If your GDPR program already covers a Swiss customer or two, you have probably assumed you're covered there as well. Switzerland is not in the EU, but its data protection law reads like a close cousin of the GDPR — same rights, similar structure, aligned vocabulary. That resemblance is exactly what causes gaps.
Switzerland's new Federal Act on Data Protection (nFADP / revFADP) has been in force since September 1, 2023, replacing the older 1992 FADP.[1] It shares the GDPR's DNA but diverges in ways that change what your team actually has to do: a different rulebook for legal basis, a lighter DPO obligation, a narrower right to erasure, and — most consequentially — fines that land on individual executives rather than on the company.
The Short Answer
Being GDPR-compliant does not automatically make you nFADP-compliant. The two laws overlap heavily on principles (transparency, purpose limitation, security), but nFADP is built on a different legal-basis model, defines "sensitive data" more broadly, treats the right to erasure as conditional rather than automatic, and enforces through criminal fines against named individuals — up to CHF 250,000 — instead of GDPR-style corporate turnover penalties.[2]
| At a glance | nFADP (Switzerland) | GDPR (EU) |
|---|---|---|
| In force since | September 1, 2023 | May 25, 2018 |
| Regulator | Federal Data Protection and Information Commissioner (FDPIC) | National DPAs (EDPB-coordinated) |
| Legal basis model | Principles-based; processing is generally permitted unless restricted | Six exhaustive legal bases required for every processing activity |
| DPO required | No, for private companies (federal bodies must appoint a Data Protection Advisor) | Yes, for public authorities and large-scale/systematic monitoring |
| DSAR deadline | 30 calendar days, no formal extension mechanism, no fee | 1 calendar month + up to 2-month extension |
| Right to erasure | Conditional — explicit request required, controller can refuse on legal grounds | Broad right (Art. 17) with defined exceptions |
| Breach notification | "As soon as possible" if significant risk (no fixed hour count) | 72 hours from awareness (Art. 33) |
| Penalties | Up to CHF 250,000, against responsible individuals | Up to €20M or 4% of global annual turnover, against the organization |
Each of these is unpacked below.
1. Scope: Who Has to Comply
nFADP applies to the processing of personal data of natural persons located in Switzerland, and it reaches beyond Swiss borders the same way GDPR does: any organization abroad that processes Swiss residents' data with effects in Switzerland falls under it.[3] If you already track GDPR extraterritorial scope (offering goods/services to, or monitoring, EU residents), the Swiss test is structurally the same exercise applied to a different population.
Key difference: no separate size or revenue threshold on either side — the difference isn't whether you're covered, it's what's expected of you once you are.
2. Legal Basis: Principles Instead of a Checklist
GDPR requires every processing activity to map to one of six legal bases before it starts (Art. 6). nFADP does not have an equivalent exhaustive list. Processing is generally lawful unless it violates data protection principles or requires a specific justification — consent is required only in defined situations: for processing sensitive personal data, for cross-border transfers without adequacy protection, and for high-risk profiling.[4]
Key difference: nFADP is more flexible on paper — there's less "which of the six boxes does this tick?" documentation. In practice this cuts less compliance overhead but offers fewer bright-line guardrails, which shifts more judgment onto the controller.
3. High-Risk Profiling: A Category GDPR Doesn't Have
This is the one that catches AI and analytics teams off guard. nFADP introduces "high-risk profiling" — profiling that reveals sensitive characteristics such as personality traits, financial situation, health, or vulnerabilities — as a category requiring explicit consent (Art. 5(f), Art. 30).[5] GDPR has no directly equivalent label; it regulates automated decision-making with legal effect (Art. 22), which is a narrower and differently-shaped rule.
If you run predictive lead scoring, behavioral segmentation, or credit-risk-style modeling on Swiss data subjects, "we're GDPR compliant" doesn't answer the nFADP question. You need a separate assessment of whether the profiling qualifies as high-risk, and if so, a documented consent basis for it.
4. Data Protection Officer: Not Mandatory, But Not Free Either
Private companies are not required to appoint a Data Protection Advisor under nFADP (only federal government bodies must).[6] But there's a strategic trade-off: voluntarily appointing one exempts the organization from having to consult the FDPIC before running high-residual-risk Data Protection Impact Assessments (Art. 22, Art. 23).
Key difference: most SMEs won't need a formal DPO for nFADP purposes the way GDPR mandates one for large-scale monitoring or special-category processing. Whether to appoint one anyway becomes a documentation-speed decision, not a legal-obligation decision.
5. DSAR Deadlines and the Right to Erasure
Both laws give data subjects the right to request their data, but the mechanics diverge:
| nFADP | GDPR | |
|---|---|---|
| Response deadline | 30 calendar days (Art. 25) | 1 calendar month (+2 months for complex requests) |
| Fee | Free, as a general rule | Free, with limited exceptions for excessive/repetitive requests |
| Extension mechanism | Informal — no defined extension procedure in the statute | Formal 2-month extension with required notice |
| Right to erasure | Conditional: requires an explicit request; controller may refuse if a legal retention ground exists (Art. 32) | Broad right (Art. 17) subject to defined exceptions |
The erasure difference matters operationally: under GDPR, "delete my data" is close to a default outcome once a valid request lands, minus the listed exceptions. Under nFADP, deletion is not automatic even on request — the controller assesses whether a legal basis to retain the data still applies, and can refuse on that ground. That assessment needs to be documented, not just decided informally.
