by Christophe Vallois
August 10, 2026
14 min read
What is the FADP? Definition and obligations for Swiss businesses
FADP: definition, differences from the GDPR, concrete obligations and penalties. The complete guide for Swiss businesses, explained simply.

TL;DR
The FADP (Federal Act on Data Protection), often called the nFADP in its revised form, is the Swiss law governing the processing of personal data. It came into force on September 1, 2023, replacing the old FADP and moving closer to the European GDPR, while keeping important Swiss specificities: it protects only natural persons, and its penalties, up to CHF 250,000, target the individually responsible person rather than the company. This article explains the definition, the concrete obligations and the risks of non-compliance.
Introduction
Any organisation that processes data of people located in Switzerland, Swiss or foreign, has been subject to the FADP since it came into force in September 2023. Yet the law remains widely misunderstood: confused with the GDPR, reduced to a compliance formality, or seen as a topic reserved for lawyers.
At Ketl, we have supported Swiss SMEs and regulated businesses with document-related compliance since 2019. This article explains what the FADP is, how it differs from the GDPR, who it concerns, and what concrete obligations it places on a business.
What is the FADP?
The FADP, Federal Act on Data Protection, is the law that governs the collection, processing and retention of personal data in Switzerland. Adopted by Parliament in autumn 2020 after a full revision, its revised version, often referred to as the nFADP, came into force on September 1, 2023, replacing the old law dating from the 1990s, which had become outdated given current digital practices.
This revision pursued two main goals: modernising data protection in light of technological change, and maintaining the compatibility of Swiss law with European law, GDPR included, to preserve the free flow of data between Switzerland and the European Union. That compatibility was confirmed by an adequacy decision from the European Commission, which nonetheless remains a reviewable political decision, not a permanent guarantee.
FADP and GDPR: the key differences
The FADP draws heavily on the GDPR, but differs on several concrete points worth knowing before any compliance effort.
The scope of protected individuals. The FADP protects only natural persons. The old Swiss law also covered legal entities (companies, associations), a protection that disappears with the revision, aligning Switzerland with the GDPR approach.
The nature of penalties. This is the most significant difference. The GDPR provides for administrative fines of up to €20 million or 4% of global annual turnover, aimed at the company as a legal entity. The FADP provides for criminal sanctions, aimed in principle at the individual natural person responsible for the breach, with a maximum fine of CHF 250,000, up from CHF 10,000 under the old law.
The breach notification deadline. The GDPR requires notification within 72 hours. The FADP requires notification "as soon as possible" (art. 24), a less rigid wording in the text, though it does not lessen the practical expectation of a rapid response.
The supervisory authority. In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) conducts investigations and can order measures, but does not itself impose fines: these fall to cantonal criminal authorities, acting on referral from the FDPIC.
| Criterion | GDPR | FADP |
|---|---|---|
| Protected individuals | Natural, and sometimes legal persons depending on the country | Natural persons only |
| Nature of penalties | Administrative, against the company | Criminal, against the responsible individual |
| Maximum fine | €20 million or 4% of global turnover | CHF 250,000 |
| Breach notification deadline | 72 hours | As soon as possible |
| Negligence punishable | Yes | No, only intent is punishable |
Who is subject to the FADP?
The FADP applies to any organisation, Swiss or foreign, that processes data of people located in Switzerland, regardless of where the processing actually takes place. This covers employees, clients, prospects, administered persons, as well as their processors and partners.
A foreign company that processes data of Swiss residents at scale, with no registered office or establishment in Switzerland, may need to appoint a representative in Switzerland depending on the circumstances. The extraterritorial reach of the law follows the same logic as the GDPR on this point.
The main obligations for a business
The register of processing activities
Art. 12 FADP requires keeping a register listing the personal data processing activities carried out. Businesses with fewer than 250 employees are generally exempt, unless they process sensitive data at scale or carry out high-risk profiling.
Privacy by design and by default
Art. 7 FADP enshrines the principles of Privacy by Design and Privacy by Default: data protection must be built in from the design stage of a processing activity or product, not added afterward.
Minimum security measures
Art. 8 FADP requires technical and organisational measures appropriate to the risk, to protect data against unauthorised access, loss or alteration.
The duty to inform
Art. 19 FADP requires informing data subjects when their data is collected: purpose of processing, identity of the controller, any recipients.
