The revised Swiss Federal Act on Data Protection (FADP) came into force on 1 September 2023. More than 18 months later, many Swiss SMEs still have not taken the necessary measures, due to a lack of information, confusion with the European GDPR, or because the obligations seem abstract. Here is what the law concretely requires.
What has changed
The old Data Protection Act dated from 1992. It was largely unsuited to the reality of a digital economy. The 2023 revision aligns Switzerland with European standards (GDPR) while keeping Swiss specificities. The main changes:
- Privacy by design and by default: an obligation to build data protection into systems from the design stage, not as an option
- Mandatory breach notification: any breach presenting a high risk must be reported to the Federal Data Protection and Information Commissioner (FDPIC) "as soon as possible"
- Record of processing activities: mandatory for companies whose processing presents a high risk to the individuals concerned
- Data protection impact assessment (DPIA): required for processing likely to entail a high risk to the individuals concerned
- Right to portability: individuals can request their data in a machine-readable format
- Personal liability: penalties can reach the responsible individuals (executives, data protection officers)
Who is concerned
The Swiss Data Protection Act applies to any organisation that processes the personal data of individuals in Switzerland, regardless of its size. There is no exemption for micro-enterprises or the self-employed.
In practice, as soon as you have employees, customers or suppliers who are individuals whose information you store (name, address, email, health data, banking data, purchase history, etc.), the Swiss Data Protection Act concerns you.
If you have customers in the European Union, the GDPR applies in parallel. The two texts have similar but not identical requirements, notably on incident notification deadlines (72h for the GDPR, "as soon as possible" for the Swiss Data Protection Act) and on certain definitions.
What you need to put in place
1. Inventory of personal data
The first mandatory step: knowing exactly what personal data you process, where it is stored, who has access to it, for what purpose and for how long. This inventory takes the form of a record of processing activities.
For a typical SME, this record covers: employee data (HR, salaries, absences), customer data (contact details, commercial history, payment data), supplier data, and data from your website (forms, possible statistics).
2. An up-to-date privacy policy
Your website must display a privacy policy that informs visitors of the data collected, the purposes of the processing, possible recipients, the retention period and their rights (access, rectification, deletion, portability).
If your policy dates from before 2023 or was generated automatically without thought, it is probably insufficient.
3. Contracts with your subcontractors
If you transmit personal data to providers (accountant, HR agency, web host, cloud CRM, etc.), you must have a data processing contract with them specifying the processing conditions, the security measures and the obligations in the event of a breach.
Point of attention: if your provider is based outside Switzerland in a country without an adequate level of protection recognised by Switzerland, additional guarantees are necessary (standard contractual clauses, binding corporate rules, etc.).
4. A data breach response procedure
In the event of a breach (leak, hacking, loss of a laptop with unencrypted data), you must be able to quickly assess the risk to the individuals concerned and notify the FDPIC if that risk is high.
This assumes you have a documented internal procedure: who is responsible for the assessment, how to inform the FDPIC, how to contact the individuals concerned if necessary.
5. Technical and organisational security measures
The Swiss Data Protection Act requires "appropriate security measures" without listing them precisely. it is deliberately general to adapt to all contexts. In practice, the following are expected:
- Encryption of sensitive data (in transit and at rest)
- Access control (principle of least privilege)
- Logging of access to sensitive data
- Regular and tested backups
- Incident management
- Training employees in the basics of data protection
The penalties
Unlike the GDPR (penalties against the company of up to 4% of worldwide turnover), the Swiss Data Protection Act punishes the individuals responsible for intentional offences. Fines can reach CHF 250,000 per offence.
The offences covered include: failure to comply with information obligations, refusal to disclose data to a person who requests it, unauthorised disclosure of data, and breach of notification obligations.
In practice, the first years of application were marked by an educational approach from the FDPIC. But the regulator has clearly signalled that it would intervene more directively in cases of persistent non-compliance or significant breaches.
Where to start
If you have done nothing, start with the data inventory: list all the places where personal data is stored in your company (software, servers, computers, cloud services). It is the foundation of everything else.
Then, have your privacy policy and your subcontracting contracts reviewed by a competent adviser. It is not necessarily a specialised lawyer. a good IT adviser with compliance expertise can do much of this work for a reasonable cost. This is the purpose of our data protection audit for SMEs, which maps your personal data and produces a documented action plan.
Written by
David Cunha
Co-founder · Technical director, AlpenData
A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.
More about AlpenData →