[codicts-css-switcher id=”346″]

Global Law Experts Logo
gdpr vs fadp switzerland

GDPR vs FADP Switzerland 2026: Key Differences, Applicability & Compliance Steps

By Global Law Experts
– posted 58 minutes ago

GDPR vs FADP Switzerland is the defining compliance question for any business that handles personal data in or with the Swiss market in 2026, because two closely related but distinct regimes now govern how that data must be collected, processed and transferred. Switzerland’s revised Federal Act on Data Protection (revised FADP, in force since 1 September 2023) operates alongside the EU’s General Data Protection Regulation (GDPR), and many organisations fall under both at once. The purpose of this guide is practical: to help you determine which law applies, where the two diverge, and what concrete steps to take.

If you operate a Swiss company, an EU business serving Swiss customers, or a hybrid group spanning both, understanding GDPR vs FADP Switzerland is the foundation of a defensible compliance programme.

TL;DR, GDPR vs FADP Switzerland at a glance

The short answer: GDPR has not replaced the FADP, and the FADP has not replaced GDPR. Both can apply to the same processing activity depending on where your organisation sits, who your data subjects are, and what you do with the data. The revised FADP is deliberately aligned with GDPR to preserve Switzerland’s EU adequacy status, but meaningful differences remain in scope, definitions, enforcement mechanics and transfer procedures.

For busy DPOs and in-house counsel, three actions cover most of the risk: map every processing activity to the correct law (or both), verify your cross-border transfer mechanisms against 2026 requirements, and align your documentation so a single set of records satisfies the stricter of the two regimes. Where you need Swiss-qualified support, our directory of Data privacy lawyers in Switzerland can help you locate counsel and DPO services quickly.

Quick facts and executive summary

The FADP is Switzerland’s primary data protection statute. The revised version, together with its implementing Ordinance (the DPO/OPDo), modernised Swiss law and brought it substantially closer to the European standard, which was essential to maintaining the free flow of data between Switzerland and the EU. GDPR, by contrast, is a directly applicable EU regulation with a broad extraterritorial reach that can catch Swiss and other non-EU organisations.

Understanding GDPR vs FADP Switzerland begins with a few high-level points:

  • Both regimes can apply simultaneously. A Swiss company selling to EU consumers is subject to the FADP for its Swiss activities and GDPR for its EU-facing ones.
  • Scope of protected persons differs. The revised FADP now protects only the data of natural persons, having removed the earlier protection of legal persons, aligning with GDPR’s exclusive focus on natural persons.
  • Enforcement architecture differs. GDPR relies on administrative fines against organisations; Swiss law leans on criminal liability that can target responsible individuals.
  • Switzerland benefits from EU adequacy, which keeps EU-to-Switzerland transfers straightforward, but transfers onward from Switzerland to third countries still require their own analysis.

The consolidated comparison table further down this page sets out the differences row by row, with references to the underlying provisions so you can verify each point against primary sources.

Does GDPR apply in Switzerland? Territorial scope explained

The single most common misconception in the GDPR vs FADP Switzerland debate is that a Swiss location shields you from GDPR. It does not. Territorial scope is activity-based, not purely geographic, and a Swiss-headquartered organisation can be squarely within GDPR’s reach.

GDPR territorial scope (Article 3), when non-EU entities are caught

GDPR Article 3 establishes two principal triggers. Under Article 3(1), the Regulation applies to processing carried out in the context of the activities of an establishment in the EU, regardless of where the processing itself occurs. Under Article 3(2), the extraterritorial limb, GDPR applies to controllers and processors not established in the EU where their processing relates to offering goods or services to data subjects in the EU (whether or not payment is required), or to monitoring the behaviour of data subjects that takes place within the EU.

The practical consequence is significant. A Swiss e-commerce business that advertises in euros, ships to EU addresses, or offers content in the languages of EU member states may be offering goods or services to EU data subjects and therefore caught by GDPR under Article 3(2). Similarly, a Swiss analytics or adtech provider tracking the behaviour of EU users may fall within the monitoring limb. The European Data Protection Board’s interpretive guidance on territorial scope confirms that mere accessibility of a website is not enough, but targeting factors, currency, language, delivery options and marketing, can collectively establish intent to offer to the EU market.

