“Our website is reachable from Europe, so we are subject to GDPR.” This sentence comes up in almost every discussion with the owners of French-speaking Swiss SMEs. It is wrong in the vast majority of cases.
This confusion is costly. Some companies apply European rules that do not concern them, imposing unnecessary constraints on themselves. Others, conversely, genuinely target the European market without realising it, and overlook obligations that do apply to them.
This article clarifies two things: when each text applies, and what concretely changes between the two. If you are first looking for your detailed Swiss obligations, start instead with your FADP obligations.
The starting point: the FADP applies regardless
The first point worth establishing, because it avoids a lot of flawed reasoning: this is not a matter of choosing between two laws.
If your company is established in Switzerland and processes personal data, the new Federal Act on Data Protection applies. There is no threshold based on headcount or turnover. A sole proprietorship is covered in exactly the same way as a large group.
There is a third text that this two-way framing often makes people forget: cantonal laws, which govern municipalities and public institutions. They concern any SME that carries out a public task or supplies a public body, and the Fribourg case is covered in our article on the cantonal LPrD and its service providers.
The real question is therefore different. It is not “GDPR or FADP”, but “the FADP alone, or the FADP plus GDPR”. The two texts apply together whenever the conditions for the second one are met.
When does GDPR really apply to a Swiss company?
The European regulation can apply to a company with no establishment in the Union at all. Two situations are covered.
You offer goods or services to people in the Union. This is the most common scenario. The criterion is not whether your site is accessible, but your intention to target that market.
You monitor the behaviour of people in the Union. Typically tracking, advertising profiling, or behavioural analysis of internet users located in the EU.
The first point deserves examples, because that is where everything is decided.
The signs that show you are targeting the European market:
- you display your prices in euros, in addition to or instead of Swiss francs;
- you offer delivery to EU countries, with shipping costs set up for those destinations;
- your site is translated into a language aimed at a European audience, beyond Switzerland’s national languages;
- you run targeted advertising at internet users located in the EU;
- you mention European clients or references to court that market;
- you use a domain name or search engine optimisation aimed at an EU country.
Conversely, what is not enough: a site simply visible from abroad, an email address accessible from anywhere, a European customer who contacts you spontaneously on one occasion, or your company’s presence in international directories.
A carpenter in Fribourg with a French-language showcase site, working exclusively in French-speaking Switzerland: FADP alone. The fact that his site displays fine from Lyon changes nothing.
An online shop in Vaud that displays its prices in CHF and EUR and delivers to France and Germany: FADP and GDPR. It clearly targets the European market.
A consulting firm in Geneva that runs targeted LinkedIn advertising aimed at French executives: GDPR also applies, on the grounds of targeting.
A useful caveat: these criteria are assessed case by case, based on a combination of indicators. No single element taken in isolation is decisive. If your situation is ambiguous, particularly if only part of your activity is directed at Europe, have your analysis validated by a specialised lawyer.
The five differences that matter in practice
The two texts share the same general philosophy: transparency, proportionality, data security, and individual rights. The 2023 Swiss revision, in fact, deliberately brought the two regimes closer together.
But the gaps that remain are precisely the ones that show up on the day something goes wrong.
| Topic | FADP (Switzerland) | GDPR (European Union) |
|---|---|---|
| Breach reporting deadline | ”As soon as possible”, no fixed deadline (Art. 24 FADP) | 72 hours after becoming aware (Art. 33 GDPR) |
| Threshold triggering a report | Only if there is a high risk to individuals | Reporting is required unless the risk is unlikely |
| Target of the sanction | The individual responsible | The company |
| Maximum amount | CHF 250,000 (Art. 60 to 63 FADP) | Up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher |
| Subjective element | Only intentional violations are punishable | Negligence is also sanctionable |
| Method of prosecution | Most often upon complaint | Action by the supervisory authority |
| Register of processing activities | Exemption below 250 employees, with two exceptions | Narrower exemption, subject to cumulative conditions |
| Data protection officer | Optional for a private Swiss company | Mandatory in certain defined cases |
Do you have 72 hours to report a breach in Switzerland?
This is the point on which the most inaccurate claims circulate, including in documents sold as compliance templates.
Swiss law sets no 72-hour deadline. Article 24 FADP requires reporting to the FDPIC “as soon as possible”. Not 72 hours, not 24 hours, no figure at all. GDPR, by contrast, does impose notification within 72 hours of becoming aware of the violation, with a mandatory justification in case of delay.
