PrivacyCache← All articles
GDPR

Swiss nFADP vs GDPR: 7 Key Differences Compliance Teams Miss

10 min read
Two bound legal document folders side by side on a wooden desk, one tied with a red and white Swiss ribbon, the other clasped in navy, next to a brass seal stamp

If your GDPR program already covers a Swiss customer or two, you have probably assumed you're covered there as well. Switzerland is not in the EU, but its data protection law reads like a close cousin of the GDPR — same rights, similar structure, aligned vocabulary. That resemblance is exactly what causes gaps.

Switzerland's new Federal Act on Data Protection (nFADP / revFADP) has been in force since September 1, 2023, replacing the older 1992 FADP.[1] It shares the GDPR's DNA but diverges in ways that change what your team actually has to do: a different rulebook for legal basis, a lighter DPO obligation, a narrower right to erasure, and — most consequentially — fines that land on individual executives rather than on the company.

The Short Answer

Being GDPR-compliant does not automatically make you nFADP-compliant. The two laws overlap heavily on principles (transparency, purpose limitation, security), but nFADP is built on a different legal-basis model, defines "sensitive data" more broadly, treats the right to erasure as conditional rather than automatic, and enforces through criminal fines against named individuals — up to CHF 250,000 — instead of GDPR-style corporate turnover penalties.[2]

At a glance nFADP (Switzerland) GDPR (EU)
In force since September 1, 2023 May 25, 2018
Regulator Federal Data Protection and Information Commissioner (FDPIC) National DPAs (EDPB-coordinated)
Legal basis model Principles-based; processing is generally permitted unless restricted Six exhaustive legal bases required for every processing activity
DPO required No, for private companies (federal bodies must appoint a Data Protection Advisor) Yes, for public authorities and large-scale/systematic monitoring
DSAR deadline 30 calendar days, no formal extension mechanism, no fee 1 calendar month + up to 2-month extension
Right to erasure Conditional — explicit request required, controller can refuse on legal grounds Broad right (Art. 17) with defined exceptions
Breach notification "As soon as possible" if significant risk (no fixed hour count) 72 hours from awareness (Art. 33)
Penalties Up to CHF 250,000, against responsible individuals Up to €20M or 4% of global annual turnover, against the organization

Each of these is unpacked below.

1. Scope: Who Has to Comply

nFADP applies to the processing of personal data of natural persons located in Switzerland, and it reaches beyond Swiss borders the same way GDPR does: any organization abroad that processes Swiss residents' data with effects in Switzerland falls under it.[3] If you already track GDPR extraterritorial scope (offering goods/services to, or monitoring, EU residents), the Swiss test is structurally the same exercise applied to a different population.

Key difference: no separate size or revenue threshold on either side — the difference isn't whether you're covered, it's what's expected of you once you are.

2. Legal Basis: Principles Instead of a Checklist

GDPR requires every processing activity to map to one of six legal bases before it starts (Art. 6). nFADP does not have an equivalent exhaustive list. Processing is generally lawful unless it violates data protection principles or requires a specific justification — consent is required only in defined situations: for processing sensitive personal data, for cross-border transfers without adequacy protection, and for high-risk profiling.[4]

Key difference: nFADP is more flexible on paper — there's less "which of the six boxes does this tick?" documentation. In practice this cuts less compliance overhead but offers fewer bright-line guardrails, which shifts more judgment onto the controller.

3. High-Risk Profiling: A Category GDPR Doesn't Have

This is the one that catches AI and analytics teams off guard. nFADP introduces "high-risk profiling" — profiling that reveals sensitive characteristics such as personality traits, financial situation, health, or vulnerabilities — as a category requiring explicit consent (Art. 5(f), Art. 30).[5] GDPR has no directly equivalent label; it regulates automated decision-making with legal effect (Art. 22), which is a narrower and differently-shaped rule.

If you run predictive lead scoring, behavioral segmentation, or credit-risk-style modeling on Swiss data subjects, "we're GDPR compliant" doesn't answer the nFADP question. You need a separate assessment of whether the profiling qualifies as high-risk, and if so, a documented consent basis for it.