FADP territorial scope and key differences

The FADP applies to processing that has an effect in Switzerland, even where the processing is initiated abroad. This effects-based reach mirrors the logic of GDPR’s extraterritoriality: a foreign controller that targets Swiss data subjects or whose processing produces consequences in Switzerland can be subject to Swiss law. Foreign controllers may be required to designate a representative in Switzerland where they process the data of Swiss data subjects in connection with offering goods or services or monitoring behaviour, where such processing is large-scale, regular, and poses a high risk to data subjects, broadly comparable in logic to GDPR’s Article 27 representative obligation.

The core difference in the GDPR vs FADP Switzerland comparison at the scope level is jurisdictional: GDPR anchors on EU establishment or EU-directed activity, while the FADP anchors on effects felt within Switzerland. Where both connecting factors are present, an organisation targeting both markets, dual compliance is the realistic outcome.

Practical examples

  • Swiss-only startup. A SaaS company based in Zurich serving exclusively Swiss customers, with no EU targeting, is governed by the FADP and generally not by GDPR.
  • Swiss subsidiary of an EU controller. A Geneva subsidiary of a Paris-headquartered group processes data in the context of the EU establishment’s activities and will typically face both the FADP and GDPR.
  • EU company serving Swiss customers. A German retailer shipping to Swiss consumers is bound by GDPR for its EU establishment and by the FADP for its effects in Switzerland.

Direct legal comparison: definitions, legal bases and data-subject rights

Beyond scope, the substance of the two laws is where a GDPR vs FADP Switzerland analysis earns its keep. The regimes are structurally similar, deliberately so, but the differences change how you draft notices, record justifications and respond to requests.

Definitions, personal data and special categories

Both laws define personal data broadly as any information relating to an identified or identifiable person. A distinctive historical feature of Swiss law was its protection of legal persons’ data; the revised FADP removed this and now protects only natural persons, bringing it into line with GDPR. Both regimes recognise a heightened category of sensitive data, the FADP’s “sensitive personal data” and GDPR’s “special categories” under Article 9, covering information such as health, religious, philosophical or political views, trade-union activity, genetic and biometric data. The Swiss concept of sensitive data notably includes data on administrative or criminal proceedings and sanctions, and data on social assistance measures, reflecting Swiss legislative priorities.

Lawful bases for processing

This is one of the most consequential structural differences in the GDPR vs FADP Switzerland comparison. GDPR requires an affirmative legal basis under Article 6 for every processing operation, consent, contract, legal obligation, vital interests, public interest, or legitimate interests. Without one of these bases, processing is unlawful.

The FADP does not adopt the same “legal basis” architecture. Under Swiss law, private-sector processing of personal data is, in principle, permitted provided the general principles are respected, lawfulness, good faith, proportionality, purpose limitation and transparency. A justification (such as consent, an overriding private or public interest, or a legal basis) becomes necessary where processing breaches those principles, involves a breach of the data subject’s personality rights, disregards an express objection, or concerns sensitive data disclosed to third parties. The practical effect is that under GDPR you must identify a basis upfront and document it, whereas under the FADP the analysis is often framed around whether a specific justification is triggered.

For dual-regime organisations, the pragmatic approach is to satisfy the GDPR standard, identify and record a lawful basis for each activity, because doing so will generally satisfy the FADP as well.

Data-subject rights

Both regimes grant robust rights: access, rectification, erasure, restriction and objection. GDPR additionally provides a well-defined right to data portability under Article 20 and detailed rights regarding automated individual decision-making under Article 22. The revised FADP introduced its own data-portability right (the right to data disclosure or transfer) and rules on automated individual decisions, again converging toward the GDPR model. Timelines and formalities differ in detail, so response procedures should be built to the more demanding standard applicable to a given data subject. When comparing GDPR vs FADP Switzerland at the rights level, the safest operational posture is a unified subject-request workflow calibrated to GDPR’s tighter deadlines and documentation expectations.

Special categories and criminal offences

Both laws impose stricter conditions on sensitive data. GDPR sets out an exhaustive list of exceptions in Article 9(2) permitting the processing of special-category data. Swiss law requires particular care and, in many cases, explicit consent or another justification for sensitive data. The FADP’s inclusion of data on legal proceedings and sanctions within its sensitive category means that Swiss litigation, HR and compliance functions must treat such records with heightened protection that maps onto but is not identical to GDPR’s treatment of criminal-conviction data under Article 10.