Switzerland's FDPIC has already enforced the 30-day window in practice: in a January 2025 case against Cembra Money Bank, the bank was found to have missed the deadline on 9 of 13 access requests reviewed.[7] That's a useful reminder that "as soon as possible" language elsewhere in the law doesn't extend to the DSAR clock, which is a hard 30 days.
You can work out an exact Swiss due date — separately from the EU GDPR calculation — with the DSAR Deadline Calculator. For how the 30-day nFADP window compares against dozens of other jurisdictions side by side, see our DSAR deadline comparison by jurisdiction.
6. Data Breach Notification
GDPR sets a hard number: 72 hours from awareness to notify the relevant DPA (Art. 33). nFADP's Article 24 uses softer language — notification "as soon as possible" once a breach is likely to result in a high risk to the data subject's personality or fundamental rights, with no statutory hour count.[8]
Key difference: don't read the flexible wording as a lower bar. FDPIC guidance treats prompt notification (in practice, in line with the same 72-hour benchmark most multinational teams already use for GDPR) as the expected standard, and the Commissioner's office has grown its staff roughly 30% over 2024–2025 with breach response as a stated enforcement priority.[9] If your incident response runbook already targets 72 hours for GDPR, keep that target for Swiss data rather than treating the vaguer wording as more room.
7. Penalties: Individuals, Not Companies
This is the structural difference that changes who in the organization should care. GDPR fines the company — up to €20 million or 4% of global annual turnover. nFADP fines named individuals — up to CHF 250,000 — for intentional violations such as failing to provide required information, violating the duty of care in data transfers, or breaching minimum data security requirements (Art. 60–64).[10] There is no equivalent administrative fine against the legal entity itself.
Key difference: nFADP puts personal liability on the specific decision-maker responsible for a violation — typically whoever signed off on the processing activity or the transfer. This is a different risk conversation for founders and compliance leads than a percentage-of-revenue number aimed at the balance sheet.
Data Transfers: Where Switzerland Actually Makes Life Easier
One area nFADP simplifies rather than complicates: cross-border transfer. The Swiss Federal Council has issued an adequacy decision covering the EU/EEA, meaning data can flow between Switzerland and EU member states without extra safeguards.[11] If your organization already has EU-Switzerland data flows mapped for GDPR purposes, that mapping largely holds for nFADP too — the gap opens up for transfers to countries without Swiss adequacy, where SCC-equivalent safeguards (or the Swiss-US framework, where applicable) are still required.
A Practical Compliance Checklist
If you're already GDPR-compliant and need to close the nFADP gap:
- Map Swiss data subjects separately. Confirm which parts of your Data Inventory involve Swiss residents specifically — the legal analysis differs even where the data flows are identical to EU processing.
- Assess your profiling activities for the high-risk category. Predictive scoring, segmentation, or personalization models need a specific look at whether they qualify — and, if so, a documented consent record.
- Set a 30-day DSAR clock, separate from your GDPR 30-day-plus-extension process. The lack of a formal extension mechanism means your default process needs to hit 30 days as the real deadline, not a soft target.
- Don't treat "delete my data" as automatic. Build a step that checks retention grounds before erasure, and document the outcome either way.
- Keep your 72-hour breach habit even though the statute doesn't require it by the hour — FDPIC's enforcement pattern rewards speed.
- Identify who is personally accountable for Swiss data processing decisions internally, since that's who carries individual exposure under Art. 60–64.
Every one of those steps produces something worth keeping as evidence — the DSAR log that shows you hit 30 days, the documented profiling assessment, the retention-ground note behind a refused erasure request. That's the same discipline our evidence collection for privacy compliance piece covers in more depth, and it's exactly what an audit-ready compliance program needs to produce on demand rather than reconstruct after the fact.
The Bottom Line
Switzerland's nFADP shares enough structure with GDPR that teams reasonably assume overlap covers them — and mostly, on principles, it does. The gaps are specific and operational: a 30-day DSAR clock with no formal extension, a conditional rather than automatic erasure right, a unique high-risk-profiling consent trigger, and penalties aimed at individuals rather than the company. None of these require rebuilding your privacy program from scratch. They require a Swiss-specific pass over the parts of it that assumed GDPR was the only rulebook in the room.
To see how other non-EU frameworks compare against GDPR on the same axes, read our breakdowns of GDPR vs CCPA and PIPL vs GDPR, or browse recent enforcement activity across jurisdictions in our enforcement monitor.
Sources:
- Federal Act on Data Protection (FADP) — full text, Fedlex (Swiss Federal Office of Justice)
- FDPIC — Federal Data Protection and Information Commissioner, official site
- Adnovum — 7 Major Differences Between the New FADP and GDPR
- Didomi — Switzerland's New Federal Act on Data Protection
- Securiti — Switzerland's Federal Act on Data Protection: Key Changes and Compliance
- SIDD — Swiss FADP Guide 2026 and Enforcement Outlook
- Global Law Experts — Subject Access Request Procedure in Switzerland 2026 (Cembra Money Bank case)
- Legiscope — FADP vs GDPR: Breach Notification, Sanctions and Authorities Compared
- SIDD — Swiss FADP Guide 2026 and Enforcement Outlook
- HÄRTING Rechtsanwälte — Data Subject Rights According to nFADP
- CookieYes — Switzerland's New Federal Act on Data Protection (FADP)
This article is for informational purposes and does not constitute legal advice. Consult qualified counsel for guidance on your specific obligations under the nFADP or GDPR.