4. Data Protection Officer: Not Mandatory, But Not Free Either

Private companies are not required to appoint a Data Protection Advisor under nFADP (only federal government bodies must).[6] But there's a strategic trade-off: voluntarily appointing one exempts the organization from having to consult the FDPIC before running high-residual-risk Data Protection Impact Assessments (Art. 22, Art. 23).

Key difference: most SMEs won't need a formal DPO for nFADP purposes the way GDPR mandates one for large-scale monitoring or special-category processing. Whether to appoint one anyway becomes a documentation-speed decision, not a legal-obligation decision.

5. DSAR Deadlines and the Right to Erasure

Both laws give data subjects the right to request their data, but the mechanics diverge:

nFADP GDPR
Response deadline 30 calendar days (Art. 25) 1 calendar month (+2 months for complex requests)
Fee Free, as a general rule Free, with limited exceptions for excessive/repetitive requests
Extension mechanism Informal — no defined extension procedure in the statute Formal 2-month extension with required notice
Right to erasure Conditional: requires an explicit request; controller may refuse if a legal retention ground exists (Art. 32) Broad right (Art. 17) subject to defined exceptions

The erasure difference matters operationally: under GDPR, "delete my data" is close to a default outcome once a valid request lands, minus the listed exceptions. Under nFADP, deletion is not automatic even on request — the controller assesses whether a legal basis to retain the data still applies, and can refuse on that ground. That assessment needs to be documented, not just decided informally.

Switzerland's FDPIC has already enforced the 30-day window in practice: in a January 2025 case against Cembra Money Bank, the bank was found to have missed the deadline on 9 of 13 access requests reviewed.[7] That's a useful reminder that "as soon as possible" language elsewhere in the law doesn't extend to the DSAR clock, which is a hard 30 days.

You can work out an exact Swiss due date — separately from the EU GDPR calculation — with the DSAR Deadline Calculator. For how the 30-day nFADP window compares against dozens of other jurisdictions side by side, see our DSAR deadline comparison by jurisdiction.

6. Data Breach Notification

GDPR sets a hard number: 72 hours from awareness to notify the relevant DPA (Art. 33). nFADP's Article 24 uses softer language — notification "as soon as possible" once a breach is likely to result in a high risk to the data subject's personality or fundamental rights, with no statutory hour count.[8]

Key difference: don't read the flexible wording as a lower bar. FDPIC guidance treats prompt notification (in practice, in line with the same 72-hour benchmark most multinational teams already use for GDPR) as the expected standard, and the Commissioner's office has grown its staff roughly 30% over 2024–2025 with breach response as a stated enforcement priority.[9] If your incident response runbook already targets 72 hours for GDPR, keep that target for Swiss data rather than treating the vaguer wording as more room.

7. Penalties: Individuals, Not Companies

This is the structural difference that changes who in the organization should care. GDPR fines the company — up to €20 million or 4% of global annual turnover. nFADP fines named individuals — up to CHF 250,000 — for intentional violations such as failing to provide required information, violating the duty of care in data transfers, or breaching minimum data security requirements (Art. 60–64).[10] There is no equivalent administrative fine against the legal entity itself.

Key difference: nFADP puts personal liability on the specific decision-maker responsible for a violation — typically whoever signed off on the processing activity or the transfer. This is a different risk conversation for founders and compliance leads than a percentage-of-revenue number aimed at the balance sheet.

Data Transfers: Where Switzerland Actually Makes Life Easier

One area nFADP simplifies rather than complicates: cross-border transfer. The Swiss Federal Council has issued an adequacy decision covering the EU/EEA, meaning data can flow between Switzerland and EU member states without extra safeguards.[11] If your organization already has EU-Switzerland data flows mapped for GDPR purposes, that mapping largely holds for nFADP too — the gap opens up for transfers to countries without Swiss adequacy, where SCC-equivalent safeguards (or the Swiss-US framework, where applicable) are still required.

