The revised Federal Act on Data Protection (revFADP) has applied since 1 September 2023. It brings GDPR-compatible duties, criminal sanctions for managing officers and new requirements for international data transfers — a practical overview.
The revised Federal Act on Data Protection (revFADP, SR 235.1) entered into force on 1 September 2023, replacing the 1992 FADP. The reform was needed to maintain the EU's recognition of Switzerland as an 'adequate third country' and to create a framework for national data-protection scandals with international consequences.
Unlike the GDPR, the revFADP does not provide direct administrative fines against companies — instead, criminal fines against responsible natural persons (up to CHF 250,000). For SMEs the risk is therefore not lower, but more personal: it hits managing officers and data-protection responsibles directly.
1. Scope of the revFADP
The act applies to processing of personal data by private persons and federal bodies (Art. 2 para. 1 revFADP). Personal data is any information relating to a determined or determinable natural person — name, email, IP address, tracking data, employee data, customer data.
The revFADP has extraterritorial effect (Art. 3 para. 1 revFADP): it also applies where a foreign company processes data of persons in Switzerland and effects arise here. Mirror image of the GDPR.
2. The eight core principles
Art. 6 revFADP requires eight principles:
• Lawfulness — processing must have a legal basis.
• Good faith.
• Purpose limitation — data only for the stated purpose.
• Proportionality — only as much data as necessary.
• Data accuracy — correct or delete incorrect data.
• Data security — technical and organisational measures.
• Recognisability — the data subject must know that and which data is being processed.
• Storage minimisation — storage only as long as necessary.
3. Information duties — Art. 19 revFADP
Anyone collecting personal data must actively inform the data subject — including where data is not collected directly from them. The information must cover identity of the controller, processing purpose, recipient categories and any disclosures abroad. Typical implementation: a properly structured privacy notice on the website and at all touchpoints (contact forms, newsletters, employee onboarding).
4. Data-protection impact assessment (DPIA, Art. 22 revFADP)
For processing with high risk (profiling, extensive processing of sensitive data, systematic surveillance), a DPIA must be carried out in advance. Practically affected: HR tools with profiling, web shops with applicant databases, marketing tools with behavioural tracking, public-space security cameras.
5. Breach notification (Art. 24 revFADP)
A data breach with probable high risk to data subjects must be notified to the FDPIC 'as quickly as possible'. Unlike the GDPR, there is no rigid 72-hour deadline — the Swiss rule is more flexible, but the risk of delay is on the company. With high risk, affected persons must also be informed directly.
In practice, many SMEs have no incident-response plans — and in a crisis lose valuable hours before the notice is sent. A ready-made template with escalation paths belongs in every IT compliance set-up.
6. International data transfers (Art. 16 revFADP)
Personal data may be transferred only to countries ensuring adequate protection. The Federal Council maintains a country list — the USA was not on it for years. For non-adequate countries, standard contractual clauses (SCC), binding corporate rules (BCR) or the data subject's consent are required.
For Ukraine, the adequacy decision currently does not apply — anyone transferring data of Swiss customers to Ukraine (e.g. for processing by a local subsidiary) needs SCC and usually a prior risk assessment.
7. Rights of the data subject
The revFADP expands rights over the old FADP:
• Right of access (Art. 25 revFADP) — free of charge within 30 days.
• Right to data release and transfer (Art. 28 revFADP, a form of data portability).
• Right to rectification, deletion, restriction of processing.
• Right to object to certain processing.
• Right not to be subject to solely automated individual decision-making with profiling.
8. Criminal sanctions — the personal threat
Art. 60 revFADP provides for fines up to CHF 250,000 — against natural persons, not companies. Covered are wilful violations of the duty to provide information, duty to inform, duty of data security and the duty to appoint a Swiss representative for foreign controllers. The fine typically hits managing officers, IT heads or the data-protection officer.
This is a key difference from the GDPR, which imposes administrative fines on companies: in the Swiss model, the management is personally on the hook, which significantly strengthens compliance motivation.
9. Compliance checklist for SMEs
• Inventory of all data processing activities — who does what for which purpose.
• Review and update the website privacy notice (mark entry into force in 2023).
• Check contracts with processors (cloud, IT providers) for revFADP-compliant clauses.
• Inform and train employees (especially HR, marketing, IT).
• Identify and legitimise international transfers (SCC, consent).
• Prepare incident-response plan with notification paths.
• Access-right process: who answers how quickly?
• Maintain a record of processing activities (Art. 12 revFADP).
10. What happens in an FDPIC investigation?
The Federal Data Protection and Information Commissioner (FDPIC) can open investigations ex officio or on complaint. He has powers to order measures (Art. 51 revFADP) — from rectification through blocking to deletion. Unlike EU data-protection authorities, the FDPIC cannot impose fines himself — he hands criminally relevant cases to the prosecutor.
Practical note
Sobiera Legal Consulting supports Swiss SMEs and international companies in revFADP compliance — from privacy notice through processing agreements to preparation for FDPIC investigations. In Ukrainian, Russian, German, English and French — particularly relevant for data transfers between Switzerland and Ukraine.