The data protection impact assessment
Art. 22 FADP requires an impact assessment when processing is likely to result in a high risk to the personality or fundamental rights of the individuals concerned.
Breach notification
Art. 24 FADP requires notifying the FDPIC, as soon as possible, of any data security breach likely to result in a high risk for the individuals concerned.
Rules for cross-border data transfers
Art. 16 and 17 FADP govern the disclosure of personal data abroad. Transfer to a country recognised as offering adequate protection, whose list is published by the Federal Council, remains possible without additional contractual safeguards. Switzerland and all EU countries appear on that list.
Penalties and risks of non-compliance
Art. 60 to 66 FADP define the criminal penalty regime. Three elements are worth retaining.
The amount. The maximum fine is CHF 250,000 per offence, up from CHF 10,000 under the old law.
The target. Unlike the GDPR, the sanction generally targets the individual natural person responsible for the breach within the organisation, not the company itself. This personal liability has direct consequences for the reputation and professional standing of the individual concerned. Under certain conditions, notably when the intended fine does not exceed CHF 50,000 and investigating a natural person would be disproportionate, the authority may convict the company instead.
The intent requirement. Only intentional violations are criminally punishable. Negligence, unlike under the GDPR, does not trigger a criminal penalty under the FADP, which obviously does not excuse careless data handling.
Worth noting: a criminal record entry becomes possible once a fine exceeds CHF 5,000, which clearly distinguishes the Swiss regime from a mere administrative sanction.
FADP and document management: the concrete link
Most FADP obligations translate, in practice, into documentary requirements: keeping an up-to-date register, proving that security measures are in place, quickly locating a person's data in response to an access or deletion request, documenting an impact assessment, notifying a breach with the necessary information gathered as soon as possible.
Document management scattered across email inboxes, local folders and spreadsheets makes these obligations hard to fulfil reliably. A DMS that automatically classifies documents, logs every access and every change, and retrieves information in seconds rather than hours, turns these theoretical obligations into a workable day-to-day process.
Ketl is designed FADP-native: hosting exclusively in Switzerland, a complete audit trail on every document, and automatic AI classification that simplifies keeping an up-to-date processing register.
In figures: Ketl processes over 46 million documents across 11 regulated sectors, with infrastructure and AI models hosted exclusively in Switzerland.
FAQ
What does FADP stand for?
FADP stands for Federal Act on Data Protection. Its revised version, often called the nFADP, is the Swiss law that came into force on September 1, 2023, governing the collection, processing and retention of personal data.
What is the difference between the FADP and the GDPR? The main difference lies in the nature of the penalties: the GDPR provides for administrative fines against the company, up to €20 million or 4% of global turnover. The FADP provides for criminal sanctions against the responsible individual, up to CHF 250,000. The FADP also protects only natural persons, unlike the old Swiss law, which also covered legal entities.
Is a foreign company subject to the FADP? Yes, if it processes data of people located in Switzerland, regardless of where the processing actually takes place. Depending on the scale of processing, a foreign company with no establishment in Switzerland may need to appoint a representative on Swiss territory.
Do all businesses need to keep a register of processing activities? No. Businesses with fewer than 250 employees are exempt, unless they process sensitive data at scale or carry out high-risk profiling.
Who can be convicted for a FADP violation? In principle, the individual natural person responsible for the breach within the company, for example an executive or the person designated as responsible for data protection. The company itself may be convicted instead of the individual under certain precise conditions, notably when the intended fine remains modest.
Conclusion
The FADP has governed the processing of personal data in Switzerland since September 2023, with an architecture close to the GDPR in substance, but concrete differences in the nature of penalties and the scope of protection. For a business, compliance depends less on a one-off legal reading than on document management capable of proving, at any moment, that obligations are genuinely being met.
The concrete next step: check whether your business already keeps an up-to-date register of processing activities, and whether you could respond within minutes to a data subject's access request. Both tests quickly reveal the real state of your compliance.
Written following a conversation with James McGill, co-founder of Ketl. Structured and optimised with Ketl AI, our sovereign AI hosted in Switzerland.
This article is for informational purposes and does not constitute legal advice. For a compliance analysis tailored to your situation, consult a specialist data protection advisor.
Sources:
- FADP — Federal Data Protection and Information Commissioner (FDPIC)
- Federal Act on Data Protection (FADP), SR 235.1 — Official Consolidated Text (Fedlex)
- Swiss Federal Act on Data Protection (FADP) Revisions Explained