Federal Act on Data Protection
Federal Data Protection and Information Commissioner
Federal Data Protection and Information Commissioner
Switzerland's modern data protection regime is anchored by the Federal Act on Data Protection, known as the FADP. The revised Act came into force on 1 September 2023 and protects the personality and fundamental rights of natural persons whose personal data is processed. It is close enough to European-style data protection to feel familiar, but its logic is distinctly Swiss: the law is framed around personality rights, proportionality, good faith, transparency and risk-based accountability.
The FADP applies to the processing of personal data by private persons and federal bodies. It protects natural persons, not legal entities. It also has territorial reach where circumstances have an effect in Switzerland, even if initiated abroad. That makes it relevant to foreign businesses that target or monitor people in Switzerland, even without a Swiss establishment.
Processing must respect core principles. Personal data must be processed lawfully, in good faith and proportionately. It may only be collected for a specific purpose that the data subject can recognise, and later processing must be compatible with that purpose. Data must be destroyed or anonymised once no longer required and must be kept accurate.
Risk determines the compliance burden. The FADP distinguishes ordinary processing from higher-risk processing such as sensitive personal data, high-risk profiling, large-scale sensitive processing, systematic large-scale monitoring of public areas, or processing that may pose a high risk to personality or fundamental rights. Higher-risk processing can trigger explicit consent, data protection impact assessments, consultation with the FDPIC, records of processing and breach notification.
The FDPIC is the federal supervisory authority. The Federal Data Protection and Information Commissioner supervises the application of federal data protection regulations. The FDPIC may investigate private persons and federal bodies, require cooperation, order processing to be modified, suspended or terminated, delay or prohibit overseas disclosure, and require deletion or destruction of personal data.
The FADP does not copy the GDPR's lawful-basis architecture. For private controllers, the law starts with principles and personality rights. A breach of personality rights may arise where personal data is processed contrary to the principles, contrary to the express wishes of the data subject, or where sensitive personal data is disclosed to third parties. Such a breach is unlawful unless justified by the data subject's consent, an overriding private or public interest, or law.
Consent is therefore important, but it is not the only mechanism that makes processing lawful. Where consent is required, it must be voluntary, specific and informed. It must be explicit for processing sensitive personal data, high-risk profiling by a private person, or profiling by a federal body.
Transparency is central. Controllers must inform data subjects when collecting personal data, including the controller's identity and contact details, the purpose of processing, and the recipients or categories of recipients where applicable. If data is not collected from the data subject, the controller must also provide the categories of processed data, subject to statutory exceptions.
Start with a map of processing activities that affect people in Switzerland. Identify the controller, processors, purposes, categories of data subjects, categories of personal data, recipients, retention periods, security measures and foreign disclosures. This map is not just a compliance artefact; it feeds the record of processing activities, transparency notices, transfer assessments and breach response.
Then review high-risk areas. Sensitive personal data, high-risk profiling, automated individual decisions, large-scale monitoring, large-scale sensitive processing and cross-border disclosures all require closer attention. Check whether explicit consent, a data protection impact assessment, FDPIC consultation, processor controls, representative appointment or transfer safeguards are required.
Finally, test data subject rights and incident response. Individuals have rights to information, correction and data portability. They may also seek civil remedies where private processing unlawfully breaches personality rights. Breaches of data security likely to create a high risk must be notified to the FDPIC as quickly as possible, and data subjects must be informed where required for their protection or where the FDPIC requests it.
Federal Act on Data Protection, 25 September 2020 - Switzerland's core federal data protection law, protecting the personality and fundamental rights of natural persons and regulating processing by private persons and federal bodies.
Switzerland compliance begins with proportionality and recognisable purpose. You need to know what data you process, why, whether it affects people in Switzerland, whether the processing is high-risk, whether foreign disclosures are protected, whether individuals can exercise their rights, and whether security and breach-notification processes work. The law analysis explains the operational requirements under the FADP.