Law note · Switzerland
Federal Act on Data Protection (nFADP), General Processing Principles
Switzerland's comprehensive private-sector data protection law is the revised Federal Act on Data Protection (nFADP in English, revDSG in German, nLPD in French), SR 235.1, in force since 1 September 2023. It replaces the 1992 FADP and is Switzerland's own statute, aligned with but distinct from General Data Protection Regulation (GDPR).
Processing personal data is not consent-gated by default the way GDPR is opt-in for many bases; the FADP instead prohibits processing that violates a data subject's personality rights unless justified, by consent, an overriding private or public interest, or law.
Controllers ("responsible persons") and processors are distinguished in Article 5 lit. j-k, with duty allocation similar in shape to GDPR's controller and processor split but not identical in mechanics; the Ordinance on Data Protection (ODP) adds implementing detail rather than a separate top-level instrument.
What it asks of an app
- Have a justification, consent, an overriding private or public interest, or a legal basis, before processing personal data of a person in Switzerland in a way that would otherwise violate their personality rights.
- Distinguish your role as controller ("responsible person") or processor under FADP Article 5 lit. j-k, and allocate duties accordingly.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: Fedlex, the Swiss Federal Council's official legislation portal