Law / Switzerland

Switzerland

privacy

Switzerland's comprehensive private-sector data protection law is the revised Federal Act on Data Protection (nFADP), SR 235.1, in force since 1 September 2023, its own statute aligned with but distinct from General Data Protection Regulation (GDPR) rather than an EU member state's implementation of it.

Biometric data has been a sensitive personal data category since the 2023 revision, with no dedicated biometric statute; the most consequential recent development is the FDPIC's 16 May 2025 order against PostFinance to obtain opt-in consent before creating a voiceprint, currently under appeal to the Federal Administrative Court.

Switzerland's own primary legislative text (fedlex.admin.ch) is served as a JavaScript single-page application that returned only its unrendered application shell to this research pass's direct crawler fetch, so several findings below rest on consistent secondary corroboration rather than an independently read primary quote; this is recorded per finding, not smoothed over.

12 instruments named 6 researched in detail As of 2026-08-24

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

FADP Article 24, Breach Notification in Switzerland

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 24 stage In effect since 2023-09-01 source Fedlex, the Swiss Federal Council's official legislation portal

A controller must notify the FDPIC as soon as possible once aware of a data security breach likely to result in a high risk to the data subject's personality or fundamental rights. Unlike General Data Protection Regulation (GDPR) there is no fixed statutory clock: commentary treats 72 hours as a practical benchmark drawn from the Federal Council's explanatory message, not a binding deadline.

Notification to the data subject is required only where necessary to protect them, or if the FDPIC orders it; the controller may limit, defer, or omit subject notification if it is impossible, disproportionate, or superseded by a public communication of comparable effect.

What it asks of an app

Comprehensive regime

Federal Act on Data Protection (nFADP), General Processing Principles

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 1-4, 6, 30-31 stage In effect since 2023-09-01 source Fedlex, the Swiss Federal Council's official legislation portal

Switzerland's comprehensive private-sector data protection law is the revised Federal Act on Data Protection (nFADP in English, revDSG in German, nLPD in French), SR 235.1, in force since 1 September 2023. It replaces the 1992 FADP and is Switzerland's own statute, aligned with but distinct from General Data Protection Regulation (GDPR).

Processing personal data is not consent-gated by default the way GDPR is opt-in for many bases; the FADP instead prohibits processing that violates a data subject's personality rights unless justified, by consent, an overriding private or public interest, or law.

Controllers ("responsible persons") and processors are distinguished in Article 5 lit. j-k, with duty allocation similar in shape to GDPR's controller and processor split but not identical in mechanics; the Ordinance on Data Protection (ODP) adds implementing detail rather than a separate top-level instrument.

What it asks of an app

Cross border transfer

FADP Articles 16-17, Cross-Border Transfer of Personal Data from Switzerland

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 16-17 stage In effect since 2023-09-01 source Fedlex, the Swiss Federal Council's official legislation portal

Transfer abroad is permitted without extra safeguards to a state or international body the Federal Council has found provides an adequate level of protection, a maintained list that includes the EU and EEA states.

Absent adequacy, a transfer needs a safeguard: standard contractual clauses, the EU SCCs work with a Swiss-law addendum, binding corporate rules, or one of the narrower Article 17 derogations, explicit consent, contract necessity, overriding public interest, life or safety, or transfer of data from a public register. This is structurally the General Data Protection Regulation (GDPR) Chapter V mechanism, adequacy or safeguards or a derogation, not a hard localization duty.

The European Commission's own adequacy decision for Switzerland was reconfirmed 15 January 2024, covering the post-revision regime, and Switzerland's own Federal Council lists the EU and EEA as adequate for outbound transfers, so the relationship is adequate in both directions.

What it asks of an app

Data subject rights

FADP Articles 25-32, Data Subject Rights in Switzerland

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 25-32 stage In effect since 2023-09-01 source Fedlex, the Swiss Federal Council's official legislation portal

Articles 25 to 32 FADP give a person in Switzerland rights of access, rectification, deletion or destruction, objection to ongoing processing at any time, and a narrower portability right under Article 28 limited to data the subject provided and that is processed by automated means, in a standard electronic format, on request. Article 32 additionally lets a person go straight to a civil court to compel correction or have disputed data flagged, independent of the FDPIC complaint route.

What it asks of an app

Enforcement supervision

FADP Articles 43, 60-65, FDPIC Supervision and Criminal Sanctions in Switzerland

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 43, 60-65 stage In effect since 2023-09-01 source Fedlex, the Swiss Federal Council's official legislation portal

The FDPIC (Federal Data Protection and Information Commissioner) is the supervisory authority: it investigates on complaint or ex officio and can order a controller to start, change, suspend, or stop processing, or to delete or destroy data, and can compel appointment of a Swiss representative. It does not hold General Data Protection Regulation (GDPR)-style direct administrative fining power.

Criminal sanctions sit in Articles 60 to 65 FADP instead: up to CHF 250,000 against the individual responsible for a willful violation, prosecuted as an offense, with a CHF 50,000 fallback fine on the company itself only when the responsible individual cannot reasonably be identified within the business.

Private civil actions run in parallel and separately, through Article 32 FADP's direct civil-court route and the general Swiss Code of Obligations and Civil Code personality-rights provisions; a claimant must plead and prove quantifiable loss, there is no BIPA-style statutory per-violation damages figure.

What it asks of an app

Sensitive categories

FADP Article 5 lit. c, Sensitive Personal Data Including Biometric Data

cite Federal Act on Data Protection (nFADP / revDSG / nLPD), SR 235.1, Art. 5 lit. c, Art. 6 para. 7, Art. 22 stage In effect since 2023-09-01 source Fedlex, the Swiss Federal Council's official legislation portal

Article 5 lit. c FADP defines sensitive personal data as a closed list: data on religious, philosophical, political or trade union views and activities; health data; data on the intimate sphere or racial or ethnic origin; genetic data; biometric data that uniquely identifies a natural person; and data on administrative or criminal proceedings and sanctions. Genetic and biometric data are the two categories the 2023 revision added.

A controller relying on consent for sensitive personal data needs express consent under Article 6 para. 7, and large-scale processing of sensitive personal data or systematic large-scale public-space monitoring triggers a mandatory Data Protection Impact Assessment under Article 22.

There is no dedicated Swiss biometric statute and no statutory biometric-specific retention or destruction schedule; retention is governed by the FADP's general proportionality and storage-limitation principle, Article 6 para. 3-4: keep only as long as the purpose requires, then delete or anonymize.

The controlling recent authority is a live FDPIC enforcement action rather than a statute amendment: on 16 May 2025 the FDPIC concluded its investigation into PostFinance's voice-recognition system and found the processing violated the proportionality principle because voiceprints were being created on an opt-out basis rather than opt-in.

The FDPIC ordered PostFinance to obtain explicit, affirmative consent before creating a voiceprint and to delete every voiceprint created without it, with a compliance deadline of 1 October 2025. PostFinance has appealed to the Federal Administrative Court, and the outcome of that appeal was not established in this research; the FDPIC's order is treated as its currently stated position, not as final.

What it asks of an app

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.