Custodos is live – all leading AI models, securely hosted in the EU or Switzerland.Start free trial
All articles
Data protectionUpdated on 26 July 20268 min readCustodos editorial team

The revFADP explained: Switzerland's revised data protection act

The revised Federal Act on Data Protection (revFADP) is the Swiss federal data protection act (FADP, SR 235.1) in the version that has applied since 1 September 2023. It governs how companies may process the personal data of natural persons, and it entered into force without a transition period: the duties applied from day one.

The revFADP brings Swiss data protection law to a level the EU recognises as equivalent. Its architecture follows the same logic as the GDPR – principles, data subject rights, documentation duties, rules for disclosure abroad. The differences sit in the detail, and that is exactly where they determine what a company actually has to do.

For AI deployment the revFADP is the central framework: every input into an AI tool is a processing operation as soon as it contains personal data. Companies that also serve clients in the EU meet the GDPR in parallel – both regimes can be covered by one common concept rather than built twice.

Who the revFADP applies to

The revFADP covers the processing of personal data of natural persons by private persons and federal bodies. Unlike the old act, it no longer protects legal entities: data about a company as such falls outside its scope.

The decisive test is the effects principle. The act also captures companies established abroad, provided their processing has an effect in Switzerland. A German provider serving Swiss clients is therefore subject to both regimes. Companies without a Swiss establishment must, under certain conditions, additionally designate a representative in Switzerland.

The core duties at a glance

The revFADP builds on the principles in Art. 6 FADP: lawfulness, good faith, proportionality, purpose limitation, accuracy and data security. Six concrete duties follow from them.

  • Duty to inform (Art. 19 FADP): data subjects must be informed at collection about the purpose, the controller and the categories of recipients – usually through the privacy policy.
  • Record of processing activities (Art. 12 FADP): documentation of which data is processed for what purpose. Companies with fewer than 250 employees are exempt, provided their processing does not carry a high risk.
  • Notification duty (Art. 24 FADP): breaches of data security likely to result in a high risk must be reported to the FDPIC as quickly as possible.
  • Data protection impact assessment (Art. 22 FADP): mandatory where processing is likely to entail a high risk to personality or fundamental rights.
  • Privacy by design and by default (Art. 7 FADP): data protection must be built in technically and organisationally, not configured afterwards.
  • Right of access (Art. 25 FADP): data subjects may request information about the processing of their data; the response is generally due within 30 days and free of charge.

revFADP and GDPR: the differences that create work

Companies that have already implemented the GDPR satisfy a large part of the revFADP along the way. Four differences nevertheless need separate attention.

revFADP (Switzerland)GDPR (EU)
Fine is directed atThe responsible natural personThe company
MaximumUp to CHF 250,000Up to 20 million euros or 4 per cent of global annual turnover
Breach notificationAs quickly as possible, to the FDPICWithin 72 hours, to the competent supervisory authority
Justifying the processingProcessing is permitted in principle; a justification is only needed once there is an infringement of personalityEvery processing operation needs a legal basis under Art. 6 GDPR from the outset
Data protection adviser or officerVoluntary; designating one brings procedural reliefMandatory in the cases set out in Art. 37 GDPR

Fines: who is liable and how much

The criminal provisions sit in Art. 60 et seq. FADP. What is fined are intentional breaches of specific duties – for example the duties to inform and to provide access, the duties of care when disclosing data abroad, or orders issued by the FDPIC. Negligence is not punishable.

The addressee is the responsible natural person, not the company. Fines of up to CHF 250,000 are possible. The act allows the company to be fined up to CHF 50,000 instead, where identifying the responsible individual would require disproportionate effort.

Unlike in the EU, the supervisory authority does not impose the fine: the FDPIC investigates and orders measures, while prosecution sits with the cantonal criminal authorities. In practice this pushes one question to the front – who inside the company is responsible for data protection decisions, and is that documented?

