Switzerland is not in the EU, and the Federal Act on Data Protection (Swiss Data Protection Act) is not the GDPR. The revised FADP, which entered into force on 1 September 2023, was drafted deliberately to close much of the gap, partly to protect Switzerland’s EU adequacy status. It succeeded on the core architecture and left material differences in place.

The differences that matter operationally are the penalty structure, which targets individuals rather than companies, the narrower legal basis requirement, the absence of a mandatory DPO, the different breach notification threshold, and the treatment of legal entity data. The differences that matter strategically are the ones affecting AI deployment, where the FADP is technology-neutral and Switzerland has no equivalent to the EU AI Act.

This guide sets out the comparison in detail, covers the AI-specific implications of Swiss Data Protection Act, and explains what dual compliance requires in practice.

Key Definitions

TermDefinition
FADPFederal Act on Data Protection. Switzerland’s principal data protection statute
revFADP / nFADPThe revised FADP, in force since 1 September 2023
DPO (Ordinance)Data Protection Ordinance. The implementing ordinance to the FADP
FDPICFederal Data Protection and Information Commissioner. Switzerland’s supervisory authority
GDPRRegulation (EU) 2016/679. The EU’s primary data protection law
Data protection advisorThe Swiss equivalent of a DPO. Voluntary for private sector organisations
Swiss representativeA Switzerland-established representative required of certain foreign controllers
Swiss-US DPFSwiss-US Data Privacy Framework. In effect since 15 September 2024
AdequacyA determination that a third country provides sufficient data protection for transfers

The Headline Position

Switzerland has held an EU adequacy decision since July 2000, one of the earliest granted. The revised FADP was drafted substantially to preserve it, and the European Commission has confirmed that Swiss law continues to provide adequacy following the revision.

The consequence for most organisations is that a GDPR-grade compliance programme carries over into Switzerland with a set of specific additions, commonly called Swiss add-ons, rather than requiring a separate parallel programme.

The reverse is not true. An FADP-compliant programme will fall short of GDPR in several areas.

Structural Comparison

FeatureEU GDPRSwiss FADP
Instrument typeDirectly applicable EU regulationSwiss federal statute plus ordinance
In force25 May 20181 September 2023 (revised version)
Supervisory authorityNational DPAs, coordinated by EDPBFDPIC
Scope of protected dataNatural persons onlyNatural persons only (legal entity data removed in revision)
Deceased personsNot coveredNot covered (changed in revision)
Territorial scopeExtraterritorial under Article 3(2)Extraterritorial, applies to processing with effect in Switzerland
Legal basis requirementArticle 6 lawful basis required for all processingNo general lawful basis requirement. Processing permitted unless it breaches personality rights
ConsentOne of six lawful basesRequired only for specific processing types
DPOMandatory in defined circumstancesVoluntary data protection advisor
RepresentativeRequired for non-EU controllers under Article 27Required for certain foreign controllers
Records of processingRequired under Article 30Required, with SME exemption under 250 employees
DPIARequired for high-risk processingRequired where high risk to personality or fundamental rights
Breach notification72 hours where risk to rights and freedomsAs soon as possible where high risk to personality or fundamental rights
PenaltiesAdministrative fines on organisations, up to €20m or 4% turnoverCriminal fines on responsible individuals, up to CHF 250,000

The Six Differences That Matter Most

1. Penalties Fall on Individuals, Not Companies

This is the single most consequential structural difference and the one most often misunderstood.

The GDPR imposes administrative fines on organisations. A supervisory authority fines the controller or processor, and the penalty is calculated against corporate turnover. Under the FADP (Swiss Data Protection Act), sanctions are criminal, not administrative, and they attach to the responsible natural person rather than the company. The maximum is CHF 250,000.

Two consequences follow. First, the headline number looks small next to GDPR maximums, which leads some organisations to treat Swiss compliance as lower risk. That reading misses the point. A criminal penalty against a named individual, typically a director or the person responsible for the failing, is a materially different exposure from a corporate administrative fine.

Second, FADP criminal liability generally requires wilful conduct rather than negligence. The threshold for enforcement is higher, which means Swiss enforcement volume is lower and Swiss enforcement, when it comes, is more serious for the individual concerned.

FeatureGDPRFADP
Nature of penaltyAdministrativeCriminal
Who is liableThe organisationThe responsible natural person
Maximum€20m or 4% worldwide turnoverCHF 250,000
Mental elementStrict, negligence sufficientGenerally requires wilful conduct
Enforced bySupervisory authorityCantonal criminal prosecution on FDPIC referral

2. No General Lawful Basis Requirement

Under GDPR Article 6, every processing operation requires a lawful basis. There is no default permission. If you cannot identify consent, contract, legal obligation, vital interests, public task, or legitimate interests, you cannot process.

