Our Expert in Switzerland
No results available
GDPR vs FADP Switzerland is the defining compliance question for any business that handles personal data in or with the Swiss market in 2026, because two closely related but distinct regimes now govern how that data must be collected, processed and transferred. Switzerland’s revised Federal Act on Data Protection (revised FADP, in force since 1 September 2023) operates alongside the EU’s General Data Protection Regulation (GDPR), and many organisations fall under both at once. The purpose of this guide is practical: to help you determine which law applies, where the two diverge, and what concrete steps to take.
If you operate a Swiss company, an EU business serving Swiss customers, or a hybrid group spanning both, understanding GDPR vs FADP Switzerland is the foundation of a defensible compliance programme.
The short answer: GDPR has not replaced the FADP, and the FADP has not replaced GDPR. Both can apply to the same processing activity depending on where your organisation sits, who your data subjects are, and what you do with the data. The revised FADP is deliberately aligned with GDPR to preserve Switzerland’s EU adequacy status, but meaningful differences remain in scope, definitions, enforcement mechanics and transfer procedures.
For busy DPOs and in-house counsel, three actions cover most of the risk: map every processing activity to the correct law (or both), verify your cross-border transfer mechanisms against 2026 requirements, and align your documentation so a single set of records satisfies the stricter of the two regimes. Where you need Swiss-qualified support, our directory of Data privacy lawyers in Switzerland can help you locate counsel and DPO services quickly.
The FADP is Switzerland’s primary data protection statute. The revised version, together with its implementing Ordinance (the DPO/OPDo), modernised Swiss law and brought it substantially closer to the European standard, which was essential to maintaining the free flow of data between Switzerland and the EU. GDPR, by contrast, is a directly applicable EU regulation with a broad extraterritorial reach that can catch Swiss and other non-EU organisations.
Understanding GDPR vs FADP Switzerland begins with a few high-level points:
The consolidated comparison table further down this page sets out the differences row by row, with references to the underlying provisions so you can verify each point against primary sources.
The single most common misconception in the GDPR vs FADP Switzerland debate is that a Swiss location shields you from GDPR. It does not. Territorial scope is activity-based, not purely geographic, and a Swiss-headquartered organisation can be squarely within GDPR’s reach.
GDPR Article 3 establishes two principal triggers. Under Article 3(1), the Regulation applies to processing carried out in the context of the activities of an establishment in the EU, regardless of where the processing itself occurs. Under Article 3(2), the extraterritorial limb, GDPR applies to controllers and processors not established in the EU where their processing relates to offering goods or services to data subjects in the EU (whether or not payment is required), or to monitoring the behaviour of data subjects that takes place within the EU.
The practical consequence is significant. A Swiss e-commerce business that advertises in euros, ships to EU addresses, or offers content in the languages of EU member states may be offering goods or services to EU data subjects and therefore caught by GDPR under Article 3(2). Similarly, a Swiss analytics or adtech provider tracking the behaviour of EU users may fall within the monitoring limb. The European Data Protection Board’s interpretive guidance on territorial scope confirms that mere accessibility of a website is not enough, but targeting factors, currency, language, delivery options and marketing, can collectively establish intent to offer to the EU market.
The FADP applies to processing that has an effect in Switzerland, even where the processing is initiated abroad. This effects-based reach mirrors the logic of GDPR’s extraterritoriality: a foreign controller that targets Swiss data subjects or whose processing produces consequences in Switzerland can be subject to Swiss law. Foreign controllers may be required to designate a representative in Switzerland where they process the data of Swiss data subjects in connection with offering goods or services or monitoring behaviour, where such processing is large-scale, regular, and poses a high risk to data subjects, broadly comparable in logic to GDPR’s Article 27 representative obligation.
The core difference in the GDPR vs FADP Switzerland comparison at the scope level is jurisdictional: GDPR anchors on EU establishment or EU-directed activity, while the FADP anchors on effects felt within Switzerland. Where both connecting factors are present, an organisation targeting both markets, dual compliance is the realistic outcome.
