# Federal Act on Data Protection (Data Protection Act, FADP)

> The revised Federal Act on Data Protection (FADP, SR 235.1) has, since 1 September 2023, governed the processing of personal data of natural persons by private companies and federal bodies in Switzerland. It obliges controllers, among other things, to data protection by design and by default (Art. 7 FADP), to keep a record of processing activities (Art. 12 FADP, with an exemption for most SMEs), and to notify data security breaches to the Federal Data Protection and Information Commissioner (FDPIC, Art. 24 FADP).

- Type: Act, Statutory
- Scope: Switzerland
- As of: 24 September 2026
- Page: https://sacosi.ch/en/norms/revdsg
- Regulatory Check: https://sacosi.ch/en/regulation#normencheck

## When does FADP apply to you?

- Activity: Customers’ personal data (Applies): You process personal data of customers - this makes you subject to the basic obligations of the FADP as soon as the processing has an effect in Switzerland (Art. 2 f. FADP).
- Activity: Special category personal data (Applies): You process special categories of personal data (e.g. health, biometric or religious data) - stricter requirements apply to this under Art. 5(c) and Art. 6(7) FADP, including on consent.
- Markets: Switzerland (applies if additionally: Markets: Switzerland) (Applies): Your activity is (also) directed at the Swiss market - even simply as an employer, you process personal data of your employees (HR data), even without separate customer data processing. Under Art. 3 FADP, the act applies to every processing that has an effect in Switzerland, regardless of where your company is based.
- Employees: from 250 (only together with industry or activity) (Applies): With 250 or more employees on 1 January of the year, the SME exemption from the record of processing activities under Art. 12(5) FADP and Art. 24 DPO does not apply to you - you must keep such a record.

## Exceptions

- Purely private, exclusively personal processing of personal data does not fall under the act (Art. 2(2)(a) FADP).
- Companies and other private-law organisations, as well as natural persons, employing fewer than 250 employees on 1 January of a year are exempt from the duty to keep a record of processing activities - unless special categories of personal data are processed on a large scale or high-risk profiling is carried out (Art. 12(5) FADP in conjunction with Art. 24 DPO).
- The FADP protects only natural persons; the processing of data of legal entities does not fall under it (Art. 1 FADP).
- The Federal Assembly, the Federal Council, the federal courts, as well as the Office of the Attorney General and adjudicating federal authorities, are exempt from FDPIC supervision for certain proceedings (Art. 4(2) FADP).

## Obligations

- Comply with processing principles: lawfulness, good faith, proportionality, purpose limitation (Art. 6 FADP).
- Ensure data protection by design and by default, starting already at the planning stage (Art. 7 FADP).
- Ensure adequate data security through suitable technical and organisational measures (Art. 8 FADP).
- Keep a record of processing activities, unless an SME exemption applies (Art. 12 FADP, Art. 24 DPO).
- Inform data subjects appropriately when collecting personal data (Art. 19 FADP).
- For processing likely to result in a high risk to personality or fundamental rights, carry out a data protection impact assessment in advance (Art. 22 FADP).
- Notify the FDPIC as quickly as possible of data security breaches likely to result in a high risk to the data subject, with the mandatory details under Art. 15 DPO (Art. 24 FADP).
- Grant data subjects the right of access, generally within 30 days (Art. 25 FADP, Art. 18 DPO).

## Evidence

- Documented record of processing activities with the minimum details under Art. 12(2) FADP.
- Documentation of data protection impact assessments carried out, to be retained for at least two years after completion of the processing (Art. 14 DPO).
- Documentation of reported data security breaches with type, effects and measures, to be retained for at least two years from the report (Art. 15(4) DPO).
- Evidence of the technical and organisational measures taken for data security (Art. 8 FADP).

## Deadlines

- 1 September 2023: The revised FADP and the Data Protection Ordinance (DPO) enter into force (Art. 74(2) FADP in conjunction with the Federal Council decision of 31 August 2022).

## Penalties

Fines of up to CHF 250,000 for private individuals for wilful breach of information, access and cooperation obligations (Art. 60 FADP) or of due-diligence obligations such as unlawful disclosure of personal data abroad, faulty transfer to a processor, or non-compliance with the Federal Council's minimum data security requirements (Art. 61 FADP). Breach of professional confidentiality (Art. 62 FADP) and disregard of FDPIC rulings (Art. 63 FADP) also carry fines of up to CHF 250,000. Administrative criminal law applies to violations within business operations (Art. 64 FADP); prosecution and adjudication fall to the cantons (Art. 65 FADP), and the limitation period for prosecution is five years (Art. 66 FADP). A breach of the notification duty for data security breaches (Art. 24 FADP) is not listed as a separate offence in the penal provisions (Art. 60-64 FADP).

## Frequently asked questions

**Does every company have to keep a record of processing activities?**
No. Under Art. 24 DPO, companies and other private-law organisations, as well as natural persons, employing fewer than 250 employees on 1 January of a year are exempt from this duty - unless they process special categories of personal data on a large scale or carry out high-risk profiling. Both elements (size and type of processing) must be checked together.

**From when does the FADP apply?**
Since 1 September 2023.

**Who supervises compliance?**
The Federal Data Protection and Information Commissioner (FDPIC, Art. 4 FADP), with the exception of the Federal Assembly, the Federal Council, the federal courts, and certain proceedings of the Office of the Attorney General and adjudicating federal authorities.

**What must a notification to the FDPIC of a data security breach contain?**
Under Art. 15 DPO, at minimum: the type of breach, where possible its time and duration, the categories and approximate number of persons or personal data affected, the consequences including any risks, measures taken or planned, and the contact details of a contact person. Missing details can be submitted later.

## Open points of the research

- The Data Protection Ordinance (DPO, SR 235.11) was not read in full text; only Art. 1 and Art. 11-34 (including Art. 15 notification, Art. 24 SME exemption) were read; the remaining approximately 10 articles of the roughly 20 pages were not examined.
- The FDPIC's exact investigative and ruling powers (Art. 49-51 FADP) were not checked in full wording; only the context from Art. 52 FADP (procedure) is available.
- Note on naming: the name 'VDSG' used in the brief refers to the old 1993 ordinance to the DSG; the current ordinance cited here is correctly called the 'Data Protection Ordinance (DPO)', SR 235.11.

## Sources

- [Bundesgesetz über den Datenschutz (Datenschutzgesetz, DSG), SR 235.1, Stand am 1. September 2023](https://www.fedlex.admin.ch/eli/cc/2022/491/de), Bundeskanzlei / Fedlex, retrieved 24 September 2026
- [Verordnung über den Datenschutz (Datenschutzverordnung, DSV), SR 235.11, Stand am 1. September 2023](https://www.fedlex.admin.ch/eli/cc/2022/568/de), Bundeskanzlei / Fedlex, retrieved 24 September 2026
- [EDÖB - Aufsichtsbehörde für Datenschutz](https://www.edoeb.admin.ch/edoeb/de/home.html), Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB), retrieved 24 September 2026

---
A professional assessment based on publicly available sources, not legal advice. Whether a given rule applies in your specific case depends on circumstances that are not fully captured here.
Source: SACOSI, Situational Awareness Consulting by Ivo Schönberner (https://sacosi.ch).
