Swiss nFADP Compliance Consulting

September 25, 2026

Swiss organizations and international companies handling personal data connected to Switzerland face a practical challenge: understanding what the revised Federal Act on Data Protection requires and translating those obligations into workable business processes. The revised Swiss Federal Act on Data Protection, commonly referred to as the nFADP or revised FADP, has applied since 1 September 2023 and places stronger emphasis on transparency, risk management, data security, governance, and the rights of individuals.

Swiss nFADP Compliance Consulting helps organizations assess how their current data-processing activities align with Swiss data protection requirements, identify compliance gaps, and establish proportionate measures for managing privacy risks. The objective is not simply to produce documentation, but to connect legal requirements with actual systems, suppliers, workflows, employees, and business decisions.

Organizations looking for broader privacy support can also review E-Privacy Company’s privacy and data protection services, including assessments, implementation support, DPIA services, DPO services, and Privacy by Design.

What nFADP Compliance Requires in Practice

The revised FADP is designed to protect the personality and fundamental rights of individuals whose personal data is processed. For organizations, compliance therefore involves more than publishing a privacy notice. Businesses need to understand what personal data they hold, why it is processed, who receives it, where it is stored, how long it is retained, and what safeguards protect it.

Transparency and information obligations

Under the revised FADP, controllers are generally required to provide appropriate information when personal data is collected. The Federal Data Protection and Information Commissioner guidance on the duty to provide information explains that individuals should receive information about processing in a concise, transparent, clear, and accessible way.

For businesses, this can require reviewing privacy notices, online forms, customer onboarding processes, employee documentation, supplier arrangements, and other situations where personal information is collected.

Records of processing and data governance

Understanding data flows is a central part of practical compliance. Organizations should identify processing activities, responsible departments, categories of personal data, recipients, systems, retention practices, international transfers, and security controls.

Private organizations with more than 250 employees are generally required to maintain a register of processing activities. Smaller organizations may also fall within the record-keeping requirement when they process sensitive personal data on a large scale or carry out high-risk profiling. Even where an exemption applies, other FADP obligations remain relevant.

A structured privacy review can help determine which requirements apply to the organization and where documentation or processes need improvement. E-Privacy Company’s privacy scans and audits can support organizations that need a clearer picture of their existing privacy framework and compliance maturity.

Data protection by design and by default

Privacy should also be considered when new systems, services, products, applications, or processing activities are designed. Rather than correcting privacy weaknesses after implementation, organizations can evaluate data collection, access controls, retention periods, user rights, security measures, and sharing arrangements during the design process.

This approach can reduce unnecessary data collection and make compliance requirements easier to integrate into normal development and operational workflows. Organizations introducing new technology can consider Privacy by Design support as part of that process.

How Swiss nFADP Compliance Consulting Works

An effective consulting engagement should begin with the organization’s actual processing environment rather than a generic compliance checklist. Different businesses face different privacy risks depending on their industry, technology, data categories, geographic reach, suppliers, and processing scale.

1. Establishing the scope

The first step is identifying which entities, systems, departments, products, services, and processing operations should be reviewed. This helps distinguish Swiss FADP obligations from other regulatory requirements that may also apply, such as the EU GDPR.

2. Mapping personal data and processing activities

The organization then needs a practical understanding of its data lifecycle. Typical questions include what information is collected, where it originates, the purpose of processing, which employees or vendors have access, whether data leaves Switzerland, and when it is deleted.

This stage often reveals undocumented processing activities, outdated retention practices, unclear vendor responsibilities, or inconsistent privacy notices.

3. Assessing compliance gaps and risks

Existing practices can then be evaluated against applicable nFADP requirements. Areas commonly reviewed include transparency, processor arrangements, information security, data subject rights, international disclosures, records of processing, retention, breach procedures, and governance responsibilities.

The assessment should distinguish between legal requirements, regulatory guidance, organizational risk decisions, and optional good practices. Not every organization requires the same controls.

4. Reviewing high-risk processing

When planned processing is likely to result in a high risk to the personality or fundamental rights of individuals, a data protection impact assessment may be required. According to the FDPIC guidance on Data Protection Impact Assessments, a DPIA should describe the planned processing, evaluate its risks, and identify measures for protecting affected individuals.

High-risk situations may involve factors such as new technologies, large-scale processing of sensitive personal data, or systematic large-scale monitoring of public areas. The requirement should therefore be assessed based on the specific processing activity rather than assumed automatically.