Beyond scope, the substance of the two laws is where a GDPR vs FADP Switzerland analysis earns its keep. The regimes are structurally similar, deliberately so, but the differences change how you draft notices, record justifications and respond to requests.
Both laws define personal data broadly as any information relating to an identified or identifiable person. A distinctive historical feature of Swiss law was its protection of legal persons’ data; the revised FADP removed this and now protects only natural persons, bringing it into line with GDPR. Both regimes recognise a heightened category of sensitive data, the FADP’s “sensitive personal data” and GDPR’s “special categories” under Article 9, covering information such as health, religious, philosophical or political views, trade-union activity, genetic and biometric data. The Swiss concept of sensitive data notably includes data on administrative or criminal proceedings and sanctions, and data on social assistance measures, reflecting Swiss legislative priorities.
This is one of the most consequential structural differences in the GDPR vs FADP Switzerland comparison. GDPR requires an affirmative legal basis under Article 6 for every processing operation, consent, contract, legal obligation, vital interests, public interest, or legitimate interests. Without one of these bases, processing is unlawful.
The FADP does not adopt the same “legal basis” architecture. Under Swiss law, private-sector processing of personal data is, in principle, permitted provided the general principles are respected, lawfulness, good faith, proportionality, purpose limitation and transparency. A justification (such as consent, an overriding private or public interest, or a legal basis) becomes necessary where processing breaches those principles, involves a breach of the data subject’s personality rights, disregards an express objection, or concerns sensitive data disclosed to third parties. The practical effect is that under GDPR you must identify a basis upfront and document it, whereas under the FADP the analysis is often framed around whether a specific justification is triggered.
For dual-regime organisations, the pragmatic approach is to satisfy the GDPR standard, identify and record a lawful basis for each activity, because doing so will generally satisfy the FADP as well.
Both regimes grant robust rights: access, rectification, erasure, restriction and objection. GDPR additionally provides a well-defined right to data portability under Article 20 and detailed rights regarding automated individual decision-making under Article 22. The revised FADP introduced its own data-portability right (the right to data disclosure or transfer) and rules on automated individual decisions, again converging toward the GDPR model. Timelines and formalities differ in detail, so response procedures should be built to the more demanding standard applicable to a given data subject. When comparing GDPR vs FADP Switzerland at the rights level, the safest operational posture is a unified subject-request workflow calibrated to GDPR’s tighter deadlines and documentation expectations.
Both laws impose stricter conditions on sensitive data. GDPR sets out an exhaustive list of exceptions in Article 9(2) permitting the processing of special-category data. Swiss law requires particular care and, in many cases, explicit consent or another justification for sensitive data. The FADP’s inclusion of data on legal proceedings and sanctions within its sensitive category means that Swiss litigation, HR and compliance functions must treat such records with heightened protection that maps onto but is not identical to GDPR’s treatment of criminal-conviction data under Article 10.