Comparison table, FADP vs GDPR

Topic GDPR (EU) FADP (Switzerland) Practical implication
Territorial scope Art. 3, EU establishment, or offering goods/services to, or monitoring, EU data subjects Effects-based, applies to processing that produces effects in Switzerland, including from abroad Which law applies depends on establishment, target audience and where effects are felt; dual application is common
Protected persons Natural persons only Natural persons only (revised FADP removed the earlier protection of legal persons) Legal-person data no longer covered; review B2B data handling
Legal bases Affirmative basis required for all processing (Art. 6) Processing permitted if principles respected; justification needed for specific triggers Build to the GDPR standard to satisfy both regimes
Sensitive data Special categories (Art. 9); criminal data (Art. 10) Sensitive data includes health, beliefs, biometrics, plus legal-proceedings and social-assistance data Swiss sensitive-data scope is broader in places; adjust classification
DPO / representative DPO mandatory in defined cases (Art. 37); EU representative under Art. 27 Data protection advisor optional (with incentives); Swiss representative required for certain foreign controllers Assess triggers separately for each regime
Records of processing RoPA required, with SME exemption (Art. 30) Records required, with an exemption for smaller organisations Maintain a single RoPA meeting the stricter requirement
Breach notification To authority within 72 hours where feasible (Art. 33) To the FDPIC as soon as possible where high risk to data subjects Standardise on the fastest applicable timeline
Maximum sanctions Administrative fines up to EUR 20 million or 4% of global turnover Criminal fines against responsible individuals up to CHF 250,000 Different risk owners, organisation vs individual
Supervisory authority National data protection authorities; coordination via the EDPB Federal Data Protection and Information Commissioner (FDPIC) Engagement channels and enforcement style differ
Transfer regime Adequacy decisions, SCCs, BCRs, derogations Adequate-country list (in the Ordinance), SCCs, BCRs, contractual safeguards Run separate transfer analyses from each jurisdiction

Controllers, processors, DPOs and obligations

Operationally, the GDPR vs FADP Switzerland comparison converges most closely on the controller/processor relationship, but the details of documentation and appointments still diverge.

Controller and processor duties and contractual requirements

Both regimes require a written arrangement governing processing carried out by a processor on a controller’s behalf. GDPR’s Article 28 prescribes detailed mandatory content for data-processing agreements, including subject matter, duration, nature and purpose, obligations to process only on documented instructions, confidentiality, security, sub-processor authorisation, assistance with data-subject rights and breach handling, deletion or return of data, and audit rights. The FADP similarly requires that a processor process data only as the controller would be permitted to, that engagement is contractually or legally grounded, that no legal or contractual duty of confidentiality prohibits delegation, and that adequate security is ensured. Because GDPR’s clause requirements are more prescriptive, a single well-drafted DPA built to Article 28 will generally cover FADP expectations.

Where both laws apply, reference both regimes expressly in the agreement.

DPO requirement differences and practical triggers

GDPR mandates the appointment of a Data Protection Officer under Article 37 where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories or criminal data. Swiss law takes a different approach: appointing a data protection advisor (Datenschutzberater) is not generally mandatory for private organisations, but doing so brings procedural advantages, particularly in relation to data protection impact assessments. Foreign controllers processing the data of Swiss data subjects at scale may need a Swiss representative.

The practical takeaway is to run the GDPR DPO test and the Swiss representative and advisor analysis as separate exercises, since a mandatory GDPR DPO does not automatically create a mandatory Swiss appointment, and vice versa.

Record keeping, DPIAs and breach notification timelines

Both regimes require records of processing activities, subject to exemptions for smaller organisations, and both require a data protection impact assessment where processing is likely to result in high risk to data subjects. On breach notification, GDPR imposes a 72-hour notification obligation to the supervisory authority where feasible under Article 33. The FADP requires notification to the FDPIC as soon as possible where a breach is likely to result in a high risk to the personality or fundamental rights of data subjects. To avoid maintaining parallel playbooks, most dual-regime organisations standardise on the fastest and most demanding requirement.

Enforcement, fines and recent Swiss/EU trends in GDPR vs FADP Switzerland

The enforcement contrast is arguably the sharpest practical difference in the GDPR vs FADP Switzerland landscape, and it changes who bears personal exposure.

