Switzerland is not in the EU, and the Federal Act on Data Protection (Swiss Data Protection Act) is not the GDPR. The revised FADP, which entered into force on 1 September 2023, was drafted deliberately to close much of the gap, partly to protect Switzerland’s EU adequacy status. It succeeded on the core architecture and left material differences in place.
The differences that matter operationally are the penalty structure, which targets individuals rather than companies, the narrower legal basis requirement, the absence of a mandatory DPO, the different breach notification threshold, and the treatment of legal entity data. The differences that matter strategically are the ones affecting AI deployment, where the FADP is technology-neutral and Switzerland has no equivalent to the EU AI Act.
This guide sets out the comparison in detail, covers the AI-specific implications of Swiss Data Protection Act, and explains what dual compliance requires in practice.
Key Definitions
| Term | Definition |
|---|---|
| FADP | Federal Act on Data Protection. Switzerland’s principal data protection statute |
| revFADP / nFADP | The revised FADP, in force since 1 September 2023 |
| DPO (Ordinance) | Data Protection Ordinance. The implementing ordinance to the FADP |
| FDPIC | Federal Data Protection and Information Commissioner. Switzerland’s supervisory authority |
| GDPR | Regulation (EU) 2016/679. The EU’s primary data protection law |
| Data protection advisor | The Swiss equivalent of a DPO. Voluntary for private sector organisations |
| Swiss representative | A Switzerland-established representative required of certain foreign controllers |
| Swiss-US DPF | Swiss-US Data Privacy Framework. In effect since 15 September 2024 |
| Adequacy | A determination that a third country provides sufficient data protection for transfers |
The Headline Position
Switzerland has held an EU adequacy decision since July 2000, one of the earliest granted. The revised FADP was drafted substantially to preserve it, and the European Commission has confirmed that Swiss law continues to provide adequacy following the revision.
The consequence for most organisations is that a GDPR-grade compliance programme carries over into Switzerland with a set of specific additions, commonly called Swiss add-ons, rather than requiring a separate parallel programme.
The reverse is not true. An FADP-compliant programme will fall short of GDPR in several areas.
Structural Comparison
| Feature | EU GDPR | Swiss FADP |
|---|---|---|
| Instrument type | Directly applicable EU regulation | Swiss federal statute plus ordinance |
| In force | 25 May 2018 | 1 September 2023 (revised version) |
| Supervisory authority | National DPAs, coordinated by EDPB | FDPIC |
| Scope of protected data | Natural persons only | Natural persons only (legal entity data removed in revision) |
| Deceased persons | Not covered | Not covered (changed in revision) |
| Territorial scope | Extraterritorial under Article 3(2) | Extraterritorial, applies to processing with effect in Switzerland |
| Legal basis requirement | Article 6 lawful basis required for all processing | No general lawful basis requirement. Processing permitted unless it breaches personality rights |
| Consent | One of six lawful bases | Required only for specific processing types |
| DPO | Mandatory in defined circumstances | Voluntary data protection advisor |
| Representative | Required for non-EU controllers under Article 27 | Required for certain foreign controllers |
| Records of processing | Required under Article 30 | Required, with SME exemption under 250 employees |
| DPIA | Required for high-risk processing | Required where high risk to personality or fundamental rights |
| Breach notification | 72 hours where risk to rights and freedoms | As soon as possible where high risk to personality or fundamental rights |
| Penalties | Administrative fines on organisations, up to €20m or 4% turnover | Criminal fines on responsible individuals, up to CHF 250,000 |
The Six Differences That Matter Most
1. Penalties Fall on Individuals, Not Companies
This is the single most consequential structural difference and the one most often misunderstood.
The GDPR imposes administrative fines on organisations. A supervisory authority fines the controller or processor, and the penalty is calculated against corporate turnover. Under the FADP (Swiss Data Protection Act), sanctions are criminal, not administrative, and they attach to the responsible natural person rather than the company. The maximum is CHF 250,000.
Two consequences follow. First, the headline number looks small next to GDPR maximums, which leads some organisations to treat Swiss compliance as lower risk. That reading misses the point. A criminal penalty against a named individual, typically a director or the person responsible for the failing, is a materially different exposure from a corporate administrative fine.
Second, FADP criminal liability generally requires wilful conduct rather than negligence. The threshold for enforcement is higher, which means Swiss enforcement volume is lower and Swiss enforcement, when it comes, is more serious for the individual concerned.
| Feature | GDPR | FADP |
|---|---|---|
| Nature of penalty | Administrative | Criminal |
| Who is liable | The organisation | The responsible natural person |
| Maximum | €20m or 4% worldwide turnover | CHF 250,000 |
| Mental element | Strict, negligence sufficient | Generally requires wilful conduct |
| Enforced by | Supervisory authority | Cantonal criminal prosecution on FDPIC referral |
2. No General Lawful Basis Requirement
Under GDPR Article 6, every processing operation requires a lawful basis. There is no default permission. If you cannot identify consent, contract, legal obligation, vital interests, public task, or legitimate interests, you cannot process.