This difference needs to be read correctly, because it is often misunderstood in both directions.
On one hand, “as soon as possible” does not mean you can wait. The standard remains demanding. You must act as soon as you have assessed the incident, and an unjustified delay would count against you. In practice, a well-organised company reports within a few days.
On the other, the absence of a countdown changes how you manage the first hours. Under GDPR, the pressure of the clock sometimes pushes companies to notify before they have understood the incident. In Switzerland, you have the time reasonably needed to establish the facts, assess the risk, and prepare a complete report.
The second difference is at least as important: the threshold. The FADP only requires reporting if the violation is likely to entail a high risk to the personality rights or fundamental rights of the individuals concerned. GDPR takes the opposite logic: you notify unless the risk is unlikely.
The consequence is very concrete. Far fewer incidents are reportable in Switzerland. A lost encrypted laptop, with no possible access to the data, generally does not trigger a reporting obligation under Swiss law, whereas the European reasoning starts from a stricter baseline. The full Swiss procedure is detailed in our article on reporting a data breach to the FDPIC.
Two points that hold true under both regimes: if you are a processor, you must report any violation to your principal, with no threshold condition. And the incidents concerned are primarily those described in our article on data theft and leaks.
Sanctions: two opposing philosophies
This is the deepest structural difference, and it explains a great many misunderstandings.
GDPR sanctions the company. Administrative fines can reach EUR 10 million or 2% of worldwide annual turnover for the less serious breaches, and EUR 20 million or 4% for the most serious ones, whichever amount is higher. The logic is deterrent and proportionate to the size of the organisation.
The FADP sanctions the individual responsible. The fine can reach CHF 250,000 under Articles 60 to 63 FADP, but it targets the executive or employee at fault, not the company. One exception exists: when the fine under consideration does not exceed CHF 50,000 and identifying the responsible individual would require disproportionate investigative measures, the authority can order the company to pay in their place (Art. 64 para. 2 FADP).
Two further filters reduce the practical scope of the Swiss figure even more. Only intentional violations are punishable: a good-faith mistake or negligence does not lead to a criminal fine. And prosecution most often happens upon complaint, which requires someone, usually a person concerned, to file one. The FDPIC can, in addition, open an investigation and issue binding decisions.
Comparing amounts gives a false sense of security. For a Swiss SME, criminal sanctions remain rare. The real risk lies elsewhere: the loss of your customers' trust after a breach, contractual liability towards a client who required guarantees from you, and business interruption. These three risks exist regardless of which text applies.
Do you need to keep a register of processing activities in Switzerland?
This is the difference that gives SMEs the most day-to-day relief.
Article 12 para. 5 FADP instructs the Federal Council to provide for exceptions for companies with fewer than 250 employees whose processing presents a limited risk. These conditions are set out in Article 24 of the Data Protection Ordinance.
In summary: a company with fewer than 250 employees on 1 January of the year is exempt from keeping a register, unless it processes sensitive data on a large scale or carries out high-risk profiling. These two exceptions are alternative: either one alone is enough to remove the exemption. A medical practice, a pension fund, or a fiduciary handling debt collection files are therefore covered, even with five employees.
Even when the exemption applies, keeping a brief one- or two-page register remains useful. It lets you respond quickly in the event of an incident and demonstrates your seriousness to a client or an insurer. And if part of your activity falls under GDPR, this document becomes necessary anyway.
What should you do in practice?
The good news is that both regimes expect the same substantive measures. Here is the most effective order to follow.
- Determine your situation. Are you actively targeting the European market, or do you work only in Switzerland? The “am I affected by the FADP?” test places you in a few questions.
- Get compliant with the FADP first. It applies in all cases and covers most of what is expected.
- If GDPR also applies, align yourself with whichever text is stricter on each point: the 72-hour deadline, the lower reporting threshold, the register.
- Write down your procedure in case of a breach. Who decides, who reports, in what order. This is the document that makes the difference on the day it matters.
- Secure access to your data. Two-factor authentication, removing the accounts of departed employees, tested backups.
One last word of caution: this article provides general guidance and does not replace an analysis of your specific situation. Mixed cases, activities partly directed at Europe, and data transfers abroad deserve the opinion of a specialised lawyer.
To place your company in three minutes, the cyber check-up gives you a score and your three priorities. The other obligations applicable to Swiss businesses are grouped in the Regulations pillar.