Sensitive personal data

Art. 5 FADP lists which data counts as sensitive: data on religious, ideological, political or trade union views and activities, data on health, the intimate sphere or belonging to a race or ethnicity, genetic data, biometric data that uniquely identifies a natural person, data on administrative and criminal proceedings, and data on social assistance measures.

Organisations processing such data – medical practices, recruitment consultancies, social authorities, law firms – need explicit consent in more situations and must size their technical safeguards accordingly. The threshold for a data protection impact assessment is also reached sooner.

Disclosure abroad: where data may sit

Art. 16 FADP permits personal data to be disclosed abroad where the Federal Council has determined that the state concerned ensures adequate protection. The list of those states sits in Annex 1 to the Data Protection Ordinance and includes the entire European Economic Area.

Absent such a decision, one of the safeguards in Art. 16 para. 2 FADP is required – in practice usually standard contractual clauses. For the United States the Federal Council has recognised the Swiss-U.S. Data Privacy Framework, but it only carries for companies certified under it.

For AI this produces a distinction that tenders often blur: the location of the data centre and the domicile of the provider are two separate questions. Both must be answered before personal data flows into a model.

What the revFADP means for AI

Switzerland has no dedicated AI act so far. General data protection law therefore applies to AI without restriction, as soon as a prompt or an attached document contains personal data. Five points are decisive.

  • Purpose limitation: data collected for handling a mandate or an order may not simply be reused to train a model.
  • Processing on behalf (Art. 9 FADP): using an AI provider requires a contract governing the processing, and the controller must satisfy itself that the provider ensures data security.
  • Disclosure abroad: the processing location of the model must be known and permissible under Art. 16 FADP.
  • Transparency: the privacy policy has to cover AI use where personal data is processed.
  • Control: employees' private AI accounts sit entirely outside the documentation and due diligence duties – from a revFADP perspective they are the hardest case.

Implementation in five steps

The order is deliberate: without an inventory, none of the duties that follow can be met cleanly.

  1. Inventory the processing: which personal data arises where, who accesses it, where does it sit? The record under Art. 12 FADP is useful even when the small-company exemption applies.
  2. Record the purposes and, where needed, the justifications for each processing operation, and flag sensitive data.
  3. Update the privacy policy and the information duties, including the service providers used and any transfer abroad.
  4. Review contracts with processors and add safeguards for disclosure abroad where necessary.
  5. Define the processes for data breaches and access requests: who reports, to whom, within what deadline, with what documentation?

Frequently asked questions

Does the revFADP apply to small companies too?

Yes. The revFADP sets no lower threshold. Companies with fewer than 250 employees are merely exempt from the record of processing activities, and only where their processing does not carry a high risk. Every other duty applies unchanged.

Do we need a data protection officer?

For private companies, designating a data protection adviser is voluntary in Switzerland. It does bring a concrete benefit: a company that designates an adviser and consults them may, under certain conditions, forgo consulting the FDPIC after a data protection impact assessment.

What happens if we breach the revFADP?

The FDPIC can open an investigation and order measures, such as adjusting or ceasing a processing operation. It does not impose fines itself. Prosecution sits with the cantonal authorities and is directed at the responsible natural person.

Is GDPR compliance enough for the revFADP?

Largely, but not entirely. The main differences are the addressee of the fine, the notification deadline for breaches and the structure of the justification regime. Companies already working to GDPR standards should close those specific gaps rather than build a second data protection framework.

May we use AI tools under the revFADP?

Yes. The revFADP does not prohibit AI; it sets requirements for it: purpose limitation, a contract with the processor, a clarified processing location, transparency and data security. What matters is that the processing stays documented and controllable.

Does the revFADP apply to companies based abroad?

Yes, where the processing has an effect in Switzerland. The effects principle also captures providers without a Swiss establishment. Under certain conditions they must additionally designate a representative in Switzerland.

Sources

Related reading

Bring AI into your company securely.

Try Custodos with your team – and see how quickly secure AI becomes productive.

Start free trial
  • Try it with the whole team
  • Set up in minutes
  • Productive from day one