The FADP operates on the opposite default. Processing of personal data by private persons is permitted unless it unlawfully breaches the personality rights of the data subject. A justification is needed only where the processing does breach personality rights, for instance through processing against the data subject’s express wishes, disclosure of sensitive data to third parties, or processing contrary to the FADP’s principles.
This is a genuine structural difference, not a drafting variation. It means Swiss-only processing carries a lighter documentation burden. It also means an organisation that has built its records around GDPR lawful bases has done more than Swiss law requires, which is the correct direction of over-compliance.
3. The Data Protection Advisor Is Voluntary
GDPR Article 37 makes a DPO mandatory for public authorities, organisations carrying out large-scale systematic monitoring, and organisations processing special categories at scale.
The FADP provides for a data protection advisor under Article 10. For private sector organisations, appointment is voluntary. The incentive is procedural: a controller that has appointed an advisor and complied with the associated requirements can rely on an exemption from the obligation to consult the FDPIC following a DPIA that identifies high residual risk.
Federal bodies must appoint an advisor. Private organisations choose.
4. Breach Notification Uses a Different Threshold and No Fixed Deadline
GDPR Article 33 requires notification to the supervisory authority within 72 hours where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons.
The FADP requires notification to the FDPIC as soon as possible where a breach is likely to result in a high risk to the personality or fundamental rights of the data subject. Two differences: the threshold is high risk rather than risk, and there is no fixed hour count.
The practical effect is that the Swiss threshold catches fewer incidents but the absence of a defined deadline removes the certainty that a 72-hour clock provides. An organisation running both regimes should notify on the GDPR trigger and timeline, which will satisfy the Swiss requirement in nearly all cases.
| Feature | GDPR | FADP |
|---|---|---|
| Threshold for authority notification | Risk to rights and freedoms | High risk to personality or fundamental rights |
| Deadline | 72 hours | As soon as possible |
| Notification to data subjects | Where high risk | Where necessary for the data subject’s protection or on FDPIC request |
| Purpose of the notification | Regulatory oversight | Protection of the data subject |
5. Sensitive Data Is Defined Differently
Both regimes protect a category of particularly sensitive information, and the categories do not match exactly.
The revision expanded the Swiss definition to include genetic and biometric data uniquely identifying a natural person, aligning it more closely with GDPR Article 9. Differences remain in the treatment of data on administrative and criminal proceedings and sanctions, and on social assistance measures, which are sensitive under Swiss law in terms that do not map directly to the GDPR categories.
| Category | GDPR Article 9 | FADP |
|---|---|---|
| Racial or ethnic origin | Yes | Yes |
| Political opinions | Yes | Yes |
| Religious or philosophical beliefs | Yes | Yes |
| Trade union membership | Yes | Yes |
| Genetic data | Yes | Yes (added in revision) |
| Biometric data for identification | Yes | Yes (added in revision) |
| Health data | Yes | Yes |
| Sex life and sexual orientation | Yes | Yes |
| Administrative and criminal proceedings | Article 10, separate regime | Yes, within sensitive data |
| Social assistance measures | Not a distinct category | Yes |
6. Legal Entity Data Is No Longer Covered
The pre-revision FADP protected data relating to legal entities as well as natural persons, which was unusual internationally. The revision removed this. Swiss law now protects natural persons only, matching the GDPR position.
This is a rare case where the revision reduced Swiss protection rather than increasing it, and it simplifies dual compliance considerably for B2B organisations.
Cookies and Tracking
The two regimes take different starting positions on cookies, and this is where a single configuration deployed across both markets most often goes wrong.
The EU position under the ePrivacy Directive requires prior consent for all non-essential cookies, including analytics. Switzerland has no direct ePrivacy equivalent. The Swiss approach under the FADP and the Telecommunications Act is risk-based: opt-out is acceptable for lower-risk categories, while advertising and profiling cookies attract an expectation of opt-in.
FDPIC expectations for high-risk tracking have been converging on GDPR practice, so the gap is narrowing rather than widening. For organisations serving both audiences, a GDPR-grade consent baseline satisfies Switzerland. A Swiss-configured banner served to EU users does not satisfy the EU.
International Transfers
Both regimes restrict transfers to countries without adequate protection and both maintain adequacy lists. The Swiss list is maintained by the Federal Council, not the FDPIC, following the revision.
| Feature | GDPR | FADP |
|---|---|---|
| Adequacy determination | European Commission | Federal Council |
| EU/EEA status | Internal, no transfer restriction | On Swiss adequacy list |
| Switzerland status | EU adequacy decision since 2000, confirmed post-revision | Not applicable |
| Standard clauses | EU SCCs | FDPIC-recognised clauses, including EU SCCs with Swiss amendments |
| US transfers | EU-US Data Privacy Framework, under CJEU challenge | Swiss-US DPF, in effect since 15 September 2024 |
| Impact assessment | TIA required where SCCs used | Assessment of destination country protection required |
The Swiss-US Data Privacy Framework is a separate instrument from the EU-US framework, with its own certification list. A US recipient certified under the EU framework is not automatically covered for Swiss transfers unless it has also certified under the Swiss framework.
