Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 24
stage In effect
since 2023-09-01
source Fedlex, the Swiss Federal Council's official legislation portal
A controller must notify the FDPIC as soon as possible once aware of a data security breach likely to result in a high risk to the data subject's personality or fundamental rights. Unlike General Data Protection Regulation (GDPR) there is no fixed statutory clock: commentary treats 72 hours as a practical benchmark drawn from the Federal Council's explanatory message, not a binding deadline.
Notification to the data subject is required only where necessary to protect them, or if the FDPIC orders it; the controller may limit, defer, or omit subject notification if it is impossible, disproportionate, or superseded by a public communication of comparable effect.
What it asks of an app →
Comprehensive regime
cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 1-4, 6, 30-31
stage In effect
since 2023-09-01
source Fedlex, the Swiss Federal Council's official legislation portal
Switzerland's comprehensive private-sector data protection law is the revised Federal Act on Data Protection (nFADP in English, revDSG in German, nLPD in French), SR 235.1, in force since 1 September 2023. It replaces the 1992 FADP and is Switzerland's own statute, aligned with but distinct from General Data Protection Regulation (GDPR).
Processing personal data is not consent-gated by default the way GDPR is opt-in for many bases; the FADP instead prohibits processing that violates a data subject's personality rights unless justified, by consent, an overriding private or public interest, or law.
Controllers ("responsible persons") and processors are distinguished in Article 5 lit. j-k, with duty allocation similar in shape to GDPR's controller and processor split but not identical in mechanics; the Ordinance on Data Protection (ODP) adds implementing detail rather than a separate top-level instrument.
What it asks of an app →
Cross border transfer
cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 16-17
stage In effect
since 2023-09-01
source Fedlex, the Swiss Federal Council's official legislation portal
Transfer abroad is permitted without extra safeguards to a state or international body the Federal Council has found provides an adequate level of protection, a maintained list that includes the EU and EEA states.
Absent adequacy, a transfer needs a safeguard: standard contractual clauses, the EU SCCs work with a Swiss-law addendum, binding corporate rules, or one of the narrower Article 17 derogations, explicit consent, contract necessity, overriding public interest, life or safety, or transfer of data from a public register. This is structurally the General Data Protection Regulation (GDPR) Chapter V mechanism, adequacy or safeguards or a derogation, not a hard localization duty.
The European Commission's own adequacy decision for Switzerland was reconfirmed 15 January 2024, covering the post-revision regime, and Switzerland's own Federal Council lists the EU and EEA as adequate for outbound transfers, so the relationship is adequate in both directions.
What it asks of an app →
Data subject rights
cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 25-32
stage In effect
since 2023-09-01
source Fedlex, the Swiss Federal Council's official legislation portal
Articles 25 to 32 FADP give a person in Switzerland rights of access, rectification, deletion or destruction, objection to ongoing processing at any time, and a narrower portability right under Article 28 limited to data the subject provided and that is processed by automated means, in a standard electronic format, on request. Article 32 additionally lets a person go straight to a civil court to compel correction or have disputed data flagged, independent of the FDPIC complaint route.
What it asks of an app →
Enforcement supervision
cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 43, 60-65
stage In effect
since 2023-09-01
source Fedlex, the Swiss Federal Council's official legislation portal
The FDPIC (Federal Data Protection and Information Commissioner) is the supervisory authority: it investigates on complaint or ex officio and can order a controller to start, change, suspend, or stop processing, or to delete or destroy data, and can compel appointment of a Swiss representative. It does not hold General Data Protection Regulation (GDPR)-style direct administrative fining power.
Criminal sanctions sit in Articles 60 to 65 FADP instead: up to CHF 250,000 against the individual responsible for a willful violation, prosecuted as an offense, with a CHF 50,000 fallback fine on the company itself only when the responsible individual cannot reasonably be identified within the business.
Private civil actions run in parallel and separately, through Article 32 FADP's direct civil-court route and the general Swiss Code of Obligations and Civil Code personality-rights provisions; a claimant must plead and prove quantifiable loss, there is no BIPA-style statutory per-violation damages figure.
What it asks of an app →
Sensitive categories
cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 5 lit. c, Art. 6 para. 7, Art. 22
stage In effect
since 2023-09-01
source Fedlex, the Swiss Federal Council's official legislation portal
Article 5 lit. c FADP defines sensitive personal data as a closed list: data on religious, philosophical, political or trade union views and activities; health data; data on the intimate sphere or racial or ethnic origin; genetic data; biometric data that uniquely identifies a natural person; and data on administrative or criminal proceedings and sanctions. Genetic and biometric data are the two categories the 2023 revision added.
A controller relying on consent for sensitive personal data needs express consent under Article 6 para. 7, and large-scale processing of sensitive personal data or systematic large-scale public-space monitoring triggers a mandatory Data Protection Impact Assessment under Article 22.
There is no dedicated Swiss biometric statute and no statutory biometric-specific retention or destruction schedule; retention is governed by the FADP's general proportionality and storage-limitation principle, Article 6 para. 3-4: keep only as long as the purpose requires, then delete or anonymize.
The controlling recent authority is a live FDPIC enforcement action rather than a statute amendment: on 16 May 2025 the FDPIC concluded its investigation into PostFinance's voice-recognition system and found the processing violated the proportionality principle because voiceprints were being created on an opt-out basis rather than opt-in.
The FDPIC ordered PostFinance to obtain explicit, affirmative consent before creating a voiceprint and to delete every voiceprint created without it, with a compliance deadline of 1 October 2025. PostFinance has appealed to the Federal Administrative Court, and the outcome of that appeal was not established in this research; the FDPIC's order is treated as its currently stated position, not as final.
What it asks of an app →