GDPR fines framework and notable EU decisions

GDPR empowers supervisory authorities to impose administrative fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements. Lower-tier infringements attract fines up to EUR 10 million or 2% of turnover. European authorities have issued substantial fines across the technology, adtech and financial sectors, and the EDPB coordinates consistent application across member states. The defining feature is corporate liability tied to turnover, which makes GDPR non-compliance a board-level financial risk.

FADP enforcement landscape

Switzerland deliberately chose a different enforcement model. Rather than large administrative fines against companies, the FADP provides for criminal fines of up to CHF 250,000 that can be imposed on the responsible individuals, for example, for intentional breaches of certain information, disclosure, diligence or duty-to-cooperate obligations. Such penalties are imposed by the competent cantonal criminal authorities, not by the FDPIC directly. The FDPIC supervises compliance, conducts investigations and can order corrective measures, but it does not levy GDPR-style turnover-based fines. This individual-liability design means Swiss compliance ownership must be clearly assigned, because the personal exposure of managers and responsible persons is real.

When weighing GDPR vs FADP Switzerland enforcement, boards should recognise that the Swiss risk is often more personal than corporate, while the EU risk is more financial and reputational at the entity level.

Cross-border data transfers and mechanisms for 2026

Transfers are where the GDPR vs FADP Switzerland comparison becomes most operationally intricate, because each jurisdiction runs its own assessment of destination countries and safeguards.

EU adequacy decision for Switzerland, implications

The European Commission recognises Switzerland as providing an adequate level of data protection. This adequacy status means personal data can flow from the EU to Switzerland without additional safeguards such as standard contractual clauses, treating Switzerland much like an EU destination for transfer purposes. Preserving this status was a central objective of the FADP revision, and it materially simplifies EU-to-Switzerland data flows. Importantly, adequacy addresses incoming transfers to Switzerland; onward transfers from Switzerland to other third countries still require a separate FADP transfer analysis.

Transfers to the US and the Swiss–US Data Privacy Framework

For transfers to the United States, the Swiss–U.S. Data Privacy Framework provides a mechanism enabling certified US organisations to receive personal data from Switzerland. Switzerland recognised the Swiss–U.S. Data Privacy Framework as providing adequate protection, with the FDPIC’s recognition taking effect in 2024. The framework operates through the Data Privacy Framework portal, where organisations self-certify and where data exporters can verify a recipient’s certification status. Swiss exporters should confirm that a US recipient’s certification expressly covers the Swiss–U.S. Data Privacy Framework before relying on it, and should document that verification. Where a recipient is not certified, alternative safeguards are required.

Use of SCCs, BCRs and technical and contractual safeguards

Where no adequacy finding or framework applies, both regimes permit transfers on the basis of appropriate safeguards, principally standard contractual clauses and binding corporate rules, supplemented where necessary by technical and organisational measures such as encryption and pseudonymisation. Under GDPR, transfer-impact assessments may be required to evaluate the destination country’s legal environment. Under the FADP, the FDPIC maintains guidance on transfers, and the Data Protection Ordinance sets out the list of states regarded as providing adequate protection. A short decision sequence helps:

  1. Is the destination on the applicable adequacy or adequate-country list? If yes, no additional mechanism is generally required.
  2. Is the recipient certified under the Data Privacy Framework (for US transfers)? If yes, verify and document the certification.
  3. If neither applies, implement SCCs or BCRs, conduct a transfer-impact assessment, and add technical safeguards as needed.

Practical compliance checklist for the GDPR vs FADP Switzerland environment

The following checklist converts the GDPR vs FADP Switzerland analysis into concrete tasks for DPOs, in-house counsel and founders.

Step-by-step compliance tasks

  1. Jurisdictional mapping. For each processing activity, determine whether GDPR, the FADP, or both apply based on establishment, targeting and effects.
  2. Records of processing (RoPA). Maintain a unified RoPA that meets the stricter documentation standard applicable to your activities.
  3. Legal-basis mapping. Identify and record a lawful basis for each GDPR activity and confirm FADP principles and justifications are satisfied.
  4. Data-processing agreements. Ensure every processor relationship has a DPA meeting Article 28 requirements and expressly covering FADP obligations where relevant.
  5. Transfer assessment. Inventory all cross-border flows and confirm each relies on adequacy, the Data Privacy Framework, SCCs or BCRs, with supporting assessments.
  6. Breach playbook. Adopt a single incident-response procedure aligned to the 72-hour GDPR deadline and FADP prompt-notification duty.
  7. DPO and representative analysis. Run the GDPR DPO test and the Swiss advisor/representative analysis separately.
  8. DPIAs. Establish a threshold process to trigger impact assessments for high-risk processing under both laws.
  9. Notices and rights workflows. Build subject-request handling to the more demanding regime and align privacy notices accordingly.
  10. Training and governance. Assign clear accountability, critical given the FADP’s individual criminal liability, and train staff on both regimes.