This distinction is worth checking carefully in 2026, given the EU-US framework’s exposure to the pending CJEU challenge. A collapse of the EU framework would not automatically invalidate the Swiss one, though it would put it under obvious pressure.
The Swiss Representative Requirement
The revised FADP introduced a requirement for certain foreign controllers to appoint a representative in Switzerland, mirroring the logic of GDPR Article 27.
The requirement applies where a controller outside Switzerland processes personal data of individuals in Switzerland, where the processing relates to offering goods or services or monitoring behaviour, where the processing is large-scale, where it occurs regularly, and where it presents a high risk to the data subject. The conditions are cumulative, which makes the Swiss requirement materially narrower than the GDPR equivalent.
| Feature | GDPR Article 27 | FADP Article 14 |
|---|---|---|
| Trigger | Offering goods or services to, or monitoring behaviour of, EU data subjects | Cumulative conditions including large scale, regular processing, and high risk |
| Scope | Broad | Narrow |
| Exemption | Occasional processing not including special category data at scale | Falls away if any cumulative condition is not met |
| Function | Point of contact for supervisory authorities and data subjects | Point of contact for FDPIC and data subjects, maintains processing register |
An organisation that needs a GDPR Article 27 representative will not necessarily need a Swiss one. The assessment must be run separately.
AI Implications: Where the Divergence Really Matters
This is the area where the gap between the two jurisdictions is widening rather than closing, and it has nothing to do with data protection law as such.
The FADP is technology-neutral. It contains no AI-specific provisions and Switzerland has not enacted an AI statute comparable to the EU AI Act. Swiss AI governance currently operates through the FADP’s general principles, sector regulation, and FINMA guidance for financial institutions.
The EU has built the AI Act on top of the GDPR. An organisation deploying a high-risk AI system to EU data subjects faces GDPR obligations and, separately, EU AI Act obligations covering risk management, data governance, technical documentation, human oversight, conformity assessment, and registration. The same system deployed to Swiss data subjects faces the FADP and nothing equivalent.
| AI governance element | EU | Switzerland |
|---|---|---|
| Comprehensive AI statute | EU AI Act, Regulation (EU) 2024/1689 | None |
| Risk classification requirement | Article 6, mandatory | None |
| High-risk system obligations | Chapters II and III | None |
| Conformity assessment | Article 43 | None |
| Technical documentation | Annex IV | None |
| Human oversight design | Article 14 | None as a standalone requirement |
| Automated decision-making | GDPR Article 22 and AI Act | FADP Article 21, right to object and request human review |
| DPIA for AI processing | Article 35 GDPR | Article 22 FADP where high risk to personality |
| AI literacy obligation | Article 4 EU AI Act, in force February 2025 | None |
Automated Decision-Making
The FADP does address automated individual decisions. Article 21 requires the controller to inform the data subject of a decision based exclusively on automated processing that has a legal effect or significantly affects them, and gives the data subject the right to request that the decision be reviewed by a natural person.
The structure differs from GDPR Article 22. The GDPR prohibits such decisions subject to three narrow exceptions. The FADP permits them subject to notification and a right to human review. The Swiss position is closer to the UK’s post-DUAA framework than to the EU’s.
For organisations deploying AI decisioning across both jurisdictions, this means the EU architecture is the binding constraint. A system designed for GDPR Article 22 and EU AI Act Article 14 compliance will satisfy FADP Article 21. A system designed to the Swiss standard will not survive EU scrutiny.
DPIAs for AI Systems
Under both regimes, a DPIA is required where processing is likely to create a high risk. The Swiss formulation is high risk to the personality or fundamental rights of the data subject.
AI use does not automatically trigger a DPIA under either regime. The relevant screening factors are the same in substance: sensitive or biometric data, profiling with significant effects, extensive monitoring, large-scale processing, and consequential automated assessment.
Where a DPIA identifies high residual risk, the GDPR requires prior consultation with the supervisory authority under Article 36. The FADP requires consultation with the FDPIC under Article 23, unless the controller has appointed a data protection advisor and sought that advisor’s opinion. This is the principal practical incentive for appointing an advisor in Switzerland.
Practical Guidance for Dual Compliance
The efficient posture for organisations operating in both jurisdictions is a GDPR baseline with Swiss add-ons, not two parallel programmes.
What carries over from a GDPR programme: processing principles, transparency and privacy notices, data subject rights handling, security measures, DPA structure under Article 28, DPIA methodology, records of processing, and breach response procedures.
What needs Swiss-specific attention: whether a Swiss representative is required under the cumulative Article 14 test, whether the Swiss-US DPF applies to your US recipients separately from the EU framework, whether the Swiss sensitive data categories capture anything your GDPR mapping missed, whether your privacy notice meets the Swiss active duty to inform, and whether to appoint a data protection advisor to secure the FDPIC consultation exemption.
What to be careful about: do not assume the lower Swiss penalty maximum means lower risk, because the liability attaches to individuals. Do not assume EU-US DPF certification covers Swiss transfers. Do not deploy a Swiss cookie configuration to EU users.