The new Federal Act on Data Protection, in force since 1 September 2023, applies to practically every Swiss company. Many SME owners discovered it at that moment, heard about six-figure fines, then set the topic aside for lack of knowing where to start.
This article answers the one question that really matters: what does this law concretely require from your company, and what can happen to you if you do nothing. If you would rather get an immediate answer, the “am I affected by the FADP?” test places you in five questions.
What did the law change for Swiss companies?
The previous act dated from 1992. It had been written before the consumer web, before the cloud, before smartphones. The revision pursues three goals: bringing Swiss law closer to the European GDPR, strengthening transparency towards the people concerned, and giving real means of sanction.
The change in philosophy is the most important point. The law no longer just asks you not to do wrong. It asks you to be able to demonstrate that you are doing things correctly: documenting your processing activities, informing individuals, securing your data with appropriate measures. This is what is called the accountability principle.
A clarification that often reassures: contrary to a widespread idea, the FADP does not require certification, no mandatory audit, and no prior declaration to an authority. There is no form to send in order to be compliant.
Is your company affected?
Yes, in almost every case. The law applies as soon as you process personal data, meaning any information relating to an identified or identifiable person.
This covers far more than what people usually imagine:
- the name and email address of a customer in your invoicing software;
- an employee’s file, their salary, their work certificates;
- the footage from your surveillance camera;
- the list of your business contacts in a CRM;
- job applications received for a position, even unsuccessful ones.
There is no headcount or turnover threshold. A sole proprietorship is subject to the law just as much as a group. What size changes is the level of measures that can reasonably be expected of you, not the fact of being affected.
One reservation concerns the public sector. Municipalities and cantonal public institutions do not fall under the federal law, but under their cantonal data protection act. An SME working for a public authority should therefore know this second regime, presented for the canton of Fribourg in our article on Fribourg’s cantonal LPrD and its service providers.
Many companies think they are subject to the GDPR because they have a website accessible from Europe. That is not enough. The GDPR applies if you actively target the European market: prices displayed in euros, delivery to the EU, a site translated for a European audience, targeted advertising. A French-speaking Swiss SME that sells only in Switzerland falls under the FADP alone.
The obligations that actually concern an SME
The text of the law has more than sixty articles. Here are the ones that produce concrete effects in an SME.
| Obligation | What it concretely means | Applies to |
|---|---|---|
| Informing individuals | A clear, accessible privacy policy stating who processes what, why, and where the data goes | All companies |
| Securing data | Technical and organisational measures proportionate to the risk: restricted access, backups, robust passwords | All companies |
| Reporting serious breaches | Notifying the FDPIC of any leak that presents a high risk to individuals | All companies |
| Responding to access requests | Providing a person, on request, with the data you hold on them, in principle within 30 days and free of charge | All companies |
| Keeping a processing register | Documenting your processing activities | From 250 employees, and certain SMEs |
| Impact assessment | Formally assessing the risks before a high-risk processing activity | Specific cases |
In practice, two obligations cause problems for SMEs: the register and breach reporting. Here they are in detail.
The processing register: the exemption and its two traps
This is the point that generates the most questions, and the answer is rather good news for SMEs.
Article 12(5) of the act instructs the Federal Council to provide exceptions for companies with fewer than 250 employees whose processing presents a limited risk. These conditions are set out in Article 24 of the Ordinance on Data Protection (DPO, SR 235.11).
In short: a company with fewer than 250 employees as of 1 January of the year is exempt from keeping a register, unless one of these two cases applies:
- it processes sensitive data on a large scale;
- it carries out high-risk profiling.
These two exceptions are alternative: either one alone is enough to remove the exemption.
Sensitive data notably includes health data, religious or political opinions, trade union membership, genetic and biometric data, and information on criminal or administrative proceedings.
A medical practice, a physiotherapy practice, a pension fund, a fiduciary handling debt-collection files, a placement agency: these SMEs regularly process sensitive data. The exemption probably does not apply to them, even with five employees. The 250-employee threshold is not the only criterion.
