Swiss revised FADP (nFADP)
In force Switzerland · In force Sep 1, 2023 · no upcoming deadlines
Deadlines
Summaries for reference, not legal advice. Check the official text.
What it does
Switzerland's modernised data protection law, closely aligned to GDPR: privacy by design/default, records of processing, DPIAs, breach notification to the FDPIC as soon as possible, and cross-border transfer rules. Protects only natural persons' data.
- Who it applies to
- Private persons and federal bodies processing personal data of natural persons, including processing abroad that has effects in Switzerland. Records-of-processing exemption for companies with fewer than 250 employees unless high-risk processing.
- Penalties
- Criminal fines of up to CHF 250,000 imposed on responsible individuals (not the company) for intentional breaches of key duties.
- Enforced by
- Federal Data Protection and Information Commissioner (FDPIC); cantonal criminal prosecution authorities
- Official name
- Federal Act on Data Protection (revised FADP) of 25 September 2020
- Citation
- SR 235.1
- Topics
- privacy, breach-notification
Verified 2026-09-22 edoeb.admin.ch
Research notes
No transition period was granted.
Related
Questions about Swiss revised FADP (nFADP)
- What are the Swiss revised FADP (nFADP) compliance deadlines?
- Sep 1, 2023: Revised FADP enters into force.
- When does Swiss revised FADP (nFADP) take effect?
- Swiss revised FADP (nFADP) took effect on Sep 1, 2023.
- Who does Swiss revised FADP (nFADP) apply to?
- Private persons and federal bodies processing personal data of natural persons, including processing abroad that has effects in Switzerland. Records-of-processing exemption for companies with fewer than 250 employees unless high-risk processing.
- What are the penalties under Swiss revised FADP (nFADP)?
- Criminal fines of up to CHF 250,000 imposed on responsible individuals (not the company) for intentional breaches of key duties.