A Practical Compliance Checklist

If you're already GDPR-compliant and need to close the nFADP gap:

  1. Map Swiss data subjects separately. Confirm which parts of your Data Inventory involve Swiss residents specifically — the legal analysis differs even where the data flows are identical to EU processing.
  2. Assess your profiling activities for the high-risk category. Predictive scoring, segmentation, or personalization models need a specific look at whether they qualify — and, if so, a documented consent record.
  3. Set a 30-day DSAR clock, separate from your GDPR 30-day-plus-extension process. The lack of a formal extension mechanism means your default process needs to hit 30 days as the real deadline, not a soft target.
  4. Don't treat "delete my data" as automatic. Build a step that checks retention grounds before erasure, and document the outcome either way.
  5. Keep your 72-hour breach habit even though the statute doesn't require it by the hour — FDPIC's enforcement pattern rewards speed.
  6. Identify who is personally accountable for Swiss data processing decisions internally, since that's who carries individual exposure under Art. 60–64.

Every one of those steps produces something worth keeping as evidence — the DSAR log that shows you hit 30 days, the documented profiling assessment, the retention-ground note behind a refused erasure request. That's the same discipline our evidence collection for privacy compliance piece covers in more depth, and it's exactly what an audit-ready compliance program needs to produce on demand rather than reconstruct after the fact.

The Bottom Line

Switzerland's nFADP shares enough structure with GDPR that teams reasonably assume overlap covers them — and mostly, on principles, it does. The gaps are specific and operational: a 30-day DSAR clock with no formal extension, a conditional rather than automatic erasure right, a unique high-risk-profiling consent trigger, and penalties aimed at individuals rather than the company. None of these require rebuilding your privacy program from scratch. They require a Swiss-specific pass over the parts of it that assumed GDPR was the only rulebook in the room.

To see how other non-EU frameworks compare against GDPR on the same axes, read our breakdowns of GDPR vs CCPA and PIPL vs GDPR, or browse recent enforcement activity across jurisdictions in our enforcement monitor.


Sources:

  1. Federal Act on Data Protection (FADP) — full text, Fedlex (Swiss Federal Office of Justice)
  2. FDPIC — Federal Data Protection and Information Commissioner, official site
  3. Adnovum — 7 Major Differences Between the New FADP and GDPR
  4. Didomi — Switzerland's New Federal Act on Data Protection
  5. Securiti — Switzerland's Federal Act on Data Protection: Key Changes and Compliance
  6. SIDD — Swiss FADP Guide 2026 and Enforcement Outlook
  7. Global Law Experts — Subject Access Request Procedure in Switzerland 2026 (Cembra Money Bank case)
  8. Legiscope — FADP vs GDPR: Breach Notification, Sanctions and Authorities Compared
  9. SIDD — Swiss FADP Guide 2026 and Enforcement Outlook
  10. HÄRTING Rechtsanwälte — Data Subject Rights According to nFADP
  11. CookieYes — Switzerland's New Federal Act on Data Protection (FADP)

This article is for informational purposes and does not constitute legal advice. Consult qualified counsel for guidance on your specific obligations under the nFADP or GDPR.

Stay ahead of privacy regulations

Get compliance insights delivered to your inbox — new regulations, enforcement actions, and practical tips.

We respect your privacy. Privacy Policy

Related articles

Professional choosing between a payment card and a two-option consent screen on a laptop in a café
GDPR6 min read

Consent or Pay: Are 'Pay-or-Okay' Cookie Walls Legal in 2026?

Are 'pay-or-okay' cookie walls legal under GDPR in 2026? What the EDPB opinion on consent-or-pay models means for your site.

Contract files, encrypted drive, and cable crossing a relief map between Europe and North America
GDPR7 min read

International Data Transfers Under GDPR: The 2026 Guide to DPF, SCCs, and TIAs

How EU data transfers really work in 2026: the Data Privacy Framework, SCCs, transfer impact assessments, and where the real GDPR risk sits.

Analytics dashboard, EU data map, and consent gate for GDPR-compliant tracking
GDPR6 min read

Google Analytics and GDPR in 2026: Is GA4 Legal in the EU?

Is Google Analytics 4 legal under GDPR in 2026? Where GA4 stands after the EU-US Data Privacy Framework, what still creates risk, and how to check.

Track real GDPR enforcement actions

Monitor privacy fines from regulators worldwide. Understand what violations get penalized and benchmark your risk.

Browse Enforcement Actions