Sample DPA clause highlights and RoPA items to record

A DPA covering both regimes should address: documented-instructions processing, confidentiality, security measures, sub-processor authorisation and flow-down, assistance with data-subject rights and DPIAs, breach notification cooperation, deletion or return of data on termination, audit rights, and international-transfer safeguards. A RoPA should record: the controller and processor identities, purposes, categories of data subjects and data, recipients, transfers and their safeguards, retention periods, and a description of security measures. Templates covering Records of Processing under Swiss law will support this documentation as part of the wider compliance cluster.

Common pitfalls and enforcement risk scenarios

Recurring failures in the GDPR vs FADP Switzerland context tend to cluster around a few predictable weaknesses:

  • Mixing or misidentifying legal bases. Relying on consent where legitimate interests or contract is appropriate, or failing to record any basis, creates GDPR exposure and undermines FADP transparency.
  • Weak transfer arrangements. Assuming adequacy covers onward transfers, or relying on an uncertified US recipient under the Data Privacy Framework, leaves flows unlawful.
  • Poor supplier oversight. Missing or outdated DPAs and unmonitored sub-processors are a frequent enforcement trigger.
  • Unclear accountability. Because Swiss law can impose personal criminal liability, undefined ownership is a genuine risk to responsible individuals.

Mitigation is straightforward: keep documentation current, review transfers periodically, audit key processors, and assign named responsibility for each obligation.

Recommended next steps and when to consult counsel

To operationalise your GDPR vs FADP Switzerland strategy, run a jurisdictional mapping across all processing activities, update your data-processing agreements and RoPA, and reassess every cross-border transfer against 2026 requirements. Where processing is high-risk, complete a DPIA that satisfies both regimes. If you are unsure whether GDPR or the FADP applies to a particular activity, or need help implementing transfer safeguards, engage Swiss-qualified counsel early, our Data privacy lawyers in Switzerland can connect you with experts and DPO services.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.

Sources

  1. GDPR, Regulation (EU) 2016/679 (official text)
  2. European Commission, Adequacy decisions & international transfers
  3. Swiss Federal Data Protection and Information Commissioner (FDPIC)
  4. Federal Act on Data Protection (FADP), Fedlex
  5. European Data Protection Board (EDPB), guidelines and opinions
  6. U.S. Department of Commerce / Data Privacy Framework (DPF) portal

FAQs

What is the current data privacy law in Switzerland?
The primary law is the revised Federal Act on Data Protection (FADP), in force since 1 September 2023, supplemented by its implementing Data Protection Ordinance and sector-specific rules. The revision modernised Swiss data protection and aligned it substantially with GDPR to preserve EU adequacy, while retaining distinct Swiss features such as criminal enforcement.
Yes, in defined circumstances. Under Article 3 of GDPR, a Swiss organisation is caught where it has an EU establishment, offers goods or services to EU data subjects, or monitors their behaviour. A Swiss business targeting only Switzerland is generally governed by the FADP alone.
No. In the GDPR vs FADP Switzerland relationship the two laws coexist. GDPR is EU law with extraterritorial reach; the FADP is Switzerland’s national statute. Many organisations must comply with both simultaneously depending on their establishments, target markets and where processing effects are felt.
Use a recognised mechanism. If the US recipient is certified under the Swiss–U.S. Data Privacy Framework, verify its certification via the official portal and document it. Otherwise, rely on standard contractual clauses or binding corporate rules, add technical safeguards, and complete a transfer assessment.
Appointing a data protection advisor is generally optional for private organisations under the FADP, though it brings procedural advantages. This differs from GDPR, which mandates a DPO under Article 37 in defined cases. Foreign controllers processing the data of Swiss data subjects at scale may also need a Swiss representative.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

GDPR vs FADP Switzerland 2026: Key Differences, Applicability & Compliance Steps

Send welcome message

Custom Message