CHSwitzerlandData protection law

FADP

Revised Swiss Federal Act on Data Protection

The revised Federal Act on Data Protection has applied since 1 September 2023. It is milder than the GDPR, but has one feature many underestimate: the fines target natural persons.

FADP at a glance

In force
Since 1 September 2023
Supervision
FDPIC
Penalty
Up to CHF 250,000 against responsible individuals
Model
Transparency, opt-out for most cookies

What is the revised FADP?

The revised Federal Act on Data Protection replaced the 1992 act in 2023 and brought Switzerland closer to European standards — without copying them. It demands transparency, data minimisation and security, but unlike the ePrivacy Directive it does not require prior consent for most cookies.

The decisive difference lies in the sanction. It is not the company that is fined but the responsible natural person — up to 250,000 francs, on complaint and where intent is shown. That hits management or the data protection officer personally.

Who does the FADP apply to?

Any processing with a Swiss connection

The act covers situations that have an effect in Switzerland — even where the company is based abroad.

Regardless of company size

There is no threshold. The only relief concerns the register of processing activities for companies with fewer than 250 employees.

Internal use counts too

Personal data of employees, applicants and customers falls under it just as website data does.

What does the FADP require of a website?

1

Transparent information

At the point of collection, data subjects must learn who processes which data for which purpose and where it goes — particularly for disclosure abroad.

2

Objection to profiling

High-risk profiling requires explicit consent. For ordinary tracking, an option to object is generally sufficient.

3

Right of access

Anyone may find out free of charge which data is processed about them. The deadline is 30 days.

4

Data security

Appropriate technical and organisational measures are mandatory; breaches of data security must be reported to the FDPIC.

5

Regulate processing on your behalf

Anyone having data processed by third parties needs a data processing agreement — including for analytics tools and hosting.

The solution

How does Aiara meet the FADP?

Aiara is built for Switzerland, not adapted to it. That shows in places European providers do not even know about.

Legal texts under Swiss law

The privacy policy cites the articles of the revised act, not only the GDPR — and covers both if you also have EU customers.

Imprint to Swiss requirements

Aiara produces an imprint meeting the requirements of the Federal Act against Unfair Competition, which most German templates miss.

Risk radar following the FDPIC guidance

A review along Annex A of the FDPIC guidance shows where your website departs from the recommended approach — with specific pointers rather than a traffic light.

Access requests in the dashboard

Requests from data subjects can be recorded and handled within the deadline instead of getting lost in an inbox.

Data processing agreement in self-service

The agreement can be concluded directly and downloaded with a checksum — no email exchange, no waiting.

Data stays in Switzerland

Operation and storage take place with a Swiss provider. No additional justification for disclosure abroad is required.

Want to understand the legal position first? The guide covers scope, obligations and the FDPIC guidance in detail.

Read the FADP guide

Frequently asked questions about FADP

Official sources

This page summarises the legal position in plain language and is no substitute for legal advice.