The New Swiss Data Protection Act 2023

With the revised Swiss Data Protection Act (revFADP), Swiss data protection law was adapted in 2023 to reflect changing conditions. At the same time, the revised law aims to align with the requirements of the EU General Data Protection Regulation (GDPR), so that Switzerland continues to be recognized by the EU as a third country with an adequate level of data protection, ensuring that cross-border data transfers remain possible.

Swiss companies must now prepare and are obliged to comply with the legal requirements immediately upon the revFADP’s entry into force. With the revFADP and the GDPR, data protection becomes a compliance factor for Swiss businesses. Non-compliance carries financial risks due to compensation claims from affected individuals and fines from supervisory authorities. To avoid unlawful corporate conduct and reduce liability risks, appropriate compliance measures must be developed and aligned with the company’s risk situation. OBSECOM GmbH supports you as a protection advisor in Switzerland in meeting your compliance obligations.

When does the revFADP come into effect?

The Swiss Parliament adopted the revFADP on September 25, 2020. For the new law to come into force, the provisions at ordinance level had to be specified by the Federal Council. The consultation period ended on October 14, 2021. The revFADP is now confirmed to enter into force on September 1, 2023.

What important changes must companies observe?

Art. 9 revFADP – When personal data is processed by processors, companies must ensure that processors are able to guarantee data security. Any subcontracting of data processing now requires approval from the controller. Data processing must be governed by contractual agreements with processors.

Art. 19 et seq. revFADP – New information obligations when collecting personal data
Affected individuals must be adequately informed via a privacy policy about the purposes of processing, any automated decision-making, and disclosures abroad. If personal data is collected from third parties, individuals must be informed about the data collection within one month. Companies must identify relevant processing activities and create appropriate privacy notices.

Art. 25 et seq. revFADP – Strengthening of data subjects’ rights
Companies should implement processes to respond to data subjects’ requests for information within 30 days. Incorrect personal data must be corrected where necessary, unnecessary data deleted, and automatically processed data disclosed or transferred upon request.

Art. 24 revFADP – Notification of data security breaches
Controllers must report data breaches to the Swiss Federal Data Protection and Information Commissioner (FDPIC) as soon as possible if the breach poses a high risk to data subjects. Companies should implement processes to detect data breaches and assess reporting obligations.

Art. 60 et seq. revFADP – Fines for violations of legal obligations
Intentional violations of due diligence, information, disclosure, and cooperation obligations can result in fines of up to CHF 250,000 for private individuals. Fines are not generally imposed on the company as a whole but rather directly target responsible individuals (e.g., CEO, CIO, or other key personnel).

Art. 10 revFADP – Data Protection Advisor in Switzerland
Companies may appoint a data protection advisor to support them in implementing and complying with data protection regulations. The advisor acts as a point of contact for both data subjects and data protection authorities. If an advisor is appointed, the company may benefit from certain reliefs in reporting obligations. OBSECOM GmbH, based in Stuttgart with a Swiss branch in Préverenges (VD), advises you as an external data protection advisor in implementing the revFADP.

Which compliance violations can result in criminal penalties??

Intentional disregard of the new data protection obligations can lead to criminal fines of up to CHF 250,000. Fines are not generally directed at the company itself, but rather at responsible individuals (e.g., CEO, CIO, or other executives). To avoid sanctions, the following areas must be implemented in a data protection-compliant manner:

  • Compliance with minimum data security requirements: Companies must take appropriate technical and organizational measures to protect data. The FDPIC may review relevant documentation in investigations of data protection violations.
  • Outsourcing data processing to processors must be contractually regulated. Companies must ensure that processors can guarantee data security.
  • Disclosure of personal data abroad is only permitted if appropriate data protection guarantees are in place.
  • Data subjects must be properly informed about the collection of personal data and any automated decision-making.
  • Companies must provide information about data processing upon request by data subjects.

What data protection processes should companies implement?

As part of their compliance obligations, companies must design suitable data protection processes. These include:

  • Establish procedures to detect, assess, and report data breaches.
  • Integrate data protection into the design of new business processes and document appropriately, in order to meet requirements for processing records, data subject information, and access rights.
  • Define responsibilities and raise employee awareness.
  • Monitor, classify, and prioritize compliance measures.

Corporate groups with international operations already face similar data protection requirements for affiliated entities within the EU and overseas. The revision of Swiss data protection law presents an opportunity to harmonize data protection structures within the group.

How can data protection advisors support compliance?

Appointing a data protection advisor is optional under the revFADP but offers benefits for companies with complex compliance requirements. The advisor serves as a point of contact for data subjects and authorities, works with the company’s compliance team, provides guidance on data protection issues, and ensures that data protection is considered in all compliance efforts. The advisor reviews personal data processing and recommends corrective actions. If a data protection impact assessment (DPIA) is required for high-risk processing, consultation with the FDPIC may be waived if a data protection advisor is involved.