| Topic | GDPR (EU) | FADP (Switzerland) | Practical implication |
|---|---|---|---|
| Territorial scope | Art. 3, EU establishment, or offering goods/services to, or monitoring, EU data subjects | Effects-based, applies to processing that produces effects in Switzerland, including from abroad | Which law applies depends on establishment, target audience and where effects are felt; dual application is common |
| Protected persons | Natural persons only | Natural persons only (revised FADP removed the earlier protection of legal persons) | Legal-person data no longer covered; review B2B data handling |
| Legal bases | Affirmative basis required for all processing (Art. 6) | Processing permitted if principles respected; justification needed for specific triggers | Build to the GDPR standard to satisfy both regimes |
| Sensitive data | Special categories (Art. 9); criminal data (Art. 10) | Sensitive data includes health, beliefs, biometrics, plus legal-proceedings and social-assistance data | Swiss sensitive-data scope is broader in places; adjust classification |
| DPO / representative | DPO mandatory in defined cases (Art. 37); EU representative under Art. 27 | Data protection advisor optional (with incentives); Swiss representative required for certain foreign controllers | Assess triggers separately for each regime |
| Records of processing | RoPA required, with SME exemption (Art. 30) | Records required, with an exemption for smaller organisations | Maintain a single RoPA meeting the stricter requirement |
| Breach notification | To authority within 72 hours where feasible (Art. 33) | To the FDPIC as soon as possible where high risk to data subjects | Standardise on the fastest applicable timeline |
| Maximum sanctions | Administrative fines up to EUR 20 million or 4% of global turnover | Criminal fines against responsible individuals up to CHF 250,000 | Different risk owners, organisation vs individual |
| Supervisory authority | National data protection authorities; coordination via the EDPB | Federal Data Protection and Information Commissioner (FDPIC) | Engagement channels and enforcement style differ |
| Transfer regime | Adequacy decisions, SCCs, BCRs, derogations | Adequate-country list (in the Ordinance), SCCs, BCRs, contractual safeguards | Run separate transfer analyses from each jurisdiction |
Operationally, the GDPR vs FADP Switzerland comparison converges most closely on the controller/processor relationship, but the details of documentation and appointments still diverge.
Both regimes require a written arrangement governing processing carried out by a processor on a controller’s behalf. GDPR’s Article 28 prescribes detailed mandatory content for data-processing agreements, including subject matter, duration, nature and purpose, obligations to process only on documented instructions, confidentiality, security, sub-processor authorisation, assistance with data-subject rights and breach handling, deletion or return of data, and audit rights. The FADP similarly requires that a processor process data only as the controller would be permitted to, that engagement is contractually or legally grounded, that no legal or contractual duty of confidentiality prohibits delegation, and that adequate security is ensured. Because GDPR’s clause requirements are more prescriptive, a single well-drafted DPA built to Article 28 will generally cover FADP expectations.
Where both laws apply, reference both regimes expressly in the agreement.
GDPR mandates the appointment of a Data Protection Officer under Article 37 where processing is carried out by a public authority, where core activities require regular and systematic large-scale monitoring, or where core activities involve large-scale processing of special categories or criminal data. Swiss law takes a different approach: appointing a data protection advisor (Datenschutzberater) is not generally mandatory for private organisations, but doing so brings procedural advantages, particularly in relation to data protection impact assessments. Foreign controllers processing the data of Swiss data subjects at scale may need a Swiss representative.
The practical takeaway is to run the GDPR DPO test and the Swiss representative and advisor analysis as separate exercises, since a mandatory GDPR DPO does not automatically create a mandatory Swiss appointment, and vice versa.
Both regimes require records of processing activities, subject to exemptions for smaller organisations, and both require a data protection impact assessment where processing is likely to result in high risk to data subjects. On breach notification, GDPR imposes a 72-hour notification obligation to the supervisory authority where feasible under Article 33. The FADP requires notification to the FDPIC as soon as possible where a breach is likely to result in a high risk to the personality or fundamental rights of data subjects. To avoid maintaining parallel playbooks, most dual-regime organisations standardise on the fastest and most demanding requirement.
The enforcement contrast is arguably the sharpest practical difference in the GDPR vs FADP Switzerland landscape, and it changes who bears personal exposure.
GDPR empowers supervisory authorities to impose administrative fines of up to EUR 20 million or 4% of total worldwide annual turnover, whichever is higher, for the most serious infringements. Lower-tier infringements attract fines up to EUR 10 million or 2% of turnover. European authorities have issued substantial fines across the technology, adtech and financial sectors, and the EDPB coordinates consistent application across member states. The defining feature is corporate liability tied to turnover, which makes GDPR non-compliance a board-level financial risk.