5. Building a practical remediation plan

Once gaps are identified, the organization can prioritize improvements based on regulatory relevance, privacy risk, operational impact, and available resources. Actions may include updating privacy notices, improving processing records, reviewing processor agreements, introducing retention rules, strengthening access controls, improving internal procedures, or establishing a formal review process for new projects.

A realistic implementation plan is usually more valuable than a long list of theoretical compliance requirements because responsibilities, priorities, and expected outcomes can be assigned to specific teams.

Example: a company expanding into Switzerland

Consider a European software company preparing to offer its platform to customers in Switzerland. The company already maintains a GDPR compliance program, but assumes that its existing documentation automatically satisfies every Swiss requirement.

A Swiss privacy review may examine how customer and employee data is collected, whether Swiss-facing privacy information is adequate, how processors are managed, whether international transfers are documented, whether the company needs a representative in Switzerland, and whether planned analytics or monitoring activities create additional risk.

For certain foreign controllers, Article 14 FADP can require the appointment of a representative in Switzerland when several statutory conditions are met, including processing connected with offering goods or services or monitoring behaviour in Switzerland, large-scale and regular processing, and a high risk to affected individuals. The FDPIC guidance on Swiss representatives provides further detail on these conditions.

The value of the assessment is not simply identifying whether a requirement exists. It is determining how that requirement affects the company’s actual operations and what proportionate steps should follow.

Building Sustainable nFADP Compliance

Data protection compliance should not be treated as a one-time documentation project. Processing activities change when companies introduce new software, adopt AI tools, engage new processors, expand into new markets, restructure operations, or collect additional categories of personal information.

A sustainable approach therefore combines documented policies with operational ownership. Privacy responsibilities should be assigned, new projects should trigger appropriate privacy reviews, vendor changes should be assessed, and employees should understand when privacy specialists need to be involved.

Prepare for data security incidents

Organizations should also maintain procedures for detecting, assessing, documenting, and escalating data security incidents. Under Article 24 FADP, controllers must notify the FDPIC as soon as possible when a personal data breach is likely to result in a high risk to the personality or fundamental rights of affected individuals. The FDPIC DataBreach guidance also explains when affected individuals may need to be informed.

A practical incident process should define who receives internal reports, who evaluates risk, what information must be collected, who makes notification decisions, and how actions are documented.

Align privacy with business processes

The most useful privacy programs connect legal requirements with normal business operations. Procurement can include processor checks, product development can include Privacy by Design reviews, HR can maintain appropriate employee privacy documentation, IT can implement technical safeguards, and management can monitor significant privacy risks.

Organizations seeking help evaluating these areas can contact E-Privacy Company to discuss their privacy environment and determine which type of assessment or implementation support is relevant.

Conclusion: Swiss nFADP compliance requires organizations to understand their processing activities, assess applicable obligations, manage privacy risks, and keep controls aligned with operational changes. A structured consulting approach can help translate the legal framework into specific actions while avoiding both unnecessary controls and overlooked obligations.

Frequently Asked Questions

What is Swiss nFADP Compliance Consulting?

Swiss nFADP Compliance Consulting is professional support for organizations assessing and improving their alignment with Switzerland’s revised Federal Act on Data Protection. It can include privacy assessments, data mapping, documentation reviews, risk analysis, governance improvements, and implementation support.

Is the nFADP the same as the GDPR?

No. Switzerland’s FADP and the EU GDPR are separate legal frameworks. They share several concepts and privacy principles, but their specific requirements, terminology, enforcement mechanisms, and applicability rules are not identical. Organizations operating under both frameworks should evaluate each separately.

Do foreign companies have to comply with the Swiss FADP?

The FADP can apply to organizations outside Switzerland depending on their processing activities and their connection with individuals in Switzerland. Additional obligations, such as appointing a Swiss representative, apply only when specific legal conditions are met.

Does every company need a Data Protection Impact Assessment under the nFADP?

No. A DPIA is required when planned data processing is likely to result in a high risk to the personality or fundamental rights of affected individuals. The nature, scope, circumstances, purpose, technology, and type of data processed should be considered when assessing that risk.

How often should an organization review nFADP compliance?

There is no single review interval suitable for every organization. Privacy controls should be reassessed when processing activities, technologies, suppliers, risks, or business models materially change. Periodic privacy audits can also help identify documentation and implementation gaps that develop over time.

Can nFADP consulting guarantee compliance?

No consulting service can guarantee a particular regulatory outcome. Professional privacy support can help organizations understand applicable requirements, identify risks, improve documentation and controls, and make more informed compliance decisions based on their specific circumstances.

Page top