The FADP operates on the opposite default. Processing of personal data by private persons is permitted unless it unlawfully breaches the personality rights of the data subject. A justification is needed only where the processing does breach personality rights, for instance through processing against the data subject’s express wishes, disclosure of sensitive data to third parties, or processing contrary to the FADP’s principles.

This is a genuine structural difference, not a drafting variation. It means Swiss-only processing carries a lighter documentation burden. It also means an organisation that has built its records around GDPR lawful bases has done more than Swiss law requires, which is the correct direction of over-compliance.

3. The Data Protection Advisor Is Voluntary

GDPR Article 37 makes a DPO mandatory for public authorities, organisations carrying out large-scale systematic monitoring, and organisations processing special categories at scale.

The FADP provides for a data protection advisor under Article 10. For private sector organisations, appointment is voluntary. The incentive is procedural: a controller that has appointed an advisor and complied with the associated requirements can rely on an exemption from the obligation to consult the FDPIC following a DPIA that identifies high residual risk.

Federal bodies must appoint an advisor. Private organisations choose.

4. Breach Notification Uses a Different Threshold and No Fixed Deadline

GDPR Article 33 requires notification to the supervisory authority within 72 hours where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons.

The FADP requires notification to the FDPIC as soon as possible where a breach is likely to result in a high risk to the personality or fundamental rights of the data subject. Two differences: the threshold is high risk rather than risk, and there is no fixed hour count.

The practical effect is that the Swiss threshold catches fewer incidents but the absence of a defined deadline removes the certainty that a 72-hour clock provides. An organisation running both regimes should notify on the GDPR trigger and timeline, which will satisfy the Swiss requirement in nearly all cases.

FeatureGDPRFADP
Threshold for authority notificationRisk to rights and freedomsHigh risk to personality or fundamental rights
Deadline72 hoursAs soon as possible
Notification to data subjectsWhere high riskWhere necessary for the data subject’s protection or on FDPIC request
Purpose of the notificationRegulatory oversightProtection of the data subject

5. Sensitive Data Is Defined Differently

Both regimes protect a category of particularly sensitive information, and the categories do not match exactly.

The revision expanded the Swiss definition to include genetic and biometric data uniquely identifying a natural person, aligning it more closely with GDPR Article 9. Differences remain in the treatment of data on administrative and criminal proceedings and sanctions, and on social assistance measures, which are sensitive under Swiss law in terms that do not map directly to the GDPR categories.

CategoryGDPR Article 9FADP
Racial or ethnic originYesYes
Political opinionsYesYes
Religious or philosophical beliefsYesYes
Trade union membershipYesYes
Genetic dataYesYes (added in revision)
Biometric data for identificationYesYes (added in revision)
Health dataYesYes
Sex life and sexual orientationYesYes
Administrative and criminal proceedingsArticle 10, separate regimeYes, within sensitive data
Social assistance measuresNot a distinct categoryYes

6. Legal Entity Data Is No Longer Covered

The pre-revision FADP protected data relating to legal entities as well as natural persons, which was unusual internationally. The revision removed this. Swiss law now protects natural persons only, matching the GDPR position.

This is a rare case where the revision reduced Swiss protection rather than increasing it, and it simplifies dual compliance considerably for B2B organisations.


Cookies and Tracking

The two regimes take different starting positions on cookies, and this is where a single configuration deployed across both markets most often goes wrong.

The EU position under the ePrivacy Directive requires prior consent for all non-essential cookies, including analytics. Switzerland has no direct ePrivacy equivalent. The Swiss approach under the FADP and the Telecommunications Act is risk-based: opt-out is acceptable for lower-risk categories, while advertising and profiling cookies attract an expectation of opt-in.

FDPIC expectations for high-risk tracking have been converging on GDPR practice, so the gap is narrowing rather than widening. For organisations serving both audiences, a GDPR-grade consent baseline satisfies Switzerland. A Swiss-configured banner served to EU users does not satisfy the EU.


International Transfers

Both regimes restrict transfers to countries without adequate protection and both maintain adequacy lists. The Swiss list is maintained by the Federal Council, not the FDPIC, following the revision.

FeatureGDPRFADP
Adequacy determinationEuropean CommissionFederal Council
EU/EEA statusInternal, no transfer restrictionOn Swiss adequacy list
Switzerland statusEU adequacy decision since 2000, confirmed post-revisionNot applicable
Standard clausesEU SCCsFDPIC-recognised clauses, including EU SCCs with Swiss amendments
US transfersEU-US Data Privacy Framework, under CJEU challengeSwiss-US DPF, in effect since 15 September 2024
Impact assessmentTIA required where SCCs usedAssessment of destination country protection required

The Swiss-US Data Privacy Framework is a separate instrument from the EU-US framework, with its own certification list. A US recipient certified under the EU framework is not automatically covered for Swiss transfers unless it has also certified under the Swiss framework.

