Skip to content
← All terms

Glossary · Privacy & regulation

FADP / nFADP

The FADP (Federal Act on Data Protection) is Switzerland’s national data protection law; its fully revised version (nFADP) took effect 1 September 2023, modernizing Swiss law to align closely — though not identically — with the GDPR.

Switzerland is not an EU member state, so the GDPR does not apply there directly; the FADP is the domestic statute that plays the equivalent role, enforced by the Federal Data Protection and Information Commissioner (FDPIC). The original FADP dated to 1992. The revised version, adopted by the Swiss Parliament in 2020 and brought into force on 1 September 2023, is what’s meant by nFADP — the "n" for "new" is a common shorthand rather than part of the law’s official name.

The revision brought Swiss law closer to the GDPR in structure: it introduced explicit data protection impact assessments for high-risk processing, a breach-notification duty to the FDPIC, an expanded definition of sensitive personal data (adding genetic and biometric data), privacy-by-design and privacy-by-default obligations, and criminal liability provisions for individuals rather than only companies. It also formalizes the requirement for a representative in Switzerland for foreign controllers processing Swiss residents’ data under certain conditions.

Notable differences from the GDPR remain. The nFADP does not include a direct equivalent to the GDPR’s 4%-of-turnover administrative fines — Swiss sanctions instead target responsible individuals with criminal fines up to CHF 250,000 for willful violations of specific duties. The nFADP also has no general "legitimate interest" balancing test framed the same way, and its territorial scope, while extraterritorial in effect (it applies wherever processing affects people in Switzerland), is drawn slightly differently than Article 3 GDPR. The European Commission has recognized Switzerland as providing an adequate level of protection for data transfers from the EU/EEA, a status that predates the revision and continues to hold.

Ciphera BV is a Belgian company, but Ciphera’s infrastructure runs on Exoscale in Zurich (availability zone CH-DK-2) specifically to keep data under Swiss jurisdiction and the nFADP’s protections — a data residency choice independent of where the company itself is incorporated.

Common questions

How does the FADP differ from the GDPR?
The nFADP shares the GDPR’s general structure — lawful processing, data subject rights, breach notification, privacy by design — but its sanctions fall on responsible individuals as criminal fines (up to CHF 250,000) rather than the GDPR’s administrative fines of up to 4% of global turnover on the company. Its legal-basis framework and territorial-scope wording also differ in detail, and it does not carry a direct GDPR-style "legitimate interest" balancing article by the same name.
Who does the FADP apply to?
It applies to private individuals and companies, as well as federal government bodies, that process the personal data of natural persons in a way that affects people in Switzerland — including foreign organizations processing Swiss residents’ data, similar in effect to the GDPR’s extraterritorial reach.
What changed in the 2023 revision?
The revised FADP (in force 1 September 2023) added mandatory data protection impact assessments for high-risk processing, a duty to notify the FDPIC of data breaches, an expanded category of sensitive personal data including genetic and biometric data, explicit privacy-by-design and privacy-by-default obligations, a requirement for a Swiss representative for certain foreign controllers, and criminal — rather than purely administrative — liability for individuals who willfully violate specific duties.

See also

Related terms