Switzerland's revised Federal Act on Data Protection is the modernised privacy law governing how personal data is collected, used, disclosed, and safeguarded. It strengthens organisational obligations, expands individual rights, and introduces clearer requirements for breach notification, impact assessments, and cross-border transfers.
What the revised FADP changes
Switzerland’s revised Federal Act on Data Protection is a modernised privacy law, but its practical significance is that it raises the bar for accountability. Organisations need clearer lawful handling, tighter documentation, and a more disciplined approach to personal-data governance.
The revision matters because it shifts privacy from a narrow compliance exercise to an operational control layer. In practice, teams must understand what data they hold, why they process it, who receives it, and whether safeguards match the sensitivity and transfer context.
Core obligations under the revised law
The revised FADP strengthens several obligations that are common pressure points in privacy programmes. These include transparency duties, breach handling, data minimisation, retention discipline, and attention to cross-border disclosures.
It also gives greater weight to impact assessment thinking for higher-risk processing. That makes the law less about one-time policy drafting and more about ongoing decision-making around data flows, vendors, systems, and change management.
Individual rights and organisational accountability
For individuals, the law expands the practical ability to understand and challenge how personal data is used. For organisations, that means requests and disclosures must be traceable, consistent, and supportable rather than handled ad hoc.
Accountability is the deeper theme. The revised FADP expects organisations to be able to explain their processing choices, justify safeguards, and show that privacy is built into operational controls rather than retrofitted after a complaint or incident.
How to interpret the law in security terms
The revised FADP is not only a privacy statute; it is also a security governance signal. Security teams, legal teams, and data owners need a shared view of where personal data lives, how it moves, and which controls protect it across the lifecycle.
That is why privacy compliance often intersects with access control, logging, retention, vendor oversight, and transfer assessments. GDPR is a useful comparison point because it shows how modern privacy regimes increasingly combine legal rights with operational safeguards.
Risk and Threat Considerations
Revised privacy laws create risk when organisations cannot evidence what personal data they process, where it travels, or who can access it. The biggest exposure is usually not the law itself, but the gap between stated privacy controls and actual operating practice.
Failure mechanism: Weak inventory, poor access discipline, or unmanaged third-party transfers can turn routine processing into a breach, unlawful disclosure, or non-compliant cross-border transfer.
Impact: The result can be regulatory action, forced remediation, loss of trust, and a wider operational cleanup when data flows, retention rules, or notification workflows are not fit for purpose.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while GDPR defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art.5 — Processing principles | Modern privacy law with shared processing principles and accountability duties |
| Art.25 — Data protection by design and by default | Matches the revised FADP's emphasis on built-in privacy safeguards | |
| Art.32 — Security of processing | Supports the need for security controls protecting personal data in transit and storage | |
| Recommendation — Align personal-data processing with lawfulness, minimisation, and purpose limitation. Build privacy safeguards into systems and defaults before processing starts. Apply appropriate technical and organisational measures to protect personal data. | ||
| NIST CSF 2.0 | GV.OC-03 — Legal and regulatory requirements | Connects privacy obligations to governance and compliance oversight |
| PR.DS-01 — Data-at-rest is protected | Relevant to safeguarding personal data covered by the revised FADP | |
| Recommendation — Track applicable privacy obligations and embed them in governance decisions. Protect stored personal data with controls that match sensitivity and exposure. | ||
Practitioner Guidance
What to watch for: Treat the revised FADP as a trigger to verify ownership of personal-data processing, not just to update legal text. The most common failure is assuming a policy exists when the underlying systems, vendors, and workflows still behave differently.
Practitioner takeaway: Privacy compliance is strongest when records, controls, and escalation paths are aligned, because that is what lets an organisation explain and defend its processing decisions under scrutiny.
Related resources from NHI Mgmt Group
- How should organisations adapt their privacy programme to the revised FADP when they handle Swiss personal data?
- Why does the revised FADP create higher governance pressure for companies processing personal data in Switzerland?
- What do organisations get wrong about breach notification and accountability under the revised FADP?
- What is the difference between the revised FADP and GDPR on data breach timing and sanctions?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org