Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Revised FADP

← Back to Glossary
By NHI Mgmt Group Updated September 30, 2026 Domain: Governance, Ownership & Risk

Switzerland's revised Federal Act on Data Protection is the modernised privacy law governing how personal data is collected, used, disclosed, and safeguarded. It strengthens organisational obligations, expands individual rights, and introduces clearer requirements for breach notification, impact assessments, and cross-border transfers.

What the revised FADP changes

Switzerland’s revised Federal Act on Data Protection is a modernised privacy law, but its practical significance is that it raises the bar for accountability. Organisations need clearer lawful handling, tighter documentation, and a more disciplined approach to personal-data governance.

The revision matters because it shifts privacy from a narrow compliance exercise to an operational control layer. In practice, teams must understand what data they hold, why they process it, who receives it, and whether safeguards match the sensitivity and transfer context.

Core obligations under the revised law

The revised FADP strengthens several obligations that are common pressure points in privacy programmes. These include transparency duties, breach handling, data minimisation, retention discipline, and attention to cross-border disclosures.

It also gives greater weight to impact assessment thinking for higher-risk processing. That makes the law less about one-time policy drafting and more about ongoing decision-making around data flows, vendors, systems, and change management.

Individual rights and organisational accountability

For individuals, the law expands the practical ability to understand and challenge how personal data is used. For organisations, that means requests and disclosures must be traceable, consistent, and supportable rather than handled ad hoc.

Accountability is the deeper theme. The revised FADP expects organisations to be able to explain their processing choices, justify safeguards, and show that privacy is built into operational controls rather than retrofitted after a complaint or incident.

How to interpret the law in security terms

The revised FADP is not only a privacy statute; it is also a security governance signal. Security teams, legal teams, and data owners need a shared view of where personal data lives, how it moves, and which controls protect it across the lifecycle.

That is why privacy compliance often intersects with access control, logging, retention, vendor oversight, and transfer assessments. GDPR is a useful comparison point because it shows how modern privacy regimes increasingly combine legal rights with operational safeguards.

Risk and Threat Considerations

Revised privacy laws create risk when organisations cannot evidence what personal data they process, where it travels, or who can access it. The biggest exposure is usually not the law itself, but the gap between stated privacy controls and actual operating practice.

Failure mechanism: Weak inventory, poor access discipline, or unmanaged third-party transfers can turn routine processing into a breach, unlawful disclosure, or non-compliant cross-border transfer.

Impact: The result can be regulatory action, forced remediation, loss of trust, and a wider operational cleanup when data flows, retention rules, or notification workflows are not fit for purpose.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt.5 — Processing principlesModern privacy law with shared processing principles and accountability duties
Art.25 — Data protection by design and by defaultMatches the revised FADP's emphasis on built-in privacy safeguards
Art.32 — Security of processingSupports the need for security controls protecting personal data in transit and storage
Recommendation — Align personal-data processing with lawfulness, minimisation, and purpose limitation. Build privacy safeguards into systems and defaults before processing starts. Apply appropriate technical and organisational measures to protect personal data.
NIST CSF 2.0GV.OC-03 — Legal and regulatory requirementsConnects privacy obligations to governance and compliance oversight
PR.DS-01 — Data-at-rest is protectedRelevant to safeguarding personal data covered by the revised FADP
Recommendation — Track applicable privacy obligations and embed them in governance decisions. Protect stored personal data with controls that match sensitivity and exposure.

Practitioner Guidance

What to watch for: Treat the revised FADP as a trigger to verify ownership of personal-data processing, not just to update legal text. The most common failure is assuming a policy exists when the underlying systems, vendors, and workflows still behave differently.

Practitioner takeaway: Privacy compliance is strongest when records, controls, and escalation paths are aligned, because that is what lets an organisation explain and defend its processing decisions under scrutiny.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org