A common-sense remark: even when the exemption applies, keeping a summary register remains useful. It is a document of one or two pages that lists your processing activities, their purpose and your service providers. It helps you respond quickly in the event of an incident and to demonstrate your seriousness to a customer or an insurer.
What to do in the event of a data leak?
Article 24 of the act requires reporting to the FDPIC any data security violation that is likely to entail a high risk to the personality or fundamental rights of the individuals concerned.
Two major differences from the GDPR deserve to be known, because they are very often misreported.
There is no 72-hour deadline. Swiss law says “as soon as possible” and sets no number of hours. This does not mean you can wait: the standard remains demanding, and an unjustified delay would be held against you. But the mechanics of the European countdown do not exist here.
The triggering threshold is higher. The GDPR requires notification unless the risk is unlikely. Swiss law only requires it in the event of a high risk. In practice, far fewer incidents are reportable in Switzerland. An encrypted laptop lost with no possible access to the data generally does not trigger a reporting obligation.
Two additional points, often overlooked:
- If you are a processor acting on behalf of someone else, you must report any violation to your principal, with no risk-threshold condition.
- The report you make cannot be used against you in criminal proceedings without your consent (Art. 24(6)). The legislator wanted to avoid the fear of self-incrimination discouraging companies from reporting. This is an argument worth knowing when the question of reporting or not comes up internally.
The report is filed via the FDPIC’s dedicated portal. It describes the nature of the violation, its consequences and the measures taken. The full procedure is detailed in our article on reporting a data breach to the FDPIC.
What do you really risk?
This is where most of the misconceptions circulate. Here is what the text actually says.
Articles 60 to 63 of the act provide for a fine of up to CHF 250,000. It notably sanctions failing to inform individuals, transferring data abroad without a valid legal basis, entrusting processing to a processor without sufficient guarantees, or failing to meet the minimum data security requirements.
Three clarifications completely change the practical scope of this figure.
The fine targets the responsible individual, not the company. This is the most striking difference from the GDPR. The manager or employee at fault is personally sanctioned. This is one more reason for management to know the topic first-hand rather than through delegation, as we explain in training management first. An exception exists, however: when the envisaged fine does not exceed CHF 50,000 and identifying the responsible person would require disproportionate investigative measures, the authority can order the company to pay instead (Art. 64(2)).
Only intentional violations are punishable. Negligence is not criminally sanctioned. A good-faith mistake does not lead to a fine.
Prosecution mostly occurs on complaint for most offences. Someone, generally an affected individual, therefore has to file a complaint. The FDPIC can also open an investigation and issue binding decisions.
For a Swiss SME, the criminal sanction remains rare. The real risk lies elsewhere: the loss of your customers' trust after a leak, the contractual liability towards a client that imposed guarantees on you, and the business interruption when the incident hits your systems. Coming into compliance mainly protects against that.
Where to start, concretely
If you are starting from scratch, this order gives the best result for the time invested.
- Take an inventory of your data. Which tools contain personal data? Invoicing software, e-mail, CRM, cloud, badge system, cameras. One page is enough.
- Identify your service providers. Who hosts this data, and where? A provider located outside Switzerland or outside the EU requires particular attention.
- Write or update your privacy policy. It is the most visible obligation, the simplest to handle, and the first one your customers check.
- Secure access to the data. Two-factor authentication, removal of accounts of departed employees, tested backups. These are the measures the law expects behind the phrase “data security”, and they all appear in the 10 essential measures for an SME, whose implementation pace by company size is set out in the action plan by company size.
- Write down the procedure for a leak. Who decides, who reports, in what order. Two paragraphs are worth more than an improvisation on the day it happens.
- Check whether the register exemption really applies to you, particularly if you process health data or debt-collection data.
These steps largely overlap with the basic security measures expected of every company. Compliance with the law and protection against cyberattacks move forward together: the same measures serve both goals.
To place your company in three minutes, the cyber check-up covers these points as a series of questions and gives you a score with your three priorities. The other obligations applicable to Swiss companies are grouped in the Regulations pillar.