This distinction is worth checking carefully in 2026, given the EU-US framework’s exposure to the pending CJEU challenge. A collapse of the EU framework would not automatically invalidate the Swiss one, though it would put it under obvious pressure.


The Swiss Representative Requirement

The revised FADP introduced a requirement for certain foreign controllers to appoint a representative in Switzerland, mirroring the logic of GDPR Article 27.

The requirement applies where a controller outside Switzerland processes personal data of individuals in Switzerland, where the processing relates to offering goods or services or monitoring behaviour, where the processing is large-scale, where it occurs regularly, and where it presents a high risk to the data subject. The conditions are cumulative, which makes the Swiss requirement materially narrower than the GDPR equivalent.

FeatureGDPR Article 27FADP Article 14
TriggerOffering goods or services to, or monitoring behaviour of, EU data subjectsCumulative conditions including large scale, regular processing, and high risk
ScopeBroadNarrow
ExemptionOccasional processing not including special category data at scaleFalls away if any cumulative condition is not met
FunctionPoint of contact for supervisory authorities and data subjectsPoint of contact for FDPIC and data subjects, maintains processing register

An organisation that needs a GDPR Article 27 representative will not necessarily need a Swiss one. The assessment must be run separately.


AI Implications: Where the Divergence Really Matters

This is the area where the gap between the two jurisdictions is widening rather than closing, and it has nothing to do with data protection law as such.

The FADP is technology-neutral. It contains no AI-specific provisions and Switzerland has not enacted an AI statute comparable to the EU AI Act. Swiss AI governance currently operates through the FADP’s general principles, sector regulation, and FINMA guidance for financial institutions.

The EU has built the AI Act on top of the GDPR. An organisation deploying a high-risk AI system to EU data subjects faces GDPR obligations and, separately, EU AI Act obligations covering risk management, data governance, technical documentation, human oversight, conformity assessment, and registration. The same system deployed to Swiss data subjects faces the FADP and nothing equivalent.

AI governance elementEUSwitzerland
Comprehensive AI statuteEU AI Act, Regulation (EU) 2024/1689None
Risk classification requirementArticle 6, mandatoryNone
High-risk system obligationsChapters II and IIINone
Conformity assessmentArticle 43None
Technical documentationAnnex IVNone
Human oversight designArticle 14None as a standalone requirement
Automated decision-makingGDPR Article 22 and AI ActFADP Article 21, right to object and request human review
DPIA for AI processingArticle 35 GDPRArticle 22 FADP where high risk to personality
AI literacy obligationArticle 4 EU AI Act, in force February 2025None

Automated Decision-Making

The FADP does address automated individual decisions. Article 21 requires the controller to inform the data subject of a decision based exclusively on automated processing that has a legal effect or significantly affects them, and gives the data subject the right to request that the decision be reviewed by a natural person.

The structure differs from GDPR Article 22. The GDPR prohibits such decisions subject to three narrow exceptions. The FADP permits them subject to notification and a right to human review. The Swiss position is closer to the UK’s post-DUAA framework than to the EU’s.

For organisations deploying AI decisioning across both jurisdictions, this means the EU architecture is the binding constraint. A system designed for GDPR Article 22 and EU AI Act Article 14 compliance will satisfy FADP Article 21. A system designed to the Swiss standard will not survive EU scrutiny.

DPIAs for AI Systems

Under both regimes, a DPIA is required where processing is likely to create a high risk. The Swiss formulation is high risk to the personality or fundamental rights of the data subject.

AI use does not automatically trigger a DPIA under either regime. The relevant screening factors are the same in substance: sensitive or biometric data, profiling with significant effects, extensive monitoring, large-scale processing, and consequential automated assessment.

Where a DPIA identifies high residual risk, the GDPR requires prior consultation with the supervisory authority under Article 36. The FADP requires consultation with the FDPIC under Article 23, unless the controller has appointed a data protection advisor and sought that advisor’s opinion. This is the principal practical incentive for appointing an advisor in Switzerland.


Practical Guidance for Dual Compliance

The efficient posture for organisations operating in both jurisdictions is a GDPR baseline with Swiss add-ons, not two parallel programmes.

What carries over from a GDPR programme: processing principles, transparency and privacy notices, data subject rights handling, security measures, DPA structure under Article 28, DPIA methodology, records of processing, and breach response procedures.

What needs Swiss-specific attention: whether a Swiss representative is required under the cumulative Article 14 test, whether the Swiss-US DPF applies to your US recipients separately from the EU framework, whether the Swiss sensitive data categories capture anything your GDPR mapping missed, whether your privacy notice meets the Swiss active duty to inform, and whether to appoint a data protection advisor to secure the FDPIC consultation exemption.

What to be careful about: do not assume the lower Swiss penalty maximum means lower risk, because the liability attaches to individuals. Do not assume EU-US DPF certification covers Swiss transfers. Do not deploy a Swiss cookie configuration to EU users.

Back to Blog