the platform
- Exportable evidence, ready when you need it
- Expandable to GDPR, ISO 27001, and the EU AI Act
- Less duplicated work across multiple frameworks








What heyData covers for your revDSG compliance
Record of processing activities
Guided workflows help you record processing activities in a structured way and keep them up to date.
TOM Documentation
Technical and organizational measures are recorded, evaluated, and documented in a transparent manner.
DPIA assessment
The platform helps you identify when a data protection impact assessment becomes relevant and how to document it.
Privacy Policy & Data Subject Rights
Create appropriate privacy notices and process requests for information, deletion, or correction in a structured manner.
Incident Response
Clear procedures help you assess and document data protection incidents internally and respond in a timely manner.

From unclear to Swiss FADP-ready in four steps
Inventory
Setup
Launch
Ongoing operations
Your Certified DPO with Industry Expertise.
What our customers say
2,500+ customers trust heyData with their information security.

Customer Story: How Ostrom Scales Data Protection Professionally with heyData
How Ostrom scales data protection with heyData from its first hundred to 100,000 customers — without a dedicated full-time role.
With heyData, we save time, reduce risks, and actively strengthen our customers' trust.
Thanks to the platform, we can handle onboarding centrally and efficiently.
What sets heyData apart is its responsiveness and fast execution.
The software helps us document all IT security measures relevant to data protection and review them regularly.
Why choose heyData over Excel, a law firm, or a standalone solution?
Most companies have tried every option. Here is what they report.

How far along is your Swiss FADP compliance, really?
FAQs
Can't find what you're looking for? Our team will get back to you within one business day.
Does the nFADP only apply to Swiss companies?
Does the nFADP only apply to Swiss companies?
No. The nFADP can also affect companies outside Switzerland if they process personal data of individuals in Switzerland. This is particularly relevant for SaaS providers with Swiss customers.
Is GDPR compliance enough for the nFADP?
Is GDPR compliance enough for the nFADP?
Not automatically. The nFADP is similar to the GDPR but has its own requirements and differences, for example regarding the record of processing activities, notification obligations, and possible personal fines.
What happens in the event of a data security breach?
What happens in the event of a data security breach?
You must assess and document the incident and inform the FDPIC if there's a high risk for the individuals affected. A clear incident response process helps you react quickly and cleanly.
Can CEOs be personally affected?
Can CEOs be personally affected?
Yes. An important difference from the GDPR is that the nFADP can impose fines on natural persons. That's why responsibilities, processes, and evidence should be clearly documented.
How long does implementation take?
How long does implementation take?
That depends on your processes, tools, and company size. An initial structure can often be set up quickly; full operation, including DPIA reviews, consent, and ongoing maintenance, takes more time depending on complexity.
What's the difference between revDSG and nFADP?
What's the difference between revDSG and nFADP?
Both terms refer to the same law. revDSG stands for the revised Swiss Data Protection Act (revidiertes Datenschutzgesetz), while nFADP stands for new Federal Act on Data Protection. The law has been in force since September 1, 2023.

Ready to make revDSG compliance easier?
revDSG is just the beginning. Your compliance will continue to grow.


GDPR
For companies with EU customers or users, GDPR compliance is often the next logical step. Many data protection processes can be maintained on a common foundation.


ISO 27001
Information security is built on clear processes, responsibilities, and evidence. Your TOM documentation is a valuable starting point for this.


EU AI Act
If you are using or developing AI, governance, risk management, and documentation become increasingly important. A solid data protection setup helps you get started.








