FADP
Revised Swiss Federal Act on Data Protection
The revised Federal Act on Data Protection has applied since 1 September 2023. It is milder than the GDPR, but has one feature many underestimate: the fines target natural persons.
FADP at a glance
- In force
- Since 1 September 2023
- Supervision
- FDPIC
- Penalty
- Up to CHF 250,000 against responsible individuals
- Model
- Transparency, opt-out for most cookies
What is the revised FADP?
The revised Federal Act on Data Protection replaced the 1992 act in 2023 and brought Switzerland closer to European standards — without copying them. It demands transparency, data minimisation and security, but unlike the ePrivacy Directive it does not require prior consent for most cookies.
The decisive difference lies in the sanction. It is not the company that is fined but the responsible natural person — up to 250,000 francs, on complaint and where intent is shown. That hits management or the data protection officer personally.
Who does the FADP apply to?
Any processing with a Swiss connection
The act covers situations that have an effect in Switzerland — even where the company is based abroad.
Regardless of company size
There is no threshold. The only relief concerns the register of processing activities for companies with fewer than 250 employees.
Internal use counts too
Personal data of employees, applicants and customers falls under it just as website data does.
What does the FADP require of a website?
Transparent information
At the point of collection, data subjects must learn who processes which data for which purpose and where it goes — particularly for disclosure abroad.
Objection to profiling
High-risk profiling requires explicit consent. For ordinary tracking, an option to object is generally sufficient.
Right of access
Anyone may find out free of charge which data is processed about them. The deadline is 30 days.
Data security
Appropriate technical and organisational measures are mandatory; breaches of data security must be reported to the FDPIC.
Regulate processing on your behalf
Anyone having data processed by third parties needs a data processing agreement — including for analytics tools and hosting.
How does Aiara meet the FADP?
Aiara is built for Switzerland, not adapted to it. That shows in places European providers do not even know about.
Legal texts under Swiss law
The privacy policy cites the articles of the revised act, not only the GDPR — and covers both if you also have EU customers.
Imprint to Swiss requirements
Aiara produces an imprint meeting the requirements of the Federal Act against Unfair Competition, which most German templates miss.
Risk radar following the FDPIC guidance
A review along Annex A of the FDPIC guidance shows where your website departs from the recommended approach — with specific pointers rather than a traffic light.
Access requests in the dashboard
Requests from data subjects can be recorded and handled within the deadline instead of getting lost in an inbox.
Data processing agreement in self-service
The agreement can be concluded directly and downloaded with a checksum — no email exchange, no waiting.
Data stays in Switzerland
Operation and storage take place with a Swiss provider. No additional justification for disclosure abroad is required.
Want to understand the legal position first? The guide covers scope, obligations and the FDPIC guidance in detail.
Read the FADP guideFrequently asked questions about FADP
Official sources
This page summarises the legal position in plain language and is no substitute for legal advice.