Switzerland deliberately chose a different enforcement model. Rather than large administrative fines against companies, the FADP provides for criminal fines of up to CHF 250,000 that can be imposed on the responsible individuals, for example, for intentional breaches of certain information, disclosure, diligence or duty-to-cooperate obligations. Such penalties are imposed by the competent cantonal criminal authorities, not by the FDPIC directly. The FDPIC supervises compliance, conducts investigations and can order corrective measures, but it does not levy GDPR-style turnover-based fines. This individual-liability design means Swiss compliance ownership must be clearly assigned, because the personal exposure of managers and responsible persons is real.
When weighing GDPR vs FADP Switzerland enforcement, boards should recognise that the Swiss risk is often more personal than corporate, while the EU risk is more financial and reputational at the entity level.
Transfers are where the GDPR vs FADP Switzerland comparison becomes most operationally intricate, because each jurisdiction runs its own assessment of destination countries and safeguards.
The European Commission recognises Switzerland as providing an adequate level of data protection. This adequacy status means personal data can flow from the EU to Switzerland without additional safeguards such as standard contractual clauses, treating Switzerland much like an EU destination for transfer purposes. Preserving this status was a central objective of the FADP revision, and it materially simplifies EU-to-Switzerland data flows. Importantly, adequacy addresses incoming transfers to Switzerland; onward transfers from Switzerland to other third countries still require a separate FADP transfer analysis.
For transfers to the United States, the Swiss–U.S. Data Privacy Framework provides a mechanism enabling certified US organisations to receive personal data from Switzerland. Switzerland recognised the Swiss–U.S. Data Privacy Framework as providing adequate protection, with the FDPIC’s recognition taking effect in 2024. The framework operates through the Data Privacy Framework portal, where organisations self-certify and where data exporters can verify a recipient’s certification status. Swiss exporters should confirm that a US recipient’s certification expressly covers the Swiss–U.S. Data Privacy Framework before relying on it, and should document that verification. Where a recipient is not certified, alternative safeguards are required.
Where no adequacy finding or framework applies, both regimes permit transfers on the basis of appropriate safeguards, principally standard contractual clauses and binding corporate rules, supplemented where necessary by technical and organisational measures such as encryption and pseudonymisation. Under GDPR, transfer-impact assessments may be required to evaluate the destination country’s legal environment. Under the FADP, the FDPIC maintains guidance on transfers, and the Data Protection Ordinance sets out the list of states regarded as providing adequate protection. A short decision sequence helps:
The following checklist converts the GDPR vs FADP Switzerland analysis into concrete tasks for DPOs, in-house counsel and founders.
A DPA covering both regimes should address: documented-instructions processing, confidentiality, security measures, sub-processor authorisation and flow-down, assistance with data-subject rights and DPIAs, breach notification cooperation, deletion or return of data on termination, audit rights, and international-transfer safeguards. A RoPA should record: the controller and processor identities, purposes, categories of data subjects and data, recipients, transfers and their safeguards, retention periods, and a description of security measures. Templates covering Records of Processing under Swiss law will support this documentation as part of the wider compliance cluster.
Recurring failures in the GDPR vs FADP Switzerland context tend to cluster around a few predictable weaknesses:
Mitigation is straightforward: keep documentation current, review transfers periodically, audit key processors, and assign named responsibility for each obligation.
To operationalise your GDPR vs FADP Switzerland strategy, run a jurisdictional mapping across all processing activities, update your data-processing agreements and RoPA, and reassess every cross-border transfer against 2026 requirements. Where processing is high-risk, complete a DPIA that satisfies both regimes. If you are unsure whether GDPR or the FADP applies to a particular activity, or need help implementing transfer safeguards, engage Swiss-qualified counsel early, our Data privacy lawyers in Switzerland can connect you with experts and DPO services.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Alexandros Manousakis at Privintelligent Solutions, a member of the Global Law Experts network.
posted 17 minutes ago
posted 37 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message