Compliance Requirements under the Revised Swiss Data Protection Act (nFADP).

Switzerland is modernizing the Federal Act on Data Protection (nFADP) to adapt data protection to changing circumstances. At the same time, the revDPA aims to align with the requirements of the European General Data Protection Regulation (GDPR), ensuring that Switzerland continues to be recognized by the EU as a third country with an adequate level of data protection. This recognition is essential to maintain the free flow of personal data across borders. With the entry into force of the revDPA, companies are required to comply with the new legal provisions.

Swiss companies need to prepare now. With the nFADP and the GDPR, data protection becomes a compliance issue. Failure to comply with data protection regulations entails financial risks through claims for damages by data subjects and fines imposed by supervisory authorities. To prevent unlawful corporate conduct and reduce liability risks, appropriate compliance measures must be developed and aligned with the company’s risk profile.

Overview of Compliance Requirements

The most important new data protection obligations under the nFADP at a glance:

  • The minimum data security requirements set out in the Data Protection Ordinance (DPO) must be observed. Companies must implement appropriate technical and organizational measures to protect personal data. The Swiss Federal Data Protection and Information Commissioner (FDPIC) may access relevant documents to verify compliance during investigations of data protection breaches.
  • If data processing is outsourced to processors, a data processing agreement must be concluded before data is transferred. Companies must ensure that processors are capable of guaranteeing data security.
  • Personal data may only be disclosed abroad if adequate data protection safeguards are in place.
  • Data subjects must be adequately informed when their personal data is collected or when automated decision-making processes are used.
  • Companies must provide information to data subjects upon request about the processing of their data. This information must be provided within 30 days.
  • Maintain a record of processing activities, documenting the purposes of each data processing operation, retention periods, data disclosures abroad, and data recipients (e.g., processors). This record must be presented to the FDPIC upon request.
  • Conduct data protection impact assessments if data processing is likely to result in high risks to the rights and freedoms of data subjects Erstellen von Datenschutz-Folgenabschätzungen, wenn die Datenbearbeitung hohe Risiken für die Betroffenen zur Folge haben kann.
  • Report data breaches to the FDPIC if they present a high risk to the data subjects. The report should include details about the nature of the breach, its consequences, and the measures taken or planned. In addition, data subjects must be informed if necessary for their protection or if required by the FDPIC.

Companies Must Implement Appropriate Data Protection Processes. As part of their compliance obligations, companies are expected to design suitable data protection processes. These include

  • Establishing procedures for the detection, assessment, and reporting of data breaches.
  • Integrating data protection into the development of new business processes and documenting appropriately to fulfill record-keeping, information, and disclosure obligations.
  • Defining responsibilities and raising employee awareness.
  • Monitoring, classifying, and prioritizing compliance measures.

Corporate groups with an international focus must take into account comparable data protection requirements for affiliated companies within the EU and overseas. The data protection organization within the group should be harmonized as much as possible.

Data Protection Officers Support Compliance

Appointing a data protection officer (DPO) is optional under the NFADP but offers advantages for companies with complex compliance requirements. The DPO serves as a point of contact for data subjects and supervisory authorities. They collaborate with the company’s compliance team, advise on data protection matters, and ensure that data protection requirements are incorporated into all compliance measures. The DPO reviews the processing of personal data and recommends corrective actions. If a data protection impact assessment is required for high-risk data processing, the controller may forgo consultation with the FDPIC if a DPO is involved.